Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|
CQCustomer Quality | Contract Audit & CRM Implementation | $7,245 | ⏱ 8–10 wks | $5,000 – $9,000 | ~1x |
DRDiligence Risk | Security Hardening & Data Room Preparation | $6,482 | ⏱ 6–8 wks | $4,500 – $7,500 | ~1x |
OROwner Risk | Succession Planning & Knowledge Capture Sprint | $6,482 | ⏱ 8–10 wks | $6,000 – $10,000 | ~1x |
HCHuman Capital | Workforce Retention & Bench Depth Sprint | $5,338 | ⏱ 10+ wks | $5,000 – $8,000 | ~1x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $4,194 | ⏱ 8–10 wks | $6,000 – $10,000 | |
FRFinancial Readiness | Books Cleanup & Add-Back Schedule | $3,813 | ⏱ 6–8 wks | $4,000 – $7,000 | ~0.5x |
OSOperational Scalability | Process Documentation & Systems Audit | $2,669 | ⏱ 10+ wks | $6,500 – $11,000 | ~0.5x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $1,907 | ⏱ 8–12 wks | $5,000 – $9,000 | |
| TOTAL | $38,130 | — | $42,000 – $71,500 | ~0.5x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
Accounting firm revenue infrastructure is driven by client retention, referral network quality, and seasonal workflow management rather than high-velocity lead automation.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv There is no evidence of AI voice agents or automated after-hours call handling in any of the retrieved documents; the excerpts focus on client onboarding, cybersecurity gaps, and HR processes with no mention of inbound call systems or after-hours automation. The firm appears to operate without documented after-hours call handling infrastructure. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv The firm uses Canopy as a practice management system with individual logins for client management and document exchange, but workflow automation is minimal and highly dependent on the managing partner ([PERSON]) to manually execute onboarding steps, follow-ups, and client management tasks. The onboarding process lacks formalized checklists, automated workflows, or systematized handoffs, as evidenced by the SOP notes stating "needs to be formalized" and the partner's admission of keeping "personal list but nothing formal." | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of after-hours or 24/7 lead capture capability in any of the retrieved documents; the company's client onboarding process is entirely manual and owner-dependent, with new client meetings and engagement letter exchanges managed directly by the managing partner. No contact form automation, chatbot, or systematic lead routing system is mentioned anywhere in the operational documentation. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of any automated SMS appointment reminder or confirmation system in the retrieved documents; the company's client onboarding and engagement processes rely entirely on manual email communication and owner-dependent interactions with no mention of SMS workflows or automation. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv There is no evidence of any systematic or automated review solicitation process in the retrieved documents; reviews appear to be organic only, with no manual follow-up emails, trigger-based requests, or formal mechanism to request client feedback post-service. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of automated follow-up sequences for leads or dormant clients in any of the retrieved documents. The onboarding process is entirely manual and owner-dependent, with [PERSON] personally managing new client setup, and no documented system exists for re-engaging unconverted leads or dormant accounts after initial contact or service completion. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
CPA firm Automation Maturity scores are structurally lower by industry norm. Absence of AI voice, 24/7 capture, and aggressive review solicitation is standard for referral-based practices.
