Internal audit, priced by the point.
Eleven engagements in three families, every one with its box printed and its price derived from a published formula. Cybersecurity, SAP and privacy engagements live on their own pages and can join any plan built here.
The plan is approved. Then the year happens.
An audit plan is signed off in February with real intent behind it. By June two audits have slipped because the bench that could run them was busy, one has been rescoped down to what the available person could cover, and the SAP audit has quietly become an IT general controls audit because nobody could open the landscape.
None of that appears in the committee pack. The pack reports what was delivered against what was delivered, and the plan gets re-cut in January as though the gap were a scheduling accident rather than a capacity one.
The failure is not effort. It is that assurance capacity is bought as projects and consumed as a year. Every engagement is negotiated from scratch, so every engagement costs weeks before it costs money — and the ones that never get negotiated are the ones that quietly leave the plan.
Bought as a project. Delivered as a product.
Neither column is a caricature. The left is how assurance is bought almost everywhere, including by people who dislike it. The right is what changes when the box is printed before the conversation instead of after.
Six weeks, printed in advance.
A mid-sized audit, week by week. Consulting keeps the schedule vague because vagueness absorbs slippage; a product publishes it because the schedule is part of what you bought.
Your transaction data mapped, control points chosen from what the data shows rather than from a standard’s list, and the count agreed in writing.
Partner gateEvery control point tested and evidenced in Clarus as it goes. No end-of-engagement scramble to assemble a file that should have been building all along.
Findings rated before management sees them, then a second specialist reviews the file against the methodology.
Partner gateThe report issued, the remediation plan prioritized with owners proposed, and the committee readout delivered.
Partner gateThe same machine, pointed somewhere new.
Repeatability is not a claim about our discipline. It is a claim about structure — and structure is checkable, which is why these four numbers are on the page rather than in a capability deck.
Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page. The board pack’s seven-page structure is published beside every subscription’s scope box, readable before any call.
Three families. Three different products.
The distinction is not taxonomy. It decides who may buy an engagement, who receives it, and whether it produces an assurance opinion at all.
| A · Assurance | B · Assessment | C · Function build | |
|---|---|---|---|
| What it produces | An opinion the committee can rely on | A diagnostic, no opinion | Your function’s own artefacts |
| Who buys | The Chief Audit Executive | The function’s own head | The Chief Audit Executive |
| Who receives it | The Audit Committee | The buyer, then the CAE | The committee |
| Unit | Control point (SoD ×1.5) | Target or domain | Auditable entity, or fixed |
| Items across all areas | 16 | 3 | 2 |
Nobody buys assurance over their own function.
A CISO can buy a maturity assessment or a penetration test of their own estate — that is management commissioning a diagnostic, and it is proper. A CISO cannot buy the Cybersecurity Framework Audit of their own controls. The Chief Audit Executive buys that, and the Audit Committee receives it.
The fieldwork can be identical. The product is not: an audit commissioned by the person being audited is not assurance, whatever the cover page says. We would rather lose the sale than sell you a report your committee shouldn’t rely on — and if you’re the wrong buyer for something here, we’ll tell you who the right one is.
A rebuild, then capacity you direct.
The rebuild is a fixed fee and comes first — it’s what makes the menu mean anything. After that you hold credits, and the audit committee decides what they buy and when.
- 01Audit universe rebuilt — auditable entities, refreshed and risk-ranked
- 02Risk assessment re-run against the register that’s actually true
- 03Annual plan re-cut to capacity — yours plus ours
- 04Methodology pack stood up in Clarus — templates, workflow, QA gates
- 05First audit-committee pack + readout
- 01Process analytics first — scope chosen because your data pointed at it, not because a standard listed it
- 02Every control point tested and evidenced in Clarus — scoping to report, one file
- 03Findings rated, every conclusion traceable to a test
- 04Remediation plan — prioritized, owners proposed, effort estimated
- 05Two gates before issue — a second specialist peer-reviews the file, and a Signify partner signs the report off. Every engagement, every subscription — the partner moment for an audit is the conclusion, which is where judgment actually changes the result
- 06Independence screen before anyone is assigned — every redemption, not just the first
Eight engagements, one opinion each.
