Technology Risk & ITGC testing — evidence-first, reviewer-ready
I help audit teams and CFO orgs get defensible ITGC results with a controlled, reviewable approach: structured testing, reviewer-ready workpapers, and exception-focused reporting. When it makes sense, I add lightweight automation and analytics for repeatable sampling and evidence QC.
Stream 1 — ITGC testing that stands up in review
Full lifecycle coverage — provisioning through termination, change approvals through CI/CD, backups through DR — tested with clear criteria, traceable evidence, and conclusion logic your reviewer can follow fast.
Stream 2 — Automation & analytics (optional)
Reproducible sampling, access/change analytics, role diffs, and evidence completeness checks — designed to reduce manual effort while staying auditable.
Powered by ITGC Factory
Not spreadsheets. A purpose-built platform I designed and developed for ITGC engagements — enforcing methodology through workflow gates.
- Evidence-First AI (no evidence = inconclusive)
- AICPA/PCAOB sampling (risk-based, reproducible)
- Professional-grade export (13-section workpaper pack)
- 26 control templates (Access, Change, IT Ops, Security)
Trust layer
You always know where evidence lives, what I retain (typically nothing), and how confidentiality is handled. NDA-ready.
- 1Scope call
- 2Proposal
- 3Execution
- 4Reviewer-ready pack
A clean engagement flow
Quick scope call → crisp deliverables → reviewer-friendly pack.