Banking & mortgage
FFIEC IT examination readiness, GLBA safeguards, vendor management programmes, and controls over core banking and loan origination systems.
A licensed California CPA who also holds CISA, CISM, CDPSE and CCSE, so attestation, IT governance and cloud security compliance come from one engagement instead of two vendors and a handoff.
Tax and accounting form the licensed base. Governance, security and technology deployment sit above it, and because they share a single practitioner, the handoffs that normally break these engagements do not exist.
Scroll or drag the panels to see all four pillars.
The licensed CPA foundation: tax, accounting, financial leadership, and the attestation work only a CPA firm can sign.
Board-level governance design, risk and control frameworks, IT general controls, and the diligence work that decides whether a deal is priced correctly.
SOC 2, cybersecurity risk, cloud platform compliance and privacy law, assessed and attested by one licensed firm rather than split across two vendors.
The build tier: AI-enabled continuous audit, ERP programmes, robotic process automation and FinOps, specified and deployed, not just recommended.
Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
There is a specific problem in this market, and it is worth naming plainly.
If you need a SOC 2 report, an IT general controls audit, or a cybersecurity assessment tied to your financial reporting, you currently have two options in Ventura County. You can hire a managed service provider or security consultancy, capable at readiness and remediation, and barred under AICPA rules from issuing the attestation. Or you can hire a CPA firm that can sign the report and has never configured an IAM policy.
So the work gets split. A local consultancy runs readiness, then hands a package to a remote CPA firm that arrives cold, disagrees with half the scoping decisions, and raises findings the first vendor considered settled. You pay twice and manage the seam yourself.
This practice holds both sides. The CPA licence permits the attestation. CISA, CISM, CDPSE and CCSE cover the systems, the security programme, the privacy engineering and the cloud architecture. One scope, one methodology, one set of judgments about what counts as evidence.
It also works in the other direction. Because the same person has spent fifteen years as a CFO and Corporate Controller and twenty auditing banks, insurers and mortgage companies, a technical finding arrives translated into what it would actually cost the business; which is the form a board can act on.
Client types accumulated since 1986, and the specific obligations each one brings.
FFIEC IT examination readiness, GLBA safeguards, vendor management programmes, and controls over core banking and loan origination systems.
Statutory reporting environments, claims system controls, and the third-party risk work that regulators now examine in detail.
SOC 2 as a condition of enterprise contracts, cloud security compliance, and revenue recognition that survives a first audit.
Inventory and cost accounting, ERP programmes, research credit documentation, and defence supply chain requirements.
FDA 21 CFR Part 11 and GxP obligations over validated systems, mapped against ITGC so the same control is not tested twice.
Multi-state sales tax nexus, marketplace facilitator analysis, and the exemption certificate discipline that decides an audit outcome.
Fund accounting, grant compliance, Single Audit requirements, and board financial oversight for volunteer directors.
Practice valuation, partner buy-in and buy-out structuring, compensation models and succession.
Not billed. Establishes what you actually need, which is frequently narrower than the initial request. Companies commission audits where a review satisfies the covenant more often than any other single mistake.
A short, defined piece of work that converts an unknown into a plan, a gap list, a control matrix, or an exposure quantification, with effort and sequence attached.
The engagement itself, run to an agreed calendar with open items raised as they arise rather than accumulated into a surprise at the end.
Documentation your team can maintain, and training so they can. Work that requires the consultant to return annually to operate it was designed badly.
Under AICPA guidance only a licensed CPA firm can issue your SOC report. The consultancies near you that understand security cannot sign it, so most companies in Ventura County run readiness with one vendor and the examination with another, and manage the seam themselves.
That seam is where scoping disagreements, duplicated evidence and re-tested controls live. Holding the CPA licence alongside CISA and CISM removes it entirely.
"MFA is not enforced on the VPN" tells a board nothing it can act on. The same finding expressed as what it permits, which systems it exposes, what a comparable incident costs, and whether a compensating control exists; that is a decision a board can make.
Making that translation needs someone who has audited the systems and closed the books. Twenty years auditing banks and insurers, fifteen as a CFO and Corporate Controller.