Bought by the Chief Audit Executive, received by the Audit Committee. Every price below comes from the same published formula — set out once, on how it works. The four business-process cycles are listed separately because they are separate audits: procure-to-pay and payroll share a method, not a scope.
D1 AI Usage Audit — 35 control points · 840 credits · $42,000 +
- 01Use inventory — every AI system in use, including the tools bought on expense and the ones embedded in software you already own
- 02Governance testing — approval, human oversight, disclosure and acceptable-use, tested against actual deployments
- 0335 control points tested — data flows into models, retention by vendors, output review, access, third-party terms
- 04Final report — with shadow usage named and quantified
- 05Remediation plan — separating what to stop from what to govern, since most programs need both
D2 Digital Transformation Program Audit — 40 control points · 500 credits · $25,000 +
- 01Program baseline review — scope, benefits case, milestones and governance as approved versus as currently reported
- 02Control testing across the delivery lifecycle — stage gates, change control, benefits tracking, dependency and risk management
- 0340 control points tested — including the reporting line from delivery to steering committee, tested for what gets softened
- 04Final report — an independent view of whether the program will deliver what was approved
- 05Remediation plan — recommendations the steering committee can act on before the next gate
Hard stop: we cannot audit a programme Signify Solution is delivering. See independence.
D3 Offshore Operating Audit — 30 control points · 680 credits · $34,000 +
- 01Delivery footprint mapped — what is actually performed offshore, against what the contract and the org chart claim
- 0230 control points tested — access and supervision, segregation from the provider’s other clients, data handling, change control, key-person dependency
- 03Service evidence tested, not accepted — SLAs checked against the records rather than the dashboard
- 04Final report — with the continuity and concentration risks the service metrics never surface
- 05Remediation plan — retain, restructure or repatriate, sequenced, with the reasoning shown
The assurance version of B3. Same ground, different product: when internal audit commissions it, it is an audit — which is exactly what this page has always said.
D4 Business Process Cycle Audit — P2P — 50 control points, 5 SoD · 800 credits · $40,000 +
- 01Process analytics — procure-to-pay mapped from your own transaction data. Volumes, exceptions, duplicate payments, vendor-master anomalies, payment-term drift
- 02Scoping from what the analytics found — control points chosen because the data pointed at them
- 0350 control points tested — 20 business process, 15 automated and configurable, 10 IT general, 5 segregation of duties
- 04Final report — findings rated, evidence attached, every conclusion traceable to a test in Clarus
- 05Remediation plan — prioritized, owners proposed, effort estimated. The plan is yours to run
This scope and this price are final. The three cycles below run the same box at their own counts.
