Corporate Governance Advisory
Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Governance advisory
Board-level governance design, risk and control frameworks, IT general controls, and the diligence work that decides whether a deal is priced correctly.
Corporate governance advisory, enterprise risk and internal controls assessment, IT audit and ITGC, and transaction advisory and financial due diligence. What groups them is the audience: each answers whether the business is actually controlled, and whether someone outside it, a board, an acquirer, or a customer's auditor, can be shown that it is.
Governance, risk and transaction advisory in California is where accounting stops being a record of what happened and starts being a mechanism for deciding what happens next. This pillar covers the structures a board relies on to know that management's reporting is trustworthy, and the diligence that tests whether a target company's numbers mean what the seller says they mean.
There is a distinction worth being precise about, because it is frequently blurred in marketing copy. An advisor designs and recommends a governance framework. An auditor tests whether that framework works. The same party cannot credibly do both for the same control, and any firm that says otherwise is selling you an independence problem. Which side of that line a given engagement sits on is agreed in writing before it starts.
Each links to a full description of scope, process, deliverables and the questions clients ask most.
Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Governance advisoryWhere the business can fail, whether the control that should catch it works, and what to fix first.
Risk & controlsAccess, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGCQuality of earnings, working capital, and the IT and privacy exposure that now decides deal terms as often as the numbers do.
Deal advisoryMid-market and private companies in Ventura County and Los Angeles County occupy an awkward position. They are large enough that a board, a lender, an insurer or an acquirer expects governance discipline, and small enough that hiring a full-time Chief Risk Officer or standing up an internal audit department is not a rational use of capital.
The options available to them are usually poor. A national firm will sell the engagement, staff it with people three years out of university, and bill accordingly. A local accounting practice will decline it, correctly, because governance advisory is not what it does. The result is that the work either gets done badly or does not get done until an event forces it, a covenant breach, a failed diligence process, a regulator's letter, a breach notification.
The four services in this pillar look different from the outside but rest on the same skill: the ability to look at a business process, identify where it can fail, and determine whether the control that is supposed to catch that failure actually operates.
That skill is what a Certified Information Systems Auditor is trained to apply to systems, what a CPA is trained to apply to financial reporting, and what a former CFO applies to the operating reality of a company that has to close its books while also shipping product. Holding all three is uncommon, and it is the reason this pillar exists in a practice of this size.
Deliverables in this pillar are written to be read by directors, not by other accountants. In practice that means:
A recurring situation: a company asks its external auditor to help design the controls the auditor will later test. Auditors generally cannot do that, and where they can, the value is compromised, nobody objectively audits structures they built themselves.
This practice is frequently engaged precisely because of that constraint. Where your audit firm cannot advise, an independent advisor can. Where this firm performs the attestation, the design work goes elsewhere. The rule is applied in both directions, and it is stated at the start of every engagement rather than discovered at the end of one.
Not answered here? Ask Javed directly
An advisor designs and recommends, governance frameworks, board and committee structures, risk appetite, delegation of authority, reporting lines. An internal auditor independently tests whether what has been designed actually operates as intended, and reports the result to the board or audit committee rather than to management.
Ultimate responsibility for governance sits with the board in either case. The practical reason to keep the two roles separate is objectivity: an auditor cannot give an unbiased opinion on a structure they personally designed. Both services are offered here, but not on the same control for the same client in the same period.
Often yes, though the framing changes. Without a board, the questions become: who approves an expenditure above a threshold, who can change a vendor's bank details, who reviews the bank reconciliation that the person preparing it cannot also approve, and what happens when the founder is unavailable for three weeks.
Those are governance questions wearing operational clothes. Companies usually encounter them at one of three moments, a first outside investor, a first material fraud loss, or a first serious acquisition conversation. The cheapest time to address them is before any of those.
For a company with one primary operating entity and a single ERP, expect four to six weeks end to end: roughly two weeks of walkthroughs and evidence review, two weeks of testing and analysis, and a week to write and present.
Multiple entities, several systems, or an active remediation programme running in parallel extend that. The variable that matters most is not company size; it is how much documentation already exists. A company with nothing written down takes longer than a company with outdated documentation, because outdated documentation at least tells you what someone once intended.
Yes, on either side. Sell-side, the work is about finding what a buyer's team will find, and finding it first, quality-of-earnings adjustments, revenue-recognition positions that will be challenged, working-capital normalisation, unaccrued liabilities, and increasingly the IT and data-privacy exposure that now forms part of most diligence scopes.
Buy-side, the same discipline runs in reverse, with particular attention to whether the target's reported EBITDA survives contact with its own general ledger.
The licensed CPA foundation: tax, accounting, financial leadership, and the attestation work only a CPA firm can sign.
Explore financial & cpa servicesSOC 2, cybersecurity risk, cloud platform compliance and privacy law, assessed and attested by one licensed firm rather than split across two vendors.
Explore cybersecurity, cloud & data privacyThe build tier: AI-enabled continuous audit, ERP programmes, robotic process automation and FinOps, specified and deployed, not just recommended.
Explore technology & engineering deploymentThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
Tell us what you are dealing with and you will get a considered reply, not a brochure.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
A short diagnostic conversation costs nothing and usually establishes whether this is the right tier of work for your situation, including when it is not.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp