Internal Audit

Understand where processes and controls need attention.

We help privately held companies review selected business processes, assess internal controls, and add capacity for defined internal-audit projects — without taking over management’s responsibilities.

A clear service boundary

Internal Audit serves management and governance.

Internal Audit examines selected processes, risks, and controls for company management or a designated governance group. It is separate from an external financial-statement audit, which John W. Halloran CPA, P.C. does not perform.

Management owns the processes and controls under review, decides how to respond to observations, and remains responsible for any corrective actions.

GrowthApprovals, access, or oversight have not kept pace with the business
ConcentrationOne person controls several stages of an important financial process
FocusManagement wants a structured review of a selected process or control area
CapacityAn existing team needs additional support for defined review work
When Internal Audit support may be useful

A defined review when controls or capacity need attention.

This service is designed for privately held companies seeking a focused review or additional capacity for defined internal-audit work. It often becomes relevant as financial processes, locations, transaction volume, or oversight needs become more complex.

Internal Audit is distinct from Audit Readiness, which prepares a company for an external financial-statement audit performed by a separate CPA firm.

Often a strong fit when

  • Approval, access, or documentation practices no longer reflect the company’s size.
  • One person controls several stages of an important financial process.
  • Management wants a structured review of purchasing, payments, payroll changes, billing, inventory, or the financial close.
  • An owner, lender, or governance group expects clearer information about selected controls.
  • An existing internal-audit or finance team needs capacity for a defined project.
  • Management wants recurring reviews organized under an approved plan.
What a scope may include

Examine the selected process and communicate what deserves attention.

Each engagement is defined around the process, business objective, management contact, intended audience for the report, available information, and timing.

Risk & scope definition

Clarify the reason for the review, understand the selected process, identify relevant risks and controls, establish responsibilities, and agree on reporting expectations.

Process & control review

Document the workflow, examine selected approvals, access, records, or transactions, and assess how important controls are designed and applied within the agreed scope.

Observations & recommendations

Discuss preliminary observations with management, prioritize them by importance, and provide written recommendations for management’s consideration.

Follow-up support

Review management’s planned responses and, where separately included, follow up on selected actions. Management determines and implements any corrective measures.

Engagement models

Choose the level of support the question requires.

Focused review

A project addressing one process, control area, or risk question, with an agreed objective, scope, and audience for the report.

Co-sourced capacity

Supplemental support for an existing internal-audit, finance, or governance-led program when the company needs additional capacity for a particular review.

Ongoing program support

A planned series of defined reviews approved by management or governance, with the scope and timing agreed for each area.

How the review works

A documented process from the initial question through reporting.

  1. Define the objective

    Agree on the business question, process, management contact, intended audience for the report, timing, and scope.

  2. Understand the process

    Review relevant documents, discuss responsibilities with designated team members, and document the workflow and important controls.

  3. Examine selected evidence

    Review the approvals, access, records, or transactions included in scope and discuss preliminary observations with management.

  4. Communicate the results

    Provide a written report describing the work performed, observations, priorities, recommendations, and management responses where requested.

Illustrative engagement

Purchasing and payment controls have not kept pace with growth.

A growing company relies on informal purchasing and payment approvals that no longer reflect its size or transaction volume. A possible engagement could document the purchasing and payment workflows, examine selected purchases, vendor changes, payment approvals, and access rights, assess segregation of duties, and provide prioritized observations and control recommendations. Management would retain responsibility for deciding and implementing any corrective actions.

Professional accountability

Professional work with clear responsibility.

Established in 2005, John W. Halloran CPA, P.C. is a licensed New York CPA firm serving privately held companies across Long Island and the New York metropolitan area.

Managing-partner supervision

John W. Halloran, CPA founded the firm in 2005 and supervises all professional work.

Management responsibility

Management retains responsibility for the processes and controls under review, the information provided, business decisions, and corrective actions.

Defined scope and suitability

Before acceptance, we consider the objective, required experience, available capacity, information access, timing, reporting expectations, and other services or relationships relevant to the proposed work.

Common questions

Before we begin

How is Internal Audit different from an external financial-statement audit?

Internal Audit serves management or a designated governance group through reviews of selected processes, risks, and controls. It is separate from an external financial-statement audit, which John W. Halloran CPA, P.C. does not perform.

Can you work alongside our existing team?

Yes. We can provide co-sourced capacity for a defined review or series of reviews while the company's internal-audit, finance, or governance-led team retains its existing responsibilities.

What types of processes can be reviewed?

A scope may address purchasing and payments, vendor changes, payroll changes, billing and collections, inventory processes, the financial close, access and approvals, or selected policy-adherence questions within the firm's accounting and business-process expertise. The work does not determine whether fraud occurred or provide legal or regulatory conclusions.

How is the scope selected?

We consider the reason for the review, the process involved, management's concerns, relevant risks, who will receive the report, available information, timing, and the company's existing resources. These factors are documented in the engagement scope.

What remains management's responsibility?

Management retains responsibility for the processes and controls under review, the information provided, decisions about recommendations, and the implementation and operation of any corrective actions.

How is the engagement scoped and priced?

We consider the process, number of entities or locations involved, expected volume of information, team participation, reporting requirements, and timing. We then provide a written proposal describing responsibilities, work to be performed, deliverables, schedule, and fees.

Start a conversation

Tell us what process, control, or risk question needs attention.

Share the business area, reason for the review, who will receive the report, and timing. We review each inquiry and generally respond within one business day with the appropriate next step.

Tell Us About Your Business