D5 Business Process Cycle Audit — O2C — 45 control points, 5 SoD · 900 credits · $45,000 +
- 01Process analytics — order-to-cash from your own data. Credit limits breached, pricing overrides, manual invoices, credit notes, unapplied cash, DSO drift
- 02Scoping from what the analytics found — not from a standard’s list of order-to-cash controls
- 0345 control points tested — 18 business process, 14 automated and configurable, 8 IT general, 5 segregation of duties
- 04Final report — findings rated, evidence attached, traceable to a test in Clarus
- 05Remediation plan — prioritized, with the revenue-recognition consequences of each finding stated plainly
D6 Business Process Cycle Audit — R2R — 45 control points, 10 SoD · 770 credits · $38,500 +
- 01Process analytics — record-to-report from your own ledger. Manual journals by preparer, late and post-close postings, top-side adjustments, reconciliation ageing, close-calendar slippage
- 02Scoping from what the analytics found — the entries that move the numbers, not a sample of the ones that don’t
- 0345 control points tested — 15 business process, 12 automated and configurable, 8 IT general, and 10 segregation of duties, because journal preparation and approval is where this cycle actually fails
- 04Final report — findings rated, every conclusion traceable to an entry
- 05Remediation plan — sequenced around your close calendar, so fixes land between closes rather than during one
D7 Business Process Cycle Audit — Payroll — 35 control points, 5 SoD · 620 credits · $31,000 +
- 01Process analytics — payroll from your own runs. Joiner and leaver timing, off-cycle payments, master-data changes against payment runs, overtime outliers, duplicate bank details
- 02Scoping from what the analytics found — including the tests most payroll audits skip
- 0335 control points tested — 14 business process, 10 automated and configurable, 6 IT general, 5 segregation of duties
- 04Final report — findings rated, with any employee-data exposure flagged for your privacy lead
- 05Remediation plan — prioritized, separating what payroll owns from what HR owns, since they are rarely the same person
A1 SoD by Business Process Detailed Assessment — 40 control points, 40 SoD · 780 credits · $39,000 +
- 01Role and authorization mining — every role, profile and composite in scope mapped to the business processes it actually touches
- 02Ruleset build or validation — your conflict ruleset tested against the process, not accepted as delivered
- 0340 conflict rules tested — each traced to real assignments and real transactions, not theoretical exposure
- 04Mitigating control assessment — every accepted conflict checked for a control that genuinely operates
- 05Remediation plan — conflicts ranked by transactional exposure, not by count
Lives on the SAP technology page — shown here because it is bought together with these as often as not.
Counts shown are the scoping defaults we start from. Your count is agreed at scope lock, with a partner in the room, before any fieldwork begins — and the formula never changes, so you can compute any variation yourself.
One diagnostic, commissioned by management.
A diagnostic is an opinion on a function’s own maturity, so the function’s own head commissions it — and every report says on its face that it is an assessment rather than assurance. A procedure produces technical findings and no opinion about anyone, so either buyer may commission it: penetration testing sits here, and internal audit can put it inside an audit as evidence.
D8 Offshore Talent and Operating Assessment — 2 sites · 440 credits · $22,000 +
- 01Operating model review — what is actually performed offshore versus what the contract and org chart say
- 02Capability and key-person assessment — skills held, skills assumed, and where a single resignation stops a process
- 03Control environment at the delivery site — access, supervision, data handling and segregation from other clients
- 04Findings report — including the cost and continuity risks the service metrics do not surface
- 05Recommendations — retain, restructure or repatriate, with the reasoning shown. Assessment, not assurance
Two engagements that build the function itself.
The audit function’s own infrastructure. C1 is the normalization every new co-source client starts with — the universe has to be true before a menu means anything.
D9 Audit Universe Setup and Refreshment — ~60 entities · 780 credits · $39,000 +
- 01Auditable entity identification — the universe rebuilt from the organization as it is now, not as the last reorganization left it
- 02Risk assessment across the universe — scored against criteria the committee has agreed, with the criteria printed
- 03Annual plan cut to capacity — yours plus ours, so the plan is deliverable rather than aspirational
- 04Methodology stood up in Clarus — templates, workflow and QA gates, ready to execute against
- 05First audit-committee pack and readout — the universe presented, challenged and adopted
D10 Internal Audit Strategy Development — fixed scope · 700 credits · $35,000 +
- 01Current-state review — mandate, charter, resourcing, methodology and standing with the committee
- 02Stakeholder expectations — what the board, the committee and the executive each actually want from assurance, which is rarely the same thing
- 03Target operating model — co-source ratio, bench composition, technology, and what the function should stop doing
- 04Three-year strategy — with the QAR path built in, since that is what the standards will eventually ask for
- 05Board-ready presentation — the strategy in the committee’s language, not ours
Fixed · where we then deliver audits under a strategy we wrote, that is disclosed in every committee pack
D11 The Risk Register, kept alive — fixed scope · 800 credits · $40,000 +
- 01Risk universe review — what belongs on this register, and what has been sitting on it because nobody ever retired it
- 02Up to 40 risks rebuilt — described in plain language, scored on one basis, and owned by a named person rather than by a department
- 03Owner interviews and a calibration workshop — leadership challenges and settles the scoring, so the register survives its first real disagreement
- 04Deployed in Risk Radar, running in your environment — the register lives in software you keep using, not in a spreadsheet somebody owns
- 05First board pack and readout, and the rhythm handed over — the register presented, challenged and adopted, with the quarterly evidence sweep documented so your team can run the next one
A build, not assurance. While we maintain your register we cannot audit it — assurance over a register we keep is not assurance. Fixed scope at up to 40 risks; beyond that it is scoped before you buy.
