Practical writing from engagements — not generic risk commentary.

When alert thresholds hide overdue attestations

How quiet threshold choices in risk control monitoring applications can mask attestations that are already late.

Control inventories that drift from the monitoring application

Why approved control lists and monitoring application records diverge — and what an auditor should reconcile first.

Shared inboxes and the illusion of escalation

Escalation paths inside monitoring applications fail quietly when exceptions land in mailboxes nobody owns.

Preparing evidence for an application control audit

A sponsor checklist for documents and access before Reason Space begins fieldwork on monitoring applications.

Ranking residual exposure without inflating every finding

How we rank findings from audits of risk control monitoring applications so committees can act in order.