Discuss your scope
Prague • Remote-first • 2–3 days/week

Technology Risk & ITGC testing — evidence-first, reviewer-ready

I help audit teams and CFO orgs get defensible ITGC results with a controlled, reviewable approach: structured testing, reviewer-ready workpapers, and exception-focused reporting. When it makes sense, I add lightweight automation and analytics for repeatable sampling and evidence QC.

ACCA-qualified • ex-PwC / BDOReviewer-ready workpapersAutomation when valuable

Stream 1 — ITGC testing that stands up in review

Full lifecycle coverage — provisioning through termination, change approvals through CI/CD, backups through DR — tested with clear criteria, traceable evidence, and conclusion logic your reviewer can follow fast.

Access & SoDChange & CI/CDIT Ops & DRException remediation

Stream 2 — Automation & analytics (optional)

Reproducible sampling, access/change analytics, role diffs, and evidence completeness checks — designed to reduce manual effort while staying auditable.

Reproducible samplingAccess/change analyticsEvidence QC

Powered by ITGC Factory

Not spreadsheets. A purpose-built platform I designed and developed for ITGC engagements — enforcing methodology through workflow gates.

  • Evidence-First AI (no evidence = inconclusive)
  • AICPA/PCAOB sampling (risk-based, reproducible)
  • Professional-grade export (13-section workpaper pack)
  • 26 control templates (Access, Change, IT Ops, Security)

Trust layer

You always know where evidence lives, what I retain (typically nothing), and how confidentiality is handled. NDA-ready.

  1. 1Scope call
  2. 2Proposal
  3. 3Execution
  4. 4Reviewer-ready pack

A clean engagement flow

Quick scope call → crisp deliverables → reviewer-friendly pack.