IT Audit · Cybersecurity · Governance

Assuring Technology, Security
& Sustainable Transformation.

Techno Consulting and Management (TCM) helps boards, executives, and IT leaders strengthen their IT governance, control environment, and cyber resilience through independent assurance and pragmatic advisory.

  • 20+ years in IT audit, risk, cybersecurity, and enterprise architecture across financial services, telecoms, public sector, healthcare, and infrastructure.
  • Deep experience with ITGC, application controls, ISAE 3402, SAP and ERP environments, and data analytics / automation.
  • Experience across large, complex organisations in sectors such as financial services, telecommunications, state-owned entities, and critical infrastructure in Southern Africa.
At a Glance
20+
Years of Collective Experience
TCM brings together extensive experience across IT audit, risk mgt, cybersecurity, and digital transformation — supporting organisations in complex technology landscapes.
Credentials
Professional Certifications
TCM draws on a network of certified professionals — including CISA, CRISC, CGEIT, CISSP, ISO 27001 Lead Auditor, cloud and cybersecurity specialists — ensuring depth across all engagements.
ITGC & Application Controls Cybersecurity Assessments ISAE 3402 & Third-Party Assurance Enterprise Architecture Advisory

TCM combines board-level insight, technical depth, and hands-on audit experience to help organisations ensure their IT environments are secure, well-controlled, and aligned with business strategy.

What We Do

Specialised IT Audit & Consulting Services

We provide independent assurance and practical advisory across IT governance, cybersecurity, enterprise architecture, and data-driven risk management.

Assurance
IT General Controls & Application Controls Review

Design and operating effectiveness reviews over ITGCs and application controls across ERP, SAP, databases, and infrastructure—aligned to financial reporting and regulatory requirements.

  • ITGC over access, change, and operations
  • Application controls over key financial processes
  • IT assurance support for internal and external audit
🔒
Cybersecurity
Cybersecurity Assessments & Vulnerability Reviews

Independent assessments of cyber posture, including vulnerability reviews, configuration checks, and governance analysis to strengthen prevention, detection, and response capabilities.

  • Vulnerability & configuration assessments
  • Cyber governance & policy gap analysis
  • Remediation roadmaps and quick-win controls
🏛
Governance
IT Governance, GRC & ISAE 3402 Support

Design, assess, or uplift IT governance frameworks and GRC practices, with specialist support for ISAE 3402 readiness and third-party assurance engagements.

  • COBIT-aligned governance reviews
  • IT risk & control assessments
  • ISAE 3402 Type I & II support for service providers
📐
Architecture
Enterprise & Solution Architecture Advisory

Assessment of architecture, data flows, and control implications to ensure secure, scalable, and well-governed technology landscapes that support strategic objectives.

  • Architecture risk & control impact assessment
  • Technology roadmap & solution reviews
  • Architecture alignment to governance frameworks
📊
Analytics
Data Analytics, Automation & CAATs

Using ACL, IDEA, Python, and BI tools to automate control testing, enhance sample coverage, and surface anomalies that traditional approaches often miss.

  • Automated ITGC & application control testing
  • Fraud and anomaly detection analytics
  • Dashboarding and continuous monitoring enablement
🤝
Advisory
IT Strategy, Service Provider & Post-Implementation Reviews

Pragmatic advisory on IT strategy, sourcing and transitions, and post-implementation reviews to ensure solutions deliver value, manage risk, and integrate into governance structures.

  • IT strategy formulation and alignment
  • IT service provider capability and transition reviews
  • Post-implementation & project assurance reviews
Who We Serve

Industry Sectors

TCM brings cross-industry insight and regulatory awareness from engagements with large and mid-sized organisations across the region.

  • Financial Services & Banking
  • Telecommunications & Technology
  • Public Sector & State-Owned Entities
  • Healthcare & Medical Schemes
  • Infrastructure, Transport & Utilities
  • Education & Research
  • Outsourced Service Providers & Shared Services
Industry Experience
Cross-sector assurance and advisory

TCM has delivered ITGC, cybersecurity, and governance-related work across organisations that:

  • Operate complex ERP, SAP, and line-of-business applications supporting critical financial and operational processes.
  • Manage high-availability networks, data centres, and cloud environments for national or regional operations.
  • Are subject to public interest oversight, regulatory scrutiny, or external audit by supreme audit institutions or regulators.
  • Rely on multiple third-party providers and shared services to deliver key technology capabilities.

