When to call
The audit planning meeting is on the calendar.
We go through last year’s findings and this year’s request list with you first, so you know which requests will be hard and what you want to say about scope.
A deficiency letter arrived.
We write the remediation plan and the memo the audit committee reads, design a compensating control your team runs while the fix is built, and tell you plainly whether the fix can run long enough to be tested before year end.
An IPO date is set.
A material weakness found before the offering is disclosed in the registration statement and in the quarterly certifications that follow it, and management’s first assessment of internal control is due with the second annual report after the offering. We find the control gaps, in the business processes and in IT, while there is time to fix them.
A sponsor, lender or buyer is asking.
When someone with money at stake asks how your controls hold up, we tell you where you stand and what to fix before they ask again.
A new ERP goes live before year end.
Implementations are where many findings start, in IT controls and in the processes that depend on them: data conversion, access granted in a hurry, change controls skipped to make a date. We look before go live, not after the auditor does.
The person who ran SOX compliance left.
A fractional lead keeps the calendar, the evidence requests and the auditor relationship running while you hire, or instead of hiring.