Internal controls and IT audit review
Independent review of your IT general controls, application controls and technology processes — delivered as specialist support to your internal audit function, or as a standalone controls review for management. Findings ranked by what actually matters, and a remediation plan your team can work through.
Three situations
Who we work with
Internal audit functions without technology depth
Chief audit executives and internal audit teams — often one to five people — whose audit plan includes technology, cyber, or AI coverage the team doesn’t have the specialist capacity to deliver. We work under your direction, to your methodology, as your co-source or outsource arm for technology audits.
Management teams who want the truth before someone else finds it
Executives who want an honest, independent read on their IT controls ahead of a regulatory exam, an external audit, a client assessment, or a financing round — while there’s still time to fix what turns up.
Audit committees and boards of smaller regulated firms
Credit unions, portfolio managers, MICs and insurers whose audit committee needs technology audit coverage to discharge its oversight duties, but whose scale doesn’t justify a permanent IT audit hire.
Why firms call us
You’re probably here because of one of these.
- Your internal audit plan has “IT general controls,” “cyber,” or “AI” on it, and no one on the team can execute those reviews credibly.
- Your external auditor’s ITGC work keeps generating deficiencies, and management wants an independent view of the control environment before next year’s cycle.
- A regulatory exam is scheduled and you’d rather find the problems yourself, first.
- Your audit committee asked when technology was last audited, and the answer was uncomfortable.
- A client’s audit rights clause is being exercised, or a SOC report request landed, and your controls have never been independently assessed.
- Something went wrong — an outage, a change gone bad, an access incident — and leadership wants to know whether it was bad luck or bad controls.
An independent review you commissioned reads very differently from a finding someone else issued. Cheaper, too.
What we deliver
Where we help
IT general controls review
Access management, change management, IT operations, and program development controls — assessed for design and operating effectiveness against your framework or a recognized baseline. The review your external auditor’s findings suggest you need, done deeply enough to fix causes rather than symptoms.
Application and automated controls review
The controls inside the systems your business runs on: configuration, interfaces, automated calculations, workflow approvals, and the report logic management relies on. Including the input-processing-output reviews that catch what ITGC work alone misses.
Internal audit co-sourcing and outsourcing
Technology, cyber and AI audit execution under your CAE’s direction and methodology — planning, fieldwork, working papers, findings and reporting in your house style. Your function keeps ownership and sign-off; we supply the specialist depth. Also available as full outsourced delivery of the technology portion of your audit plan, or as quality review of technology audit work performed by others.
AI and model audit support
Audit programs and execution support for reviews of AI governance, model risk management and automated decision systems — the coverage audit committees are beginning to ask for and few internal audit teams can yet staff. Builds directly on our AI governance advisory practice.
Pre-examination and pre-audit readiness reviews
A dry run before the real thing: regulatory exam, external audit, client assessment, or SOC examination by your service auditor. We review against the ruler that’s coming, so the findings are yours to fix quietly rather than theirs to report formally.
Post-incident control reviews
After an outage, a failed change, or an access incident: what failed, whether it was control design or operation, and what to change so the answer to “could it happen again?” is credible.
Remediation validation
Independent confirmation that closed findings are actually closed — the evidence-based follow-up that lets internal audit, the audit committee, or a regulator retire an issue with confidence.
Engagement shapes
Typical engagements
Focused controls review
One domain done properly — access, change, a critical application, or a specific process. The usual entry point when a particular finding or incident is driving the need.
Full ITGC review
The complete IT general controls environment, design and operating effectiveness, with risk-ranked findings and a sequenced remediation plan.
Annual technology audit plan delivery
We deliver the technology audits on your internal audit plan each year, under your methodology, with working papers that stand up to external inspection of your function.
Pre-exam readiness review
Assessment against the specific ruler that’s coming — B-13, your external auditor’s ITGC scope, a client’s control schedule, or a SOC examination — timed so findings can be fixed before it arrives.
Fluency, not jargon
Standards and frameworks
Audit practice
- IIA International Professional Practices Framework (Global Internal Audit Standards)
- ISACA IT audit frameworks and practice guidance
Control reference points
- COBIT 5
- COSO Internal Control — Integrated Framework
- ITGC and application control baselines
- SOX 404 / ICFR, where applicable
Regulatory rulers we review against
- OSFI B-13 and B-10
- OSFI E-23, for model and AI reviews
- Provincial regulatory expectations, as applicable
Our founder holds the CISA and CFSA designations — ISACA’s information systems audit credential and the IIA’s financial services audit credential — and has led or delivered well over fifty technology audit and controls engagements across financial services.
Why Hosmak
Reviewed by someone who has sat on every side of the finding.
Findings land differently depending on who writes them. A finding written by someone who has only ever audited reads as a checklist exception. A finding written by someone who has also owned controls — who has been the remediation owner explaining a slipped date to a governance committee — reads as something a reasonable person should fix, sequenced by what actually matters.
Our founder started in IT audit — leading a bank’s internal IT audit unit, then over a decade of Big 4 practice at PwC and EY managing more than fifty engagements: ITGC audits, application controls reviews, IT risk assessments, regulatory compliance reviews and SOX programs for financial services clients. Then nearly ten years inside one of Canada’s five largest banks on the other side of the table: building the control frameworks auditors tested, directing design-effectiveness testing across an enterprise control library, and independently challenging remediation owners at governance committees.
For your internal audit function, that history means working papers your external assessor won’t pick apart. For your management team, it means findings ranked by risk rather than by ease of detection, and remediation advice from someone who has actually had to operate the fixes.
Credentials
- FCA (Nigeria) — see designation note
- CISA
- CRISC
- AAIR
- CFSA
- COBIT 5 Accredited
Questions
Common questions
Is this an external audit? Will we get an audit opinion?
No — and the distinction matters. We provide internal audit services and controls reviews for management and internal audit functions. We do not perform external audits, issue assurance opinions, or provide public accounting services. If you need a financial statement audit or a SOC report, that comes from a licensed public accounting firm — and we’re happy to get you ready for them and work alongside them.
Our external auditor already tests ITGCs. Why would we need this?
Their testing serves their financial statement opinion: scoped to what’s material to the financials, timed to their cycle, and reported as exceptions. A management-commissioned review serves you: scoped to your risks, timed to your needs, and reported with root causes and a fix sequence. The two are complements — and this work typically makes their work go better.
Can you work under our internal audit methodology?
Yes — that’s the default for co-source work. Your templates, your risk assessment approach, your reporting format, your QA process. The work belongs to your function; we’re the specialist capacity inside it.
How do you maintain independence if you also do advisory work?
By not reviewing our own work. Where we’ve designed or built something in an advisory capacity, we don’t subsequently provide the independent review of it — and we’ll flag the conflict before you do. For everything else, the review is delivered with the same independence discipline the IIA standards require.
What do we get at the end?
A findings report ranked by risk with root causes, not just exceptions; a sequenced remediation plan; working papers that support every finding; and a closing session where we walk your team through all of it. For co-source work, deliverables land in your function’s format under your CAE’s sign-off.
How disruptive is fieldwork?
Less than an external audit. We work from documentation and evidence requests first, interview second, and observe only where necessary. Expect focused hours from control owners, not weeks of shadowing.
Hosmak Solutions provides internal audit services and controls reviews for management and internal audit functions. We do not perform external audits, issue assurance opinions, or provide public accounting services.
Start with a conversation
Bring the audit plan, the finding, or the exam notice. Thirty minutes, no cost, and you’ll leave knowing what a sensible scope looks like — whether or not you work with us.
Book a 30-minute consultationOr email hello@hosmaksolutions.ca