CPA · CISA · CISM · CDPSE · CCSE · MBA

5.0 on Google, from 6 client reviews 5.0 · 6 Google reviews

One CPA for the audit and the IT controls behind it

A licensed California CPA who also holds CISA, CISM, CDPSE and CCSE, so attestation, IT governance and cloud security compliance come from one engagement instead of two vendors and a handoff.

A CPA and a client reviewing financial statements and management reports together
  • CPACalifornia Board of Accountancy, permits attestation
  • CISACertified Information Systems Auditor
  • CISMCertified Information Security Manager
  • CDPSEData Privacy Solutions Engineer
  • CCSECertified Cloud Security Engineer
  • MBAFifteen years as CFO and Corporate Controller
  • Since 1986Serving Los Angeles and Ventura County
  • 30 yearsAudit, financial leadership and IT governance
  • Six credentialsCPA, CISA, CISM, CDPSE, CCSE, MBA
  • Seventeen service linesAcross four practice pillars

One practice, layered from compliance to capability

Tax and accounting form the licensed base. Governance, security and technology deployment sit above it, and because they share a single practitioner, the handoffs that normally break these engagements do not exist.

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

A CPA who can also read the control evidence

There is a specific problem in this market, and it is worth naming plainly.

If you need a SOC 2 report, an IT general controls audit, or a cybersecurity assessment tied to your financial reporting, you currently have two options in Ventura County. You can hire a managed service provider or security consultancy, capable at readiness and remediation, and barred under AICPA rules from issuing the attestation. Or you can hire a CPA firm that can sign the report and has never configured an IAM policy.

So the work gets split. A local consultancy runs readiness, then hands a package to a remote CPA firm that arrives cold, disagrees with half the scoping decisions, and raises findings the first vendor considered settled. You pay twice and manage the seam yourself.

This practice holds both sides. The CPA licence permits the attestation. CISA, CISM, CDPSE and CCSE cover the systems, the security programme, the privacy engineering and the cloud architecture. One scope, one methodology, one set of judgments about what counts as evidence.

It also works in the other direction. Because the same person has spent fifteen years as a CFO and Corporate Controller and twenty auditing banks, insurers and mortgage companies, a technical finding arrives translated into what it would actually cost the business; which is the form a board can act on.

Industries served across thirty years

Client types accumulated since 1986, and the specific obligations each one brings.

Banking & mortgage

FFIEC IT examination readiness, GLBA safeguards, vendor management programmes, and controls over core banking and loan origination systems.

Insurance

Statutory reporting environments, claims system controls, and the third-party risk work that regulators now examine in detail.

Technology & SaaS

SOC 2 as a condition of enterprise contracts, cloud security compliance, and revenue recognition that survives a first audit.

Semiconductor & manufacturing

Inventory and cost accounting, ERP programmes, research credit documentation, and defence supply chain requirements.

Life sciences & medical device

FDA 21 CFR Part 11 and GxP obligations over validated systems, mapped against ITGC so the same control is not tested twice.

E-commerce & retail

Multi-state sales tax nexus, marketplace facilitator analysis, and the exemption certificate discipline that decides an audit outcome.

Nonprofit & education

Fund accounting, grant compliance, Single Audit requirements, and board financial oversight for volunteer directors.

Professional practices

Practice valuation, partner buy-in and buy-out structuring, compensation models and succession.

Four steps, and an honest answer at each one

  1. Diagnostic conversation

    Not billed. Establishes what you actually need, which is frequently narrower than the initial request. Companies commission audits where a review satisfies the covenant more often than any other single mistake.

  2. Scoped assessment

    A short, defined piece of work that converts an unknown into a plan, a gap list, a control matrix, or an exposure quantification, with effort and sequence attached.

  3. Execution

    The engagement itself, run to an agreed calendar with open items raised as they arise rather than accumulated into a surprise at the end.

  4. Handover

    Documentation your team can maintain, and training so they can. Work that requires the consultant to return annually to operate it was designed badly.

Engineering and finance teams working through a SOC 2 readiness assessment together

SOC 2 readiness and the attestation, under one licence

Under AICPA guidance only a licensed CPA firm can issue your SOC report. The consultancies near you that understand security cannot sign it, so most companies in Ventura County run readiness with one vendor and the examination with another, and manage the seam themselves.

That seam is where scoping disagreements, duplicated evidence and re-tested controls live. Holding the CPA licence alongside CISA and CISM removes it entirely.

Directors and advisers around a boardroom table working through an assessment report

Findings translated into what they actually cost you

"MFA is not enforced on the VPN" tells a board nothing it can act on. The same finding expressed as what it permits, which systems it exposes, what a comparable incident costs, and whether a compensating control exists; that is a decision a board can make.

Making that translation needs someone who has audited the systems and closed the books. Twenty years auditing banks and insurers, fifteen as a CFO and Corporate Controller.

Local across Ventura County, corporate across Los Angeles

Each city page covers the industries, obligations and engagements specific to that market, not the same page with the name changed.

All service areas

Moorpark

Governance advisory, internal controls, tax and accounting for Moorpark businesses. Licensed California CPA also holding CISA, CISM and CDPSE.

CPA services in Moorpark

Camarillo

Cloud security compliance, ERP advisory, cybersecurity assessment and CPA services for Camarillo technology, semiconductor and aerospace businesses.

CPA services in Camarillo

Ventura

Audit and attestation, risk advisory, nonprofit and transaction services for Ventura businesses and organisations across Ventura County.

CPA services in Ventura

Writing on governance, assurance and finance technology

Every article is written by Javed Peeran, no ghostwriters, no syndicated content.

Questions people ask before getting in touch

Not answered here? Ask Javed directly

What makes this different from any other CPA firm in Ventura County?

The combination of credentials, and what it lets a single engagement cover. A CPA licence permits audit and attestation work. CISA, CISM, CDPSE and CCSE cover IT audit, security management, privacy engineering and cloud security.

In practice that means the person who signs your financial statements can also read your access listings, so a company needing SOC 2 does not have to hire a security consultancy for readiness and a separate remote CPA firm for the report, and manage the seam between them. Across Ventura County, no other CPA practice currently holds both sides.

Do you still do ordinary tax and accounting work?

Yes. The firm has filed returns and prepared financial statements for Los Angeles businesses since 1986 and continues to. Tax, accounting, payroll and outsourced CFO work form the base tier of the practice.

What has changed is the emphasis. Governance, IT assurance and security compliance are where the practice is distinctive, so they lead, but a company that needs a corporate return and a clean monthly close is well served here.

How large a company do you work with?

Most engagements sit between roughly $2M and $150M in revenue, plus public filers of comparable size and financial institutions of varying scale.

Smaller than that, a full governance or risk programme is usually disproportionate and a focused controls review is the better use of budget. Substantially larger, or requiring standing capacity across several offices, and a national firm is genuinely the better answer; you will be told that directly rather than sold an engagement that does not fit.

Can you both advise us and audit us?

No, and that constraint is applied in both directions. AICPA independence rules restrict a firm performing an attestation engagement from also designing or operating the controls it will later test, and an opinion issued in those circumstances would not be usable by whoever relies on it.

Which role applies is settled in writing before an engagement letter exists. Where a conflict arises you will be told which piece of work to take elsewhere, and where it helps, who is competent to do it.

What areas do you cover?

On-site work across Ventura County (Moorpark, Thousand Oaks, Simi Valley, Camarillo, Ventura, Westlake Village, Newbury Park and Oak Park) and into Los Angeles County for corporate, governance and financial-institution engagements.

Most evidence review, testing and reporting is handled remotely because it is faster that way. On-site presence is reserved for the things that genuinely benefit from it: process walkthroughs, audit fieldwork and board meetings.

How do engagements usually start?

With a short diagnostic conversation that is not billed. Its purpose is to establish what you actually need, which is frequently narrower or differently shaped than the initial request, companies commission audits where a review satisfies the covenant, or a full risk programme where a segregation of duties review would close most of the exposure.

After that, compliance work is quoted as a fixed fee and project work is scoped following a short assessment.

Moorpark office

Office address

11843 Nightingale Street
Moorpark, CA 93021
By appointment

Business hours

Monday to Friday, 9:00 AM to 5:30 PM PT

Enquiries answered within one business day.

Get in touch

Tell us what you are dealing with

A sentence or two is enough. You will get a considered reply from Javed Peeran directly, within one business day.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk to a CPA who also reads the control evidence

Thirty years of audit, financial leadership and IT governance in one engagement, no handoff between your accountant and your security consultant.

WhatsApp Us
Call Now