Vertical-specific operational automation gaps identified in Accounting Practice Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Client Document Collection | 1/2 | PARTIAL | Document collection automation compresses the tax season intake window by 2-3 weeks and eliminates the most common source of extension filing and client frustration. | |
| Engagement Letter & E-Signature | 1/2 | PARTIAL | Engagement letter automation ensures 100% signed engagement coverage — a critical diligence item for buyers assessing client relationship transferability and E&O exposure. | |
| Deadline & Filing Calendar | 0/2 | MANUAL | Deadline automation eliminates the most common source of penalty exposure and provides the workload visibility needed to staff engagements efficiently during peak season. | |
| Recurring Invoice & Billing Automation | 0/2 | MANUAL | Billing automation converts the accounts receivable function from a partner time sink to a self-managing revenue stream — directly improving realization rates. | |
| Client Communication & Seasonal Outreach | 0/2 | MANUAL | Automated seasonal outreach surfaces advisory opportunities the client didn't know to ask about and drives year-round engagement beyond the annual return. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.Schedule a Discovery Call →
Buyer Discount Risk
EBITDA (most recent FY): $254,200 (AI-extracted) · Exit Readiness: 3.7/10 — Material Gaps
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- High client retention >90%
- Engagement letters assignable
- Staff CPA capacity beyond owner
- Seasonal workflow documented
↓ What buyers will flag
- Owner performs all technical work
- Client relationships not transferable
- No engagement letter documentation
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company has minimal documented processes with heavy reliance on key individuals. The Customer Onboarding SOP is explicitly labeled as "[PERSON]'s notes — needs to be formalized" with a manual personal checklist rather than a formal procedure, and the onboarding program is "primarily learning by doing alongside managing partner; no formal program" with "no documented onboarding checklist or milestone review." Critical process knowledge remains concentrated in the owner, as evidenced by his required involvement in all new hire orientations and discretionary control over compensation decisions with no documented formula. | 3/10 | CRITICAL RISK | |
| fix_02 | Cybersecurity Posture GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company has critical cybersecurity gaps that present material risk for a sale process. MFA is only enabled for 2 of 5 staff members, client financial data including SSNs and EINs are stored on unencrypted local drives, all staff share a single QuickBooks login with no audit trail, and there is no EDR solution deployed—only Windows Defender. The assessment acknowledges these are "fast and cheap to remediate" with an estimated remediation cost under $2,000, but in their current state they represent significant vulnerabilities for an accounting firm handling sensitive data for 67 clients. | 4/10 | NEEDS WORK | |
| fix_03 | Owner Dependency GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The owner ([PERSON]) is the primary operator and single point of failure across critical functions: he holds direct relationships with 48 of 67 clients (72% of revenue), manages all new client onboarding, approves all hiring decisions, conducts all new hire orientations, and handles staff supervision with no documented backup or succession plan in place. The firm has no formal delegation of authority, with one senior CPA ([PERSON]) able to independently manage only 19 clients (28% of revenue), and no cross-training program exists; the documents explicitly state "The firm has not operated without [PERSON] for [DATE_TIME] in the past 3 years" and that if he were absent, "client relationship continuity would be at risk." | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company demonstrates strong revenue quality with 78% recurring revenue from tax preparation and bookkeeping retainers, well above the 50-70% threshold for this score band. Revenue concentration is excellent across 67 active client relationships with the largest client representing only 2.3% of revenue, significantly below the 15% threshold. Multi-year engagement letters and retainer agreements averaging $12,200 per client support predictable, recurring revenue streams across diversified verticals including SMB owners, real estate investors, and professional services. | 8/10 | STRONG | |
| fix_05 | Customer Contracts GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated Customer contracts lack standardization, centralized documentation, and change-of-control language. The onboarding process relies on email-based engagement letters stored in Outlook drafts (per GPA_Customer_Onboarding_SOP.txt), with no formal contract repository, DocuSign integration, or documented assignment clauses. Contract renewal tracking is entirely informal—the SOPs note that checklists are "personal lists" with "nothing formal"—and no renewal dates or rates are systematically tracked across the customer base. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company lacks formal IT infrastructure and asset documentation. The cybersecurity assessment identifies critical gaps including unencrypted local drives storing client tax files with SSNs and EINs, no endpoint detection and response (EDR) protection, no cloud backup for tax files, and consumer-grade networking infrastructure with no formal firewall policy or network segmentation. While basic controls exist (QuickBooks Online cloud backup to external drive, Microsoft 365 adoption), the absence of documented asset inventory, inconsistent security controls across staff, and reliance on local-only backups with no offsite redundancy indicate incomplete and poorly maintained IT infrastructure documentation. | 3/10 | CRITICAL RISK | |
