Loading
Loading
LoadingServices · IS / IT Audit
Information-systems audits, IT general controls (ITGC) reviews, SOC 2 readiness and control testing.

What this covers
How the work runs
An audit that a regulator will accept is one where every number can be re-derived from the evidence behind it. This is how we get there.

Which systems, which controls, which period, and why. Testing effort lands where a control failure would actually matter — not evenly across everything you happen to own.
OutputScope and risk assessment

How a control is designed to run, how it runs on an ordinary week, and where those two diverge. Walkthroughs with the people who operate it, not a reading of the policy.
OutputProcess narratives and control matrix

Completeness and accuracy of the population established before a sample is drawn from it. Then the sample is tested, and each exception is chased to its cause.
OutputTest results with exceptions

Every conclusion referenced to the evidence that supports it, pulled from the system of record. A workpaper cites a source, not a screenshot somebody took on a Tuesday.
OutputReferenced workpaper file

A findings register with an owner, a date and a management response against each item — then tracking through to close, so the report is the start of the remediation rather than the end of the engagement.
OutputFindings register, tracked to close