Javed Peeran, CPA, CISA, CISM, CDPSE, CCSE, MBA
Thirty years across external audit, corporate financial leadership and IT governance, held by one practitioner rather than assembled from a team.
Most professional biographies list credentials and leave the reader to guess what they mean. This one sets out what each period of work actually taught, because that is the part that determines whether someone can help you.
The practice
Javed Peeran CPA is a licensed certified public accounting practice at 11843 Nightingale Street, Moorpark, CA 93021, serving clients across Ventura County and Los Angeles County. The firm has served Los Angeles businesses since 1986, individual taxpayers, insurance companies, banks, mortgage companies, technology companies and semiconductor manufacturers.
It is deliberately structured as a single-principal practice. The person who scopes an engagement performs it and signs it. That is a genuine constraint on capacity, and it is the reason the practice declines work that requires a standing team across several offices.
Twenty years auditing financial institutions
The first long phase was external audit of banks, insurance companies and mortgage companies. Financial services is a demanding environment to learn in because the regulatory expectations are prescriptive and the examiners are specific. FFIEC IT examination requirements, GLBA safeguards obligations, third-party and vendor management programmes, business continuity, and the controls over core banking, loan origination and claims systems.
What that period taught, more than any framework, was what an examiner or an auditor actually opens first; which is consistently narrower and more particular than published guidance suggests. It is also where the habit of asking for evidence rather than accepting description was formed, and that habit shapes every assessment performed here.
Fifteen years as CFO and Corporate Controller
The second phase was inside technology companies rather than outside them, closing the books, building the reporting, managing the lenders and auditors, and living with the consequences of decisions made under a quarter-end deadline.
This is the experience that changes how advice is given. It is straightforward to recommend a control from the outside. It is different to have been the person who had to implement it while also closing the month with a team that was already stretched. Recommendations here are sequenced against what a finance function can realistically absorb, because the alternative (a beautifully designed programme that nobody has capacity to operate) is a familiar and expensive failure.
That period also included migrating legacy accounting systems to Oracle E-Business Suite across General Ledger, Accounts Receivable, Accounts Payable, Inventory and Fixed Assets, with the data reconciliation and cleansing that consumes most of the real effort in any ERP programme.
IT governance, security and privacy
The third strand runs alongside both: SOX and IT audit execution across the frameworks that govern how systems and data are controlled (ISO 27001 and 27002, SOC 1 and SOC 2, FISMA, FedRAMP, PCI DSS, CCPA, GDPR, HITECH and HIPAA) together with cloud security engineering and compliance strategy for both commercial and federal requirements.
More recently that has extended to automated security solutions for continuous monitoring, and to the use of generative AI for audit automation. The position taken on AI is deliberately narrow: it reduces the cost of finding things by a large factor and changes the process of concluding about them not at all. That argument is set out in full in the article on AI agents in continuous audit.
Credentials, and what each is for
- CPA, licensed by the California Board of Accountancy. The licence that permits audit, review and attestation work. Without it, no firm can issue a SOC report or an audit opinion, whatever else it can do.
- CISA. Certified Information Systems Auditor (ISACA). IT audit and control testing: access, change management, operations.
- CISM. Certified Information Security Manager (ISACA). Security programme governance rather than security operations.
- CDPSE. Certified Data Privacy Solutions Engineer (ISACA). The technical implementation of privacy obligations, which is where CCPA and GDPR stop being legal questions.
- CCSE. Certified Cloud Security Engineer. Cloud security architecture across the major platforms.
- MBA, the commercial framing that keeps a technical finding connected to what it costs the business.
How the work is approached
Say what the requirement actually is. A meaningful share of first conversations end with a client commissioning less than they intended, a review rather than an audit, a segregation of duties fix rather than a risk programme. That is the correct outcome and it is worth more than the fee foregone.
Rank findings by consequence. A hundred-page report listing every deviation is not a deliverable, it is an abdication. Twelve findings ordered by what they would actually cost, each with an owner and a date, is something a management team can act on.
State the independence position first. Where attestation and advisory cannot both be performed, that is settled in writing before an engagement letter exists rather than discovered halfway through a year.
Build for handover. Documentation the client's team can maintain, and training so they can. An engagement that creates a permanent dependency was designed badly.
Writing and executive education
Every article on this site is written personally, no ghostwriters and no syndicated content. The books and executive education page covers board briefings and executive workshops on governance, cybersecurity oversight and AI risk, and the Insights section holds the published writing.
About the practice: common questions
Not answered here? Ask Javed directly
Is Javed Peeran personally involved in every engagement?
Yes. This is a practice built around one practitioner rather than a firm that sells partner access and delivers with junior staff. The person who scopes the engagement performs it, and the person who signs the report formed the judgments in it.
That has a real limit attached, and it is stated plainly: capacity is finite. Where an engagement requires standing capability across several offices or a large team, a national firm is the better answer and you will be told so.
What does holding CPA, CISA, CISM, CDPSE and CCSE together actually enable?
Each credential covers a domain that the others do not, and the combination is what allows a single engagement to cross a boundary that normally requires two firms.
The CPA licence permits attestation, only a licensed CPA firm can issue a SOC report or an audit opinion. CISA covers IT audit and control testing. CISM covers security programme management. CDPSE covers privacy engineering, which is where CCPA and GDPR obligations become technical rather than legal. CCSE covers cloud security architecture. Together they mean an assessment finding can be traced from a misconfigured IAM policy through to the financial statement assertion it affects.
Which industries do you know best?
Financial services first, twenty years auditing banks, insurance companies and mortgage companies produced the deepest familiarity, particularly with FFIEC expectations and the controls over core banking and origination systems.
Then technology and semiconductor manufacturing, from fifteen years inside those companies as CFO and Corporate Controller rather than as an outside adviser. That is a different kind of knowledge, knowing what a close actually feels like when the quarter is tight.
Do you work with individuals as well as companies?
Yes, primarily where the personal return connects to a business, owners, executives with equity compensation, and families whose personal filing cannot sensibly be separated from an entity return.
Equity compensation is where this matters most: incentive stock options and the AMT, 83(b) elections that cannot be fixed after thirty days, and qualified small business stock holding periods. These are ordinary features of working at a technology company in this region and are routinely handled badly when the entity return and the personal return are treated as separate engagements.
Organisations we have worked with
Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
Get in touch with Javed
Enquiries are read and answered personally within one business day.
Have a deadline, or just a question?
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years, one practitioner, no handoffs
If your situation sits across the line between accounting and technology (which is where most difficult engagements now sit) that is precisely what this practice was built for.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp







