Services

Assurance and risk advisory, scoped like an engagement — not a retainer that never ends.

Every engagement below is delivered against IIA standards, with a written scope, a fixed timeline, and deliverables an audit committee can act on. If you’re not sure which one fits, a 30-minute scoping call sorts that out at no charge.

01 — What I take on

Six engagement types, one standard of evidence.

01

Internal Audit & SOX Compliance

Risk-based audit planning, fieldwork, and reporting aligned to IIA standards, COSO, and SOX/COBIT control frameworks — whether you need a full audit plan executed or a co-sourced pair of hands for one cycle.

Typical deliverablesAudit universe & annual plan, risk-based work programs, workpapers, committee-ready reports.
02

Enterprise Risk Management

Risk register design, control matrices, and heat-mapping that survives contact with an actual board meeting — built so your team can maintain it after I leave.

Typical deliverablesRisk register, RACM, heat maps, risk appetite statement, ERM playbook.
03

SOC 1 & 2 Audits

Service organization control audits for vendors and platforms handling client data and financial processes — from first readiness assessment through the external auditor’s fieldwork.

Typical deliverablesReadiness/gap assessment, control mapping, evidence preparation, auditor liaison.
04

ISO Audits

Management system audits against ISO standards, from gap assessment through certification readiness — internal audits your certification body will accept.

Typical deliverablesGap assessment, internal audit reports, corrective-action tracking, certification-readiness review.
05

Forensic Investigations & Fraud Detection

Targeted investigations and red-flag analysis when something doesn’t reconcile and leadership needs answers fast — handled discreetly, documented to an evidentiary standard.

Typical deliverablesInvestigation plan, evidence file, findings report, recovery support.
06

GRC Advisory & Training

Audit committee briefings and in-house training that builds risk literacy beyond the audit function — for boards, finance teams, and first-line managers.

Typical deliverablesCommittee briefings, training curricula, control-owner playbooks.
02 — How an engagement runs

No surprises. That’s the whole methodology.

Step 01

Scoping call

Thirty minutes, no charge. We agree on the question that actually needs answering — before anyone talks about fees.

Step 02

Proposal & plan

Fixed scope, timeline, and named deliverables in writing. You know what you’re getting before work starts.

Step 03

Fieldwork

Interviews, walkthroughs, and testing — with a short written status every week so nothing lands as a surprise.

Step 04

Reporting & follow-up

Findings ranked by exposure, management actions agreed in the room, and a plain-English brief your board will actually read.

Engagements are delivered remotely or on-site across Canada, the US, and the GCC. Independence is documented at acceptance — if I can’t be independent on a matter, I’ll tell you on the scoping call and point you to someone who can.

Not sure if this needs an audit or an investigation?

That’s exactly what the scoping call is for. Bring the symptom — a number that doesn’t reconcile, a control nobody owns, an auditor’s finding you disagree with — and leave with a recommended scope, even if you don’t hire me.