Skip to main content
    How we work

    How AuditPartners Assesses and Tests Controls

    Our assessment process connects each conclusion to an agreed scope, relevant evidence and documented procedures. AI-assisted work supports preparation and analysis; qualified professionals review the evidence, challenge exceptions and approve engagement conclusions.

    A defined engagement, not an open-ended programme

    Assess → Test → Report → Recommend

    A smaller team may need a focused workflow review. A larger organization may need multiple systems or deeper sampling. In either case, the procedures and evidence requirements follow the question and risk, and are agreed before the work begins.

    1. 01Assess

      Inputs
      Your assurance question, system boundaries, risk concerns, applicable criteria and available documentation.
      Activities
      Understand the workflow and risks; agree scope, period, exclusions, evidence handling and the depth of testing.
      Outputs
      A scope memo, assessment plan and evidence request list.
      Who decides
      The engagement professional proposes the scope and procedures; the client agrees the engagement boundaries and identifies evidence owners.
    2. 02Test

      Inputs
      Relevant policies, system configuration, approvals, logs and other records for the agreed period.
      Activities
      Inspect evidence, perform documented procedures, select agreed samples and investigate exceptions. Keep design, implementation and operation distinct.
      Outputs
      Procedure records, evidence references, sample results, exceptions and explicit evidence gaps.
      Who decides
      The engagement professional evaluates evidence sufficiency, challenges explanations and determines what the procedures support.
    3. 03Report

      Inputs
      Test results, criteria, exceptions, contextual explanations and evidence limitations.
      Activities
      Develop findings, discuss factual accuracy with evidence owners and document the basis and limits of each conclusion.
      Outputs
      A scoped report with classified findings, evidence references and limitations.
      Who decides
      The responsible engagement professional reviews and approves conclusions. Management can clarify facts but does not replace professional judgment.
    4. 04Recommend

      Inputs
      Findings, risk context, dependencies and management priorities.
      Activities
      Develop practical recommendations, distinguish immediate evidence needs from control changes and discuss next steps in a closing readout.
      Outputs
      Prioritized recommendations and suggested owners for management consideration.
      Who decides
      The engagement professional owns the recommendations; client management decides which actions to take and remains responsible for implementation.

    How evidence is classified

    A written policy, a configured control and a record of successful operation answer different questions. We do not turn self-report or a completed checklist into a tested control conclusion. Evidence gaps and observed failures are also distinguished: missing records may limit a conclusion without establishing what happened.

    Design

    Whether the stated control could address the identified risk if performed as intended.

    Fictional example: A release policy requires an independent reviewer before production deployment; we evaluate the rule and its coverage, not assume it was followed.

    Implementation

    Whether the control has been put in place in the environment reviewed.

    Fictional example: Inspection shows a required review gate configured for the selected repository; configuration alone does not demonstrate its operation throughout the period.

    Operating effectiveness

    Whether the control worked as intended for the period and sample actually tested.

    Fictional example: Sampled releases show the required approval before deployment; the conclusion is limited to those procedures, records and samples.

    Evidence not available (unknown)

    The necessary evidence is missing, inaccessible or insufficient to answer the control question.

    Fictional example: Approval history is unavailable for a selected release; we cannot conclude that approval occurred, even if the policy requires it.

    What AI assistance does and does not do

    Supports the work

    • RiskAssist™ supports preparation and structured evidence organization.
    • Supporting tools help organize control mappings, flag inconsistencies and prepare analysis or draft findings for review.
    • Tool-assisted outputs remain linked to the agreed criteria and source evidence; a draft is not a conclusion.

    Does not replace judgment

    • Qualified professionals inspect evidence, challenge exceptions and assess its sufficiency.
    • Professionals review AI-assisted output and approve the final findings and engagement conclusions.
    • No autonomous audit conclusions, automated attestations or inferred passes for missing evidence.
    Understand the roles of AuditPartners, AIGC™ and RiskAssist™

    Fictional example excerpts only

    Sample deliverables (fictional)

    These original, short excerpts illustrate structure, not completed engagement work. Deliverables are tailored to each agreed scope. Nothing here is client evidence, a tested customer control or a complete proprietary workbook.

    Fictional example

    Scope statement: Northwind Freight Analytics (fictional)

    Review the approval and release controls for one AI-assisted routing application during a fictional one-month period. Inspect the documented release rule and repository gate configuration, and test a selected sample of release approvals against the agreed rule. Exclude model accuracy, other applications and third-party infrastructure. Conclusions apply only to this scope, period and sample.

    Fictional example

    Evidence request row

    Request
    Reviewer approval and deployment timestamp for a selected release.
    Owner
    Application release owner (fictional role).
    Period
    The fictional one-month review period.
    Source
    Repository approval history and deployment log.
    Status
    Requested; not yet received.
    Purpose
    Compare approval time with release time.
    Sensitivity
    Restricted engineering metadata; redact secrets and unrelated personal details.
    Limitation
    A current screenshot alone cannot demonstrate historical approval.

    Fictional example

    Finding: release before independent approval

    Classification: operating-effectiveness exception in the fictional sample.

    Condition
    One sampled release was deployed before the recorded independent approval.
    Criteria
    The fictional organization's agreed release rule requires independent approval before deployment.
    Cause
    The fictional configuration review identified a manual deployment path that did not enforce the approval gate.
    Effect
    An unreviewed change could reach production; this example does not establish an incident or quantify loss.
    Recommendation
    Restrict the bypass path, define any emergency approval procedure and retain records demonstrating that approval precedes release. Test subsequent operation under a separately agreed scope.

    Independence and limitations

    Before agreeing work, we discuss responsibilities and any potential conflicts or limitations relevant to the engagement. We do not presume that a separate certification or attestation requirement is satisfied by an internal assessment.

    AuditPartners is not a certification body or CPA firm. An assessment does not issue a certificate or replace a SOC 2 examination by an independent CPA firm. Findings are not legal advice and do not guarantee compliance or external acceptance.

    Conclusions are limited to the agreed scope, period, criteria, available evidence and tested sample. The separately agreed engagement letter governs the work, responsibilities and deliverables. Where evidence cannot support a conclusion, that limitation is reported rather than concealed.

    Start with the question you need answered

    Agree a proportionate scope, evidence plan and deliverables before the engagement begins.