I help companies get audit ready on the first pass, so a security review stops being the reason a deal sits still.
Formerly KPMG IT Advisory · Diligent · Galvanize
15+
Years in audit, risk and compliance
4.5
Years at KPMG in IT advisory
The situation
SOC 2 rarely shows up on a roadmap. It shows up in a procurement email, with a date attached.
A security questionnaire landed mid deal. Now the close date depends on a report nobody internally has been through before.
There is no security lead, and the work quietly lands on engineering, who already have a roadmap they are behind on.
A tool got bought, some policies got written, and the gap between that and an actual audit turned out to be wider than expected.
The engagement
A defined scope with a defined end. You come out of it audit ready, with the evidence already in place.
We map your current state against the Trust Services Criteria and agree the scope. You get a gap list that is ranked by what an auditor will actually flag, not a generic checklist.
Policies, controls and process, built to fit how your team already works. I write what needs writing and sit with your engineers on the rest, so nothing gets designed that nobody will follow.
Evidence organised, walkthroughs rehearsed, auditor questions anticipated. I stay in the room through fieldwork so requests do not pile up on your team.
One thing worth saying plainly. I am not your auditor, and that is deliberate. An independent CPA firm issues the report. My job is to make sure that when they arrive, there is nothing left to find.
Who this is for
About
I have spent about fifteen years on the inside of audit and controls work, most of it looking at the same question from different chairs.
I started at KPMG in IT advisory, running information systems audits and testing controls across SAP, Oracle and PeopleSoft environments, including SOC engagements. From there I moved into risk and controls at a public company, then spent seven years at GRC software companies helping compliance teams actually run the programs they had bought tools for.
What that adds up to is a fairly unglamorous kind of usefulness. I know what auditors ask for, I know what they do with the answer, and I know which controls look tidy on paper and fall apart in fieldwork.
I went independent in 2025 and work with a small number of companies at a time, out of Vancouver, across North America.
Contact
Twenty minutes. Tell me where you are, what is forcing the timeline, and I will tell you honestly whether I am the right person for it.
Vancouver, BC · Remote across North America