How the audit works
Read-only, five days, fixed fee.
The audit is deliberately boring to buy. A short call, permission to look at the systems that keep records, five working days, and a written report at the end. No changes to your systems, no discovery phase, no open-ended engagement.
- Takes
- 5 working days
- Costs
- £1,500–£3,000 fixed
- Access
- Read-only
- You get
- A written report
Five steps
From first call to written report.
Same shape every time. Note where it stops: nothing gets looked at until you have decided what I am allowed to see.
A short call
Thirty minutes on what made you ask, which tasks run with nobody watching, and which of them carry a deadline, a filing or a number someone relies on. If an audit isn't worth doing, I'll say so.
You give me permission to lookyour call
We agree exactly what I can see and how you grant it. Read-only, time-limited, and removed at the end. If access is slow to arrange, I scope around what is available rather than stalling.
Access granted · read-only
I find everything that runs
Before anything can be checked it has to be found. Scheduled jobs, integrations, and things somebody set up years ago and left running. The list is almost always longer than the one in people's heads.
I check each one
Did it run when it should have, and did it produce something real? The report shows you the findings and the evidence behind each one.
Report and walkthrough
A written report, ranked by what each gap could cost you rather than by technical severity. Then an hour on a call going through it, because the ranking is a judgement and you may disagree with it.
Typical engagement
Five working days, start to written findings.
Access is the variable. Everything after it is predictable, which is why the fee can be fixed.
Day 1
Find everything
List everything that runs unattended. Agree what is in scope and what is out.
Day 2–3
Check each one
Did it run, and did it produce what it should? Anything unclear gets flagged rather than guessed.
Day 4
Work out the cost
Work out what each gap actually costs. This is where your knowledge of the business matters more than mine.
Day 5
Written report
The document, then a walkthrough call.
After the report
Most people take the findings and fix them internally, which is the intended outcome. If you would rather not, help with the fixes, a rebuild that proves it ran, and a longer fractional arrangement are all available, but they are a separate decision made after you have the document, not a condition of getting it.
Principles
Five rules I work to.
These shape how I scope, what I say no to, and how I hand the work back to your team.
01Read-only, always
I can look, but not change. That means the records of what ran and when, and the places the results should end up. No changes to settings, and nothing touched in your live systems during an audit. If something needs fixing, that is a separate conversation you are free to have with someone else.
02The fee does not move
Fixed before I start, and the same whether I find six problems or none. Nobody should be paid more for finding more, because that is how you end up with a report full of findings.
03Evidence, not opinion
Every finding points at a record: what should have run, what the system says happened, what came out. If I cannot evidence it, it goes in the report as a question rather than a finding.
04A clean report is a real result
If everything is running and producing what it should, that is what the document says. Worth having in writing on its own, particularly heading into an audit, a refinancing or a sale.
05You keep what I set up
The last section of the report is what to instrument so this stays visible without me. I would rather you did not need a second audit. Repeat work should come from you growing, not from me withholding something.
Ready to scope?
Start with one process. I'll tell you honestly whether it's worth checking.
No slides and no paid discovery phase. If your monitoring already covers it, I'll say so.