Overview

What do business and risk advisory services cover?

Business and risk advisory services are project engagements that sit outside the monthly compliance cycle: building a risk register and control framework, modelling scenarios, planning business continuity, valuing shares for a transaction or a tax event, and redesigning how the finance function itself works.

Most accounting firms stop at compliance. Books closed, tax filed, statutory accounts lodged: see you next year. For SMEs facing scale, regulation, capital raises or transactions, that's not enough. The work that determines whether a business survives a bad quarter, defends a valuation, or passes regulator scrutiny is strategic and risk-oriented, and it's the work we live for.

Our business and risk advisory scope covers strategic financial advisory (forecasting, scenario modelling, capital allocation), enterprise risk management (risk register, control framework, business continuity), valuation (for fundraising, M&A or internal share schemes), and operational consultancy (process re-engineering, finance-function design, system selection).

Engagement is typically project-based: a six-week sprint to build a risk register, a three-month engagement to design controls, a one-off valuation for a tax event. Some clients retain us on an ongoing advisory cadence; others use us for specific decisions and return when the next big question lands.

Where our advisory work touches on regulated activities (investment advice, audit) we coordinate with appropriately-licensed partners, but the substantive analysis, modelling and recommendations are ours.

A risk register is only useful when it is specific enough to argue with. Each entry names the risk, scores likelihood and impact on a fixed scale, names one accountable owner (a person, not a department), states the control already in place, then scores the residual risk after that control. The register is reviewed quarterly and anything scored high with no dated mitigation goes to the board as an exception. Registers that list "cyber attack" and "key person risk" with no owner and no score are decoration.

The internal controls that matter most in a business under 100 people are unglamorous and cheap:

  • Dual authorisation on payments above a stated threshold, with the threshold written down.
  • Bank payee changes verified by a call to a number you already held, not one on the email.
  • Supplier onboarding separated from payment approval, so one person cannot create and pay a vendor.
  • Monthly reconciliation reviewed by someone other than the preparer.
  • Access rights removed on the leaver checklist, on the leaving date.
  • A payroll change log reviewed against the pay run before it is approved.

Business continuity planning turns on two numbers per critical process: how long you can be down (recovery time) and how much data you can afford to lose (recovery point). Once those are agreed, most of the plan writes itself, because the numbers decide whether a nightly backup is adequate or whether you need a warm standby. The test is not the document. It is whether someone who is not the finance director can run the payroll in the week the finance director is unreachable.

Valuation work is usually driven by an event with a deadline. A share valuation agreed with HMRC for an EMI option grant holds for a limited window, so the grants have to be made inside it or the exercise starts again. A transaction valuation needs a defensible method (earnings multiple, discounted cash flow, or net asset, and usually more than one as a cross-check) with the assumptions stated so a buyer can test them rather than dismiss them.

A worked example of scenario modelling. A business with £4.2m of revenue and a 21 percent net margin models three cases: base, a 15 percent revenue fall, and the loss of its largest customer at 18 percent of revenue. The third case turns net margin negative in month two, not month five, because two thirds of the cost base is fixed inside a quarter. That single finding changes the contract renewal strategy and the notice periods on two supplier agreements. The model is worth more than the forecast.

This work assumes reliable numbers underneath it, which is why it pairs with monthly management accounts and, where the engagement is continuous rather than project-based, with fractional CFO services. Control frameworks built here feed directly into audit and SOC readiness work, and governance documentation into company secretarial support. Most of our valuation and option-scheme work comes from VC-backed startups. Retainer and project fee bands are on the fixed-fee pricing page. Advisory projects are quoted separately from the retained work in our accounting and tax services directory.

What you get

What advisory engagements cover.

Specific, scoped, time-bound projects with clear deliverables.

  • Strategic financial forecasting3- to 5-year financial models, scenario-tested, defensible. Used for board strategy, fundraising prep, capital-allocation decisions and acquisition planning.
  • Risk register & ERM framework Enterprise risk identification, scoring, ownership and mitigation tracking. Reviewed quarterly with the leadership team.
  • Internal control design Process maps, segregation of duties, approval matrices, audit trails. Suitable for SOC 2 readiness or simply preventing the kind of slip that triggers regulator scrutiny.
  • Business continuity & resilience Continuity plans, disaster-recovery procedures, key-person risk mitigation. Documented to a standard auditors and insurers expect.
  • Business valuation For fundraising, internal share schemes, EMI exercises, divorce settlements or shareholder buyouts. Multiple methodologies applied where defensible.
  • Process & system selection When you're selecting a new ERP, payroll system, HRIS or CRM, we provide vendor-neutral selection advice and post-implementation review.
  • Pricing & unit economics Customer-level margin analysis, pricing-elasticity studies, gross-margin decomposition. The analytical work pricing decisions should be grounded in.
  • M&A & transaction support Buy-side and sell-side. Working-capital adjustments, quality-of-earnings, financial model build, integration planning.
How we work

How advisory engagements run.

