Corporate Governance Advisory
Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Governance advisory
Where the business can fail, whether the control that should catch it works, and what to fix first.
Whether anything would catch a failure before it mattered. The answer is usually yes for the risks a company has already experienced and no for the ones it has not, because control environments grow reactively: each control traces back to an incident, so the set covers history rather than exposure. The assessment establishes where the business can fail, whether the control that should catch it works, and what to fix first.
An internal controls assessment in California answers a question most companies assume they already know the answer to: if something went wrong in this process, would anything catch it before it mattered?
The reason is that controls get added after incidents and almost never get retired afterwards. What accumulates is a record of what has already gone wrong here, not a map of where this business can fail next. The process redesigned last year and the system that replaced the one a control was written for are both sitting outside it.
Assessing controls without first assessing risk produces a list of what exists rather than a view of what is missing. The sequence has to run the other way.
A workable risk assessment is not a hundred-line register scored one to five. It is a short conversation with each function about what would actually damage the business, converted into a small number of scenarios with a plausible magnitude attached. Ten to fifteen risks that a management team genuinely recognises is more useful than eighty that were generated to be comprehensive.
The output then drives everything: control testing goes where the exposure is, remediation is sequenced by consequence, and the board receives something it can act on rather than a heat map.
The textbook answer (separate the initiation, approval, recording and custody of every transaction) assumes enough people to separate them. A five-person finance team cannot fully segregate, and pretending otherwise produces documentation nobody follows.
The realistic approach is to identify the small number of combinations that genuinely enable material loss and address those specifically. In practice that is a short list:
Where separation is impossible, compensating detective controls do real work: a monthly review of new and changed vendor master data by someone outside AP, an out-of-band confirmation for bank detail changes, and an owner review of the payment run against supporting documents. These are cheap, and each of them defeats a specific fraud that occurs regularly to companies of this size.
Companies rarely required to have internal audit still benefit from the function once complexity passes a threshold, multiple entities, regulated activity, a lender requiring assurance, or a board wanting independent verification of what management reports.
Building it internally is expensive and produces a function reporting to the people it examines. Outsourcing gives independence and a broader skill base; co-sourcing pairs an internal resource with external specialists for areas requiring depth the in-house team does not have. IT controls, privacy, treasury.
The deliverable that matters is an annual plan tied to the risk assessment, a small number of substantive reviews executed properly, and findings reported to the board with management's response alongside. What does not work is an internal audit function producing volume to justify its existence.
Occupational fraud in owner-managed companies follows a small number of patterns, and they are not sophisticated. Fictitious vendors created by someone with vendor master access. Payroll additions or unauthorised rate changes. Expense reimbursement abuse that grows because nobody checks. Cheque and ACH tampering. Diversion of customer receipts where the same person banks and posts them. Business email compromise, in which a convincing email redirects a legitimate payment to a new account.
Each has a specific, inexpensive control. The reason they succeed is not that the controls are hard; it is that nobody assigned ownership of the review, so it happened for two months and then stopped.
Findings ranked by consequence, not by discovery order, with an owner and a date against each. A distinction drawn between what must be fixed, what should be, and what is worth knowing but not acting on. And a remediation sequence that respects dependencies, several fixes only work once a prior one is in place, and attempting them in the wrong order wastes a quarter.
Where the assessment feeds a SOX 404 programme or a SOC 2 engagement, the control documentation is written in a form those frameworks can consume directly, rather than being rewritten later.
Interviews across functions to establish what would genuinely damage the business, converted into a small number of scenarios with magnitude attached.
Follow real transactions end to end through the systems and the people. Documented process and actual process diverge more often than not, and the divergence is where the exposure lives.
Sample-based testing of the controls that address the significant risks. Design effectiveness and operating effectiveness are assessed separately, a well-designed control that nobody performs is still a gap.
Findings ranked by consequence, remediation sequenced by dependency, and a briefing to the board or owner that says plainly what is not working.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
You cannot fully, and a framework that pretends otherwise will be ignored. Target the specific combinations that enable material loss rather than attempting textbook separation everywhere.
The highest-value single change in most small finance functions is removing the ability for one person to both create a vendor and approve payment to it. After that, an out-of-band verification step for any change to a vendor or employee bank account, and a review of the bank reconciliation by someone who did not prepare it, typically the owner, which is perfectly acceptable.
Different purpose, and much narrower scope on the auditor's side. An external auditor evaluates internal control only to the extent needed to plan the financial statement audit. They are not looking for operational risk, fraud exposure outside financial reporting, or process inefficiency, and they are not obliged to tell you about weaknesses that do not affect their opinion.
The management letter you receive is a by-product of the audit, not an assessment. It is genuinely useful and it is not the same thing.
Below roughly $10M in revenue with a single location and one product line, a formal programme is usually disproportionate; the risks are visible to the owner without a framework. A focused fraud risk and segregation of duties review is the better use of the budget.
The threshold is complexity rather than revenue. Multiple entities or locations, regulated activity, significant third-party dependency, or an owner no longer close enough to daily operations to see problems directly, any one of those makes formal assessment worth the cost.
No, where the assessment amounts to designing or operating the controls. Independence rules restrict a firm performing an attestation engagement from also performing management functions or designing the controls it will subsequently test.
Assessment and testing performed on behalf of management, for a company audited elsewhere, is entirely appropriate; and is how most of this work is structured.
This is agreed before the engagement begins, not after a finding arises. The reporting line for the engagement is defined at the outset (typically to the board, the audit committee, or the owner) and it is defined so that a finding involving a member of management does not have to pass through that person to reach the people who need it.
Where a finding suggests possible fraud, the work stops and the matter is escalated immediately rather than continuing under an assessment scope, because an assessment is not an investigation and conflating the two damages both.
Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Governance advisoryScoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.
SOX 404 supportAccess, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGCThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp