Client stories

Evidence from engagements, not star ratings

These accounts name the audit type, the constraint we worked under, and what changed afterward. Names of companies are withheld where clients requested anonymity.

Full application control audit

Mika S.

Finance director, food distribution, Miyagi

We asked for a full control audit on our order-entry and inventory applications before a group review. The team spent two days with warehouse supervisors, not only with IT. The findings pack flagged missing restore tests — something we had postponed for three years. Scheduling interviews around our peak shipping weeks was awkward, and we had to push two sessions; still, the written owners and deadlines made remediation trackable.

Privileged access review

Tomohiro K.

IT governance lead, regional bank subsidiary

The privileged access review compared our admin exports against HR leavers for a six-month window. They found emergency IDs that had not been rotated after a vendor cutover. The tone of the report was stricter than our previous internal memo, which some colleagues disliked, but the evidence citations left little room to argue.

Pre-external readiness check

Elena R.

Compliance coordinator, manufacturing joint venture

With fourteen business days before parent-company auditors arrived, the readiness check told us which evidence folders would embarrass us. We rebuilt the change-ticket index and rehearsed the opening narrative. External reviewers still raised two points, but neither was a surprise.

Application change sampling

Yuta N.

Operations manager, logistics firm

Change sampling over one quarter showed approvals arriving after production moves on our routing application. We did not enjoy reading that. We did tighten the emergency-change path afterward, which was the point.

Workshop reviewing remediation owners after an application audit

Extended story

Inventory application, three plants, one findings pack

A Tohoku manufacturer asked Software Hub Audit Co. to audit its inventory application across three plants that shared a vendor instance but kept local configuration habits. Scope covered access, change, and backup proof — not network testing.

Week one confirmed that plant B still used a shared operations ID for cycle counts. Week three showed backup jobs succeeding while restore drills had never been recorded. The closing workshop assigned owners by plant rather than a single “IT” bucket, which matched how budgets actually worked.

Six months later the client reused the same evidence index for their statutory auditors. They still debate one medium finding on vendor remote access; we left it open with a clear residual-risk note rather than forcing agreement.

Discuss a similar engagement