I’m Mohammad Siddiqui, CIA — an internal audit and enterprise risk consultant with 11+ years across banking, construction, and nonprofit sectors in Qatar, Canada, and the United States. I help audit committees and management teams close control gaps before the regulator, the fraudster, or next year’s audit report does.
Every engagement starts by plotting exposure like this — before we talk about controls, we agree on what actually matters.
Over eleven years I’ve sat on both sides of the audit committee table — building internal audit functions from scratch inside holding companies, and stepping in from the outside when a control has already failed and someone needs to know why. I built and led the internal audit department at a $500M+ multi-entity group in Doha from the ground up, ran forensic investigations that recovered 100% of contested funds, and delivered GRC advisory work that prevented an estimated $1.2M in annual revenue leakage for healthcare and retail clients.
That’s the lens the CIA Exam Prep bank below is built from — not generic theory, but the syllabus mapped against how these standards actually get used in the field. I’m also building a lightweight audit & risk platform for teams still running their risk register in a spreadsheet — more on that below.
Risk-based audit planning, fieldwork, and reporting aligned to IIA standards, COSO, and SOX/COBIT control frameworks.
Risk register design, control matrices, and heat-mapping that survives contact with an actual board meeting.
Service organization control audits for vendors and platforms handling client data and financial processes.
Management system audits against ISO standards, from gap assessment through certification readiness.
Targeted investigations and red-flag analysis when something doesn’t reconcile and leadership needs answers fast.
Audit committee briefings and in-house training that builds risk literacy beyond the audit function.
An AI-agent pipeline that drafts a risk register and control matrix in minutes — grounded in COSO ERM and ISO 31000, built from the same templates used across the engagements below. Free to try, live now.
Try AuditFlow →3,500+ scenario-based MCQs mapped to the current CIA syllabus, split by part so you can drill exactly where you’re weak — built from the same standards I audit against.
A repeat fraudster’s guilty plea days after release proves incarceration alone isn’t a control — screening needs to be continuous, not one-time.
Read the post → Jan 14, 2026A nonprofit treasurer’s conviction shows how easily trusted insiders exploit organizations that run on good faith instead of segregation of duties.
Read the post → Jan 14, 2026The exploitation of an elderly couple’s finances is a reminder that unsupervised access, regardless of the relationship, always invites fraud.
Read the post →Every engagement starts the same way: a short call to understand what’s actually keeping you up at night, followed by a written scope — no generic proposal template, no obligation. — Mohammad Siddiqui, CIA