IT audit & ITGC
End-to-end testing of general controls across the applications and infrastructure that carry financial and operational reporting.
- SOX ITGC testing
- SOC 1 & SOC 2 readiness
- Application & interface controls
- Remediation support
Independent IT & AI audit practice
Yinsight Capital is the independent practice of Kevin Yin — IT audit, AI governance, and controls assurance for teams whose systems now make decisions on their own.
Practice
Most control failures are not exotic. They are a review nobody performed, an approval nobody kept, a model nobody owns. The work is finding those before an auditor, a regulator, or an incident does.
End-to-end testing of general controls across the applications and infrastructure that carry financial and operational reporting.
Governance that survives review: a real inventory, owners with authority, evaluations on the record, and oversight that leaves a trail.
Designing controls people can actually run — and the evidence pipeline that makes the next audit a query instead of a scramble.
Method
Four stages, in order. Each one ends with something written down, so you are never waiting until the final report to learn where you stand.
Systems, processes, and obligations in play. What is material, what is noise, and which framework you are actually answering to.
Sit with the people who run the control. Trace one transaction, one deployment, one model release, from request to record.
Sampling and inspection against the design. Gaps are raised as they surface — with severity, root cause, and the fix that closes them.
A findings register your team can work from, and a summary your board or auditor can read without translation.
Coverage
The frameworks I work in most often, and the deliverable each engagement typically ends with.
| Framework | Scope | Engagement | Typical output |
|---|---|---|---|
| SOX ITGC | Access, change, operations over in-scope financial systems | Test | Control matrix, test workpapers, deficiency log |
| SOC 2 (TSC) | Security, availability, confidentiality criteria | Readiness | Gap assessment and remediation plan ahead of the examination |
| ISO/IEC 27001 | ISMS scope, Annex A controls, risk treatment | Readiness | Statement of applicability review, internal audit programme |
| ISO/IEC 42001 | AI management system, roles, lifecycle controls | AI | AIMS gap assessment and control design |
| NIST AI RMF | Govern, map, measure, manage across the AI portfolio | AI | Model inventory, risk profiles, oversight controls |
| EU AI Act | Role and risk-tier classification, obligation mapping | AI | Obligation register with owners and evidence requirements |
Insights
Short pieces on where control frameworks and AI systems meet — and where they do not yet.
Contact
Whether it is a first SOC 2, an ITGC remediation that has run too long, or a board asking who signs off on the models — send the situation and I will tell you plainly whether I am the right person for it.