Review cycle

One cycle, then the next—on purpose

Recurring compliance reviews only work when fieldwork, findings, and remediation sit on a visible calendar shared by every entity owner.

This page is the working map we use with multi-entity groups. It is not software workflow jargon—it is the sequence of human steps between one board pack and the next.

1. Scoping & entity inventory

Confirm legal entities, ownership, systems, and the hard deadlines that fix the review window. Agree what is in and out of scope for this cycle.

2. Evidence pack request

Send a labelled request list tied to each entity’s registry name. Controllers assemble ledgers, policies, reconciliations, and sample vouchers before fieldwork starts.

3. Fieldwork & walkthroughs

Sample testing plus on-site days where satellite entities need them. Remote review covers complete packs; walkthroughs catch workarounds documents miss.

4. Draft findings workshop

Ranked register discussed with finance and operations owners. Mild disagreements are welcome—ranking must survive a director-level question.

5. Final pack & remediation window

Final report, tracker, and owners with target dates. Optional remediation tracking support runs until items close or the next cycle begins.

6. Next-cycle planning

Closed items archive with evidence; open items carry forward; new entities join with a short onboarding checklist. The shared calendar updates.

Who owns which step

Your group finance lead owns the calendar and entity inventory. Process owners own remediation. AutoDevOps owns testing design, fieldwork execution, ranking rationale, and the written pack. Statutory auditors remain separate—we do not replace their opinion work.

Read the flagship engagement Book a scoping call