Audit Process
How a Reason Space application audit of risk control monitoring applications moves from enquiry to final report.
Application audits of risk control monitoring applications succeed or stall on access, scope clarity, and honest draft discussions. This page shows how we run an engagement so sponsors know what to prepare.
Enquiry and fit
You name the monitoring applications and control families. We confirm independence (we do not sell or implement the software) and propose whether a full audit or a shorter review fits.
Scoping workshop
We lock applications, sample periods, sites, report language, and access paths. The fixed fee for audit-style work is set here. A short note records what is in and out of scope.
Fieldwork
Configuration and rule review, operator walkthroughs, and sample re-performance. We raise factual questions as we go so surprises stay limited to judgment calls, not missing documents.
Draft findings
You receive a draft findings register for factual accuracy. We do not negotiate residual exposure ratings, but we correct errors of fact before the final report.
Final report and briefing
The final report and optional committee briefing close the engagement. Remediation design is yours; a separate readiness review is available if you want challenge on proposed fixes.
What we need from you
A sponsor who can grant read access, a current control inventory, alert or rule exports, recent exception logs, and time with operators who actually work the queues. Delays in access lengthen fieldwork more than complex control families do.
Where this leads
Browse engagement options or request an engagement brief when you are ready to put applications into scope.