Flagship course
Vendor Control Assurance Studio
A six-week practice path for financial auditing guidance for vendor due diligence in finance systems — built for auditors, controllers, and risk partners.
At a glance
- Duration: 6 weeks, ~5 hours per week
- Format: live online labs + asynchronous critique
- Informational fee: ₩1,950,000 per seat (Diligence Studio tier)
- Language: English instruction with Korea-context examples
Modules
- 01Intake & system mapping
Draw the path from vendor feature to ledger, subledger, and stored reports before you open a questionnaire.
- 02Data classes & access rights
Classify what the vendor can read, write, export, or retain — including “temporary” integrations.
- 03Evidence design
Choose between SOC reports, configuration exports, walkthroughs, and sample testing for finance stacks.
- 04Findings that survive challenge
Write issues procurement and IT can act on, with clear residual-risk language.
- 05Monitoring after go-live
Set re-test triggers when vendors add modules that touch posting or payment files.
- 06Capstone diligence pack
Deliver a complete pack on an anonymized or live (redacted) finance-system vendor.
Learning outcomes
- Produce a system-access map tied to finance processes
- Select evidence types with documented rationale
- Draft findings and residual-risk memos reviewers accept
- Brief stakeholders in Korea subsidiary and HQ contexts
Instructor
Yuna Bergstrom
Former IT audit manager for a Korea-listed manufacturer; now designs diligence labs for cloud finance tools. Focus areas: treasury APIs, payroll connectors, and invoice automation.
Informational pricing
Individual seat under the Diligence Studio tier: ₩1,950,000. Team packs sit under Assurance Cohort — see Pricing. No payment is processed on this website.
FAQ
Do I need an audit background?
Comfort with finance processes helps. We explain control language as we go, but we do not teach double-entry accounting from scratch.
Can I bring a live vendor?
Yes — office hours support one live vendor if you can redact confidential terms. We never ask you to upload production data to our systems.
What is a real limitation of this course?
We do not certify you under a professional license, and we do not cover every Korea regulatory filing in depth. The Studio teaches a diligence method; your legal and compliance teams still own formal opinions.
How is this different from generic vendor-risk courses?
Every case is a finance-system vendor — tools that post, approve, store, or move accounting data — not generic SaaS productivity apps.
Course reviews
“Week two’s access-mapping exercise exposed that our ‘read-only’ BI vendor could schedule exports of the entire AP aging.”
Short take: dense. Worth it if you already have vendors waiting.
“I still needed our counsel for contract clauses, but the residual-risk memo from the capstone is what the CFO signed.”