Audit engagement

Full application control audit

A thorough audit of applications covering access, change, operations, and vendor dependencies for one application family or a bounded portfolio.

Request a scoping call
Two practitioners reviewing application control evidence together

Who this is for

Organisations that rely on a handful of business applications — payroll, inventory, customer records, or production scheduling — and need an independent reading of whether those applications are controlled in practice, not only on paper.

Result you receive

A findings pack with rated observations, evidence references, named owners, and a sequenced remediation roadmap. You also receive a management summary suitable for directors who will not read every workpaper.

Scope included

  • Application inventory confirmation and criticality ranking with owners
  • Access control walkthroughs, including privileged and emergency accounts
  • Change management sampling for configuration and release records
  • Backup and restore evidence review for in-scope applications
  • Vendor and hosted-service dependency mapping where relevant
  • Closing workshop to walk through findings before the written report is final

Explicitly excluded

Penetration testing, source-code review, and continuous monitoring retainers are outside this engagement. We can introduce specialists if those needs appear during scoping.

Provider and process

Lead auditors from Software Hub Audit Co. run the engagement. Work begins with a scope letter, proceeds through evidence requests and interviews, and closes with a findings meeting. Typical duration is four to eight weeks once evidence starts arriving.

Preparation we ask of you

Nominate an application owner per system, provide read-only access or screenshots as agreed, and reserve interview time with operations staff who actually run month-end closes or batch jobs.

Next step

Request a scoping call so we can confirm application boundaries and a realistic fee range.