Services


Services

Six services. One standard: senior US-based consultants, ready to work on day one, at a price you know before we start.

SOX and IT controls testing

Fixed fee, priced per control and per system.

Your team is leaner than it was two years ago, and the testing calendar didn’t shrink with it. We handle walkthroughs, design testing, and operating-effectiveness testing for business process controls, IT general controls, and automated controls.

Instead of an hourly estimate, you get one fixed price built from your own control inventory:

  • Key controls are priced by how often they operate: annual or quarterly, monthly, weekly, or daily.
  • IT general controls are priced per system, in two tiers: Standard for a single cloud or SaaS application, and Complex for on-premises systems with multiple layers.
  • SOC report reviews, deficiency evaluations, and remediation retesting are priced per item.

Our IT audit consultants hold CISA, CISSP, and other relevant credentials, and cover change management, logical access, computer operations, and system development across the platforms your business runs on.

AI governance review

Three fixed tiers, starting at $10,000.

Your people are already using AI tools, whether you’ve approved them or not. We identify what’s in use, assess the risks, and tell you what controls you need.

  • An inventory of the AI tools in use, approved or not, and the data going into them.
  • A review of your AI policy, approval process, and oversight against a recognized framework.
  • A review of controls over any AI used in finance or accounting, including the close, reconciliations, estimates, and reporting.
  • A findings report with recommendations, and a one-page summary for leadership or the board.
TierCompany sizePrice
Focused10–50 employees$10,000
Expanded51–100 employees$15,000
ComprehensiveOver 100 employees$25,000

Companies with multiple legal entities, or with AI used in finance or accounting, move up one tier.

Co-sourced internal audit

Senior help when your plan outgrows your team.

The audit plan that made sense in January doesn’t survive contact with reality by Q3. Turnover, shifted priorities, a special project that ate three months of capacity.

R-VMC consultants join your team for a defined period, take ownership of specific audits or workstreams, and hand the work back cleanly when the engagement ends. They average 15+ years of experience, so there’s no ramp-up time and no training your staff has to absorb.

Outsourced internal audit

A complete internal audit function, run by R-VMC.

For companies that don’t have an internal audit function and need one, or have one that isn’t working and need to replace it.

We work directly with your leadership team and external auditors, build the annual audit plan, execute it, and report results to your audit committee.

SOX program support

For public companies and recent IPOs.

Scoping, walkthroughs, internal controls documentation, deficiency tracking, and management’s annual assessment, handled end to end or in pieces. We’ve supported SOX programs from the first year of compliance through companies that have been at it for a decade.

SOC 2 advisory

Building or maintaining a SOC 2 program.

For a first SOC 2, we help you scope the engagement, select the trust services criteria that fit your business, design the controls, and prepare for the auditor. For an existing report, we manage the ongoing work so your team isn’t scrambling every audit cycle.

Let’s talk through what you need.

Thirty minutes. We’ll figure out whether R-VMC is the right fit and send a fixed quote. If we’re not the right fit, we’ll tell you that too.

Schedule an intro call