Controls & assurance
IT audit & governance
Control environments assessed against the framework you are actually held to, not a generic maturity model. Findings written so that the remediation owner knows what to do on Monday morning.
In scope
- Control design and operating effectiveness review
- Pre-audit readiness and gap assessment
- Third-party and vendor risk review
- Access, change, and segregation-of-duties testing
- Remediation plans with named owners and dates
Out of scope
- Signed attestation or certification opinions
- Building or operating the controls being reviewed
- Tool selection where a referral fee exists
- Standing in as your security function