Audit & Assurance
Control weaknesses are what produce management letter comments. Closing them beforehand is materially cheaper than being told about them afterward.
Controls sized for the business you are now, not the one you were at founding, and not a Fortune 500 framework bolted onto a team of twelve. Documented well enough that they survive the person who designed them leaving.
Controls are not paperwork. A control that exists only in a binder has failed by definition: the test is whether it changes what happens on a Tuesday.
No individual can both cause a misstatement and conceal it. Where full segregation is impossible, a documented compensating control closes the gap.
Written procedures with named roles rather than named individuals, so a resignation is an inconvenience rather than an operational crisis.
A single compliance calendar covering tax, payroll, licensing, insurance, registration and reporting: each item with an owner, a lead time and a visible status.
Assessment first, always. We will not design controls for a business we have not walked through, because the controls that exist on paper and the controls that operate are rarely the same set.
Process walkthroughs across the revenue, purchasing, payroll, treasury and financial close cycles, documenting the controls that actually operate, including the informal ones nobody wrote down and the formal ones nobody performs.
A role-by-function matrix tested against real system access rather than the org chart, identifying every incompatible combination (authorization, custody, record-keeping and reconciliation) and where a compensating control is required.
Controls designed to the actual size and risk of the business, with the specific system configuration, approval threshold or procedural change needed to implement each one, not a generic framework you will quietly abandon in six weeks.
Written policies covering expenditure authority, travel and expense, purchasing, cash handling, journal entry approval, system access and change management, credit and collections, and conflict of interest, in language your team will actually read.
A single register of every recurring obligation (tax, payroll, sales tax, information returns, annual reports, licenses, insurance renewals, registrations and covenant reporting) with owners, lead times and status visible to leadership.
Gap assessment against the relevant trust services criteria or control objectives, remediation planning, evidence and artefact preparation, and support through the service auditor's examination. We prepare you for the report; an independent firm issues it.
For companies approaching an IPO, held by a private equity sponsor with a portfolio standard, or being acquired by a public filer: building a Section 404-capable control environment and documentation set ahead of the requirement rather than in response to it.
Periodic independent testing that the controls still operate as designed, with results reported to leadership or the board. Controls decay quietly, through system changes, staff turnover and workarounds adopted under deadline pressure.
Cybersecurity penetration testing and technical IT security assessment (we assess IT general controls, and will refer you to specialist security firms for the technical work), legal compliance opinions, and issuing the SOC report itself: the service auditor examination must come from an independent firm.
You cannot run a forty-control framework with nine people. These are the seven that prevent most of the damage in a small or mid-sized business, in the order we test them.
| # | Control | Exposure it closes |
|---|---|---|
| 01 | Independent bank reconciliation review | Whoever reconciles the bank should not also authorize payments. An owner or board member reviewing the completed reconciliation catches most diversion. |
| 02 | Vendor master change control | Adding or amending a vendor (especially bank details) requires a second approver. This is the single most exploited weakness in payment fraud. |
| 03 | Dual authorization above a threshold | Payments over an agreed amount need two approvals. Set the threshold where it bites without paralysing operations. |
| 04 | Purchase approval before commitment | Approval at the point of order rather than at the point of invoice. Approving an invoice for goods already received is not a control. |
| 05 | Payroll change review | New starters, leavers and pay rate changes reviewed against HR records by someone outside payroll. Ghost employees survive precisely where this is absent. |
| 06 | Journal entry review | Manual journals above a threshold, and all journals posted after close, reviewed and approved. Most financial statement manipulation happens through manual journals. |
| 07 | System access review | Quarterly review of who has access to what, with prompt removal on departure. Access accumulates over careers and is almost never revoked. |
The full reasoning behind each is set out in Internal Controls for Small Businesses: The Seven That Actually Matter.
Assessment is a fixed-fee project. Remediation and ongoing testing can be a project or a retainer, depending on whether you have the internal capacity to execute the plan yourselves.
Walkthroughs of every significant cycle, system access extraction, and documentation of what actually operates, producing a findings report ranking gaps by likelihood and impact.
A remediation plan with a specific control, an owner and a date for each gap, sequenced so the highest-exposure items are closed first rather than the easiest ones.
Policies written, system approvals configured, thresholds set, roles reassigned and the team trained on what changed and why. Adoption is the hard part, and it is included.
Periodic independent testing that controls still operate as designed, reported to leadership or the board, with re-testing of anything previously found deficient.
Some sectors carry regulatory obligations that dwarf the ordinary financial control set. These are the ones where the compliance calendar does most of the work.
It means no single person controls a transaction end to end. The four incompatible functions are authorization, custody of assets, record-keeping and reconciliation.
When one person can set up a vendor, approve an invoice, release the payment and reconcile the bank account, there is no point at which an error or a diversion would be caught by the process itself: detection depends entirely on someone happening to look. It is the most common control gap we find in businesses under fifty employees, and the one most frequently cited in occupational fraud cases.
Not completely, and pretending otherwise produces a control matrix nobody follows, which is worse than admitting the constraint.
In a small team the answer is compensating controls: an owner or board member reviews the bank statement independently of whoever reconciles it; new vendors need a second approval; payments above a threshold need dual authorization; someone outside accounting reviews the monthly close. The objective is that no single person can both cause and conceal a misstatement. That is achievable at nine people even when full segregation is not.
SOC 1 reports on controls relevant to a client's financial reporting: what a payroll processor or claims administrator provides so their clients' auditors can rely on their processing. SOC 2 reports on security, availability, processing integrity, confidentiality and privacy, and is what a SaaS or technology vendor is usually asked for in procurement.
Each comes as Type I, testing design at a point in time, or Type II, testing operating effectiveness over a period of usually six to twelve months. Most enterprise buyers want Type II, so plan for the observation window rather than assuming it can be produced in a fortnight.
Section 404 internal control reporting applies to SEC registrants, so a private company is not directly subject to it.
It becomes relevant in three situations: you are preparing for an IPO and need a control environment that will withstand scrutiny; a private equity sponsor requires SOX-equivalent controls as a portfolio standard; or you are being acquired by a public company and will be folded into their framework. In all three, the work is far cheaper done ahead of the requirement than in response to it.
For a business under 100 employees, four to six weeks: process walkthroughs across the revenue, purchasing, payroll, treasury and close cycles; documentation of the controls that actually operate rather than those written down; a segregation of duties matrix tested against real system access; and a findings report ranking gaps by likelihood and impact with a remediation plan.
Remediation itself typically runs a further one to two quarters, depending on how much of it is system change rather than process change. System change is slower but sticks; process change is faster but decays without testing.
Control weaknesses are what produce management letter comments. Closing them beforehand is materially cheaper than being told about them afterward.
Controls address known risks. A risk assessment identifies which risks you should be controlling for in the first place.
A reliable close depends on controls that work. Most close failures we investigate trace back to a control gap rather than an accounting error.
Could one person in your business set up a vendor, approve an invoice, release the payment and reconcile the bank? If the answer is yes (or you are not certain), that is the conversation to have.