Financial and IT Audit Support
Internal control, FFMIA compliance, IT general controls and audit remediation for federal financial managers, from an SBA-certified service-disabled veteran-owned small business.
We help federal financial managers get ready for audit, answer findings, and keep them closed.
We work for agency management under OMB Circular A-123 and the Federal Financial Management Improvement Act. We support the audit and do not perform it, which keeps our work clear of your independent auditor’s independence rules.
Four lines of work, one audit cycle
Internal control
We document processes, assess risk, and test control design and operating effectiveness. The output supports the agency’s annual Statement of Assurance.
- Process narratives and risk and control matrices
- Appendix A reporting and data integrity testing
- Enterprise risk profiles and registers
- Statement of Assurance support
FFMIA compliance and financial systems
We test financial systems against the three FFMIA requirements: system requirements, federal accounting standards, and the USSGL at transaction level.
- Appendix D compliance assessments
- USSGL posting-logic and crosswalk reviews
- Remediation plans for substantial noncompliance
- System migration readiness
IT audit and IT general controls
Auditors test the systems that produce the numbers. We assess IT general controls the way the auditor will, before the auditor does.
- Access, configuration and segregation of duties
- Interface and application controls
- SOC 1 reviews and user-entity controls
- POA&M support
Audit remediation and readiness
A finding becomes a Notice of Findings and Recommendations, then a corrective action plan, then evidence the auditor accepts. We run that chain.
- Root-cause analysis for each finding
- Corrective action plans with closure criteria
- Validation testing before the retest
- PBC list management and audit liaison
From finding to closure
Each step leaves a document the auditor can test.
-
1NFR mapped
Assess
Trace the finding to the control, process and system that failed.
-
2Corrective action plan
Remediate
Fix the control with the process owner, with milestones and an owner per action.
-
3Closure package
Validate
Test the fix ourselves and assemble the evidence before the auditor retests.
-
4Procedures and monitoring
Sustain
Hand over procedures and monitoring so the finding does not come back next year.
We support management. Your auditor stays independent.
The opinion audit is performed by an independent auditor under Government Auditing Standards. MGI works on the management side of the table, so the agency can use us and its auditor in the same year without a conflict.
- Small business
- SBA-certified SDVOSB. Eligible for VA veteran set-aside and sole-source awards under 38 U.S.C. 8127.
- NAICS
- 541611, Administrative Management and General Management Consulting
- Cyber posture
- SPRS score 110, NIST SP 800-171 compliant
Common questions
Do you perform financial statement audits?
No. The opinion audit must be performed by an independent auditor under Government Auditing Standards. We support agency management before, during and after that audit.
Can a VA program use a veteran set-aside for this work?
Yes, when two or more veteran-owned small businesses can perform at a fair price. VA market research, usually a request for information, is how the contracting officer establishes that.
What does an engagement look like at the start?
We begin with the open findings and the prior-year management letter, then agree a remediation schedule tied to the next audit cycle.
Have open findings?
Tell us what the auditor found and when the next cycle starts.