Risk & scope definition
Clarify the reason for the review, understand the selected process, identify relevant risks and controls, establish responsibilities, and agree on reporting expectations.
Understand gaps in approvals, access, or oversight and prioritize practical improvements. Support may address a selected process or add capacity to an internal-audit program.
Prefer to call about becoming a client? (631) 677-1344
When responsibilities are concentrated or approvals no longer match the business, a focused review can help management identify the gaps and decide what to address first. An existing internal-audit team may instead need additional capacity for a defined review.
This work is distinct from Audit Readiness, which prepares a company for an external financial-statement audit performed by a separate CPA firm.
To evaluate whether a focused review may fit, read When should a privately held company consider an internal-control review? For one practical process example, see accounts-payable controls for a lean finance team.
Each engagement is defined around the process, business objective, management contact, intended audience for the report, available information, and timing.
Clarify the reason for the review, understand the selected process, identify relevant risks and controls, establish responsibilities, and agree on reporting expectations.
Document the workflow, examine selected approvals, access, records, or transactions, and assess how important controls are designed and applied within the agreed scope.
Discuss preliminary observations with management, prioritize them by importance, and provide written recommendations for management’s consideration.
Review management’s planned responses and, where separately included, follow up on selected actions. Management determines and implements any corrective measures.
A management-directed project addressing one process, control area, or risk question. The deliverable provides observations and recommendations; it does not express an attest opinion or conclusion on control effectiveness.
A defined review or series of reviews for management or governance, including capacity alongside an existing internal-audit function. The reporting line, applicable criteria or standards, responsibilities, and objectivity safeguards are documented before work begins.
Work may be scoped as nonattest controls consulting for management or as formal or co-sourced Internal Audit for management or a designated governance group. The written engagement identifies the mode, objective, reporting line, responsibilities, deliverables, and any applicable criteria or standards.
Before accepting the work, we consider current and recent firm responsibilities and other relationships that could affect objectivity. Areas that would create an unacceptable impairment are excluded; other potential impairments and safeguards are addressed in the written scope.
Neither mode produces an external financial-statement audit, review, compilation, or other attest report. Management owns the processes and controls under review and remains responsible for corrective action.
Agree on the business question, process, management contact, intended audience for the report, timing, and scope.
Review relevant documents, discuss responsibilities with designated team members, and document the workflow and important controls.
Review the approvals, access, records, or transactions included in scope and discuss preliminary observations with management.
Provide a written report describing the work performed, observations, priorities, recommendations, and management responses where requested.
When informal approvals no longer match the company’s size or payment volume, a focused review can map purchasing and payment workflows, examine vendor changes, approvals, and access rights, and identify segregation-of-duties gaps. Management receives prioritized observations and practical recommendations for deciding what to address first.
It may be scoped as nonattest controls consulting for management or as formal or co-sourced Internal Audit for management or a designated governance group. The written scope identifies the engagement type, objective, reporting line, responsibilities, deliverables, applicable criteria or standards, and any objectivity safeguards.
Formal or co-sourced Internal Audit serves management or a designated governance group through reviews of selected processes, risks, and controls. Nonattest controls consulting addresses a defined management question. Neither is an external financial-statement audit, which John W. Halloran CPA, P.C. does not perform.
Yes. We can provide co-sourced capacity for a defined review or series of reviews while the company's internal-audit, finance, or governance-led team retains its existing responsibilities.
A scope may address purchasing and payments, vendor changes, payroll changes, billing and collections, inventory processes, the financial close, access and approvals, or selected policy-adherence questions within the firm's accounting and business-process expertise. The work does not determine whether fraud occurred or provide legal or regulatory conclusions.
We first define whether the need is nonattest controls consulting or formal or co-sourced Internal Audit. We then consider the reason for the work, process involved, management's concerns, relevant risks, reporting line and audience, applicable criteria or standards, current and recent firm responsibilities, available information, timing, and the company's existing resources. These factors are documented in the engagement scope.
Management retains responsibility for the processes and controls under review, the information provided, decisions about recommendations, and the implementation and operation of any corrective actions.
We consider the process, number of entities or locations involved, expected volume of information, team participation, reporting requirements, and timing. We then provide a written proposal describing responsibilities, work to be performed, deliverables, schedule, and fees.
Share the process or concern and any timing that matters. We’ll discuss what kind of review may fit.
Discuss Controls or Internal Audit