UHUBS POLICY

Audit & Assurance Policy

Last reviewed on 30 October 2025
This document outlines Uhubs Audit & Assurance Policy. It covers compliance verification, risk analysis, risk identification, escalation of known risks, correcting risks, audit management process, advisory board and independent guidance, and continuous improvement. The policy emphasizes regular checks, documentation, reporting, risk assessments, incident reporting, corrective actions, audit planning, conclusion and report generation, and engagement with an advisory board for feedback and guidance.

1. Compliance Verification

1.1 Legal and Tech Team Responsibilities

Our teams will regularly conduct thorough checks to verify compliance with relevant standards, regulations, legal/contractual, and statutory requirements. This includes staying updated on changes in the regulatory landscape and ensuring Uhubs adherence.

1.2 Frequency of Compliance Checks

These compliance checks will be conducted on a regular basis, ensuring that Uhubs remains in alignment with the latest industry standards and legal obligations.

1.3 Documentation and Reporting

The results of compliance checks will be documented, and reports will be generated for internal review and reference. Any deviations from compliance standards will be documented with details of corrective actions.

2. Risk Analysis

2.1 Methodology

Uhubs will conduct comprehensive risk analyses to identify potential threats and vulnerabilities within our operational framework.

2.2 Risk Classification

Identified risks will be classified based on their potential impact, likelihood of occurrence, and the level of control in place.

3. Identifying Risks

3.1 Regular Assessments

Regular internal assessments will be conducted to identify risks associated with data security, operational integrity, and compliance.

3.2 Incident Reporting

Employees are expected to report any incidents or potential risks promptly through established channels.

4. Escalation of Known Risks

4.1 Escalation Procedure

If a known risk is deemed significant, the escalation process will be initiated. This involves notifying relevant stakeholders, including senior management and legal advisors. Impacted clients will also be notified.

4.2 Evaluation of Severity

The severity of each identified risk will be evaluated, considering its potential impact on operations, compliance, and data security.

5. Correcting Risks

5.1 Risk Mitigation Plans

Uhubs will establish risk mitigation plans outlining specific actions to correct identified risks.

5.2 Timely Resolution

Corrective actions will be implemented in a timely manner, with clear timelines for resolution communicated to relevant teams.

6. Audit Management Process (5-Step Process)

6.1 Audit Planning

Before each audit, a comprehensive plan will be established, outlining the scope, objectives, and resources required.

6.2 Risk Analysis and Security Control Assessment

Risk analysis will be conducted, and security controls will be assessed to identify potential vulnerabilities.

6.3 Conclusion and Report Generation

A conclusion will be drawn based on the findings, and a detailed report will be generated, highlighting areas of strength and improvement.

6.4 Remediation Schedules

A risk-based corrective action plan will be developed, outlining schedules for remediation of identified issues.

6.5 Review of Past Reports

Past audit reports and supporting evidence will be thoroughly reviewed, ensuring continuous improvement and learning from previous assessments.

7. Advisory Board and Independent Guidance

7.1 Advisory Board Formation

Uhubs has established an Informal Advisory Board comprising seasoned ex-operators, founders, and advisors with firsthand experience in security, data governance, and related topics.

7.2 Roles and Responsibilities

The Advisory Board holds the responsibility of providing critical feedback on security and data governance matters, leveraging their extensive industry experience.

7.3 Accountability Standards

While the board may not be technically independent, it plays a crucial role in holding Uhubs accountable to high standards, fostering a culture of continuous improvement.

7.4 Higher-Risk Projects

For specific projects deemed higher-risk, Uhubs actively seeks external, independent guidance and assessments. This ensures an unbiased evaluation and brings in diverse perspectives to enhance our risk management strategies.

7.5 Engagement Frequency

The Advisory Board will be engaged regularly to provide insights, assess current policies, and offer guidance on emerging threats, ensuring that Uhubs remains at the forefront of security and data governance.

8. Continuous Improvement

8.1 Feedback Integration

Feedback from the Advisory Board and external assessments will be systematically integrated into our audit and assurance processes, driving continuous improvement.

8.2 Adaptation to Industry Changes

Uhubs commits to adapting its policies, procedures, and risk management strategies based on the evolving landscape, leveraging the expertise of the Advisory Board and external assessments.

9. Regular Policy Review and Updates

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.