| fix_07 | CRM & Pipeline Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated While the company uses Canopy for practice management and mentions a sales pipeline of $185K with $92K weighted value in the CIM, the retrieved documents provide no evidence of disciplined CRM adoption, pipeline stage tracking, or forecast validation. The onboarding documentation shows that [PERSON] manages client intake informally with personal notes and checklists kept outside any formal system, and the cybersecurity assessment references basic system usage (QuickBooks Online, Drake Tax, Canopy) without demonstrating pipeline governance or deal stage discipline. The owner appears to be the sole driver of new business development with no documented sales process or visibility into pipeline currency. | 3/10 | CRITICAL RISK | |
| fix_08 | Key Employee Risks GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The firm has multiple critical single points of failure with minimal documentation or retention safeguards. The managing partner holds direct relationships with 48 of 67 clients (72% of revenue) with no documented succession plan, while the bookkeeper/admin role has no identified backup despite being the sole resource for bookkeeping operations. There are no formal retention agreements, no bonus structures, associate compensation is below market (partially explaining 38% first-year turnover), and institutional knowledge exists only in informal personal lists—the onboarding SOP itself is marked "[PERSON]'s notes — needs to be formalized" with no documented checklist or formal training program beyond "learning by doing." | 3/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company reported $820K in [DATE_TIME] revenue with a 31% EBITDA margin ($254K EBITDA) and normalized EBITDA of $298K after add-backs, but the retrieved documents contain no audited or reviewed financial statements, no multi-year growth trajectory documentation, and no detail on the nature or legitimacy of the $44K in add-backs between reported and normalized EBITDA. While the CIM indicates stable recurring revenue (78% from retainers) and reasonable client diversification across 67 relationships, the absence of third-party financial review, historical financial statements, or documented add-back justification prevents a higher assessment despite the firm's profitability metrics. | 5/10 | NEEDS WORK | |
| fix_10 | Data Room Readiness GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company lacks an organized data room and has not prepared key documents for due diligence. While a Confidential Information Memorandum (CIM) exists, the internal documents reveal significant disorganization: the client onboarding process relies on informal personal checklists rather than formalized procedures, compensation and HR policies lack documentation, and critical cybersecurity assessment findings indicate that client data is stored on unencrypted local drives and accessible without proper access controls. The firm would require substantial cleanup and remediation of both documentation and security posture before presenting materials to potential buyers. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated No formal succession plan exists for the firm. The documents explicitly state "No documented succession plan for any key role" and "The firm has not operated without [PERSON] for [DATE_TIME] in the past 3 years," with [PERSON] holding primary contact relationships with 72% of clients by revenue and serving as the sole decision-maker for hiring, staff supervision, and client relations. While [PERSON] has independently developed relationships with 19 clients (28% of revenue), there is no formal introduction as backup for top accounts, no cross-training program, and no documented handoff protocols for key relationships or client transitions. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Critical processes remain largely undocumented and dependent on key individuals. The client onboarding SOP explicitly states "[PERSON]'s notes — needs to be formalized" with informal checklists kept personally rather than in accessible documentation, and onboarding training is "primarily learning by doing alongside managing partner; no formal program" with no documented checklist or milestone reviews. The firm's institutional knowledge is heavily concentrated in the owner, who holds direct relationships with 72% of clients by revenue and must be involved in all new hire orientations, with "no documented succession plan for any key role" and no cross-training program. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The firm lacks formal management depth with the owner ([PERSON]) serving as the primary decision-maker across all critical functions—client relations (72% by revenue), tax preparation, staff supervision, and new hire orientation—with no documented succession plan or cross-training program in place. While a Senior CPA ([PERSON]) can handle 19 clients independently and has onboarded two associates, the documents explicitly state "the firm has not operated without [PERSON] for [DATE_TIME] in the past 3 years" and that "if [PERSON] were absent for an extended period, client relationship continuity would be at risk." The onboarding and hiring processes remain informal with owner approval required for all hires and no formal management authority delegated to other staff members. | 4/10 | NEEDS WORK | |
