Audits & compliance
Sooner or later, somebody asks you to prove it.
A client, an insurer, a funder, a regulator, a board, or the firm buying your business. We do the audit, produce the evidence, and write the report in language the person asking can actually read.
The email this is for
Please complete the attached and return it by the end of the month.
It runs to four pages. It asks whether every account uses multi-factor authentication, how often you test restores, who has administrator access, where your data is stored, when staff last had security training, and what your incident response plan says. It was written by somebody who assumes you have an IT department.
Answering it wrongly is worse than not answering it. Guessing on an insurance form can void the cover. Overstating on a client questionnaire is a contractual problem later. And the honest answer to several questions is often “I do not know”, which nobody wants to write down.
Three reasons people call
Which one is yours?
Someone is auditing you
There is a deadline attached
An insurer at renewal, a client running a vendor review, a funder before releasing money, a regulator, or an acquirer doing due diligence. Somebody external has asked, and there is a date on it.
This is the most common way people arrive here, and usually the most urgent.
You want to know first
Before anybody else tells you
No deadline, just a sensible instinct that you would rather find the gaps yourself than have a client find them. Often prompted by a near miss, a new contract, or a competitor’s bad week making the news.
Far cheaper than the version where somebody else sets the timetable.
Your board needs a report
Written for people who are not technical
Directors carry real duties around risk, and “our IT guy says it is fine” does not discharge them. What a board needs is a short, honest, comparable report they can minute.
Common for charities, family offices, professional firms and anyone with a funder.
What an audit produces
Six things you keep, whatever you decide next.
Deliverables, not a conversation. If you walk away afterwards, all of this is still yours.
Where you actually stand
- Every system, account and device found and listed
- Checked against a named framework, not our opinion
- Written in plain language, with the jargon in an appendix
- Including the things nobody mentioned because everyone stopped noticing
The evidence file
- Screenshots, settings and records that back each answer
- Organised against the questions people actually ask
- Dated, so its age is visible rather than assumed
- Reusable for the next questionnaire instead of starting again
The gap list, in order
- What is genuinely exposed, and what merely looks untidy
- Sequenced by risk reduced per dollar spent
- Costed, so it can go into a budget
- Including what can safely wait, said out loud
The board summary
- One page, written for directors rather than technicians
- Risk framed as business consequence, not vulnerability count
- A clear position you can minute and act on
- Comparable to the next one, so trend is visible
The questionnaire answers
- The actual form you were sent, completed
- Honest answers, with the uncomfortable ones flagged first
- Wording checked so nothing overstates your position
- A note of what would turn each no into a yes
The re-check
- Once the fixes are done, we confirm they actually took
- The evidence file updated rather than rewritten
- A repeat on whatever cycle your obligations need
- Trend across audits, which is what boards ask for
Third-party audits
When somebody else is doing the auditing, we answer for you.
An external auditor arrives with their own checklist and their own language. They want evidence in a particular form, they ask follow-up questions, and an answer that is technically true but badly worded turns into a finding.
We act as the technical respondent. We sit in the meetings, produce what is asked for in the form it is asked for, and push back where a finding is wrong or where a recommendation does not fit a business your size. Your staff should not have to learn audit language to get through this.
That works whether we look after your IT or not. If you have your own provider, we can respond alongside them.
- Insurer and broker reviews
- Client and vendor security assessments
- Funder and grant requirements
- Due diligence before a sale
Nonprofits and charities
Funders ask harder questions than clients do.
And they ask them of organisations with the least capacity to answer, which is a real problem rather than an unfair one.
What funders and grant bodies want
- How donor and client information is protected, specifically
- Who has access to the database, and how that is reviewed
- Whether the financial system has proper separation of duties
- What happens if the data is lost, and whether that has been tested
- Evidence rather than assurance, increasingly
What a charity board needs
- A report a volunteer director can read in ten minutes
- Risk described as consequence, not as technical findings
- Something that can be minuted and returned to next year
- An honest position, including where the answer is not yet good
- Costs that reflect a charity budget, not a corporate one
The people holding the most sensitive information in a small charity are often volunteers, working from their own devices, with no IT function at all. An audit that ignores that reality produces a report nobody can act on. More on how we work with nonprofits →
Board and governance reporting
A report your directors can act on.
Most technology reporting to boards fails in one of two directions. It is either forty pages of findings nobody reads, or a verbal assurance that everything is fine, which is not evidence of anything.
What is in it
Where the organisation stands against a named framework. The three or four risks that genuinely matter, described as what would happen rather than what is technically wrong. What changed since last time. What is planned, and what it costs.
What is not in it
Vulnerability counts, product names, and severity scores that mean nothing outside a technical context. If a director cannot decide something from a line in the report, that line does not belong in it.
Why it repeats
A single report is a snapshot and tells a board very little. The same report, produced the same way each year, shows direction. Direction is what a board is actually being asked to oversee.
Included, not extra
Two ways to get this.
If we look after your IT
Part of the agreement
For fully managed and co-managed clients, this is included rather than quoted separately. The controls get checked at your regular review, the evidence stays current, and when a questionnaire lands we work through it with you.
Which means the answer to most audit requests already exists, rather than being assembled in a fortnight of panic.
If somebody else does
A project on its own
You do not have to be a client, and a fair amount of this work is for businesses who already have an IT provider or their own IT person. Scoped and priced before it starts, like any other project.
Being independent of whoever built the environment is sometimes the point, particularly for a board or a buyer. How project work runs.
What we audit against
Named standards, not house preferences.
The technical side
The CIS Controls, a prioritised list of safeguards ordered by what prevents the most damage, grouped so a small organisation starts at the first group and grows into the second. The NIST Cybersecurity Framework supplies the structure: identify, protect, detect, respond, recover.
Using a named framework matters for a practical reason. When an auditor or a board asks what you were measured against, there is an answer with a name on it.
The legal side
PIPEDA federally and PIPA in British Columbia, both of which carry obligations most businesses are surprised to learn apply to them. GDPR where you hold information about people in Europe. Alongside those, whatever your contracts, professional body or insurer require, which is often stricter.
We are not a law firm and we will not certify you as compliant. We build the technical and evidence side so your lawyer has something to work from.
Questions we get asked
The things owners actually want to know.
Pulled from the central library, tagged for this page. All questions and answers →
Related
Often taken alongside this.
Send us the form you have been given.
Half an hour, no charge. We will read it, tell you which answers you can already give, and be honest about the rest.
Would rather write?
Send this and we will reply, usually the same business day. No call unless you want one.
Protected by reCAPTCHA.