Build a risk practice without building a risk department
Internal audit, SOX testing, ERM and forensic capability available by the seat. Take on risk engagements you would otherwise have to decline.
What we handle
The full scope, grouped the way your engagements are actually structured.
Internal audit
- Risk assessment
- Audit planning
- Control testing
- Walkthroughs
- Deficiency documentation
- Remediation tracking
SOX and compliance
- Scoping
- Narrative and flowchart preparation
- Control testing
- Management testing support
- Compliance framework mapping
Investigation
- Forensic investigations
- Fraud risk assessment
- Financial risk management
- ERM framework design
Roles you can hire
Every seat is a named professional who works an overnight shift against your business day and reports into your team. You interview them before they start. On an FTE, that person is dedicated to your firm alone.
| Seat | What they own | Typical profile |
|---|---|---|
| Internal Audit / SOX Seat | Control testing, walkthroughs, deficiency documentation, remediation tracking | 4–8 yrs, CA / CIA |
| IT Audit / SOC Seat | ITGC testing, SOC 1 and SOC 2 readiness and fieldwork support, evidence collection | 4–8 yrs, CISA |
| Audit Senior Seat | Engagement section ownership, planning support, review of associate work | 5–8 yrs, CA / ACCA |
Software we work in
Yours. Your team starts fluent because we implemented these platforms before we staffed them.
Plus your client’s ERP for control testing: NetSuite, Sage Intacct, Microsoft Dynamics and the QuickBooks family.
How the engagement works
From first call to productive team in about four weeks.
Scoping call
We map the roles, volumes, software and review model. You leave with a written recommendation, whether or not you proceed.
Team match
Shortlisted profiles with credentials and relevant experience. You interview. You choose. Nobody is assigned without your approval.
Security & access
MSA and individual NDAs executed, background verification confirmed, access provisioned through your controls with MFA and least privilege.
Ramp
Risk seats ramp against a live engagement. Your seat prepares walkthrough documentation and test workpapers under review, then takes ownership of a control area. Because the deliverable is documentation, quality is visible from week one rather than at the end.
Steady state
Weekly check-in, monthly performance review, quarterly capacity planning. Scale up for busy season, scale back after. Thirty days’ notice, either direction.
Your client data never leaves your environment
Work happens inside your systems through a hardened virtual desktop or your VPN. No local downloads, no data at rest offshore, no shadow copies. Every team member is background-verified and signs an individual confidentiality agreement. Access is least-privilege and MFA-enforced.
Read the full security posture →Questions about risk & internal audit
Can they run a SOX engagement end to end?
Do they have CIA or CISA credentials?
We don’t have a risk practice yet. Can we still take this on?
How is this different from a staffing agency?
Find out what your firm could take on with two more people.
Thirty minutes. We map your roles, volumes and software, and you leave with a written recommendation on team structure. No obligation, and no pitch deck.
Firms who use this also use
