Frequently Asked Questions
Practitioner-level answers to the questions internal audit leaders, audit committee chairs, CFOs, and general counsel ask before they engage Cherry Hill. If your question is not here, tell us what to add.
Internal Audit Co-Sourcing
What is internal audit co-sourcing?
Internal audit co-sourcing is when an outside firm works alongside your in-house internal audit team on specific audits or capacity gaps, under your Chief Audit Executive's direction. The senior practitioners brought in plug into the existing function rather than replacing it, which is why it works when the alternative (hiring or running a Big Four engagement) is too slow or too heavy. Cherry Hill's co-sourcing model is senior-led, so the practitioner who shows up at the kickoff is the practitioner doing the work.
How is co-sourcing different from outsourcing internal audit?
Co-sourcing keeps the internal audit function in-house and adds external expertise on specific audits or specialty areas. Outsourcing replaces the function entirely, which most organizations with a real internal audit charter do not want, since the function exists to provide independent assurance from inside the company. Cherry Hill leads with co-sourcing, so your CAE keeps ownership of the plan, and supports full outsourcing where a company has no internal function to build around.
When should we co-source internal audit work?
Co-source when your team has the right judgment but not the right capacity or specialty for the audit in front of them. Common triggers include AI governance audits, third-party risk work, cybersecurity audits, and External Quality Assessment preparation. The pattern that does not work is co-sourcing as a permanent way to avoid building team depth; co-sourcing extends the team, it does not replace headcount strategy.
External Quality Assessment (EQA)
What is an internal audit External Quality Assessment?
An External Quality Assessment is an independent review of how well an internal audit function complies with the IIA Global Internal Audit Standards. It evaluates the function's charter, methodology, audit plan, technology, talent, reporting, and governance against the Standards, and produces a graded conformance report. The audit committee and the CAE use the result to decide what to fix and what to scale, and Cherry Hill's EQA practice is built to deliver findings the CAE can act on within ninety days.
How often is an EQA required?
The IIA Standards require an external quality assessment at least every five years for any internal audit function representing conformance with the Standards. Most CAEs run a self-assessment with independent validation in years two or three to avoid surprises in the formal year-five assessment. Cherry Hill performs EQAs under the 2024 IIA Global Internal Audit Standards.
What happens during an EQA engagement?
The assessor reviews the function's charter, methodology, audit plan, completed work papers, technology stack, and team capability, then interviews the CAE, senior management, and audit committee. The output is a conformance rating, specific improvement opportunities, and a benchmark against comparable functions. The strongest EQAs end with findings the CAE can act on within ninety days, not a binder, which is the Cherry Hill standard.
SOX Compliance and Advisory
Does my company need SOX compliance if we are not public yet?
Pre-IPO companies preparing to file an S-1 typically need to demonstrate SOX readiness during the IPO process and become fully subject to SOX once public. Private companies under a parent that is SEC-registered may also fall in scope. The strongest signal that pre-IPO SOX work has started in earnest is when the audit committee asks for an ICFR readiness plan with named owners, which is where Cherry Hill's SOX readiness practice typically starts.
What is SOX 404 testing?
SOX 404 testing is the work of testing whether internal controls over financial reporting are designed effectively and operating effectively. Section 404(a) requires management to assess and attest; section 404(b) requires the external auditor to attest separately for larger filers. Most of the cost in any SOX program is in the 404 testing cycle, not in the documentation work that precedes it, which is why SOX co-sourcing often makes more sense than building out a permanent testing team.
How long does SOX readiness take for a pre-IPO company?
Most pre-IPO SOX readiness programs run twelve to eighteen months from kickoff to full operational effectiveness, depending on the maturity of the existing control environment. Companies with documented processes, an ERP, and a finance function in place can compress this; companies still on QuickBooks with informal processes cannot. Cherry Hill's SOX readiness engagements run alongside the existing finance and IT teams, not separately.
AI Governance and Emerging Risk
What does internal audit do about AI risk?
Internal audit reviews how the organization governs, monitors, and controls AI deployments, then reports findings to the audit committee. The scope typically includes the AI governance framework, model risk management practices, training data controls, ongoing monitoring, and the controls that prevent unintended use. The reference frameworks most audit committees expect to see are NIST AI RMF and, for European exposure, the EU AI Act, and Cherry Hill's AI governance work ties the audit findings back to both.
