ISQM 1 evaluation cycle ACTIVE lobal
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
PDPL fully enforceable — SAR 5M exposure
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE — global
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE lobal
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
PDPL fully enforceable — SAR 5M exposure
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
ISQM 1 evaluation cycle ACTIVE — global
FRC / PCAOB inspections 2026 PLANS FILED
SOCPA peer review UNDERWAY
EU audit reform oversight RAMPING
IRBA, ICPAK, FRC Nigeria QR CYCLES LIVE
Audit firms live on falconry.one across 4 REGIONS
Audit firms are increasingly asked to opine on systems they don't run, controls they don't operate, and journal entries that flow through ERPs they didn't implement. Falconry's audit delivery team plugs into your engagement — under your firm's letterhead, your methodology, your QC review — and delivers the IT audit work that earns the opinion. Looking for vCISO, DPO, or SoQM cycle support inside your firm? See Managed services.
Audit firms are not technology firms. The talent market for Quality Partners, DPOs and CISOs is thin, and getting thinner. Some functions are easier to source as a service than to recruit, train, and retain.
The four ITGC domains, scoped to the financial assertions that depend on them. Tested every year you rely on the controls, walked through every year you don't.
Coverage: SAP · Oracle · MS Dynamics · cloud-native
Automated and configurable controls embedded in the financial-reporting flow. Mapped to your assertions. Tested with evidence the inspector can follow.
Calibrated to: your firm's audit methodology
Risk-based JE selection, completeness reconciliations, period-end manual review. Built around your audit methodology's JE testing framework, not a one-size template.
Tools: IDEA · ACL · client-system extracts
A four-step rhythm from scoping to deliverable. Falconry sits inside the engagement — under your firm's planning lead and Quality Partner. Working papers route through your firm's review trail.
STEP 01
Scope & methodology
Engagement-team kick-off. Risk discussion with your audit partner. Methodology alignment to your firm's audit manual — not ours.
STEP 02
Plan under your letter
Planning memo and testing strategy go through your firm's planning review. Independence declarations filed. Restricted entities checked.
STEP 03
Fieldwork & testing
Falconry team on-site or remote — your call. Daily check-ins with the engagement manager. Issues escalated through your engagement partner.
STEP 04
Deliver in your format
Working papers in your firm's working-paper structure. Reviewed by your audit team. Filed in your engagement file. Opinion is yours.
ERP & PLATFORM COVERAGE
SAP S/4 HANA
FICO · MM · SD · basis
Oracle Fusion
Cloud ERP · EBS · security
MS Dynamics
F&O · Business Central · BC365
NetSuite
Cloud ERP · access · SuiteCloud
Mid-market
QuickBooks · Sage · Xero · cloud
Each one is a real call from an audit partner. Each one is fixable inside the engagement — not by punting the work back to the client or by trying to hire IT auditors mid-cycle.
In-region IT audit specialists. Across KSA, UAE, Cairo, Nairobi, Lagos and Johannesburg — our team works on-site or hybrid. CISA, CISSP, CRISC credentials. Native or fluent Arabic where needed.
Continuity team within five business days. Pick up the working papers, complete the fieldwork, hand back a finished file. We've done it for three firms in the last 18 months. Discreet, no client-facing handover.
ERP-specialist coverage. SAP S/4 HANA, Oracle Fusion, NetSuite, Dynamics F&O. Not just controls testing — we know the security model, the segregation-of-duties matrix, and the upgrade pitfalls.
Whatever managed service the firm chooses, the operating cadence is the same — a four-step quarterly rhythm that surfaces decisions to your Managing Partner without surfacing operational noise.
01 · DAILY
Operations
The Falconry mandate-lead operates the function on the platform — DSR queue, control attestations, evidence capture, inspection prep — visible to your firm's Quality Partner in real time.
02 · MONTHLY
Partner brief
One 30-minute call per month with the firm's Quality Partner (or DPO sponsor). Status, exceptions, decisions needed, evidence delta. Minutes auto-logged on the platform.
03 · QUARTERLY
Managing Partner review
One quarterly review with the firm's Managing Partner. Higher-altitude: programme posture, regulatory horizon, talent decisions, commercial scope. Designed to be the only call required.
04 · ANNUAL
Independent review
Once a year, an independent Falconry Engagement Partner — not the mandate lead — reviews the function against the original SLA, the platform evidence, and emerging regulatory expectations.
Acknowledgement of any data-subject right or material breach indicator, business hours.
Inspection response retainer activation from formal regulator notice.
Quarterly evidence refresh cycle from quarter-end across all 8 ISQM 1 components.
Quarterly cyber control attestation cycle close, from period-end through partner sign-off.
A live walkthrough of an ISQM 1 SoQM evaluation on the platform — against your firm's existing manual and inspection history. You see exactly what the partner view looks like, what the evidence pack contains, and what the 8-week deployment would mean for your cycle.