| owr_04 | Key Person Concentration Beyond Owner GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company exhibits critical key person concentration beyond the owner, with the Senior CPA ([PERSON]) holding exclusive client relationships and technical knowledge across tax and bookkeeping services, while the onboarding SOP document shows that the same individual "meets with them — gets a sense of their situation" and "reviews everything before any return is filed" with no documented backup or cross-training. Additionally, the owner maintains sole hiring authority and must be "involved in all new hire orientations," creating a single point of failure for both client continuity and staff development, and the 62% new-hire retention rate over the assessment period indicates difficulty replacing key personnel when departures occur. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company demonstrates excellent customer diversification with no single customer concentration risk. The CIM explicitly states "67 active client relationships — low concentration" with the largest customer (Peachtree Partners at $4,200) representing less than 1% of the $820K annual revenue, and the top 5 customers combined representing approximately 2.3% + 2.2% + 2.0% + 1.9% + 1.8% = 9.2% of total revenue, well below the 40% threshold for top 5 concentration. | 9/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The firm demonstrates strong revenue predictability with 78% recurring revenue from tax preparation and bookkeeping retainers, with 67 active client relationships under engagement letters and retainer agreements averaging $12,200 per client. However, the assessment is constrained by the absence of documented renewal rates, formal retention tracking, or multi-year contract terms in the retrieved excerpts—the CIM states recurring revenue composition but provides no evidence of renewal rates >90% or explicit contract durations required for a 9-10 score. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of engagement letters, customer contracts, or formal assignment/change-of-control clauses for any of the 67 clients served by Garrison Professional Advisors. The customer onboarding SOP [2] describes engagement letters as informal email templates in "Outlook drafts" that "should probably" be formalized using DocuSign, indicating contracts lack standardized language. The firm's 72% revenue concentration with one owner [PERSON] as primary client contact, combined with the absence of any documented contract transferability analysis, suggests customer relationships are personality-dependent and cannot be transferred without individual client consent or relationship disruption. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated There is no documented churn rate, retention metrics tracking, or formal retention programs evident in the provided documents. The only retention data available relates to employee turnover (new-hire retention of 62% over an unspecified period per GPA_HC_Profile.txt), not customer churn. Customer onboarding is informal and lacks standardized processes (GPA_Customer_Onboarding_SOP.txt notes "needs to be formalized" with no documented checklist), and there is no evidence of monthly or quarterly churn analysis, root-cause investigation, or recovery playbooks for at-risk clients. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Core operational processes lack formal documentation and are heavily dependent on specific individuals. The customer onboarding SOP is marked as "[PERSON]'s notes — needs to be formalized" with critical steps like engagement letter management still relying on Outlook drafts rather than formal systems, and the bookkeeper notes "I keep a personal list but nothing formal" regarding onboarding checklists. New staff onboarding is primarily "learning by doing alongside managing partner" with no documented checklist or milestones, the owner must be involved in all orientations, and new-hire 12-month retention is only 62%, indicating processes cannot be reliably executed or transferred to new employees. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company relies on a mix of cloud-based systems (QuickBooks Online, Canopy) and legacy local installations (Drake Tax on unencrypted drives), with critical infrastructure gaps that would require material modernization before scaling. Key systems lack documented architecture, formal onboarding processes, and scalability planning—the cybersecurity assessment identifies "no cloud backup for client tax files," "no network segmentation," and reliance on a "consumer-grade Netgear router," while the onboarding SOP notes that processes are undocumented and dependent on individual staff members (e.g., "[PERSON] keeps a personal list but nothing formal"). Scaling to 3x would necessitate replacing legacy tax file storage, implementing proper backup infrastructure, formalizing system documentation, and addressing the owner's bottleneck role in all hiring and system decisions. | 4/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated The firm demonstrates significant vendor concentration risk, with critical dependencies on a small number of platforms without documented alternatives or formal SLAs. Specifically, all 67 client QuickBooks accounts are accessed through a single shared login with no audit trail, Drake Tax files are stored locally on unencrypted drives with no cloud backup alternative identified, and Canopy is the sole client portal for document exchange—creating single points of failure for core tax and bookkeeping operations. While the cybersecurity assessment identifies these gaps as "fast and cheap to remediate" (suggesting alternatives like QuickBooks Online accountant logins and cloud backup services like Backblaze exist), there is no evidence of formal vendor agreements, documented switching procedures, or tested alternatives in place, leaving the firm vulnerable to service interruption or data loss. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company lacks formal financial close processes and documented controls. The retrieved documents contain no evidence of monthly financial closing timelines, budget vs. actual reviews, or a CFO/Controller overseeing financial reporting; instead, documents reference a bookkeeper managing accounts with informal controls and ad-hoc processes (e.g., "no formal comp benchmarking process" and onboarding notes stating "needs to be formalized" with only "personal lists but nothing formal"). The cybersecurity assessment notes the firm maintains "basic controls appropriate for a small CPA practice" but identifies multiple high-risk gaps in data security and access controls, and there is no mention of regular management financial review cadence or clean audit trails in any of the excerpts provided. