SHAHEER.
All services

The internal audit that is not about the books

Who has access, what changed, which vendors hold your data, and whether the backup restores.

Talk to an expert How we work

Who still has access?

Three numbers you already know and one answer. It updates as you type.

When somebody leaves, what happens

Accounts to check

First move

Start with how many systems hold company or customer data.

In short

Most internal audit writing is about the accounts. This one is about the systems: who still has access after leaving, what changed last quarter and who approved it, which vendors hold your data, and whether anyone has restored a backup. Four checks on a schedule, producing most of the evidence a buyer or an insurer asks for.

Work it out in a minute

Where is your business losing value? →

Nine questions across revenue, capacity and control. Shows which of the three is costing you most, and where to start.

What we take on

Access, quarterly

Every system, every account, matched against the people who still work here. Leavers keep access longer than anyone assumes, and it is the finding that turns up in almost every first pass.

Change, with a name against it

What changed last quarter, who asked, who approved, and what happened after. Not process for its own sake. The record is what turns a bad week into a short one.

Vendors who hold your data

A list, what each one holds, who owns the relationship, when it renews, and what happens to the data if you leave. The list is usually longer than anyone expects.

A backup somebody has restored

A backup nobody has restored is a file. One restore to a spare location tells you whether the rest of it is real.

Evidence kept as you go

Screenshots, tickets, approvals and dates, collected while the work happens rather than assembled the week a buyer asks. It is the difference between a two day answer and a two week scramble.

Run from outside the team

The person who set a system up is the last to notice what it is missing. An outside pass finds the ordinary things quickly and costs nobody internally a week.

Why this one is worth running

Search internal audit and you get the accounts: bookkeeping, reconciliations, tax exposure. That work matters and somebody else does it. The audit that catches companies this size is the one nobody owns, because it sits between the person who runs the systems and the person who signs the contracts.

The four checks are ordinary. Access, change, vendors, restore. None needs a framework and none takes a week. What they need is a date in the calendar and a name against each, which is the part that never happens on its own.

The payoff is rarely the audit itself. It is the day a customer sends a security questionnaire, an insurer asks how access is controlled, or an investor asks who can move money. Companies running these four answer in two days.

Access is where the first pass almost always lands. Somebody left and kept a login. A shared account has no owner. A contractor from last year is still in the repository. None of it is malicious and all of it is what an auditor, an insurer or an attacker looks at first.

Change control sounds heavy and does not have to be. One line per change: who asked, who approved, what it touched. Written down, it turns "the site broke and nobody knows why" into a five minute answer.

If ISO 27001 or SOC 2 is anywhere in your future, this is the same work with a different cover on it. If neither ever happens, you still get the questionnaire answered in two days and a restore you have watched with your own eyes.

Questions we get

Is this a financial audit?

No. This is systems and operations: access, change, vendors and backups. A financial audit looks at the books and needs an accountant. Neither one covers the other.

How long does the first one take?

A week where there are a handful of systems, longer where nobody has a full list of what is running. Most of that time goes into assembling the inventory, which is why the second round is much faster than the first.

How often should it run?

Access quarterly, because leavers and role changes happen continuously. Vendors and backups twice a year. Change control is continuous by nature, and the audit is a read on whether the record was kept.

Do we need a tool for this?

A spreadsheet is fine for the first two rounds and it is the honest answer for most companies this size. Buy a tool once the list of systems is long enough that maintaining the spreadsheet is itself the work.

What comes out of it?

A list of findings with a name and a date against each, worst first, and an evidence pack that answers most of a customer security questionnaire. Written to be handed to somebody rather than interpreted.

Can you run it, or only set it up?

Either. Some companies want the first pass done and the process handed over. Others want it run on a schedule from outside so nobody internally has to hold it.

More in the guides and every answer in one place.

Services
Fractional operations Operations assessment AI strategy Process automation Website development App development SEO and search traffic Lead generation PR and billboards Legal operations Business notices Business documents
Who does the work

Shaheer leads the work, with engineers, writers, filers and analysts behind him. C-suite operations for a San Francisco AI company, Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. See what we have built

Tell us what you are working on

Building, fixing or improving something. A rough question is enough to start.

A person replies within one business day. Or pick a time, or [email protected]