Planning resources

Turn a broad concern into a defined review.

Start with the question you need answered. These editable templates help your team organize systems, owners and evidence before scoping an engagement.

Prepared by MarkKings Group LLC | Published September 17, 2026

Choose the right starting point

Compare the question and deliverable for each assessment
ReviewQuestion it answersTypical output
IT controls reviewAre our access, change and operational controls working?Tests, evidence, findings and remediation owners
Cybersecurity assessmentWhere is our environment exposed?Validated technical findings and remediation priorities
SOC 2 readinessWhat must be in place before the CPA examination?Control gaps, evidence requests and preparation plan
AI governance reviewWho owns our AI uses, risks and oversight?AI inventory, risk decisions and monitoring responsibilities

An IT controls review tests control design or operation over an agreed scope and period. A cybersecurity assessment investigates technical exposure. Readiness consulting prepares for an independent examination; it does not provide an audit opinion.

Editable planning templates

Download the CSV files and open them in Excel or Google Sheets. No email is required. Each contains illustrative rows to replace with your own information; they are not client findings, a complete control framework or a compliance determination. Keep completed copies in your own approved workspace.

IT control evidence checklist

Record the system, control owner, review period, evidence location and any gaps before an assessment. The examples cover access, changes, recovery and vendor oversight.

Download evidence checklist (CSV)

AI use-case inventory

Record each AI system's intended use, owner, data categories, vendor terms, human oversight and evaluation needs. Begin with one team, then expand the inventory.

Download AI inventory (CSV)

What a finding should explain

The example below illustrates a report format. It does not describe a client or a tested environment.

Observation
An access-review record lacks evidence of the reviewer's decision.
Evidence and limitation
Reference the requested review, period and records inspected. Missing documentation alone does not prove the review never occurred.
Risk and action
Unneeded access may persist without a traceable review decision. Agree a documented approval and exception process with the owner.
Owner and follow-up
Assign an accountable role, due date and the evidence needed to demonstrate the next review operated.

Use the underlying guidance

Discuss your review scope