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company maintains internally prepared financial records with no evidence of CPA-prepared, reviewed, or audited financial statements in the retrieved documents. While the firm itself is a CPA practice, the documents show significant operational deficiencies including shared QuickBooks credentials with no audit trail, unencrypted client tax files on local drives, and informal bookkeeping cleanup processes ("usually going back [DATE_TIME]") rather than formalized accounting controls, indicating the company's own books would require substantial rework before diligence-readiness. The cybersecurity assessment identifies the firm as MEDIUM risk overall with material data security gaps that would need remediation before a sale process, suggesting the financial records and underlying systems are not immediately diligence-ready. | 3/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The CIM references a "Normalized EBITDA of $298K after add-backs" but provides no supporting schedule, documentation, or breakdown of which expenses were added back or how they were calculated. The HC Profile identifies specific add-backs (managing partner draw normalized from $195,000 to $148,000) with benchmarking rationale, but these appear in an internal HR document rather than a formal, auditable add-back schedule that a buyer's accountant could independently verify. No evidence exists of CPA-prepared add-back documentation, working papers, or a clear separation between personal and business expenses that would support the normalized EBITDA claim. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of a documented revenue recognition policy, GAAP compliance framework, or deferred revenue tracking system. The company's onboarding SOP references informal, undocumented processes ("needs to be formalized," "I keep a personal list but nothing formal"), and there is no mention of revenue recognition methodology, audit procedures, or consistent application across client engagements in any of the provided excerpts. This represents a critical gap for exit readiness, as acquiring firms will require clear documentation of revenue recognition practices and proper deferred revenue accounting before closing. | 2/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The retrieved documents do not contain three-year financial statements, revenue trends, or EBITDA data across multiple years needed to assess growth consistency. Only a single data point is provided—$820K revenue and $254K EBITDA (31% margin) for an unspecified year in the CIM—with no year-over-year comparisons, prior-year figures, or trend analysis. Without multi-year comparable financials, exit readiness cannot be evaluated on this critical dimension. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The documents provide no evidence that Garrison Professional Advisors has documented, verified, or confirmed the transferability of its Georgia CPA firm license or individual CPA licenses in a change-of-control scenario. While the CIM states the firm is "Licensed CPA firm — Georgia State Board of Accountancy" and [PERSON] "holds a [LOCATION] CPA license," there is no documentation of current license status, good standing verification, bar-imposed restrictions on firm transfer, or any legal counsel review of transferability requirements—all critical for accounting firm M&A. The firm operates with material compliance gaps in client data security and lacks formal operational controls, raising additional regulatory risk that could jeopardize license renewal or transfer approval. | 2/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The documents contain no evidence of legal review of engagement letter assignment clauses or change-of-control provisions, and the onboarding process describes engagement letters as informal templates sent via email without documented assignment language or AICPA compliance procedures. The CIM references "67 active client relationships under [DATE_TIME] engagement letters and [DATE_TIME] retainer agreements" but provides no detail on whether these agreements are assignable to a buyer or include change-of-control language, creating material risk that client relationships may not transfer with the entity in a sale. | 3/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The firm maintains all staff on standard W-2 employment with compensation benchmarked against AICPA surveys, but has material documentation and structural gaps that create exit risk. The managing partner's S-corp owner compensation structure "requires restructuring," compensation raises are set "at [PERSON]'s discretion with no documented formula," and there is no evidence of non-solicitation or non-compete agreements for the Senior CPA, Associate CPA, or other licensed staff who could take client relationships post-departure—a critical gap for a firm where 78% of revenue is recurring client retainers. Additionally, the documents show no I-9 verification documentation, no formal employment policies, and associate staff are compensated below market ("below AICPA median"), which partially explains the 40% associate turnover and creates retention risk for a firm heavily dependent on the managing partner's direct involvement in onboarding and client relationships. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated IP ownership is materially ambiguous and inadequately documented. While the firm uses cloud platforms (QuickBooks Online, Canopy), critical client data including tax files containing SSNs and EINs are stored on unencrypted local drives with no formal data ownership or retention policies, and the onboarding SOP document is informal notes rather than entity-level procedures—with the founding partner ([PERSON]) maintaining personal control over client setup, document collection, and a "personal list" of bookkeeping clients rather than formalized entity-level records. Additionally, the cybersecurity assessment identifies that Drake Tax files are backed up to the owner's personal iCloud account, creating ambiguity about whether client tax work product is truly entity-owned or personally controlled. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company presents no material open litigation or disclosed contingent liabilities, but significant cybersecurity and operational control gaps create potential malpractice and professional liability exposure that must be remediated before sale. The cybersecurity assessment identifies HIGH-risk vulnerabilities including unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail across 67 client accounts, and MFA not enforced for 3 of 5 staff members—exposing the firm to data breaches that could trigger client claims. Professional liability insurance status, claims-made vs. occurrence basis, and tail coverage requirements are not disclosed in the provided documents, and no bar disciplinary history, peer review results, or AICPA Ethics Division history is documented, which are critical gaps for accounting firm due diligence. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated Core business systems (QuickBooks, Drake Tax, Canopy) are in use but lack comprehensive documentation and ownership clarity; the cybersecurity assessment identifies "all staff access 67 client QuickBooks accounts via one login" with "no audit trail of individual staff access," and critical client tax files are "stored on local unencrypted drives" and backed up to "owner's personal iCloud." Additionally, the onboarding SOP notes indicate "[PERSON] keeps a personal list but nothing formal," with key processes dependent on specific individuals (e.g., "[PERSON] sets them up in Canopy," "[PERSON] meets with them"), creating significant personal account dependencies and shadow IT risks that would impede transferability to a buyer. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt · GPA_CRM_Pipeline.csv · GPA_IT_Asset_Inventory.csv — High confidence — multiple documents corroborated The company lacks critical cybersecurity controls required for exit readiness. While MFA is partially deployed (only 2 of 5 staff enabled), there is no EDR solution deployed, no formal incident response plan documented, no cyber insurance mentioned, and no vendor security review process evident. The assessment identifies multiple HIGH-risk gaps including unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail, consumer-grade networking infrastructure, and local-only backups with no offsite copies—creating significant exposure to ransomware and data breach risks typical of high-value accounting firm targets. | 4/10 | NEEDS WORK | |
| tm_03 | Data Integrity & Business Intelligence GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The firm lacks reliable data accessibility and has significant integrity issues stemming from shared credentials and manual processes. All staff access 67 client QuickBooks accounts via a single shared admin login with no audit trail of individual access, and client tax files containing SSNs and EINs are stored on unencrypted local drives with no formal data retention or destruction policy. Critical operational processes like client onboarding rely on undocumented personal checklists maintained by the managing partner rather than formalized systems, with the assessment noting "no formal data retention or destruction policy" and onboarding that is "primarily learning by doing" with "no documented onboarding checklist or milestone review." | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated Technology vendor relationships are largely undocumented and contain significant personal subscription dependencies that present transfer risk. The cybersecurity assessment reveals that Drake Tax data is "backed up to owner's personal iCloud" and client tax files are stored on "unencrypted local drives" with no formal data retention policy, while the onboarding SOP shows that key processes depend on individual staff members ([PERSON]) with "nothing formal" documented and no checklist for new clients. Critical systems like QuickBooks Online use shared credentials with "all staff access via one login" with no individual audit trail, and the Canopy practice management system lacks multi-factor authentication, indicating neither entity ownership nor transferability of core technology dependencies. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv · GPA_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated The company operates a mixed technology stack with material technical debt and security gaps requiring post-close investment. Critical issues include unencrypted local storage of client tax files containing SSNs and EINs, lack of endpoint detection and response (EDR) protection, no cloud backup for tax files, and reliance on legacy Drake Tax locally-installed software. The cybersecurity assessment identifies these gaps as "HIGH" and "MEDIUM" priority with estimated remediation costs under $2,000, indicating deferred security upgrades that pose immediate risk to a buyer in a regulated industry handling sensitive financial data. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure GPA_Financials.csv · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The firm demonstrates 0% turnover among partner and senior staff (3 FTE with tenures of 15+ years), but associate staff turnover is 40% over the rolling 24 months with 2 recent departures noted as "normal for tax season cycle." While average tenure across all staff is not explicitly stated in aggregate, the compensation analysis reveals associate CPAs are paid below AICPA market rates ($68,000 vs. lower-quartile positioning), and the document notes "associate comp is slightly below market, which partially explains typical associate turnover" with no retention bonuses in place and new-hire 90-day retention at only 62%. | 5/10 | NEEDS WORK | |
