Yinsight Capital

Independent IT & AI audit practice

Evidence your controls actually work.

Yinsight Capital is the independent practice of Kevin Yin — IT audit, AI governance, and controls assurance for teams whose systems now make decisions on their own.

Practice

Three lines of work, one standard of evidence.

Most control failures are not exotic. They are a review nobody performed, an approval nobody kept, a model nobody owns. The work is finding those before an auditor, a regulator, or an incident does.

IT audit & ITGC

End-to-end testing of general controls across the applications and infrastructure that carry financial and operational reporting.

  • SOX ITGC testing
  • SOC 1 & SOC 2 readiness
  • Application & interface controls
  • Remediation support

AI governance & assurance

Governance that survives review: a real inventory, owners with authority, evaluations on the record, and oversight that leaves a trail.

  • NIST AI RMF alignment
  • ISO/IEC 42001 readiness
  • EU AI Act obligation mapping
  • Model & vendor risk review

Controls advisory

Designing controls people can actually run — and the evidence pipeline that makes the next audit a query instead of a scramble.

  • Control design & rationalisation
  • Evidence automation
  • Risk & control matrices
  • Audit-readiness rhythm

Method

How an engagement runs.

Four stages, in order. Each one ends with something written down, so you are never waiting until the final report to learn where you stand.

STAGE 01

Scope

Systems, processes, and obligations in play. What is material, what is noise, and which framework you are actually answering to.

STAGE 02

Walkthrough

Sit with the people who run the control. Trace one transaction, one deployment, one model release, from request to record.

STAGE 03

Test

Sampling and inspection against the design. Gaps are raised as they surface — with severity, root cause, and the fix that closes them.

STAGE 04

Report

A findings register your team can work from, and a summary your board or auditor can read without translation.

Coverage

Frameworks and what comes out of them.

The frameworks I work in most often, and the deliverable each engagement typically ends with.

Framework Scope Engagement Typical output
SOX ITGC Access, change, operations over in-scope financial systems Test Control matrix, test workpapers, deficiency log
SOC 2 (TSC) Security, availability, confidentiality criteria Readiness Gap assessment and remediation plan ahead of the examination
ISO/IEC 27001 ISMS scope, Annex A controls, risk treatment Readiness Statement of applicability review, internal audit programme
ISO/IEC 42001 AI management system, roles, lifecycle controls AI AIMS gap assessment and control design
NIST AI RMF Govern, map, measure, manage across the AI portfolio AI Model inventory, risk profiles, oversight controls
EU AI Act Role and risk-tier classification, obligation mapping AI Obligation register with owners and evidence requirements

Contact

Tell me what you are being asked to prove.

Whether it is a first SOC 2, an ITGC remediation that has run too long, or a board asking who signs off on the models — send the situation and I will tell you plainly whether I am the right person for it.

Based in
Add your city
Engagements
Remote & on-site