Services

Where we come in

Each of these starts from a date on your audit calendar. Tell us the date and we will tell you what we would do and what we would leave alone. Scoping runs top down, from the financial statements to the controls that matter. Testing starts with the IT general controls, because the business process controls, the automated controls and the reports they use depend on them.

I

SOX and ICFR readiness

A review of the internal controls over financial reporting the external auditor will test, done before they test them: entity level controls, the business process controls in the cycles that matter (revenue, purchasing, payroll, the financial close) and the IT general controls under them. We identify which processes and applications are in scope, which controls actually operate, what evidence exists today, and what will fail if nothing changes.

What it takes from your team
Last year’s scoping or the financial reporting process map, system access or screen shares, and about an hour a week from each control owner.
What you receive
A gap list with an owner and a date on every line, the in scope process and application list with the reason each one is in, and a one page summary for the audit committee.
Typical duration
Three to five weeks.
Sample gap listPDF · one page Sample summary for the audit committeePDF · one page
II

ITGC and business process controls, documented and tested

Documentation and testing of the controls in scope, starting with the IT general controls (access to programs and data, program changes, IT operations and program development), then the automated controls and the segregation of duties the applications enforce, then the business process controls that depend on them, with entity level controls alongside. Narratives, control matrices, walkthroughs and test workpapers built to the standard an external auditor applies to their own, so the auditor can use them. How much they rely on them is their decision. Where change control runs through pull requests and deployment pipelines, we test it there.

What it takes from your team
A control owner for a walkthrough of each control, the reports, records and evidence for the period, and prior year workpapers if any exist.
What you receive
A control matrix, a narrative for each process, a walkthrough and test workpaper for each control, an evidence index, and a summary of exceptions with a recommendation for each.
Typical duration
Four to eight weeks, depending on the number of processes and applications and the length of the evidence period.
III

Deficiency remediation

Fixing the controls that failed. Where the design was the problem we redesign the control. Where the fix takes time we design a compensating control for your team to run. And we write the memo the audit committee reads.

What it takes from your team
The auditor’s deficiency letter or management’s own findings, and the people who own the affected controls.
What you receive
A remediation plan for each deficiency, redesigned control descriptions, compensating controls where needed, a remediation memo written for the audit committee, and a retest before your auditor’s, so you hear the result first.
Typical duration
Two to six weeks, plus the time a new control has to run before it can be retested.
IV

PCAOB grade testing for management

For controls already documented: management’s own testing, done to the standard an inspector applies to the auditor. Sample sizes and a depth of review that hold up. Evidence of review that shows what the reviewer looked at. The reports each control relies on, checked for completeness and accuracy. And the questions an inspection team asks that have not reached your team yet.

What it takes from your team
The control population, the evidence for the period, and time with the people who perform and review the controls.
What you receive
Test workpapers built to the standard an external auditor applies to its own work, a list of the points your auditor would raise because an inspector would raise them with the auditor, and a plan to close each one before the audit.
Typical duration
Four to eight weeks.
V

Fractional SOX compliance lead

A set number of days a month running the SOX compliance program: the calendar, the control owners across finance and IT, the evidence requests, the auditor relationship, management’s assessment and the status the audit committee sees. For a company that has the controls but not the person.

What it takes from your team
A named executive sponsor, access to the systems and the people, and a seat at the audit planning meetings.
What you receive
The program, run month after month: a compliance calendar, evidence requests sent and tracked, a written status every month, and the same lead every time.
Typical duration
A monthly retainer.
VI

Key reports and SOC 1 reviews

The reports each control relies on, tested for completeness and accuracy, with the parameters and the logic behind them documented so the test can be repeated. SOC 1 Type 2 reports from your service organizations (the reports many still call SSAE 18), issued under AT-C section 320, reviewed for the opinion, the scope, the period, the exceptions, the complementary user entity controls your team has to operate and the subservice organizations carved out of the report, with a bridge letter plan for the gap to your year end.

What it takes from your team
The list of reports used in controls and where each one comes from, report parameters and logic where they exist, and the SOC 1 reports your service organizations provided, with their bridge letters.
What you receive
A key report inventory with a completeness and accuracy test for each report, a review memo per service organization with exceptions and complementary user entity controls mapped to your controls, and the list of gaps to close before your auditor asks, including the service organizations that provide no SOC 1 report.
Typical duration
Two to four weeks, alongside the evidence work or on its own.

AI in the work

Every service above uses AI models on the volume: populations read against their tickets, user lists reconciled to the HR file, report logic checked against its source, narratives drafted from walkthrough notes, the evidence index kept current. That is why the durations above are weeks and why control owners hear from us once. The person running your engagement reviews every result before it reaches a workpaper, the workpaper says what was machine assisted, and your information stays in your systems: a model runs inside an environment you control or under an agreement that bars training on your data, and nothing of yours is kept once the engagement ends.

Why not your auditor, and who does the work

Your external auditor can tell you a control failed. Independence rules keep them from designing or implementing the fix for you. That work is ours, with management, and the opinion stays theirs. We have no software to sell, so any tool we suggest is one you buy for your own reasons. The work is senior from the first call to the retest, with no handoff to junior staff after the letter is signed. Where a scope needs more hands, we add them only with your written consent, and the same person stays on the work.

Start with a scoping call

Send the date on your audit calendar and a sentence on what is coming up.