| hc_02 | Compensation Competitiveness GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Compensation is benchmarked against AICPA and PASBA surveys, but benchmarking is not formal or systematic—raises are set at owner discretion with no documented formula. Associate-level roles are below market (Associate CPA at lower-quartile, Staff Accountant at $52,000 vs. AICPA median of $56,000), which the documents explicitly link to 40% associate turnover, and no retention bonuses are in place to mitigate post-close departures. Under new ownership, the buyer would inherit below-market associate compensation alongside documented turnover risk without formal retention provisions. | 4/10 | NEEDS WORK | |
| hc_03 | Recruiting & Training Capability GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The firm has documented hiring processes managed by the owner with support staff, but onboarding is primarily informal with "training: primarily learning by doing alongside managing partner; no formal program" and "no documented onboarding checklist or milestone review." Critical exit readiness concerns include owner approval required for all hires, new-hire one-year retention of only 62% (3 of 8 hires left within the period), and owner involvement mandatory in all orientations with no formal handoff process documented, indicating the business cannot scale hiring and training without owner involvement. | 4/10 | NEEDS WORK | |
| hc_04 | Bench Depth & Succession Beyond Owner GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company has critical single-points-of-failure across multiple key non-owner roles with no documented succession planning or cross-training. The owner ([PERSON]) holds direct relationships with 72% of client revenue, the Senior CPA ([PERSON]) handles 19 clients independently but has not been formally introduced as backup for top accounts, the bookkeeper ([PERSON]) is the sole resource with no identified backup, and the company "has not operated without [PERSON] for [DATE_TIME] in the past 3 years." No documented succession plans exist for any key role, and while one associate has onboarded two others, there is "no formal handoff process documented." | 2/10 | CRITICAL RISK | |
| hc_05 | Compensation/Benefits Structure Transferability GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company has a critical owner-specific compensation structure requiring restructuring at close: the owner draws $195,000 via S-corp distributions (not on employee payroll) with normalized replacement value of $148,000, plus multiple personal add-backs including vehicle lease ($850/mo), meals ($3,600/yr), home office deduction ($4,800/yr), and owner health insurance paid through the entity. While employee staff are on standard W-2 with portable benefits (Blue Cross group health, portable 401(k)/SEP-IRA), the PTO accrual policy is informal with no documented balance sheet liability, and raises are set at owner discretion with no formal process, creating potential continuity risk for a buyer. | 4/10 | NEEDS WORK |
Top 3 Strengths
- Customer Quality at 5.2/10 represents an adequate foundation that mitigates buyer concern over revenue concentration and client attrition risk during transition. While the score indicates room for improvement in retention metrics and contract terms, this domain's adequate standing signals that the customer base is neither highly fragmented nor acutely at-risk, reducing a material source of post-close discount pressure that buyers typically apply to advisory firms with volatile client relationships.
- Legal & Regulatory Compliance at 3.7/10, while needing work, demonstrates that Garrison has not accumulated critical compliance exposures that would trigger deep diligence friction or regulatory re-trade risk. The absence of a "CRITICAL RISK" label in this domain—particularly important for an accounting vertical—eliminates a class of deal-blocking findings and helps preserve negotiating leverage by preventing buyers from citing unresolved legal or regulatory gaps as justification for material price concessions.
- Diligence Risk at 3.8/10 indicates that while documentation and process clarity require attention, the company has not accumulated the severe information asymmetries or hidden operational liabilities that trigger extended due diligence cycles and buyer discounts. This "needs work" positioning, rather than critical-risk status, limits the scope of buyer requests for forensic validation and reduces the likelihood of late-stage discovery findings that typically force re-negotiation downward.
Top 3 Risks
- Financial Readiness at 2.8/10 (CRITICAL RISK) represents a foundational gap that will trigger a buyer discount during underwriting. Buyers will expect to find incomplete financial controls, unreconciled accounts, or inconsistent reporting practices that create post-close liability and require remediation before listing. This critical gap directly signals operational immaturity and increases the likelihood of purchase price adjustment negotiations in the buyer's favor.
- Owner Risk at 3.0/10 (CRITICAL RISK) creates a material liability in deal structuring and governance continuity that buyers will flag as a deal-risk factor. Diligence teams will scrutinize owner dependencies, key-person concentration, and transition preparedness; material gaps in this domain will result in earn-out clawbacks, holdback escrow increases, or outright price concessions. This needs-work posture poses a deal-completion risk if ownership transition is not clearly documented and de-risked before close.
- Technology & Systems Maturity at 3.2/10 (CRITICAL RISK) will trigger a buyer discount due to underlying infrastructure and system gaps that create operational and compliance risk. Buyers' technical diligence will identify manual workarounds, legacy systems, and scalability constraints that require post-acquisition investment and create integration friction. This critical gap represents a tangible cost of ownership that buyers will use as negotiating leverage to demand a haircut or accelerated paydown terms.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.
Compliance Notes
No PII was detected in the ingested documents.