D12 Policy Framework, kept alive — fixed scope · 500 credits · $25,000 +
- 01Policy inventory and rationalization — every policy in force, including the ones nobody has opened since approval and the two that contradict each other
- 02An owner and a review date on each — a policy without a named owner is a document, not a control
- 03Gap and overlap analysis — what you are required to have and don’t, what you have twice, and what no longer applies to a business you have since changed
- 04Stood up in Clarus — the register lives in software you keep using, not in a folder somebody owns
- 05First refresh cycle run with your team — what changed, what lapsed its review date, what was approved and never communicated — handed over as a pack they can repeat without us
A build, not assurance. While we keep your policy framework alive we cannot audit it. Fixed scope, shown at around 60 policies in force.
E2 Audit Analytics Enablement — 8 routines · 780 credits · $39,000 +
- 01Test library built — the recurring analytics your plan needs, written as routines your own team can re-run without us
- 02Data access documented — where each extract comes from, who authorizes it, how it refreshes, and what breaks when a source system upgrades
- 03Routines validated against known results — an analytic nobody has proven is an opinion with a chart attached
- 04Handover and training — your team runs these next quarter. If they cannot, we have not finished
- 05Stood up in Clarus beside the methodology, so the routines survive the person who learned them
Family C because it builds your function's own capability — the same precedent that lets us rebuild your universe and write your methodology without crossing the guardrail.
Lives on the analytics page — shown here because it is bought together with these as often as not.
Or take a named block.
Seven named blocks, including The Annual Plan — the one that runs the full year, in one committee-ready purchase. The other six land inside one or two quarters and are then done. A bundle never changes what an engagement costs; it makes a block worth buying at once.
Assurance · Internal audit
- 01Two audits in flight per client. A third queues to the next start slot
- 02Partner sign-off is a gate on every engagement — a gate that queues is honest, a gate that is skipped is not
- 03A program block is therefore four to five quarters of delivery, not a year — which is why we’d usually sell you the plan block first
- 04Ten clients per pod, one normalization start per month — the cap that makes the gate above possible
Why the ceiling is published.
Credits let you buy a year of capacity in one purchase. Partner sign-off means each engagement costs partner judgment at three gates — scope lock, finding rating, report issue. Those two facts have to meet somewhere, and we would rather they met on this page than in your fourth month.
It also means a program block is a commitment we make about sequencing, not just a discount you receive. If you need eight audits inside two quarters, tell us on the call and we will tell you honestly whether the answer is no.
How credits work →Bring the plan. We’ll bring the bench.
Thirty minutes: your approved plan, your capacity gap, and which engagements your credits should buy first — with an independence screen before anyone is assigned.
Part of the Signify family
Solve · Build · Teach · Sustain. Four properties, one design language — consulting, software, interactive learning and sustained advisory, built in Philadelphia since 2019.
Premium management consulting across strategy, cybersecurity, audit, GRC and regulatory readiness. Every engagement partner-led.
signifysolution.comConsulting, new age. Seven practitioner-built products — the tools that stay behind at clients as running value.
signifyhive.comPlay, test, think. Games, assessments, simulations and Points of View — learn the work by doing it.
signifyinsights.com You are hereConsulting, sustained. Time-boxed, and scope-boxed engagements at transparent rates. Clear pricing. Explicit scope.
signifyimpact.com