Skip to content

Assurance & Controls

Controls that hold up before someone else checks them.

Internal control design, financial statement review and compilation support, fraud-risk assessment, and audit-prep readiness for companies answering to a lender, investor, board, or outside audit firm. NEXACC does not issue opinion audits.

Schedule Discovery Call

What's included

  • Financial statement reviews and compilations
  • Internal control design and testing
  • Segregation-of-duties and fraud-risk assessment
  • Audit-prep (PBC list) management for your external auditor

Built for

  • Companies preparing for a lender, investor, or board review
  • Businesses using an outside audit firm for opinion audits
  • Buyers and sellers in an M&A process needing diligence support
  • Nonprofits and grant recipients with funder reporting requirements

Every engagement

Control gaps documented with a written remediation plan

First request

PBC items prepared before auditor fieldwork begins

0

Opinion audits issued (by design — not our engagement type)

How engagements work — Fixed fee by engagement type (compilation, review, control assessment, or diligence support), scoped after an initial file review.

The problems we solve

You don't know if your controls would survive a real test.

A documented internal control walkthrough covering cash, revenue, payroll, and disbursements, with gaps ranked by risk and a remediation plan attached.

One person can request, approve, and pay an invoice.

A segregation-of-duties review mapped against your actual headcount, with compensating controls designed for the roles you can't fully separate.

Your outside auditor's PBC list turns into a fire drill every year.

A managed PBC (provided-by-client) tracker with owners and due dates, so audit fieldwork starts with a complete file instead of a scramble.

A buyer wants quality-of-earnings support and you have no internal finance team to produce it.

Buy-side and sell-side diligence support — normalized EBITDA schedules, working capital analysis, and data-room organization — built alongside your deal counsel.

A lender or grantor wants financial statements you can't produce in-house.

Compiled or reviewed financial statements prepared under the applicable AICPA standard, with disclosures and a formal accountant's report.

Full scope of work

Financial statement services

  • Compilation engagements (AR-C 80)
  • Review engagements with analytical procedures (AR-C 90)
  • Footnote disclosure drafting and financial statement formatting
  • Lender- and grantor-specific reporting formats

Internal controls

  • Control design across cash, revenue, procurement, and payroll cycles
  • Segregation-of-duties mapping and compensating-control design
  • Fraud-risk assessment and cash-handling control testing
  • Written SOPs and control-narrative documentation

Audit-prep & transactions

  • PBC list management and workpaper organization for your external audit firm
  • Buy-side and sell-side due diligence support
  • Quality-of-earnings schedules and working-capital analysis
  • Data-room preparation and management-representation support

Where the money comes back

Every engagement is scoped against a return: cost removed, margin recovered, cash pulled forward, or exposure closed.

Faster external audit fieldwork

A managed PBC list and pre-cleared workpapers shorten the time your outside audit firm spends chasing documents. On a firm billing audit fees by the hour, cutting two weeks of back-and-forth can mean a meaningfully lower audit invoice.

Fewer losses from control gaps

Segregation-of-duties and cash-control reviews catch the single-approver and single-signer gaps that are the most common entry point for internal fraud. Closing them before an incident avoids losses that, industry surveys suggest, average well into six figures per event.

Cleaner diligence, better deal terms

A normalized quality-of-earnings schedule and organized data room reduce the working-capital and EBITDA adjustments a buyer's diligence team can push for at the negotiating table.

Lender and grant terms preserved

Delivering a review or compilation on the format and schedule a lender or grantor requires avoids covenant-default notices and funding holds tied to late or non-conforming reporting.

What actually lands in your inbox

  • Compilation or review report

    Annual or per lender/grant cycle

    Financial statements prepared under AR-C 80 (compilation) or AR-C 90 (review) standards, with footnote disclosures and a formal accountant's report addressed to the requesting party.

  • Internal control assessment

    Annual, or one-time baseline

    A walkthrough of cash, revenue, procurement, and payroll cycles with control gaps ranked by risk and a written remediation plan.

  • Segregation-of-duties matrix

    One-time, refreshed on org changes

    A role-by-role mapping of who requests, approves, records, and reconciles each transaction type, with compensating controls where full separation isn't staffable.

