Common questions

What institutions ask us first.

The engagement

Who actually performs the audit?
Both partners. Testing, workpapers, conversations, and the audit committee presentation are done by Brody and Jason directly. Nothing is delegated to a first-year associate or an overseas team.
Do you replace our internal audit function, or work alongside it?
Either. Fully outsourced, where we are the internal audit function, or co-sourced, where we take specific areas alongside the internal auditor you already have. Institutions with one internal auditor often co-source the specialty work such as IT, BSA, and compliance testing, and keep non-complex operational audits in house.
How long does an engagement take?
Fieldwork closes the same week it starts, with a draft report shortly after. We scope tightly and request documents before fieldwork begins, so the time on site or remote is spent testing rather than waiting on document requests.
We are mid-year with another firm. Can we still switch?
Yes. We review what has already been completed against your approved audit plan, confirm the coverage that still remains for the year, and pick up from there. Nothing is re-tested for the sake of it.
Can we speak with a reference?
Not yet. We are a new firm. What we can do instead is walk you through our methodology in detail, and the engagement experience both partners bring from prior firms.
What do you need from us to start?
Your institution size, the areas on this year’s audit plan, and when your audit committee meets. That is enough for a written scope and a fee. Once the scope is agreed, we send an engagement letter and request list well ahead of fieldwork.

Fees

How are fees set?
We start with your institution’s scope, timing, and audit priorities, then provide a clear proposal and agreed fee before work begins. The engagement structure is tailored to the work and support your team needs.
Why are your fees lower than larger firms?
We do not carry the cost structure of a national firm: regional offices, a large recruiting pipeline and sales organization, overseas offices, or private equity ownership. The partners you meet perform the work directly, and that fundamentally smaller cost structure shows up in our fees.
How do you keep engagements efficient?
You work directly with the partners leading the engagement. We keep the team focused, use practical technology where it helps, and design the work around your institution’s actual risks rather than a one-size-fits-all program.

Standards and independence

What standards do you work to?
The Institute of Internal Auditors’ International Standards for internal audit work, the FFIEC IT and BSA Handbook, FDICIA and SOX requirements for internal control over financial reporting, and audit procedures and scopes pulled directly from the OCC, FDIC, FRB, and NCUA examiner handbooks. We also follow the AICPA’s Statements on Standards for Attestation Engagements (SSAEs) for agreed-upon procedures and other attestation work. Workpapers, issue tracking, and committee reporting are prepared to be handed directly to your regulator, so you can be confident that the work meets the expectations of your examiners.
Is any of the work outsourced or performed offshore?
No. Every engagement is led and performed by a partner you have met. Nothing is subcontracted and nothing leaves the firm.
How do you handle independence?
Under the FDIC Independence Rule, we maintain strict independence from management and any parties that could impair our objectivity. We work directly with your internal audit team, CRO, Audit Committee, and those charged with governance to scope and execute our audit work.
Do you carry professional liability insurance?
Yes. We carry professional liability, general liability, and cyber insurance, and will provide certificates of insurance on request.

Documents and access

How do we send you documents?
Through the secure client portal, you get a sign-in, see every document we have asked for in one list, and upload each file to the request it answers, so nothing gets lost in a thread. Reports come back the same way. Nothing sensitive moves as an email attachment.
How is our information protected?

Documents are uploaded directly into our Microsoft Azure environment. You sign in with your own work email through Microsoft Entra External ID, so we never issue or hold a password for you. Files are encrypted in transit and at rest, and are accessible only to the two partners and the people you authorize at your institution.

We do not keep client documents on personal devices, and we do not use consumer file-sharing services.

Still have a question?

Ask a partner directly. We answer our own email.

Get in touch