01 — Engagement Overview
Live nowAuditFlow — a risk register that isn’t a spreadsheetTry it free →

Independent assurance and risk advisory for organizations that can’t afford blind spots.

I’m Mohammad Siddiqui, CIA — an internal audit and enterprise risk consultant with 11+ years across banking, construction, and nonprofit sectors in Qatar, Canada, and the United States. I help audit committees and management teams close control gaps before the regulator, the fraudster, or next year’s audit report does.

11+Years in internal audit & risk
$500M+Portfolio scope audited
3Countries of engagement
40+Executive audit reports authored

Risk Heat Matrix

Sample output
← LikelihoodImpact ↑

Every engagement starts by plotting exposure like this — before we talk about controls, we agree on what actually matters.

Mohammad Siddiqui
  • CIACertified Internal Auditor, The IIA (ID CIA-194601-SMHRV)
  • CPA CandidateCalifornia Board of Accountancy
  • PGDMUniversity of California, Riverside
  • BSc Accounting & BusinessOxford Brookes University, First Class Honours
  • Higher Diploma, AccountingCollege of the North Atlantic
Who’s behind this

A practitioner’s background, not a brochure.

Over eleven years I’ve sat on both sides of the audit committee table — building internal audit functions from scratch inside holding companies, and stepping in from the outside when a control has already failed and someone needs to know why. I built and led the internal audit department at a $500M+ multi-entity group in Doha from the ground up, ran forensic investigations that recovered 100% of contested funds, and delivered GRC advisory work that prevented an estimated $1.2M in annual revenue leakage for healthcare and retail clients.

That’s the lens the CIA Exam Prep bank below is built from — not generic theory, but the syllabus mapped against how these standards actually get used in the field. I’m also building a lightweight audit & risk platform for teams still running their risk register in a spreadsheet — more on that below.

02 — Scope of Services

What an engagement can include

01

Internal Audit & SOX Compliance

Risk-based audit planning, fieldwork, and reporting aligned to IIA standards, COSO, and SOX/COBIT control frameworks.

02

Enterprise Risk Management

Risk register design, control matrices, and heat-mapping that survives contact with an actual board meeting.

03

SOC 1 & 2 Audits

Service organization control audits for vendors and platforms handling client data and financial processes.

04

ISO Audits

Management system audits against ISO standards, from gap assessment through certification readiness.

05

Forensic Investigations & Fraud Detection

Targeted investigations and red-flag analysis when something doesn’t reconcile and leadership needs answers fast.

06

GRC Advisory & Training

Audit committee briefings and in-house training that builds risk literacy beyond the audit function.

Live Now

AuditFlow — a risk register that isn’t a spreadsheet.

An AI-agent pipeline that drafts a risk register and control matrix in minutes — grounded in COSO ERM and ISO 31000, built from the same templates used across the engagements below. Free to try, live now.

Try AuditFlow →
Access provisioning — core systemHigh
Vendor approval workflow gapHigh
Inventory cycle-count varianceMedium
Expense policy exception rateLow
03 — CIA Exam Prep

A practice bank built the way the exam is actually written.

3,500+ scenario-based MCQs mapped to the current CIA syllabus, split by part so you can drill exactly where you’re weak — built from the same standards I audit against.

04 — Representative Engagements

A sample of engagements, not testimonials.

Arctic Co-operatives Limited
Winnipeg, Canada — Internal Auditor, 2024–2025
Scope
Forensic audits and financial fraud investigations across three operating subsidiaries.
100% recovery of contested funds; reporting accuracy up 15%.
Qaprefab Contracting Establishment
Doha, Qatar — Internal Audit Manager, 2023–2024
Scope
Built and led the internal audit function from scratch for a $500M+ multi-entity holding company.
Redundant processes cut 20%; team of 4, 100% timely resolution of high-risk queries.
Independent Consulting Practice
Vancouver, Canada — Principal Consultant, 2019–2023
Scope
GRC advisory for healthcare and retail clients — control matrices and process flowcharts.
~$1.2M in annual revenue leakage identified and prevented.
Mazars
Doha, Qatar — GRC Consultant, 2017–2019
Scope
GRC engagements across hospitality, healthcare, and insurance — underwriting and claims audits.
40+ executive audit reports, aligned to COBIT and SOX.
06 — Start an Engagement

Every engagement starts the same way: a short call to understand what’s actually keeping you up at night, followed by a written scope — no generic proposal template, no obligation. — Mohammad Siddiqui, CIA