Discovery → diagnostic → recommendation → implementation support.

STEP 01

Scoping call

Sixty minutes to define the problem, agreed deliverables, timeline and fee. No engagement until you accept a written scope.

STEP 02

Diagnostic

Two-week deep dive. Existing data, processes and decisions reviewed. Stakeholder interviews. State-of-play documented.

STEP 03

Recommendation phase

Analysis, modelling and written recommendations produced. Reviewed with leadership. Iterated until decisions can be made on the back of them.

STEP 04

Implementation support

Where you want it: ongoing support during implementation, training of internal teams, refresh cycles built into a retainer.

STEP 05

Review & refresh

Most advisory deliverables (risk registers, forecasts, valuations) need annual or quarterly refresh. We schedule and resource that.

"They built our risk register and control framework ahead of a Series B. The lead investor told us afterwards that our governance materials were the cleanest they'd seen at our stage. Worth every penny."
C
CEO · Health-tech scaleupLondon & Boston
Engagement shapes

How long each advisory project runs, and what it leaves behind

These are project engagements priced per piece of work rather than per month. The lengths are typical scoping ranges shown for illustration, agreed in writing before anything starts.

How long each advisory project runs, and what it leaves behind
EngagementTypical lengthWhat you are left holdingWhat usually triggers it
Risk register buildSix weeksA scored register with one named owner and a residual score per riskA board, lender or insurer asks to see one
Internal control designThree monthsA control framework, written authorisation thresholds and a segregation of duties mapA near miss, an attempted payment fraud, or a first external audit
Business continuity planFour to six weeksRecovery time and recovery point targets per critical process, and a run book somebody outside finance has testedA customer contract or an insurer requires it
ValuationTwo to four weeksA written valuation with the method and assumptions statedA share issue, a buyback, an option scheme or a tax event
Scenario and forecast modelFour to eight weeksA driver based model with downside cases that hold togetherA raise, a facility renewal or a large capital decision
Finance function redesignThree monthsA process map, a system selection and a target operating modelGrowth has outrun the setup that got you here

Common questions about advisory work.

Is this different from CFO-as-a-Service?
One finishes and one does not. Advisory work is scoped against a named deliverable and signed off against an output, so it has an end date on it from the start. A CFO retainer buys a seat at the table and carries into the following month by design. The mistake we see is buying a project when what is missing is somebody owning the numbers between board meetings. Many clients run both.
How are engagements priced?
Project-based, quoted upfront. A risk register build is typically £8k–£15k. A 5-year strategic forecast £6k–£12k. Business valuation £3k–£10k depending on complexity. We send a written scope and fee before any work begins.
Can you give investment advice?
Modelling whether the business can afford a capital commitment, or what a purchase does to covenants and cash, is analysis, and that part we do. Naming the fund or product you should hold is a personal recommendation, which is regulated. Directors asking where personal surplus should sit get referred out. Where a conversation drifts across that line we stop and say so.
Do you do business valuations for tax purposes?
Yes: valuations for EMI exercises, growth-share schemes, BADR claims, IHT planning and divorce proceedings are within scope. We document methodologies that withstand HMRC scrutiny.
How do you handle confidential M&A work?
Mutual NDAs in place before sensitive information is shared. Project teams are siloed from regular accounting teams where required. Document handling follows the same SOC 2 protocols as the rest of our engagements.
What does a risk register engagement actually deliver?
A scored register with a named owner per line, a control description and a residual score, plus a one-page board summary of everything still rated high after existing controls. Typically six weeks: two weeks of interviews across the business, two weeks drafting and challenge, one week of scoring workshops, one week to finalise. You get the working file, not a locked PDF, because the register has to be maintained after we leave.
Do you build three-way financial models?
Profit and loss, balance sheet and cash flow are linked, so the model balances and the cash line is derived rather than typed. That matters because an unlinked model can show profit and hide a working capital hole. We build them for fundraising, bank facilities and internal planning, and we hand over the file with the assumptions on a separate input sheet.
Related

Often paired with advisory.

ADVISORY

CFO-as-a-Service

Ongoing strategic leadership alongside project work.

Explore
ASSURANCE

Audit & assurance

Internal audit and SOC readiness as part of risk programmes.

Explore
REPORTING

Management accounts

The monthly numbers underpinning strategic decisions.

Explore
SECTOR

Startup accounting

Valuations, option schemes and investor-grade modelling.

Explore
GOVERNANCE

Company secretary

Governance documentation behind the control framework.

Explore
MARKET

UK accounting services

Where the UK regulatory and filing obligations sit.

Explore
Strategic engagements

Have a strategic project on your plate?

Thirty minutes to define the scope. Fixed-fee proposal within 24 hours.