You will get SOC 1 & SOC 2 Report Reviews | CPA | Vendor Risk & CUEC Expert


Project details
Organizations rely on SOC reports to manage vendor risk—but many reports contain gaps, unclear exceptions, or unaddressed Customer/User Entity Controls (CUECs) that leave your business exposed.
As a CPA with 20+ years of audit, governance, and risk management experience, I provide clear, actionable SOC 1 and SOC 2 (Type I & II) reviews that help startups, growing companies, and mid-market organizations confidently assess risk and implement the right controls.
Every engagement is documented using a structured SOC Review Template built to SSAE 18 / AT-C 205 & 320 and COSO 2013 standards—covering system description, control-by-control testing, exception tracking, CUEC evaluation, and risk assessment.
What you receive:
✔ Completed SOC Review Template (audit-ready)
✔ Control-by-control analysis with risk ratings (H/M/L)
✔ Exception identification and root cause assessment
✔ Plain-language findings and remediation steps
Tier 1 — SOC report review with findings and risk ratings
Tier 2 — Adds full CUEC evaluation and gap analysis
Tier 3 — Adds COSO/SOX control mapping and reliance documentation.
No jargon. No generic checklists. Just expert guidance you can act on.
As a CPA with 20+ years of audit, governance, and risk management experience, I provide clear, actionable SOC 1 and SOC 2 (Type I & II) reviews that help startups, growing companies, and mid-market organizations confidently assess risk and implement the right controls.
Every engagement is documented using a structured SOC Review Template built to SSAE 18 / AT-C 205 & 320 and COSO 2013 standards—covering system description, control-by-control testing, exception tracking, CUEC evaluation, and risk assessment.
What you receive:
✔ Completed SOC Review Template (audit-ready)
✔ Control-by-control analysis with risk ratings (H/M/L)
✔ Exception identification and root cause assessment
✔ Plain-language findings and remediation steps
Tier 1 — SOC report review with findings and risk ratings
Tier 2 — Adds full CUEC evaluation and gap analysis
Tier 3 — Adds COSO/SOX control mapping and reliance documentation.
No jargon. No generic checklists. Just expert guidance you can act on.
Project Type
Business Consulting, Financial Consulting, Human Resources, LegalWhat's included
| Service Tiers |
Starter
$400
|
Standard
$850
|
Advanced
$1,500
|
|---|---|---|---|
| Delivery Time | 3 days | 5 days | 10 days |
Number of Revisions | 0 | 1 | 1 |
Optional add-ons
You can add these on the next page.
Fast Delivery
+$100 - $200
1-hr consultation
(+ 2 Days)
+$150
Add'l SOC report review
(+ 3 Days)
+$300
Executive Summary
(+ 2 Days)
+$150Frequently asked questions
About Michelle
Fractional CFO | Finance Operations | Strategic Advisor
Philadelphia, United States - 12:21 am local time
The reality is much different. The business isn't broken — it's outgrown the infrastructure underneath it. That gap between where the business is and where it needs to be is only getting wider.
Here's where I thrive. I'm a fractional executive with 20+ years in accounting, audit, risk management, and internal controls — work I've done across a wide range of industries, ownership structures, and levels of operational complexity.
That experience produces pattern recognition — I can usually identify where things are breaking down, where they're about to, and what's being missed because everyone is too close to it. But pattern recognition doesn't mean a repeatable playbook. No two organizations are the same, and no two engagements should look the same either.
My clients range from start-ups to Fortune 500 public companies — and their needs range just as widely. Some have everything together and just need a little help getting a project over the finish line or filling a technical gap. Others are constantly on fire and don't know where to start.
Where I Come In
⚠️Something isn't working, and you're not sure where — The numbers are off, the close takes too long, or a process that used to hold is starting to show cracks.
⚠️ You're growing faster than your reporting can keep up with — Leadership needs better visibility, the business has outgrown the tools and structures it started with, and owners or investors want more.
⚠️ You need an experienced person, not just a deliverable — There's a gap at the leadership level that was never filled, someone left, or the role has expanded beyond what's in place.
What to Expect
🤝Built on collaboration — I get to know the business, the team, and the actual constraints — and I stay involved through implementation rather than just handing off a report. This is a partnership. The best outcomes happen when both sides are genuinely invested.
🤝Designed to flex — Projects start with a conversation about what you actually need, not a predefined scope. We design the structure, cadence, and deliverables together — and adjust when priorities shift or the real problem turns out to be different from the initial one.
🤝No surprises — Issues get raised as soon as they surface. Scope changes get discussed before they're acted on. You stay informed without it creating work for you.
The work rarely stays in one lane — my services range from executive support and strategic advisory to accounting & finance, FP&A, and management reporting — and clients often come in for one thing and find that the problem, or the opportunity, runs deeper.
The rate in my profile reflects that flexibility — it's a starting point, not a fixed number. I price engagements after we've scoped them together because the work should reflect what you actually need, not what fits a predetermined number.
Happy to have a conversation about what you're working on before committing to anything.
✨ Check out my profile portfolio for some recent WINS ✨
Steps for completing your project
After purchasing the project, send requirements so Michelle can start the project.
Delivery time starts when Michelle receives requirements from you.
Michelle works on your project following the steps below.
Revisions may occur after the delivery date.
Project Requirements provided by client
Project Intake form, SOC Report, Bridge Letter, Evidence of CUEC Controls in Place (Tier 2 & 3), SOX Control Framework / Documentation (Tier 3)
SOC Review Completed
This includes review of the SOC report and completion of SOC Review Template deliverable.




