Skip to content

Audit scope

What we examine

Each area below is reviewed against how your business actually operates, not against a generic checklist.

01

Email and identity security

How your email accounts and identities are protected and monitored.

We review how staff sign in to email, whether multi-factor authentication is enforced everywhere it should be, and how quickly a stolen password would be noticed.

We look at forwarding rules, mailbox delegation, domain protections that make your address harder to spoof, and the alerts that would tell you a mailbox has been taken over.

02

Employee access and permissions

Who can reach which systems, and what happens when roles change.

We examine who holds administrator rights, who can approve money movement, and whether access is still assigned to people who changed roles or left the company.

We check onboarding and offboarding steps, shared logins, and whether permissions match each person's actual job.

03

Vendor onboarding and payment changes

How a new vendor or a changed bank account gets accepted.

We review how vendor records are created, who is allowed to change banking details, and how a change request is verified before it takes effect.

We look for an independent call-back procedure using a known number, rather than confirmation by replying to the same email thread.

04

Banking and payment approvals

The approval chain that stands between a request and a transfer.

We map who can initiate, approve, and release payments, what limits apply, and whether a single person can move significant money alone.

We review bank platform controls, dual approval, positive pay or equivalent services, and how exceptions are handled under time pressure.

05

Devices and network protection

The computers, phones, and network your money passes through.

We review endpoint protection coverage, patching, disk encryption, and whether personal devices touch financial systems.

We examine remote access, firewall and network segmentation, and how unmanaged devices are handled.

06

Backups and recovery

Whether you could actually recover, and how long it would take.

We review what is backed up, how often, where copies are stored, and whether a copy is isolated from the systems an attacker would reach.

We ask when a restore was last tested and what your realistic recovery time would be for the systems that run the business.

07

Employee fraud awareness

Whether your people can recognize and stop a believable request.

We review what training exists, how staff are expected to verify unusual requests, and whether anyone has been penalized for slowing down a suspicious payment.

We look at how an employee reports a concern and how quickly that report reaches someone who can act.

08

Cyber-insurance requirements

The controls your policy assumes you already have in place.

We compare the security representations and conditions in your policy and application against what is actually implemented.

We identify gaps that could complicate a claim, and document the evidence that supports the controls you do have.

09

Incident-response readiness

What happens in the first hour after something goes wrong.

We review who is called, in what order, and whether contact details for your bank, insurer, IT provider, and counsel are reachable when systems are down.

We check whether staff know how to escalate a suspected fraudulent payment quickly enough for a recall attempt.

10

Documentation and evidence

Proof that safeguards exist and are maintained over time.

We review written procedures for payments, vendor changes, access, and recovery, and whether they match daily practice.

We assemble the records that demonstrate controls were in place before an incident, not reconstructed afterward.

Exact scope depends on the client's size, systems, and complexity. Some businesses need a focused review; others require a broader audit across multiple entities, locations, and financial platforms.

What you receive

  • Pass/fail findings
  • Priority risk summary
  • Estimated exposure areas
  • Insurance-readiness observations
  • Immediate protective actions
  • Prioritized corrective-action plan
  • Optional implementation proposal