Florida  ·  Puerto Rico  ·  New York  ·  Washington, DC [email protected] +1 917 410 3335
Sosa & Arvelo, LLC Request a consultation
Sosa & Arvelo, LLC
ServicesCyber & InnovationFinancial AdvisoryRisk & ComplianceStrategy & OperationsSectorsAll sectorsFinancial Services & CommercialNonprofits & Faith-BasedInsightsFirmAboutTeamHow we workCareersContact Request a consultation

Who we serve

For Financial Services & Commercial Organizations

Built by people who have been on the other side of the table.

This page is for the organization that is examined rather than merely audited — a bank, an insurer, a licensed financial business, a fund or an advisory firm — and for the commercial organization that has taken on the same obligations through a regulator, a contract, or a counterparty that will not simply take your word for it.

What those organizations have in common is that the work is graded twice: once on whether it was done, and once on whether you can prove it was done. We build the finance, control, and security programs so that the evidence exists before anyone asks for it.

Between them the partners have run the financial operation of one of Puerto Rico’s largest municipalities, served as deputy administrator of a government retirement system managing roughly $2 billion, directed a state cybercrime investigative unit, and advised banking, defense, and energy clients from inside a Big Four consulting practice. The examiner, the prosecutor, and the finance officer are all roles someone here has actually held.

01What we help with

01

Examination readiness and regulatory change

The first question is not whether you are compliant. It is which rules actually reach you, and whether you can show it. We inventory the regimes that bind the organization — the regulator that licenses it, the framework a counterparty imposes by contract, the standard a large buyer requires of its suppliers — and turn them into a dated obligation list with a named owner against each item.

Rules move, and a change process that is nobody’s job is not a process. We define who watches, what triggers a review, and how a change reaches the policy, the control, and the calendar — before it reaches a findings letter.

02

Internal control design and testing

Controls built to be examined, with the testing evidence produced as you go. A control that exists only in a narrative will not survive a request for the sample.

Most finance offices cannot staff textbook segregation of duties on the headcount they have. We design the compensating controls that work with the team you actually have — dual authorization on disbursements, documented approval limits, a reconciliation signed by someone other than the preparer — and then we test them. When a control fails, we say whether the failure is design or operation, and what it costs to fix. We do not bury a fail in a management comment.

03

Financial reporting and the close

A close that produces numbers nobody can trace is a reporting problem this year and a finding next year. We work on the close calendar, the reconciliation discipline underneath it, and the reporting package that goes to the board, the lender, and the auditor — one set of records that answers all three, rather than three versions that disagree quietly.

Budgets a board can hold management to, forecasts that state their assumptions, and variance reporting that names a cause rather than a number. Where the finance function needs to be rebuilt rather than tuned, we say that instead of selling a longer engagement around the symptom.

04

Enterprise risk management

A risk framework that cannot name the ten risks the board actually owns is a binder. We build a register tied to the organization’s real exposures — a single person who can move funds, a vendor holding production data, an obligation with a deadline nobody owns, a facility that cannot operate if the office is closed — and give each one an owner, an existing control, a residual rating, and a decision the committee can record.

Cyber exposure belongs inside that register rather than beside it: where the actual exposure is, what it would cost, and what to do first — in a document an executive committee can act on in one sitting. Architecture follows the risk register, not the other way around.

We do not import a two-hundred-row bank template into a fifty-person company and call it maturity. The test of the framework is whether it changes a budget or a vendor decision.

05

Cybersecurity regulation and annual certification

Program design and annual certification for examined institutions: written policies, CISO reporting to the board, testing and vulnerability-scanning cadence, audit trails, access-privilege review, authentication and encryption standards, retention and disposal, incident response, and the notification obligations that run on a clock.

The certification is an attestation, made annually, that the program is what you say it is. We build the program and we prepare the certification. We do not treat a policy binder as a program.

06

Framework alignment and control mapping

Recognized control frameworks, mapped across overlapping regimes so one control set answers several regulators instead of three programs answering one each. When a federal directive or an executive order shifts expectations, we say what it does — and does not — require of a non-federal entity.

07

Third-party and vendor risk

Assessment programs, contractual security requirements, and ongoing monitoring for the vendors that hold your data. You remain responsible for what your vendors do with your data. A questionnaire that no one scores is not a program.

08

Privacy and data protection

Program design, data mapping, retention and disposal, and breach-notification obligations across jurisdictions. Privacy work that cannot produce an inventory, a retention schedule, and a notice decision tree is not ready for examination.

09

Incident response and electronic evidence

Response planning before an incident; during one, handling that preserves the evidence. This is the capability most firms cannot offer, and it comes directly from prosecutorial experience — chain of custody, imaging decisions, and what will still be usable if the matter becomes an examination or a case.

10

Business continuity and disaster recovery

Plans that are tested, not filed. Recovery-time and recovery-point objectives, alternate processing, and evidence that someone has run the plan since it was approved.

11

Corporate transparency and beneficial ownership

Corporate Transparency Act and FinCEN reporting posture — including what the August 2026 final rule eliminated for U.S. companies and U.S. persons, what still applies to foreign reporting companies, and what state transparency regimes and bank KYC/AML requirements continue to demand regardless. Do not assume prior BOI records have been deleted until FinCEN says the deletion is complete.

12

Program execution and system change

Control programs and finance-system changes fail the same way: the scope drifts, nobody owns the milestone, and the control set gets rebuilt after go-live instead of during it. We run this work as a program — a scope, a named owner, a change log, and evidence that a milestone actually happened.

Typical work is a control-program build against a fixed certification deadline, a finance-system cutover with its controls intact, or a remediation plan that has to close before the next examination. Program management here is partner-led. It is not a reporting layer over work other people are doing somewhere else.

Before the examination

A fixed-scope review against the regime you actually answer to, delivered as a gap analysis with a prioritized remediation plan.

Request an assessment

02How we work

Most engagements start with a regulatory readiness assessment — a fixed-scope review against the specific regime you answer to, delivered as a gap analysis with a prioritized remediation plan and realistic effort estimates. You will know what is required, what you have, and what it takes to close the distance.

Where the question is financial rather than regulatory — a close that takes too long, a reporting package the board does not trust, a control environment that has not kept up with the size of the company — the assessment is scoped to that instead.

We are a small firm. That means the people who scope your engagement are the people who do it.

Sosa & Arvelo, LLC

Next step

Tell us what you’re facing.

A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.