Review cycle
One cycle, then the next—on purpose
Recurring compliance reviews only work when fieldwork, findings, and remediation sit on a visible calendar shared by every entity owner.
This page is the working map we use with multi-entity groups. It is not software workflow jargon—it is the sequence of human steps between one board pack and the next.
1. Scoping & entity inventory
Confirm legal entities, ownership, systems, and the hard deadlines that fix the review window. Agree what is in and out of scope for this cycle.
2. Evidence pack request
Send a labelled request list tied to each entity’s registry name. Controllers assemble ledgers, policies, reconciliations, and sample vouchers before fieldwork starts.
3. Fieldwork & walkthroughs
Sample testing plus on-site days where satellite entities need them. Remote review covers complete packs; walkthroughs catch workarounds documents miss.
4. Draft findings workshop
Ranked register discussed with finance and operations owners. Mild disagreements are welcome—ranking must survive a director-level question.
5. Final pack & remediation window
Final report, tracker, and owners with target dates. Optional remediation tracking support runs until items close or the next cycle begins.
6. Next-cycle planning
Closed items archive with evidence; open items carry forward; new entities join with a short onboarding checklist. The shared calendar updates.
Who owns which step
Your group finance lead owns the calendar and entity inventory. Process owners own remediation. AutoDevOps owns testing design, fieldwork execution, ranking rationale, and the written pack. Statutory auditors remain separate—we do not replace their opinion work.