3P StrategyProduct · Process · People

Process — the second P

How to start, and how the audit runs.

Four steps, a fixed scope and a fixed window. You know what is being reviewed, what I need from you, and what lands at the end — before anything is signed.

How it works

Four steps, no surprises.

  1. Intro call

    30 minutes to confirm what is in scope, what access is needed, and whether an audit is even the right instrument. If it is not, I will say so.

  2. Audit window

    1–2 weeks of document review, technical checks and stakeholder interviews. You keep working; the review runs around you.

  3. Report delivery

    Full written report, risk register and roadmap, plus a live walkthrough with the people who have to act on it.

  4. Optional follow-up

    An implementation sprint or retainer to work the roadmap — only if you want it, and priced against the actual findings.

Inside the audit window

What actually happens across the two weeks.

Days 1–2 · Kickoff and access
Scope confirmed in writing, NDA in place if you want one, and a single shared folder set up for documents. No production access unless the scope requires it.
Days 2–5 · Document and technical review
Financial controls, delivery workflow, architecture, repositories, roadmap history, governance records and investor communications, read against each other rather than in isolation.
Days 4–8 · Stakeholder interviews
30–60 minutes each with two or three key people, plus community and stakeholder signal where relevant. This is where paper governance and real governance separate.
Days 8–10 · Scoring and drafting
Each dimension scored, findings written up with severity, impact, owner and effort. Draft shared for factual corrections before it is finalized.
Day 10–14 · Delivery and walkthrough
Final report, risk register and 30/60/90-day roadmap, followed by the review call with your team, investor or committee.

From your side

What I need from you.

Less than most teams expect. If a document does not exist, that absence is itself a finding — do not build it for the audit.

  • Existing documentation as it stands today — no tidying up first
  • A repository or architecture walkthrough where the scope is technical
  • 30–60 minutes each with two or three key people
  • One named point of contact who can answer or route questions

FAQ

Before you book

Is this confidential?

Yes. All findings, documents and communications stay strictly between you and me unless you choose to share the report with investors or a committee yourself. NDA on request before anything substantive is exchanged.

Do you need admin access to our systems?

Only what the agreed scope requires. Most audits run from documentation, repositories and interviews rather than production access.

Can this be used for a live raise or grant application?

Yes. Many clients commission the audit specifically to get ahead of investor or committee diligence, and use the report as a supporting document.

What if the audit finds serious problems?

That is the point of doing it before capital moves. Every finding comes with a specific, prioritized fix and actionable recommendations — the report is a work plan, not a verdict.

How long does it take, and what do you need from us?

One to two weeks from kickoff for a full audit. From your side: access to existing documentation, a repository walkthrough where relevant, and 30–60 minutes each with two or three key people.

Can you run the audit while we are mid-raise?

Yes, and it is a common reason to commission one. The scope can be narrowed to the areas a specific investor or committee is most likely to probe, so the timeline fits inside your process.

Next step

Start with the intro call.

Thirty minutes to confirm scope and access. No preparation needed — the current state of your documentation is the useful input.

Confidential · NDA on request · Typical turnaround 1–2 weeks