top of page
How Mature Are Your Monitoring Activities?
Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are still working? A control may have been properly designed two years ago. It may have worked perfectly when Internal Audit tested it last year. But what about today? Perhaps: The employee performing the control changed. Transaction volumes doubled. A new information system was imple

John C. Blackshire, Jr.
Sep 410 min read
How Mature Are Your Information and Communication Controls?
Measuring Whether the Right Information Reaches the Right People at the Right Time Organizations generate enormous amounts of information: Financial reports. Budgets. Operational dashboards. Risk reports. Compliance reports. Audit findings. Cybersecurity alerts. Customer complaints. Performance measures. Emails. Policies. Board packages. Management presentations. But having enormous amounts of information does not necessarily mean that an organization has effective Informati

John C. Blackshire, Jr.
Sep 48 min read
A Free Tool for Assessing GAO Green Book Compliance: Using Virginia's ARMICS Assessment Guides
Governmental Organizations Don't Have to Start Their Green Book Assessment From Scratch How does a governmental organization determine whether its system of internal control complies with the GAO Green Book? That can be a surprisingly difficult question. The U.S. Government Accountability Office's Standards for Internal Control in the Federal Government—better known as the Green Book—provides an excellent framework for internal control. But reading the Green Book is one thing

John C. Blackshire, Jr.
Sep 49 min read
True Quality Management with COSO needs a Maturity Model!
The History of Maturity Models—and How Auditors Can Put Them to Work How good is your organization's system of internal control? For decades, auditors have approached that question primarily by determining whether controls are properly designed and operating effectively. Those are essential questions—but they don't tell the whole story. Consider two organizations with the same key control. At Organization A, the control is performed manually by an experienced employee who kno

John C. Blackshire, Jr.
Sep 49 min read
How Mature Are Your Control Activities? Measuring Whether Controls Really Manage Risk
Organizations frequently spend enormous amounts of time documenting internal controls. They build: Risk and control matrices Policies and procedures Approval requirements Reconciliations Segregation-of-duties controls System access controls Management reviews Automated controls Exception reports Supervisory reviews Then Internal Audit, external audit, compliance, or management tests those controls and asks: “Is the control operating effectively?” That is an important question

John C. Blackshire, Jr.
Sep 48 min read
Managing Partner: Your Firm Is Facing Its First PCAOB Inspection. Are You Ready?
Your accounting firm is PCAOB registered. You audit two SEC issuers. And now, for the first time, your firm is facing the prospect of a PCAOB inspection. Do not make the mistake of thinking that being a small firm with only two issuer clients makes the inspection less important. It may make preparation even more important. Two Issuers Means a Concentrated Risk A registered public accounting firm that regularly provides audit reports for 100 or fewer issuers generally falls wi

John C. Blackshire, Jr.
Aug 314 min read
How Mature Is Your Control Environment? A Better Way to Measure the Foundation of Internal Control
Organizations frequently ask Internal Audit a deceptively simple question: “Are our internal controls effective?” There is another question that may tell management and the Audit Committee considerably more: “How mature is our control environment?” The distinction matters. A control may exist and operate today while the broader control environment remains dependent on particular individuals, informal practices, management intervention, or institutional memory. Another organiz

John C. Blackshire, Jr.
Aug 2510 min read
PCAOB Audit Evidence: The Auditor's Opinion Is Only as Good as the Evidence Behind It
PCAOB Audit Evidence — September 17 and November 12, 2026 Every external audit ultimately comes down to one question: What evidence supports the auditor's opinion? An audit program is not evidence. A completed checklist is not evidence. Management's explanation is not automatically sufficient evidence. And a workpaper conclusion saying “No exceptions noted” is only as reliable as the audit evidence and procedures supporting it. That is why PCAOB AS 1105 — Audit Evidence is on

John C. Blackshire, Jr.
Aug 258 min read
PCAOB AS 2810: The Audit Is Not Finished Until You Evaluate the Results
Evaluating Audit Results — October 1 and December 3, 2026 Auditors spend enormous amounts of time planning and performing an audit. They assess risk. Test controls. Confirm balances. Inspect documents. Perform substantive procedures. Analyze transactions. Investigate exceptions. Document their work. But eventually the engagement team must answer the question that matters most: What do all of these audit results, taken together, tell us? That is the purpose of PCAOB Auditing S

John C. Blackshire, Jr.
Aug 257 min read
The GAO Green Book Changed for FY2026: Government Auditors and Managers Need to Understand What Changed
GAO Green Book Standards — Wednesday, October 28, 2026 The GAO Green Book is not simply another government compliance manual. It provides the framework federal agencies use to design, implement, operate, and evaluate an effective system of internal control. The framework is also highly relevant to state and local governments, grant recipients, public authorities, government contractors, auditors, and other organizations responsible for public funds. And in 2026, there is an e

John C. Blackshire, Jr.
Aug 257 min read
Technical Skills Get You Into Internal Audit. Soft Skills Make You Effective.
Soft Skills for Auditors — September 14 and November 9, 2026 Internal Auditors spend years developing technical skills. We learn COSO, risk assessment, internal controls, sampling, fraud, cybersecurity, accounting, regulatory requirements, data analytics and audit documentation. All of those skills matter. But consider a different problem. What happens when the auditor identifies the right issue—but cannot persuade management that it matters? What happens when the evidence is

John C. Blackshire, Jr.
Aug 257 min read
How Mature Is Your Risk Assessment Component? Why COSO Should Start With Objectives
The COSO Internal Control—Integrated Framework is usually presented in this order: Control Environment Risk Assessment Control Activities Information and Communication Monitoring Activities That is COSO’s formal structure. But from a practical management and auditing perspective, there is a strong argument that Risk Assessment should be the first component considered when evaluating how an organization manages internal control. Why? Because COSO’s Risk Assessment component be

John C. Blackshire, Jr.
Aug 2510 min read
COSO Framework and ICFR Assessments: Stop Treating SOX Compliance as a Checklist
Two-Day COSO & ICFR Training — September 16–17 and November 11–12, 2026 Internal Control over Financial Reporting should answer a straightforward question: Can management demonstrate that the controls protecting financial reporting are properly designed and actually operating effectively? That sounds simple. In practice, organizations can accumulate hundreds—or thousands—of controls, spreadsheets, narratives, certifications and testing workpapers without maintaining a clear c

John C. Blackshire, Jr.
Aug 258 min read
PCAOB AS 1215: If It Is Not Documented, Can You Prove the Audit Work Was Performed?
Audit Documentation Training — September 29 and December 1, 2026 An auditor can perform an excellent audit procedure, reach the correct conclusion and still have an audit-quality problem. Why? Because the workpaper does not demonstrate what the auditor actually did. That is the problem addressed by PCAOB Auditing Standard AS 1215 — Audit Documentation. Corporate Compliance Seminars' PCAOB AS 1215: Audit Documentation is a focused 1-CPE Auditing webinar designed to help audito

John C. Blackshire, Jr.
Aug 257 min read
What the CIA Taught Me About Audit Tradecraft
I learned the real meaning of tradecraft while designing a training-tracking system for new intelligence officers at the Central Intelligence Agency. The system had to track more than completed courses and classroom hours. The CIA was developing professionals who needed to acquire, demonstrate and continuously improve the practical skills required to perform difficult work in uncertain and high-risk environments. Those skills represented their tradecraft. The auditing profess

John C. Blackshire, Jr.
Aug 247 min read
PCAOB Audit Tradecraft for Broker-Dealer Auditors: Specialized Work Demands Specialized Skills
A broker-dealer audit is not an ordinary financial-statement audit with a different client name. Broker-dealers operate under specialized SEC financial-responsibility, customer-protection, net-capital and reporting requirements. Their auditors must understand both PCAOB auditing standards and the regulatory framework governing the client’s operations. A technically weak broker-dealer audit can expose the accounting firm to PCAOB inspection findings, regulatory enforcement, re

John C. Blackshire, Jr.
Aug 246 min read
PCAOB QC 1000: Audit Firms Are Running Out of Time to Build Effective Quality Control Systems
The PCAOB’s new quality control standard becomes effective on December 15, 2026. For registered public accounting firms, that deadline is no longer distant. A firm cannot comply with QC 1000 by revising a policy manual during the final weeks before implementation. It must design a risk-based system, assign accountability, identify quality risks, implement responses, monitor performance, remediate deficiencies and document that the system actually operates. Corporate Complianc

John C. Blackshire, Jr.
Aug 246 min read
Auditing Procure-to-Pay: Follow the Money From Purchase Request to Final Payment
The Procure-to-Pay cycle is one of the largest, most complicated and most fraud-prone business processes in most organizations. It touches procurement, operations, receiving, accounts payable, treasury, accounting, information technology and third-party management. A control failure at any point can result in overpayments, duplicate payments, unauthorized purchases, vendor fraud, supply-chain disruption or financial-reporting errors. Corporate Compliance Seminars’ Auditing Pr

John C. Blackshire, Jr.
Aug 245 min read
World-Class Enterprise Risk Management: Turning Risk Information Into Better Decisions
Many organizations claim to have an enterprise risk management program. They maintain a risk register, assign risk ratings and present a colorful heat map to the board once or twice a year. That does not necessarily mean they are managing risk. A world-class Enterprise Risk Management program must influence strategy, resource allocation, performance, internal controls and daily decision-making. If ERM exists only as a compliance document, it is not protecting the organizatio

John C. Blackshire, Jr.
Aug 245 min read
Auditing Social Media: Protecting Your Organization’s Brand, Data and Digital Assets
Organizations spend heavily protecting buildings, computer systems, financial records and intellectual property. Yet many fail to apply comparable controls to their social media accounts. That is a serious oversight. A compromised account, unauthorized post or poorly managed response can damage an organization’s reputation within minutes. Social media therefore belongs in the audit universe—not solely under marketing or public relations. Corporate Compliance Seminars’ Auditin

John C. Blackshire, Jr.
Aug 245 min read
bottom of page