Skip to content

The firm

Technology professionals who spent their careers on the other side of the audit.

Rosewood is an independent technology risk and assurance practice based in Nairobi. We are small on purpose: the people who scope the work are the people who do it.

11

African markets

6

professional certifications held

4

client sectors served

2016

practising since

What we do

Where the experience comes from.

The facts, unembellished.

Rosewood was founded by technology professionals with risk and technology management experience across eleven African markets — Kenya, Uganda, Tanzania, Zimbabwe, Mauritius, Rwanda, Egypt, Zambia, Ghana, South Africa and Mozambique.

The team holds local and international qualifications across the spectrum of technology and its risk: qualified information risk managers, IT system auditors (CISA), information security specialists (CEH), and system management practitioners (CISM, ITIL). Qualified accountants — CPA and ACCA — sit inside the team rather than beside it, which is why our findings survive contact with finance and audit.

That mix gives us an in-depth understanding of the strategic, operational and technology management issues facing leading financial service providers, telcos, international development agencies and NGOs.

We consider the team’s experience vital in contextualising the working realities and operating challenges that face organisations. A control that cannot be operated on a Tuesday afternoon in a branch is not a control.

Qualifications in the team

  • CISA IT system audit

    Certified Information Systems Auditor

  • CEH Information security

    Certified Ethical Hacker

  • CISM System management

    Certified Information Security Manager

  • ITIL System management

    ITIL service management

  • CPA Finance and audit

    Certified Public Accountant

  • ACCA Finance and audit

    Chartered Certified Accountant

These are individual credentials held by team members, not accreditations held by the firm. We name the difference because a firm that advises on assurance should.

How we hold ourselves

Principles, in the operational sense.

Four commitments that decide what we will and will not do on an engagement.

  1. 01

    Independence is the product

    We do not sell the technology we assure, and we do not resell anyone else’s. If a finding points at a vendor, nothing about our position changes.

  2. 02

    Findings are ranked by consequence

    A report with forty findings and no order is a report that has moved the work back to you. We say which three matter this quarter and why.

  3. 03

    We test what people actually do

    Documented procedure and real practice diverge everywhere. The second one carries your risk, so it is the one we test against.

  4. 04

    Nothing is closed until it is retested

    A ticket marked done is not evidence. We retest, confirm in writing, and leave the evidence in your file for whoever asks next.

Footprint

Eleven markets.

Work delivered from Nairobi and on site across the region.

Outline map of Africa marking the eleven markets in which the Rosewood team has worked.

Eleven markets, one team. Work is delivered from Nairobi and on site, which keeps engagement costs closer to a local rate than a fly-in one.

Clients

Who we work with.

Where the team’s sector understanding sits.

  • 01

    Leading financial service providers

  • 02

    Telcos

  • 03

    International development agencies

  • 04

    NGOs

Working together

We will tell you when we are not the right firm.

If the work needs a capability we do not have, or a conflict makes us the wrong choice, you will hear that on the first call rather than in month three.

Start a conversation

+254 721 687846 taarifa@techrisk.co.ke