Why an external audit
Policies show intent. Evidence shows what happens.
Arizona Alternative Business Structures (ABS) are licensed and regulated by the Arizona Supreme Court under Arizona Code of Judicial Administration § 7-209. Each ABS designates a Compliance Lawyer, and that lawyer conducts a semi-annual internal compliance audit of the firm's policies and procedures. The program may also conduct its own compliance audit of an ABS. The internal review is required and useful. It is also a self-assessment.
A policy binder shows what an organization intends. It does not show whether conflicts are checked before a matter opens, whether trust reconciliations are completed on time, or whether the controls that protect professional independence hold under commercial pressure. Those are questions of operating effectiveness. They are answered by evidence: records, samples, system access, and interviews with the people who do the work.
An independent external review adds what a self-assessment cannot, and it can be scheduled before the next internal audit or the regulator's own audit. Koers evaluates its own independence before accepting the work, tests controls rather than describing them, and reports what the evidence shows. The result is a finding a board, a Compliance Lawyer, or an investor can rely on, with remediation that fits how the firm actually runs.
What we evaluate
Ten domains, each tested against evidence.
The Koers ABS Governance Assessment covers the areas where an ABS is most exposed. Each domain is assessed on how its controls operate, not on whether a policy exists.
-
Ownership & Governance
Who holds economic interest and decision-making authority, how the board and management are structured, and whether governance operates as documented.
-
Regulatory Compliance
How the firm meets its obligations under the Arizona Supreme Court's ABS program, including the Compliance Lawyer's role and the semi-annual compliance audit.
-
Professional Independence
Whether lawyers' professional judgment is protected from ownership and commercial pressure in practice, not only in policy.
-
Financial Controls
Trust accounting, reconciliations, billing review, debt obligations, and the financial stability of the business.
-
Client Protection
Conflict checking, engagement and disengagement practices, confidentiality, and how client complaints and regulatory inquiries are handled.
-
Operational Controls
Intake, matter workflow, supervision of nonlawyer staff, training, and the procedures that keep daily work within policy.
-
Technology & Cybersecurity
The systems that hold client and financial data, who can access them, and the security practices around documents and communication.
-
Vendor Management
Third-party and ancillary-service relationships, contract disclosures, and whether outside parties can reach client information.
-
Risk Management
How the firm identifies, escalates, and resolves regulatory, financial, and operational risk before it becomes a finding.
-
Documentation & Reporting
Whether policies, audit reports, training records, and required notices are complete, current, and retained.
The Koers audit process
Eight steps from conflict review to remediation.
The sequence is fixed. Scope and timing are confirmed during scoping and depend on the size of the organization, the domains in scope, and how readily evidence is available.
-
Independence & conflict review
Koers reviews prior relationships and potential conflicts before accepting the engagement, and documents the result.
-
Scope definition
Domains, locations, systems, sample periods, and timing are agreed in writing with management.
-
Evidence request
A written request lists the policies, records, samples, and system access the audit needs.
-
Interviews and testing
Koers interviews the people who run the controls and tests whether the controls operate as described.
-
Findings and risk classification
Each finding is tied to evidence and classified by risk so leadership can prioritize.
-
Final report
A written report covering executive summary, scope, methodology, findings, and recommendations.
-
Remediation roadmap
Practical actions, prioritized and sequenced to fit the firm's capacity and obligations.
-
Optional follow-up review
At the client's request, Koers re-tests remediated controls and reports on progress.
What clients receive
A written report a board can act on.
- Executive summary
- Scope and methodology
- Findings
- Risk classifications
- Evidence observations
- Recommendations
- Remediation priorities
- Optional management presentation
Independence
How independence is protected.
Koers may provide both audit and consulting services, so independence is protected through defined controls rather than assumed.
-
Koers evaluates independence before accepting an audit.
-
Prior consulting relationships are reviewed.
-
Potential conflicts are documented.
-
Audit conclusions are based on evidence.
-
Consulting opportunities do not influence audit findings.
Who this is for
Built for the people accountable for an ABS.
-
Existing ABS organizations
Licensed firms that want independent testing of whether their controls work as intended.
-
New ABS applicants
Organizations building governance and controls ahead of licensure.
-
Boards
Directors who need an evidence-based view of governance and risk.
-
Compliance counsel
Compliance Lawyers and outside counsel who want independent testing alongside the firm's own audit.
-
Management teams
Leaders responsible for operations, finance, and technology.
-
Investors evaluating governance maturity
Investors who need to understand how a firm is governed and controlled.
Common questions
Before you inquire.
Is a Koers external audit required?
A Koers external audit is voluntary. It is separate from the Compliance Lawyer's semi-annual internal compliance audit and from any compliance audit the Arizona Supreme Court's ABS program conducts itself, and it does not replace either. What the program requires of a particular firm is a question for its Compliance Lawyer or counsel.
How long does an audit take?
Scope drives duration. The number of domains, the size of the organization, and how quickly evidence is available all matter. Timing is confirmed during scoping and set out in the engagement terms.
What evidence will Koers request?
Policies and procedures, governance and financial records, samples of matters and transactions, system access where agreed, and interviews with the people who operate the controls. The evidence request is issued in writing after scope is agreed.
Who sees the report?
The client. Koers reports to the engaging organization, typically its board or management, and does not report to the regulator. How the report is used and shared is the firm's decision, subject to its own obligations to the regulator.
How is confidentiality handled?
Confidentiality is set in the engagement terms before any evidence is exchanged. Access to records and systems is limited to what the agreed scope requires. Do not send privileged or client-confidential material through this website; the inquiry form is for arranging a conversation only.
Inquiry
Discuss an audit
Tell us about the organization and when an audit might fit. Koers will follow up to arrange a scoping conversation. Please do not include privileged or client-confidential details.