Engagement
Full Application Control Audit
A complete examination of how your risk control monitoring applications detect exceptions, evidence status, and escalate unresolved items.
Request an engagement briefWho this is for
Control owners, second-line risk teams, and internal audit functions that rely on monitoring applications to track control performance — and need an independent view of whether those applications actually surface failures in time.
What you receive
A written audit report covering configuration of monitoring rules, completeness of control inventories linked in the application, alert thresholds and routing, evidence retention, operator handoffs, and residual exposure where monitoring is weak or silent.
We include a findings register ranked by residual exposure and evidence strength, plus a remediation outline that names owners and sequencing — not a product roadmap.
What is included
- Scoping workshop to lock applications, control families, and sample periods
- Document and configuration review for the in-scope monitoring applications
- Walkthroughs with operators and control owners
- Sample re-performance of selected monitoring routines
- Draft findings discussion before the final report
- Final report and optional short briefing for the audit committee
What is excluded
We do not implement software changes, sell monitoring licences, or act as ongoing managed monitoring. Penetration testing of application infrastructure is outside this engagement unless separately agreed in writing.
Provider and approach
Reason Space auditors with experience examining risk control monitoring applications in banking, logistics, and corporate second-line settings lead the work. A named engagement lead remains your contact from scoping through report delivery.
Process and timeline
- Scoping (week 1) — agree applications, control families, access, and sample windows.
- Fieldwork (weeks 2–5) — configuration review, interviews, and sample testing.
- Draft (week 6) — findings discussion with factual accuracy checks.
- Final (weeks 7–8) — report delivery and optional committee briefing.
Timelines stretch when access is delayed or inventories are incomplete; we flag that early.
Preparation
Please provide application access (read-only where possible), current control inventories, alert rule exports, recent exception logs, and a list of operators and control owners. Incomplete access slows fieldwork more than any other factor.
Constraints
We work in English and Japanese as needed for interviews. Reports are delivered in English by default; Japanese executive summaries can be arranged. We require a single client sponsor who can unblock access.
Pricing basis
Fixed fee after the scoping workshop, based on number of applications, control families, and sites. See Rates for indicative ranges, then enquire with your scope.
Next step
Request an engagement brief with the application names and control families you want examined. We respond within two business days.