Audit & Assurance
A clean audit opinion says the numbers are right. It does not say the controls that produced them are any good.
Goldenthal & Suss Consulting P.C. performs internal control assessments for businesses, nonprofits, and government entities. An assessment examines how transactions are authorized, recorded, and reviewed — segregation of duties, cash handling, payroll, procurement, revenue, financial close, and IT access — and reports specific weaknesses and practical improvements, using the COSO Internal Control–Integrated Framework or, for organizations with federal awards, the GAO's Green Book as the benchmark. It is a separate engagement from a financial statement audit, which evaluates controls only as far as needed to plan the audit.
The usual triggers are a change that outgrew the existing controls — rapid growth, a new finance team, a new system, a first federal grant — or an event that exposed them, such as a fraud, a bounced payroll, or a significant audit finding. Owners of closely held businesses frequently commission an assessment when they step back from day-to-day operations and need to know the business can be trusted to run without them watching every check.
Organizations with federal awards have a specific obligation: the Uniform Guidance requires them to maintain effective internal control over those awards, and the auditor will test it.
Small organizations rarely have enough people to achieve textbook segregation of duties. Recommending two more hires is easy and useless. The better answer is usually compensating controls — owner or board review of bank statements and payroll registers, dual authorization in the banking platform, restricted system permissions, and a documented monthly close — that close the real gaps with the staff that exists.
Only partially. A financial statement audit considers internal control as needed to plan and perform the audit, and auditors communicate significant deficiencies they find, but the audit is not designed to evaluate your controls comprehensively. A dedicated assessment is.
Usually the COSO Internal Control–Integrated Framework (2013), the standard reference for businesses and nonprofits. For organizations with federal awards we also refer to the GAO's Standards for Internal Control in the Federal Government (the Green Book), which the Uniform Guidance names alongside COSO.
With limits. An audit firm can generally assess and recommend, but cannot design and implement the controls or take on management's responsibility for them without impairing independence — and the restrictions are stricter under Government Auditing Standards. We set the scope accordingly when we are also the auditor.
Sources & review
Internal control requirement for federal awards at 2 CFR 200.303 (COSO / GAO Green Book). Reviewed 2026-10-01. Thresholds and deadlines change — confirm current requirements before relying on them.
Tell us about your organization and the deadline you are working toward. We will tell you what the engagement involves and what it costs.
Request a ProposalStaten Island, NY · Freehold, NJ
(718) 227-6035