Internal Audit

Understand where processes and controls need attention.

Understand gaps in approvals, access, or oversight and prioritize practical improvements. Support may address a selected process or add capacity to an internal-audit program.

Prefer to call about becoming a client? (631) 677-1344

GrowthApprovals, access, or oversight have not kept pace with the business
ConcentrationOne person controls several stages of an important financial process
FocusManagement wants a structured review of a selected process or control area
CapacityAn existing team needs additional support for defined review work
When controls consulting or Internal Audit may be useful

A defined review when controls or capacity need attention.

When responsibilities are concentrated or approvals no longer match the business, a focused review can help management identify the gaps and decide what to address first. An existing internal-audit team may instead need additional capacity for a defined review.

This work is distinct from Audit Readiness, which prepares a company for an external financial-statement audit performed by a separate CPA firm.

To evaluate whether a focused review may fit, read When should a privately held company consider an internal-control review? For one practical process example, see accounts-payable controls for a lean finance team.

Often a strong fit when

  • Approval, access, or documentation practices no longer reflect the company’s size.
  • One person controls several stages of an important financial process.
  • Management wants a structured review of purchasing, payments, payroll changes, billing, inventory, or the financial close.
  • An owner, lender, or governance group expects clearer information about selected controls.
  • An existing internal-audit or finance team needs capacity for a defined project.
  • Management wants recurring reviews organized under an approved plan.
What a scope may include

Examine the selected process and communicate what deserves attention.

Each engagement is defined around the process, business objective, management contact, intended audience for the report, available information, and timing.

Risk & scope definition

Clarify the reason for the review, understand the selected process, identify relevant risks and controls, establish responsibilities, and agree on reporting expectations.

Process & control review

Document the workflow, examine selected approvals, access, records, or transactions, and assess how important controls are designed and applied within the agreed scope.

Observations & recommendations

Discuss preliminary observations with management, prioritize them by importance, and provide written recommendations for management’s consideration.

Follow-up support

Review management’s planned responses and, where separately included, follow up on selected actions. Management determines and implements any corrective measures.

Engagement modes

Define the mode before the work begins.

Nonattest controls consulting

A management-directed project addressing one process, control area, or risk question. The deliverable provides observations and recommendations; it does not express an attest opinion or conclusion on control effectiveness.

Formal or co-sourced Internal Audit

A defined review or series of reviews for management or governance, including capacity alongside an existing internal-audit function. The reporting line, applicable criteria or standards, responsibilities, and objectivity safeguards are documented before work begins.

A defined engagement type

Controls consulting and Internal Audit are separately scoped.

Work may be scoped as nonattest controls consulting for management or as formal or co-sourced Internal Audit for management or a designated governance group. The written engagement identifies the mode, objective, reporting line, responsibilities, deliverables, and any applicable criteria or standards.

Before accepting the work, we consider current and recent firm responsibilities and other relationships that could affect objectivity. Areas that would create an unacceptable impairment are excluded; other potential impairments and safeguards are addressed in the written scope.

Neither mode produces an external financial-statement audit, review, compilation, or other attest report. Management owns the processes and controls under review and remains responsible for corrective action.

How the review works

A documented process from the initial question through reporting.

  1. Define the objective

    Agree on the business question, process, management contact, intended audience for the report, timing, and scope.

  2. Understand the process

    Review relevant documents, discuss responsibilities with designated team members, and document the workflow and important controls.

  3. Examine selected evidence

    Review the approvals, access, records, or transactions included in scope and discuss preliminary observations with management.

  4. Communicate the results

    Provide a written report describing the work performed, observations, priorities, recommendations, and management responses where requested.

When growth exposes a control gap

Purchasing and payment controls have not kept pace with growth.

When informal approvals no longer match the company’s size or payment volume, a focused review can map purchasing and payment workflows, examine vendor changes, approvals, and access rights, and identify segregation-of-duties gaps. Management receives prioritized observations and practical recommendations for deciding what to address first.

Common questions

Before we begin

How can the work be structured?

It may be scoped as nonattest controls consulting for management or as formal or co-sourced Internal Audit for management or a designated governance group. The written scope identifies the engagement type, objective, reporting line, responsibilities, deliverables, applicable criteria or standards, and any objectivity safeguards.

How is Internal Audit different from an external financial-statement audit?

Formal or co-sourced Internal Audit serves management or a designated governance group through reviews of selected processes, risks, and controls. Nonattest controls consulting addresses a defined management question. Neither is an external financial-statement audit, which John W. Halloran CPA, P.C. does not perform.

Can you work alongside our existing team?

Yes. We can provide co-sourced capacity for a defined review or series of reviews while the company's internal-audit, finance, or governance-led team retains its existing responsibilities.

What types of processes can be reviewed?

A scope may address purchasing and payments, vendor changes, payroll changes, billing and collections, inventory processes, the financial close, access and approvals, or selected policy-adherence questions within the firm's accounting and business-process expertise. The work does not determine whether fraud occurred or provide legal or regulatory conclusions.

How is the scope selected?

We first define whether the need is nonattest controls consulting or formal or co-sourced Internal Audit. We then consider the reason for the work, process involved, management's concerns, relevant risks, reporting line and audience, applicable criteria or standards, current and recent firm responsibilities, available information, timing, and the company's existing resources. These factors are documented in the engagement scope.

What remains management's responsibility?

Management retains responsibility for the processes and controls under review, the information provided, decisions about recommendations, and the implementation and operation of any corrective actions.

How is the engagement scoped and priced?

We consider the process, number of entities or locations involved, expected volume of information, team participation, reporting requirements, and timing. We then provide a written proposal describing responsibilities, work to be performed, deliverables, schedule, and fees.

Define the right review

Get clearer visibility into the process or risk that matters now.

Share the process or concern and any timing that matters. We’ll discuss what kind of review may fit.

Discuss Controls or Internal Audit