This industry breadth enables TCM to anticipate typical control gaps, benchmark maturity, and propose pragmatic improvements that fit real-world constraints and budgets.

How We Work

A Structured Yet Pragmatic Approach

Our approach blends formal audit methodology with collaborative engagement, ensuring insight that is technically sound, risk-focused, and actionable for management.

01
Discover & Align

Clarify business strategy, regulatory drivers, and stakeholder expectations. Define scope, material risks, and success measures upfront to ensure focused, value-adding work.

02
Assess & Test

Perform ITGC and application control testing, cybersecurity assessments, and analytics-driven procedures using proven methodologies and CAATs to validate design and operating effectiveness.

03
Interpret & Prioritise

Translate technical findings into business impact, focusing on root causes, control themes, and prioritised remediation that balances risk reduction, cost, and complexity.

04
Partner & Embed

Support management in defining remediation plans, strengthening governance structures, and embedding practices that sustain control effectiveness and resilience over time.

Frameworks & Standards
Aligned to recognised best practice

TCM’s work is informed by globally recognised frameworks and standards, including:

  • COBIT-based IT governance and control principles
  • ISAE 3402 for service-organisation assurance
  • ISO 27001 and NIST Cybersecurity Framework guidance
  • Leading practice internal audit methodologies

This ensures that recommendations are defensible, audit-ready, and aligned with board and regulator expectations.

About TCM

Led by Tapuwa Makowe

Techno Consulting and Management is led by Founder and Principal Consultant, Tapuwa Makowe, a CISA-certified IT audit and cybersecurity specialist with a Master of Information Technology and over two decades of experience in IT governance, risk management, and digital transformation.

TCM draws on Tapuwa’s experience leading complex ITGC, ERP, cybersecurity, and architecture-related engagements for large organisations across financial services, telecommunications, public sector, and infrastructure. This includes working with audit committees, executive teams, internal audit functions, and technology leadership.

Since 2019, TCM has operated as an independent IT audit and advisory practice, providing organisations with senior-level attention, structured methodologies, and practical support to strengthen IT governance, controls, and cyber resilience.

Certified Information Systems Auditor (CISA) Master of Information Technology ERP & SAP Environment Expertise Generative AI & Innovation Speaker
Why Organisations Choose TCM
Independent, experienced, and hands-on
  • Direct senior-level involvement from scoping through to reporting.
  • Balanced perspective across IT, finance, risk, and operations.
  • Ability to translate complex technology topics into clear messages for boards and executives.
  • Focus on practical, prioritised recommendations—not just long issue lists.

TCM operates as a trusted partner, invested in helping organisations build a resilient, well-governed, and future-ready technology landscape.

Insights

Perspectives on Risk, Technology & Governance

Use this space to share articles, thought leadership, or case studies on IT audit, cybersecurity, and digital governance.

Thought Leadership
From Controls to Confidence

How risk-focused ITGC and application control reviews can move organisations beyond compliance to genuine assurance and resilience.

Coming soon – article link or PDF.

Cybersecurity
Prioritising Cyber Controls That Matter

A practical approach to focusing cyber investments on controls with measurable impact on threat reduction and incident response maturity.

Use this block for blogs, webinars, or speaking engagements.

Digital Transformation
Embedding Governance in Architecture

Why enterprise and solution architecture should be treated as a governance asset, not just a technical diagram.

Add case studies or client stories here.

Contact

Let’s Discuss Your IT Risk & Assurance Needs

Share a brief overview of your environment, challenges, or upcoming audit, and we’ll respond with proposed next steps for a structured engagement.

Email: tapuwa@tcmgt.co.za

Mobile: +27 82 818 2898

Location: Gauteng, South Africa

LinkedIn: Tapuwa Makowe


Prefer a structured briefing? We can provide a short pre-read outlining our methodology, industry experience, and proposed engagement model ahead of a workshop or audit.

TCM ©
TCM ©