How do we audit a machine learning model?
A machine learning audit reviews the model's training data, design choices, ongoing performance monitoring, drift detection, retraining cadence, and the controls around access and change management. The audit also tests whether the use case sits inside the organization's AI risk policy. Auditing the model in isolation without auditing the controls around it is the most common mistake, which is why Cherry Hill scopes ML audits to cover both.
Does the EU AI Act apply to US companies?
The EU AI Act applies to US companies if their AI systems are placed on the EU market, used by parties in the EU, or produce output used in the EU, regardless of where the company is headquartered. High-risk AI systems carry the heaviest compliance obligations and the longest preparation runway. Most US companies first realize they have EU exposure when a customer in the EU asks for the documentation, which is the point at which Cherry Hill's AI governance practice typically gets the call.
Fraud Risk and Investigations
When should we run a fraud risk assessment?
Run a fraud risk assessment when the audit committee asks for one, when a near-miss surfaces a control gap, when a major business change (acquisition, system migration, new product line) shifts the risk profile, or annually as part of the broader risk assessment cycle. The output is a documented inventory of fraud risks, the controls in place, and the gaps the audit plan should close. The fraud risk assessment is one of the most under-used assurance tools in mid-market companies, and Cherry Hill runs these regularly for clients who want a defensible baseline before something goes wrong.
What happens during a fraud investigation?
A fraud investigation is a controlled inquiry into a specific allegation or anomaly, conducted under legal privilege where available. The work includes preserving evidence, interviewing relevant parties, reconstructing transaction histories, and producing a factual report that withstands later scrutiny. Cherry Hill investigators do not represent any party; the work is independent fact-finding.
Cybersecurity Risk Consulting for Internal Audit
How does internal audit assess cybersecurity risk?
Internal audit assesses cyber risk by testing the organization's cyber controls against NIST CSF, ISO 27001, or another adopted framework, and by examining incident response, third-party cyber risk, and material disclosure readiness. The work typically informs the audit committee report and the cybersecurity disclosures the SEC now requires. The cyber audit is different from a penetration test or a vulnerability scan; it is an assurance review of the program, which is what Cherry Hill delivers.
What does the SEC cybersecurity rule require of public companies?
The SEC rule requires public companies to disclose material cybersecurity incidents within four business days of determining materiality, and to disclose annually their cybersecurity risk management strategy, governance, and the board's oversight role. Internal audit is one of the functions the board relies on for that oversight signal. Companies with mature cyber programs find the rule lower-stress; the rule is the catalyst that exposes the immature ones, which is when Cherry Hill gets the call.
Expert Witness and Litigation Support
When would I retain an internal audit expert witness?
A general counsel or litigation team retains an internal audit expert witness in disputes turning on internal control quality, audit committee oversight, fraud investigation procedure, or governance failures, where credentialed practitioner judgment will be tested in deposition or at trial. Cherry Hill principals serve as testifying and consulting experts in commercial litigation and regulatory matters. Discretion is non-negotiable; expert engagements are run separately from advisory engagements.
About Cherry Hill Advisory
What is Cherry Hill Advisory?
Cherry Hill Advisory is an independent internal audit and risk advisory firm. We provide internal audit co-sourcing, External Quality Assessments, fraud risk and investigations, Sarbanes-Oxley compliance advisory, AI governance, cybersecurity risk consulting, and expert witness services to organizations in the United States. The firm also operates a separate practice, Cherry Hill Accounting and CFO, for fractional CFO, managed accounting, and tax services.
Who is Cherry Hill for?
Cherry Hill works with Chief Audit Executives, CFOs and Chief Risk Officers at companies without a full internal audit function, audit committee chairs, general counsel handling investigation or expert witness matters, and growth-stage founders looking for senior accounting and CFO support. The common thread is a buyer who wants senior judgment in the room rather than a Big Four pyramid or a generalist consultant. Most engagements start with a conversation about one specific need.
How is Cherry Hill different from a Big Four firm?
The senior practitioner who sells the engagement is the senior practitioner doing the work, not a partner handing off to a senior manager handing off to a team of juniors. Cherry Hill is also boutique in size, which means the practice owner is involved in every engagement, and fixed-fee or scoped-engagement structures replace the leverage-model hourly billing common at large firms. Both models have their place; companies pick Cherry Hill when senior judgment matters more than scale.