Each city page covers the industries, obligations and engagements specific to that market, not the same page with the name changed.
Governance advisory, internal controls, tax and accounting for Moorpark businesses. Licensed California CPA also holding CISA, CISM and CDPSE.
CPA services in MoorparkIT audit, ITGC, SOC 2 readiness and validated-systems assurance for Thousand Oaks biotech, medical device and technology companies. CPA, CISA and CISM.
CPA services in Thousand OaksAccounting, outsourced CFO, payroll and sales tax compliance for Simi Valley manufacturers, contractors and closely held businesses.
CPA services in Simi ValleyCloud security compliance, ERP advisory, cybersecurity assessment and CPA services for Camarillo technology, semiconductor and aerospace businesses.
CPA services in CamarilloAudit and attestation, risk advisory, nonprofit and transaction services for Ventura businesses and organisations across Ventura County.
CPA services in VenturaCorporate governance, SOX 404, IT audit and transaction advisory for Los Angeles public companies and financial institutions. Serving LA since 1986.
CPA services in Los AngelesEvery article is written by Javed Peeran, no ghostwriters, no syndicated content.
Most SOC 2 projects slip for the same handful of reasons. Here is what a readiness assessment actually covers, the gaps that turn up almost every time, and honest numbers on cost and timeline.
Read the articleA badly scoped first-year SOX programme costs roughly three times what a well-scoped one costs, every year, indefinitely. The decisions that determine which you get are made in the first quarter.
Read the articleThe vendor pitch implies an agent that audits your company. The sceptical response is that none of it counts as evidence. The useful territory is in between, and it is narrower and more specific than either.
Read the articleNot answered here? Ask Javed directly
The combination of credentials, and what it lets a single engagement cover. A CPA licence permits audit and attestation work. CISA, CISM, CDPSE and CCSE cover IT audit, security management, privacy engineering and cloud security.
In practice that means the person who signs your financial statements can also read your access listings, so a company needing SOC 2 does not have to hire a security consultancy for readiness and a separate remote CPA firm for the report, and manage the seam between them. Across Ventura County, no other CPA practice currently holds both sides.
Yes. The firm has filed returns and prepared financial statements for Los Angeles businesses since 1986 and continues to. Tax, accounting, payroll and outsourced CFO work form the base tier of the practice.
What has changed is the emphasis. Governance, IT assurance and security compliance are where the practice is distinctive, so they lead, but a company that needs a corporate return and a clean monthly close is well served here.
Most engagements sit between roughly $2M and $150M in revenue, plus public filers of comparable size and financial institutions of varying scale.
Smaller than that, a full governance or risk programme is usually disproportionate and a focused controls review is the better use of budget. Substantially larger, or requiring standing capacity across several offices, and a national firm is genuinely the better answer; you will be told that directly rather than sold an engagement that does not fit.
No, and that constraint is applied in both directions. AICPA independence rules restrict a firm performing an attestation engagement from also designing or operating the controls it will later test, and an opinion issued in those circumstances would not be usable by whoever relies on it.
Which role applies is settled in writing before an engagement letter exists. Where a conflict arises you will be told which piece of work to take elsewhere, and where it helps, who is competent to do it.
On-site work across Ventura County (Moorpark, Thousand Oaks, Simi Valley, Camarillo, Ventura, Westlake Village, Newbury Park and Oak Park) and into Los Angeles County for corporate, governance and financial-institution engagements.
Most evidence review, testing and reporting is handled remotely because it is faster that way. On-site presence is reserved for the things that genuinely benefit from it: process walkthroughs, audit fieldwork and board meetings.
With a short diagnostic conversation that is not billed. Its purpose is to establish what you actually need, which is frequently narrower or differently shaped than the initial request, companies commission audits where a review satisfies the covenant, or a full risk programme where a segregation of duties review would close most of the exposure.
After that, compliance work is quoted as a fixed fee and project work is scoped following a short assessment.
Monday to Friday, 9:00 AM to 5:30 PM PT
Enquiries answered within one business day.
Get in touch
A sentence or two is enough. You will get a considered reply from Javed Peeran directly, within one business day.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, no handoff between your accountant and your security consultant.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp