Portfolio / Expertise / Audit & Internal Controls
Audit & Internal Controls
An audit that stops at verification is a report; an audit that reaches root cause is a control improvement. I bring the lens forged at Deloitte — 45+ files a day, every discrepancy traced to its source — so audits strengthen the process instead of just satisfying the standard.
The Workflow — How I Approach It
Think like the auditor
Start from what a reviewer would challenge — not from what the template asks.
Map the process and the controls
Trace each process to the control designed to catch its errors — and find the gaps between them.
Trace discrepancies to root cause
Never flag-and-move-on. Ask which control failed and why the figure sits where it does.
Document so logic is followable in seconds
Supporting schedules organized so a senior reviewer can trace the logic without asking.
Close and remediate
Turn each finding into a fix that prevents recurrence — not a record of weakness.
My Operating View — The 2 Cents
Controls exist to prevent errors, not to catch them later. My 2 cents: the value of an audit is in the why, not the tick. When volume is high, the discipline that survives is curiosity under deadline — checking the box is easy; asking what failed is the job.
What Worked & What Didn’t
What Worked
- Root-cause tracing turned findings into process fixes clients could act on.
- Audit-ready documentation built in advance made reviews rework-free.
What Didn’t
- Checklist audits — pass the standard, learn nothing about the system.
- Flagging discrepancies without asking why — the same error recurs next year.