+27 21 486 3920 Cape Town, South Africa
VAT 4820571639 EN
Financial risk advisory · Cape Town

Steady ground for growing capital

We turn scattered supplier records, unverified counterparties and gut-feel exposure into a scored, defensible view of where your money is actually at risk — quantified, documented and audit-ready.

ISO 19011 audit principles · CIPC-registered · Serving South African firms since 2019

Arid Karoo landscape framing a working desk — Ardelio's grounded approach to financial risk
The Karoo Ledger Method
The Karoo Ledger Method

A five-phase methodology built on ISO 19011

Every engagement follows the same audited path, so findings hold up in front of a board, a lender or a regulator. The standard governs how we plan, collect and weigh evidence; the phases below are how it runs in practice.

Aligned to ISO 19011:2018 — Guidelines for auditing management systems.

01

Scope & risk framing

We define the boundary of the review — entities, suppliers, capital flows and the exposures that matter to you — and agree the criteria each will be measured against. Nothing is scored until the rules are written down.

02

Evidence collection

We pull registration data, financials, ownership chains, sanctions and adverse-media records into a single evidence file per counterparty, with source and date stamped on every field.

03

Verification & sampling

Following ISO 19011 sampling principles, we test claims against independent records rather than accepting self-declaration. Unverifiable items are flagged, not quietly assumed.

04

Scoring & weighting

Each counterparty is scored against a documented weighting model. The number is reproducible: two analysts working the same file land within one band of each other.

05

Reporting & monitoring

You receive a ranked register, a defensible methodology appendix and a monitoring cadence, so a clean supplier that drifts is caught before it costs you.

How the work happens

From first call to a register you can defend

01

Intake call

A 45-minute scoping call to map your exposures, data sources and deadline. You leave with a written scope and a fixed fee — no open-ended retainers.

02

Data handover

You share what you have — supplier lists, contracts, statements — through an encrypted channel. We tell you within two days what is missing and how we will fill it.

03

Analysis

We run verification and scoring against the agreed model. Typical turnaround is 10 to 15 business days for a portfolio of up to 250 counterparties.

04

Handover & review

We walk your team and board through the register, the high-risk cases and the monitoring plan in a single working session, with the full methodology attached.

Standards we work to

Named standards, not vague assurances

Each credential below changes something concrete about how your file is built and defended.

Audit standard

ISO 19011:2018

What it guarantees Our audit planning, sampling and evidence rules are documented and repeatable — findings survive challenge from a lender or regulator.
Compliance

FICA-aligned due diligence

What it guarantees Counterparty checks are structured to support your own Financial Intelligence Centre Act obligations, with the paper trail to prove it.
Data protection

POPIA data handling

What it guarantees Personal and company data is processed under the Protection of Personal Information Act, encrypted in transit and deleted on an agreed schedule.
Legal entity

CIPC-registered practice

What it guarantees Ardelio Financial Advisory (Pty) Ltd, reg. 2019/348217/07 — a legally accountable entity you can contract with directly.
Dedicated solutions by sector

Dedicated solutions by sector

The method is constant; the risk criteria and evidence sources shift with your industry.

01Manufacturing & logistics
We weight single-source dependencies, lead-time fragility and offshore ownership chains — the failures that halt a production line rather than just a payment.
02Agriculture & agri-processing
Focus moves to seasonal cash-flow exposure, export-buyer solvency and input suppliers whose failure lands mid-harvest.
03Financial services
Counterparty scoring is tightened to FICA and prudential expectations, with beneficial-ownership tracing as a first-class check, not an add-on.
04Construction & infrastructure
We test subcontractor solvency, retention exposure and the concentration of work in a handful of undercapitalised suppliers.
05Retail & FMCG
Emphasis on high-volume, low-margin supplier books where a single defaulting distributor quietly erodes working capital.
Client story

From 600 unverified suppliers to a defensible view

The situation

A Western Cape food manufacturer carried roughly 600 active suppliers on its ledger, almost none independently verified. A lender covenant required a documented supplier-risk position within eight weeks, and the finance team had spreadsheets, not evidence. Exposure was concentrated in a handful of names nobody had checked in years.

