Engagement

From scope letter to findings workshop

Application audits fail when boundaries stay vague. This page shows the sequence we use so owners know when interviews happen, what evidence we expect, and how disagreements are handled before the report is final.

Planning an application audit timeline with stakeholders

Scoping conversation

You name the applications, the reason for the audit, and any fixed external date. We ask about environments, owners, and whether evidence exports already exist. This call is not billed.

Scope letter and fee

We issue a letter listing in-scope applications, control themes, sample periods, deliverables, timeline, and fee. Work starts only after written acceptance and the deposit invoice.

Evidence request list

A structured request covers inventories, access exports, change tickets, backup logs, and vendor contracts. We agree formats that your teams can actually produce within the calendar.

Interviews and walkthroughs

We sit with application owners and operators — often in Miyagi, sometimes by video — to test whether procedures match the screenshots. Anomalies are noted with evidence references, not hallway gossip.

Findings workshop

Before the report is locked, we walk through draft observations. Clients may provide clarifying evidence. We do not remove a finding without a documented reason; we may reclassify severity when evidence supports it.

Final pack and handover

You receive the management summary, detailed findings, evidence index, and remediation roadmap. Optional follow-up days can verify closed items; they are scoped separately.

Application owners reviewing draft audit findings

Practical notes

Calendars, language, and access

  • We avoid major evidence pulls during your month-end close unless you insist.
  • Findings can be delivered in English, Japanese, or a dual pack — confirmed in the scope letter.
  • Read-only access is preferred; when that is impossible, supervised screenshots are acceptable if timestamps are visible.
  • We will not install monitoring agents or alter application configuration.
Browse audit types Request a scoping call