Austin, Texas. Remote or on site, nationwide.

Internal controls, ready before the auditors arrive.

We prepare public companies, companies heading to an IPO and PE backed companies for their external auditors: which controls are in scope, which ones operate, what evidence exists, what will fail, and the fix, retested before the auditor tests it. Behind the work is a career in Big Four and national firm risk practices, on audit work that held up to annual PCAOB inspection.

Call us when the audit planning meeting is on the calendar, a deficiency letter has arrived, an IPO date is set, or the person who ran SOX compliance left.

Start with a scoping call
First stepA two hour scoping call.
FeeIn writing before any work begins.
GuaranteeIf your external auditor writes up a deficiency on a control we documented and tested, we remediate it at no charge.
I

When to call

  • The audit planning meeting is on the calendar.

    We go through last year’s findings and this year’s request list with you first, so you know which requests will be hard and what you want to say about scope.

  • A deficiency letter arrived.

    We write the remediation plan and the memo the audit committee reads, design a compensating control your team runs while the fix is built, and tell you plainly whether the fix can run long enough to be tested before year end.

  • An IPO date is set.

    A material weakness found before the offering is disclosed in the registration statement and in the quarterly certifications that follow it, and management’s first assessment of internal control is due with the second annual report after the offering. We find the control gaps, in the business processes and in IT, while there is time to fix them.

  • A sponsor, lender or buyer is asking.

    When someone with money at stake asks how your controls hold up, we tell you where you stand and what to fix before they ask again.

  • A new ERP goes live before year end.

    Implementations are where many findings start, in IT controls and in the processes that depend on them: data conversion, access granted in a hurry, change controls skipped to make a date. We look before go live, not after the auditor does.

  • The person who ran SOX compliance left.

    A fractional lead keeps the calendar, the evidence requests and the auditor relationship running while you hire, or instead of hiring.

II

Where we come in

Service details
  • SOX and ICFR readiness

    Before your auditor plans the year, we find out which processes and applications are in scope, which controls actually operate, what evidence exists and what will fail. You get a gap list with an owner and a date on every line, and a one page summary for the audit committee, in three to five weeks.

  • ITGC and business process controls, documented and tested

    The IT general controls first, then the business process controls that depend on them, with entity level controls alongside, documented and tested to the standard your auditor applies to its own work, so the auditor can use it, in four to eight weeks. How much they rely on it is their decision.

  • Deficiency remediation

    When a control is written up, we redesign it, design a compensating control your team runs while the fix is built, and write the remediation memo the audit committee reads. Then we retest it before your auditor does, so you know the result before they do. Two to six weeks, plus the time a new control has to run before it can be retested.

  • PCAOB grade testing for management

    Your own testing, done the way your auditor’s own testing is judged: sample sizes, how closely the reviewer looks, evidence of what the reviewer looked at, and the completeness and accuracy of the reports each control relies on. What inspectors flag at your auditor tends to become your auditor’s request to you, so we build to it now, in four to eight weeks.

  • Fractional SOX compliance lead

    For a company that has the controls but not the person to run the program. A set number of days each month on the calendar, the evidence requests, the control owners and the auditor relationship, with a written status every month and the same lead every time, on a monthly retainer.

  • Key reports and SOC 1 reviews

    The reports each control relies on, tested for completeness and accuracy. SOC 1 Type 2 reports from your service organizations reviewed for the opinion, scope, period, exceptions, subservice organizations and the complementary user entity controls your team has to operate, in two to four weeks.

III

How an engagement runs

  1. A two hour scoping call.

    We look at your applications, your key controls and your audit calendar, and say what we would do and what we would leave alone.

  2. A fixed price and a short letter.

    The letter names the deliverables, the dates and the fee.

  3. The work, with a written status every week.

    One page: what was done, what is blocked, and what you need to decide.

  4. The handoff and the retest.

    Your team gets the workpapers, the evidence index and the gap list. We retest what was remediated and confirm the result in writing.

Sample weekly statusPDF · one page
IV

AI in the work

We put AI models on the parts of control work that are volume: reading a change population against its tickets, reconciling a user list to the HR file, checking a report’s logic against its source, drafting a narrative from a walkthrough, keeping the evidence index current. The person running your engagement reviews every result before it reaches a workpaper, and the workpaper says what was machine assisted.

Less of your team’s timeControl owners answer fewer questions, once, because the first pass on the evidence is done before we ask.
Revenue protectedFindings surface in weeks, not at the opinion, so a deficiency is fixed before it reaches the audit committee, a lender or a registration statement.
Cheaper every yearThe scripts, checks and workpapers are yours. The second year’s program starts from them, not from scratch.

Your information stays in your systems. Where a model is used it runs inside an environment you control or under an agreement that bars training on your data, and nothing of yours is kept once the engagement ends.

V

The guarantee

Ready before the auditors are.

  1. If your external auditor writes up a deficiency on a control we documented and tested, we remediate it at no charge.

  2. If a control fails testing for a reason in our work, that deliverable’s fee is refunded.

The engagement letter or statement of work sets the terms.

Capability statementPDF · one page
VI

How we charge

Fixed feeDefined work product.
HourlyAdvice.
RetainerA fractional SOX compliance lead, monthly.

The scoping call sets the number and the letter puts it in writing.

VII

Why not your auditor, and who does the work

Your external auditor can tell you a control failed. Independence rules keep them from designing or implementing the fix for you. That work is ours, with management, and the opinion stays theirs. We have no software to sell, so any tool we suggest is one you buy for your own reasons. The work is senior from the first call to the retest, with no handoff to junior staff after the letter is signed. Where a scope needs more hands, we add them only with your written consent, and the same person stays on the work.

Start with a scoping call

Send the date on your audit calendar and a sentence on what is coming up.