
Home/What we do/Assurance
Service
Assurance
Assurance advisory — technology and AI first. We are not an audit firm.
Independent review of the systems, models, controls and reported information a board, a regulator or an acquirer tests first. No statutory audit, no attest work, no opinion signed.
The practice
We are an assurance advisory practice. We review technology, models, controls and reported information, and we write the result for the person who has to act on it — a board committee, an examiner, a lender, a buyer. We are not a licensed CPA firm and we do not sign audit opinions.
Most review work fails on sequencing rather than rigour. A finding raised in month nine that could have been raised in month two costs the same to fix and far more to explain. We front-load the things that change a decision and leave the housekeeping for the back half.
What this practice is
An assurance advisory practice. Not an audit firm.
We are not a licensed CPA firm and we do not perform statutory audit or attest engagements. What we do is assurance advisory — principally technology assurance and AI assurance, and around those the controls, readiness, reporting and remediation work that decides whether an audit, an examination or a diligence process goes well. Every organization already believes its controls hold. The question is whether that belief survives contact with a board committee, an examiner, a lender or a buyer.
Independent by construction
We sell no software, take no referral fees and have no audit relationship to protect. There is nothing downstream of the finding that would make us soften it.
Sequenced by consequence
Findings are ordered by what gets tested first and what carries the most exposure — not by what is easiest to close before a status meeting.
Technology inside the scope
Systems, access, interfaces and the controls that only exist in configuration. Reviewing the process and ignoring the platform it runs on is how findings get missed.
Written to be acted on
A findings list nobody can act on is a document, not an outcome. Each item carries an owner, a date and a plain-language statement of what happens if it stays open.
Our offerings
Eight ways this practice is bought.
Most engagements start as one of these and pull in a second. None of them require a licensed CPA firm — the boundary above is the reason this list looks the way it does.
Technology assurance
Our core offering. Access, change management, interfaces, automated controls and the parts of the control environment that exist only in system configuration — reviewed on the platform itself rather than from a process narrative somebody wrote three releases ago.
AI assurance
Independent review of models in production: what the system decides, on what data, with what oversight, and whether any of that can be reconstructed when someone asks. Written for a risk committee or a regulator, not for the build team.
Controls design & testing
Design effectiveness and operating effectiveness across the processes that carry genuine financial or operational consequence — not every process, which is how these exercises become unaffordable and get ignored.
Assurance readiness
Preparing for a SOC 1 or SOC 2 examination, a first audit or a new regime — scoping, control narratives, evidence discipline and a dry run — so the real thing is a retrieval exercise rather than a discovery exercise.
Diligence preparation
What a buyer, lender or investor tests first — and what they will find if nobody has looked. Run early enough that the answers change the outcome rather than the price.
Non-financial reporting
Operational, supply chain and sustainability reporting is increasingly read by people who did not write it. We get it to a standard that survives that reading.
Regulatory & emerging regimes
New regimes arrive faster than the control environment adapts. We map what has changed to what you already have, so the gap is a short list rather than a programme.
Remediation & follow-through
A findings list is not a plan. We sequence remediation against what gets tested first, assign owners, and stay through the closing and re-testing of it.
How we are different
Three things that change what the report says.
Independence is structural, not a statement
We hold no audit relationship, sell no compliance software and take no referral fees from anyone whose product might appear in a remediation plan. That is not a values claim — it is the reason a finding can be written the way the evidence supports it. Firms that audit you cannot also advise you on what they audited; firms that sell you the control cannot independently assess it. We do neither, which narrows what we can sell and widens what we can say.
Our thinking
What we pride ourselves on.
Three of these are true of every Taidou engagement regardless of practice. They are also the three things we are most often told are unusual — which says more about the industry than about us.
The person who scopes it runs it.
There is no handoff between the team that wins the work and the team that does it. If you met someone in the first conversation, you will still be dealing with them in the last one. This is the single thing clients tell us they notice first.
We write down what we are not doing.
Every engagement starts with a scope that names the things we have deliberately excluded and why. It makes the first conversation harder and every conversation after it easier.
We stay past the point it is comfortable.
Most firms hand over when the design is agreed and the change has been announced — the moment of maximum fragility. We hand over to named owners after it is running, and we come back to check.
We tell you what we cannot do, first.
The second line of this page names the work we are not permitted to perform. That is unusual for a services page and it is deliberate: a client who hires us expecting an audit opinion has a problem in month three, and so do we.
Where this lands
The industries we bring Assurance to.
Related thinking
What we have published on this.
Interoperability isn't a compliance deadline. It's a business model.
CMS-0057-F is being treated as a date to survive. The organizations treating it as an operating decision are the ones still compounding on it in three years.
ResearchWhy transformation programmes stall at month nine
WorkBack-office migration across three delivery centres
Taidou Answer
Not sure this is the practice you need?
Describe the problem in your own words. Taidou Answer indexes it across every industry and service line we practice in, and routes you to the senior consultant who has handled it before.
Explore more