From the first call to a letter your committee can file.
This is the sequence we use for an application financial audit. Control testing, lineage reviews, and pre-submission work follow the same spine, shortened to the window you give us.
Scoping conversation
You name the platform, the report it produces, the legal entity, and the period. We say whether the work fits, what we will not do (implementation, statutory opinion on the financial statements, vendor certification), and what access we need. If it fits, we send a scoping letter with fee, timing, and a request list.
Request list and freeze
You return organisation charts for report owners, a list of production runs in the period, and a way to obtain extracts. We agree a freeze date for report definitions where the cycle allows it. Missing documents are noted; we do not invent them.
Fieldwork on the run
Sampling is of actual report runs, not reconstructed demos. We trace selected lines, test access and change around the freeze, and read overlays against tickets. Farid keeps the request log current so finance is not answering the same question twice.
Findings, then the letter
Draft findings go to the report owner for factual check. The signed letter states the scope, the opinion on the application for the named reporting purpose, and a ranked schedule. Remediation verification is a separate letter after you confirm a fix is live.
We store a single preference on this device so the banner does not return every visit. No advertising cookies. Read the cookie note.