The work

We ran the full five-phase method against the book: registration and ownership verification, sanctions and adverse-media screening, and financial-health scoring on every counterparty above a materiality threshold. Unverifiable suppliers were flagged and ranked rather than removed, so procurement kept control of the decisions.

The result

Inside seven weeks the client held a ranked register with a documented methodology appendix. The covenant was met at first submission, and two of the top-ten suppliers were re-tendered before they failed the following quarter.

600 → 41
suppliers reduced to a monitored high-risk watchlist
7 weeks
from handover to lender-accepted register
R14.2m
spend re-tendered away from failing counterparties
0
covenant queries returned on first submission
Straight answers

Questions we get before signing

Are you licensed financial advisers?

We are a registered advisory practice — Ardelio Financial Advisory (Pty) Ltd, CIPC reg. 2019/348217/07. We provide risk analysis and due diligence, not regulated investment product advice; where a licensed intermediary is required we say so and point you to one.

How is a risk score actually calculated?

Each counterparty is measured against a written weighting model covering financial health, ownership, verification quality and adverse findings. The weights are agreed with you before scoring begins and shipped as an appendix, so the number is reproducible rather than a black box.

How long does a typical engagement take?

A portfolio of up to 250 counterparties usually takes 10 to 15 business days from full data handover. Larger books are staged, and we give you a fixed timeline in the written scope.

What data do you need from us?

Supplier or counterparty lists, any contracts or statements you hold, and registration numbers where available. We tell you within two working days exactly what is missing and how we source the rest independently.

How do you handle our data?

All data is processed under POPIA, transferred over an encrypted channel and deleted on an agreed schedule once the engagement closes. You own the register and the evidence files.

What does it cost?

Engagements are fixed-fee against a written scope, priced on counterparty count and depth of verification — not an open-ended retainer. You approve the number before any work starts.

Can findings stand up to a lender or auditor?

That is the point. The work follows ISO 19011 audit principles, every field is source- and date-stamped, and the methodology appendix travels with the register so a third party can retrace it.

Do you monitor suppliers after the review?

Yes — we agree a monitoring cadence so a clean counterparty that deteriorates is flagged before it reaches your payment run, rather than at year-end.

The scoring model

How we quantify supply chain risk

Every counterparty lands on a 0–100 scale built from five weighted criteria. Weights are agreed with you up front and printed in the report.

Criterion Weight What it measures
Financial health 30% Solvency signals, judgments, payment-default records and available financials. The single largest driver of a score.
Verification quality 25% How much of the counterparty's own claims we could confirm against independent records versus what remains self-declared.
Ownership & control 20% Beneficial ownership traced, related-party links and offshore layers that obscure who ultimately gets paid.
Adverse findings 15% Sanctions, adverse media, regulatory action and litigation weighted by recency and materiality.
Concentration & dependency 10% How exposed you are to this single counterparty — single-source status, share of spend and switching difficulty.

Bands: 80–100 Low · 60–79 Watch · 40–59 Elevated · 0–39 High. A score is never issued without a documented reason for the band.

By the numbers

What the work delivers

5,400+
counterparties scored across South African portfolios
10–15
business days for a standard portfolio review
±1 band
agreement between independent analysts on the same file
R240m
supplier spend brought under documented risk cover
The ledger

Our latest guides

p. 01Due diligence

Why self-declared supplier data fails a lender review

Most supplier registers collapse under the first independent check. We break down the three fields lenders test first and how to close them before submission.

p. 02Method

Reading a counterparty score: what a 58 actually means

A number without a band and a reason is just noise. A worked example of how our five criteria turn into a single, defensible figure.

p. 03Compliance

FICA, POPIA and due diligence: where the lines actually sit

The two acts pull in different directions on data. Here is how we structure a file so it satisfies FICA obligations without breaching POPIA.

Start here

Request a risk review

Request a risk review

Tell us roughly how many suppliers or counterparties you carry and what deadline you're working to. We reply within one business day with a scoping call slot — no obligation, no sales script.

  • Fixed-fee scope before any work begins
  • Data handled under POPIA, deleted on an agreed schedule
  • An adviser, not a call centre, answers

By sending this you agree we may contact you about your enquiry. See our Privacy Policy.