Audits & compliance

Sooner or later, somebody asks you to prove it.

A client, an insurer, a funder, a regulator, a board, or the firm buying your business. We do the audit, produce the evidence, and write the report in language the person asking can actually read.

The email this is for

Please complete the attached and return it by the end of the month.

It runs to four pages. It asks whether every account uses multi-factor authentication, how often you test restores, who has administrator access, where your data is stored, when staff last had security training, and what your incident response plan says. It was written by somebody who assumes you have an IT department.

Answering it wrongly is worse than not answering it. Guessing on an insurance form can void the cover. Overstating on a client questionnaire is a contractual problem later. And the honest answer to several questions is often “I do not know”, which nobody wants to write down.

Three reasons people call

Which one is yours?

Someone is auditing you

There is a deadline attached

An insurer at renewal, a client running a vendor review, a funder before releasing money, a regulator, or an acquirer doing due diligence. Somebody external has asked, and there is a date on it.

This is the most common way people arrive here, and usually the most urgent.

You want to know first

Before anybody else tells you

No deadline, just a sensible instinct that you would rather find the gaps yourself than have a client find them. Often prompted by a near miss, a new contract, or a competitor’s bad week making the news.

Far cheaper than the version where somebody else sets the timetable.

Your board needs a report

Written for people who are not technical

Directors carry real duties around risk, and “our IT guy says it is fine” does not discharge them. What a board needs is a short, honest, comparable report they can minute.

Common for charities, family offices, professional firms and anyone with a funder.

What an audit produces

Six things you keep, whatever you decide next.

Deliverables, not a conversation. If you walk away afterwards, all of this is still yours.

Where you actually stand

  • Every system, account and device found and listed
  • Checked against a named framework, not our opinion
  • Written in plain language, with the jargon in an appendix
  • Including the things nobody mentioned because everyone stopped noticing

The evidence file

  • Screenshots, settings and records that back each answer
  • Organised against the questions people actually ask
  • Dated, so its age is visible rather than assumed
  • Reusable for the next questionnaire instead of starting again

The gap list, in order

  • What is genuinely exposed, and what merely looks untidy
  • Sequenced by risk reduced per dollar spent
  • Costed, so it can go into a budget
  • Including what can safely wait, said out loud

The board summary

  • One page, written for directors rather than technicians
  • Risk framed as business consequence, not vulnerability count
  • A clear position you can minute and act on
  • Comparable to the next one, so trend is visible

The questionnaire answers

  • The actual form you were sent, completed
  • Honest answers, with the uncomfortable ones flagged first
  • Wording checked so nothing overstates your position
  • A note of what would turn each no into a yes

The re-check

  • Once the fixes are done, we confirm they actually took
  • The evidence file updated rather than rewritten
  • A repeat on whatever cycle your obligations need
  • Trend across audits, which is what boards ask for

Third-party audits

When somebody else is doing the auditing, we answer for you.

An external auditor arrives with their own checklist and their own language. They want evidence in a particular form, they ask follow-up questions, and an answer that is technically true but badly worded turns into a finding.

We act as the technical respondent. We sit in the meetings, produce what is asked for in the form it is asked for, and push back where a finding is wrong or where a recommendation does not fit a business your size. Your staff should not have to learn audit language to get through this.

That works whether we look after your IT or not. If you have your own provider, we can respond alongside them.

  • Insurer and broker reviews
  • Client and vendor security assessments
  • Funder and grant requirements
  • Due diligence before a sale

Nonprofits and charities

Funders ask harder questions than clients do.

And they ask them of organisations with the least capacity to answer, which is a real problem rather than an unfair one.

What funders and grant bodies want

  • How donor and client information is protected, specifically
  • Who has access to the database, and how that is reviewed
  • Whether the financial system has proper separation of duties
  • What happens if the data is lost, and whether that has been tested
  • Evidence rather than assurance, increasingly

What a charity board needs

  • A report a volunteer director can read in ten minutes
  • Risk described as consequence, not as technical findings
  • Something that can be minuted and returned to next year
  • An honest position, including where the answer is not yet good
  • Costs that reflect a charity budget, not a corporate one

The people holding the most sensitive information in a small charity are often volunteers, working from their own devices, with no IT function at all. An audit that ignores that reality produces a report nobody can act on. More on how we work with nonprofits →

Board and governance reporting

A report your directors can act on.