  • PBC tracker

    Weekly during audit fieldwork

    A live list of every item your external auditor has requested, who owns it internally, and its status, updated through the close of fieldwork.

  • Quality-of-earnings schedule

    Per transaction

    A normalized EBITDA build with add-backs and one-time items documented, plus a working-capital analysis, for buy-side or sell-side diligence.

  • SOP and control-narrative binder

    One-time, updated annually

    Written procedures for the financial cycles reviewed, so controls survive staff turnover instead of living in one person's head.

What working with us feels like

One control file, not a scramble every year

Control narratives, SOPs, and the PBC tracker live in one maintained file, so next year's review or audit prep starts from a known baseline instead of zero.

Plain-language findings

Control gaps and fraud-risk findings are written for an owner or board, not just an auditor — what's wrong, why it matters, and what closing it requires.

Coordination with your outside auditor

When an opinion audit is required, we work directly with your audit firm's engagement team so requests come to us once, not to five different people in your company.

Deal-side responsiveness

During diligence, data-room requests and buyer follow-up questions are turned around on the deal's timeline, not a standard monthly cadence.

Benchmarked against the usual option

  • Audit prepPBC requests answered piecemeal as the auditor asksFull PBC tracker built and staged before fieldwork begins
  • Control documentationControls exist informally, undocumentedWritten control narratives and SOPs maintained on file
  • Segregation of dutiesReviewed only after an incidentMapped proactively with compensating controls designed in
  • Diligence readinessData room assembled reactively once a buyer asksQuality-of-earnings and working-capital schedules built ahead of the ask
  • Scope clarity"Audit" used loosely to mean any financial reviewEngagement type (compilation, review, control assessment) stated up front — no opinion audits performed

Your first 90 days

  1. Week 1

    Scope confirmed, file requested

    We confirm whether the requirement is a compilation, review, control assessment, or diligence support, and request the prior-period file and current trial balance.

  2. Week 2–3

    Walkthroughs and testing

    Control walkthroughs, segregation-of-duties mapping, or analytical review procedures are performed and findings drafted.

  3. Week 4

    Draft report and findings review

    Draft financial statements or the control-gap findings are reviewed with you before anything is finalized.

  4. Week 5–6

    Final report and remediation plan

    Final compilation/review report or control assessment is issued, with a written remediation plan for any open items.

Platforms included

Configuration, integration, and day-to-day administration are part of the fee — you are not billed to keep your own systems running.

The cost of leaving it alone

  • No segregation-of-duties review performed

    A single employee with request, approval, and payment access is the most common setup behind internal fraud losses, which can run into six figures before detection.

  • PBC list unmanaged going into an audit

    Fieldwork stalls on missing documents, extending audit timelines and increasing audit fees billed by the hour.

  • Diligence file not organized before a buyer asks

    Unsupported add-backs and disorganized data rooms give buyers leverage to push for lower purchase price or unfavorable working-capital adjustments.

How we run it

  1. 01

    Scope

    We confirm the standard required — compilation, review, control assessment, or diligence — and who the report is for.

  2. 02

    Test

    Walkthroughs, sampling, and analytical procedures performed against the applicable standard or risk framework.

  3. 03

    Document

    Findings, control gaps, and schedules documented in a file that holds up to lender, funder, or auditor scrutiny.

  4. 04

    Report

    Formal report or schedule package delivered, with a remediation plan for anything short of clean.

Why clients choose us over the firm down the street

We name the limits

We are explicit that a compilation, review, or control assessment is not an opinion audit — and we tell you when you actually need one.

Built for the audit you already have

If you use an outside audit firm for opinion audits, we manage the PBC list and workpapers so their fieldwork goes faster, not in competition with them.

Controls sized to your headcount

Segregation-of-duties recommendations account for the team you actually have, not a textbook org chart you can't staff.

Deal-ready documentation

Diligence schedules and data rooms built the way buyers and their counsel expect to see them.

Talk through your situation

Common questions

Text us on WhatsApp
TextInstagram