CPA · CISA · CISM · CDPSE · CCSE · MBA
Board directors reviewing a governance and risk report in a California boardroom

Governance, Risk & Transaction Advisory

Board-level governance design, risk and control frameworks, IT general controls, and the diligence work that decides whether a deal is priced correctly.

What does governance, risk and transaction advisory cover?

Corporate governance advisory, enterprise risk and internal controls assessment, IT audit and ITGC, and transaction advisory and financial due diligence. What groups them is the audience: each answers whether the business is actually controlled, and whether someone outside it, a board, an acquirer, or a customer's auditor, can be shown that it is.

Governance, risk and transaction advisory in California is where accounting stops being a record of what happened and starts being a mechanism for deciding what happens next. This pillar covers the structures a board relies on to know that management's reporting is trustworthy, and the diligence that tests whether a target company's numbers mean what the seller says they mean.

There is a distinction worth being precise about, because it is frequently blurred in marketing copy. An advisor designs and recommends a governance framework. An auditor tests whether that framework works. The same party cannot credibly do both for the same control, and any firm that says otherwise is selling you an independence problem. Which side of that line a given engagement sits on is agreed in writing before it starts.

Governance, Risk & Transaction Advisory, 4 service lines

Each links to a full description of scope, process, deliverables and the questions clients ask most.

The gap governance, risk and transaction advisory fills in California

Mid-market and private companies in Ventura County and Los Angeles County occupy an awkward position. They are large enough that a board, a lender, an insurer or an acquirer expects governance discipline, and small enough that hiring a full-time Chief Risk Officer or standing up an internal audit department is not a rational use of capital.

The options available to them are usually poor. A national firm will sell the engagement, staff it with people three years out of university, and bill accordingly. A local accounting practice will decline it, correctly, because governance advisory is not what it does. The result is that the work either gets done badly or does not get done until an event forces it, a covenant breach, a failed diligence process, a regulator's letter, a breach notification.

Four engagements, one underlying discipline

The four services in this pillar look different from the outside but rest on the same skill: the ability to look at a business process, identify where it can fail, and determine whether the control that is supposed to catch that failure actually operates.

That skill is what a Certified Information Systems Auditor is trained to apply to systems, what a CPA is trained to apply to financial reporting, and what a former CFO applies to the operating reality of a company that has to close its books while also shipping product. Holding all three is uncommon, and it is the reason this pillar exists in a practice of this size.

What a board actually gets

Deliverables in this pillar are written to be read by directors, not by other accountants. In practice that means:

  • A findings register that ranks by consequence, not by count. Twelve observations sorted by severity, with an owner and a date against each, is useful. A hundred-page report listing every deviation found is not.
  • A control matrix your team can maintain. If the documentation only makes sense while the consultant is in the building, it will be stale within two quarters.
  • A short verbal briefing to the board or audit committee. Half an hour, no slides beyond a single page, questions answered directly, including the ones about what is not working.
  • A remediation plan sequenced by dependency. Some fixes have to happen before others are worth attempting. Saying so is most of the value.

When independence changes the answer

A recurring situation: a company asks its external auditor to help design the controls the auditor will later test. Auditors generally cannot do that, and where they can, the value is compromised, nobody objectively audits structures they built themselves.

This practice is frequently engaged precisely because of that constraint. Where your audit firm cannot advise, an independent advisor can. Where this firm performs the attestation, the design work goes elsewhere. The rule is applied in both directions, and it is stated at the start of every engagement rather than discovered at the end of one.

Governance, Risk & Transaction Advisory: common questions

Not answered here? Ask Javed directly

What is the difference between a governance advisor and an internal auditor?

An advisor designs and recommends, governance frameworks, board and committee structures, risk appetite, delegation of authority, reporting lines. An internal auditor independently tests whether what has been designed actually operates as intended, and reports the result to the board or audit committee rather than to management.

Ultimate responsibility for governance sits with the board in either case. The practical reason to keep the two roles separate is objectivity: an auditor cannot give an unbiased opinion on a structure they personally designed. Both services are offered here, but not on the same control for the same client in the same period.

We are a private company with no board. Is governance advisory relevant?

Often yes, though the framing changes. Without a board, the questions become: who approves an expenditure above a threshold, who can change a vendor's bank details, who reviews the bank reconciliation that the person preparing it cannot also approve, and what happens when the founder is unavailable for three weeks.

Those are governance questions wearing operational clothes. Companies usually encounter them at one of three moments, a first outside investor, a first material fraud loss, or a first serious acquisition conversation. The cheapest time to address them is before any of those.

How long does an internal controls or governance assessment take?

For a company with one primary operating entity and a single ERP, expect four to six weeks end to end: roughly two weeks of walkthroughs and evidence review, two weeks of testing and analysis, and a week to write and present.

Multiple entities, several systems, or an active remediation programme running in parallel extend that. The variable that matters most is not company size; it is how much documentation already exists. A company with nothing written down takes longer than a company with outdated documentation, because outdated documentation at least tells you what someone once intended.

Can you support us through a buyer’s due diligence process?

Yes, on either side. Sell-side, the work is about finding what a buyer's team will find, and finding it first, quality-of-earnings adjustments, revenue-recognition positions that will be challenged, working-capital normalisation, unaccrued liabilities, and increasingly the IT and data-privacy exposure that now forms part of most diligence scopes.

Buy-side, the same discipline runs in reverse, with particular attention to whether the target's reported EBITDA survives contact with its own general ledger.

How this connects to the rest of the practice

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed California CPA and the author of every article on this site. Thirty years spanning external audit of banks, insurers and mortgage companies; fifteen years as CFO and Corporate Controller at technology companies; and IT governance work across SOX, SOC 2, ISO 27001, FedRAMP, PCI DSS, HIPAA, CCPA and GDPR.

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about governance, risk & transaction advisory

Tell us what you are dealing with and you will get a considered reply, not a brochure.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Discuss a governance, risk & transaction advisory engagement

A short diagnostic conversation costs nothing and usually establishes whether this is the right tier of work for your situation, including when it is not.

WhatsApp Us
Call Now