Most technology reporting to boards fails in one of two directions. It is either forty pages of findings nobody reads, or a verbal assurance that everything is fine, which is not evidence of anything.

What is in it

Where the organisation stands against a named framework. The three or four risks that genuinely matter, described as what would happen rather than what is technically wrong. What changed since last time. What is planned, and what it costs.

What is not in it

Vulnerability counts, product names, and severity scores that mean nothing outside a technical context. If a director cannot decide something from a line in the report, that line does not belong in it.

Why it repeats

A single report is a snapshot and tells a board very little. The same report, produced the same way each year, shows direction. Direction is what a board is actually being asked to oversee.

Included, not extra

Two ways to get this.

If we look after your IT

Part of the agreement

For fully managed and co-managed clients, this is included rather than quoted separately. The controls get checked at your regular review, the evidence stays current, and when a questionnaire lands we work through it with you.

Which means the answer to most audit requests already exists, rather than being assembled in a fortnight of panic.

If somebody else does

A project on its own

You do not have to be a client, and a fair amount of this work is for businesses who already have an IT provider or their own IT person. Scoped and priced before it starts, like any other project.

Being independent of whoever built the environment is sometimes the point, particularly for a board or a buyer. How project work runs.

What we audit against

Named standards, not house preferences.

The technical side

The CIS Controls, a prioritised list of safeguards ordered by what prevents the most damage, grouped so a small organisation starts at the first group and grows into the second. The NIST Cybersecurity Framework supplies the structure: identify, protect, detect, respond, recover.

Using a named framework matters for a practical reason. When an auditor or a board asks what you were measured against, there is an answer with a name on it.

The legal side

PIPEDA federally and PIPA in British Columbia, both of which carry obligations most businesses are surprised to learn apply to them. GDPR where you hold information about people in Europe. Alongside those, whatever your contracts, professional body or insurer require, which is often stricter.

We are not a law firm and we will not certify you as compliant. We build the technical and evidence side so your lawyer has something to work from.

Questions we get asked

The things owners actually want to know.

Pulled from the central library, tagged for this page. All questions and answers →

Can you audit us if you are also the ones running our IT?
Audits

We can, and we will tell you where that is and is not appropriate. Ongoing control checks and questionnaire responses are fine. Where a board, a funder or a buyer specifically wants independence, they should have it, and we will say so and help you find someone rather than take work we should not.

What if the audit finds something bad?
Audits

You will hear it from us first, privately, with a plan attached rather than just a finding. Almost every audit turns up something, and the ones that do not usually mean the audit was not thorough. Knowing about it is the entire point.

Our insurer sent a questionnaire and we cannot answer half of it.
Audits

Common, and it is a sensible reason to call. We go through it question by question, establish which answers are genuinely yes today, and deal with the ones that are not. Do not guess on that form. An inaccurate answer can void the cover you are paying for.

How long does an audit take?
Audits

For a small business, usually a couple of weeks from starting to a report in your hands, and very little of that is your staff’s time. If you are working to somebody else’s deadline, tell us the date at the first conversation and we will say honestly whether it is achievable.

We are a charity with a volunteer board. Is this affordable?
Audits

Registered charities and nonprofit organisations may qualify for better rates, so it is worth asking. The scope also tends to be smaller than a commercial audit, and a great deal of what a funder wants can be answered without a full engagement. Ask, and we will tell you what you actually need.

Send us the form you have been given.

Half an hour, no charge. We will read it, tell you which answers you can already give, and be honest about the rest.

Would rather write?

Send this and we will reply, usually the same business day. No call unless you want one.

  • This field is for validation purposes and should be left unchanged.

Protected by reCAPTCHA.