Review process
From intake call to signed findings pack
A plain map of how App CloudConnect runs an internal controls review so finance teams know when we will be in the building, what we need, and when drafts arrive.
Intake and objectives
We confirm why you want the review—board request, pre-audit calm, or follow-up on last year’s letter—and which cycles sit in scope. You leave with a draft document request list, not a vague “please send everything.”
Preliminary risk notes
Using your org chart, prior letters, and a short reading of policies, we mark where design weaknesses often hide: shared logins, missing secondary reviews, or cut-off blind spots. These notes guide walkthrough agendas; they are not findings yet.
Walkthroughs
Process owners narrate a real transaction from initiation to recording. We ask for screens, stamps, and exceptions. Sticky notes and whiteboard sketches are normal; polished process maps are not required on day one.
Sample testing
We agree attributes and sample sizes in writing, then pull evidence for the period under review. Failures are logged with the document reference so debates stay factual.
Draft findings challenge
Process owners see drafts first. Wording changes for accuracy are welcome; severity debates are documented. This stage keeps the final pack free of surprises that sour board conversations.
Final report and owners
You receive a severity table, narrative for material items, and a working session to assign owners and dates. Remediation support can continue if you want a later retest.
What we need from you
- Access to a knowledgeable process owner for each cycle
- Sample transaction listings for the agreed period
- Prior management letters if they exist
- A quiet room or secure remote folder for evidence