Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
OROwner Risk | Succession Planning & Knowledge Capture Sprint | +2% | $6,101 | ⏱ 8–10 wks | $6,000 – $10,000 | ~1x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +2% | $5,720 | ⏱ 6–8 wks | $3,500 – $6,500 | |
DRDiligence Risk | Security Hardening & Data Room Preparation | +2% | $5,338 | ⏱ 6–8 wks | $4,500 – $7,500 | ~1x |
CQCustomer Quality | Contract Audit & CRM Implementation | +2% | $5,338 | ⏱ 8–10 wks | $5,000 – $9,000 | ~1x |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +2% | $5,338 | ⏱ 8–10 wks | $5,000 – $9,000 | |
FRFinancial Readiness | Books Cleanup & Add-Back Schedule | +2% | $4,194 | ⏱ 6–8 wks | $4,000 – $7,000 | ~1x |
OSOperational Scalability | Process Documentation & Systems Audit | +1% | $3,050 | ⏱ 10+ wks | $6,500 – $11,000 | ~0.5x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +1% | $3,050 | ⏱ 8–12 wks | $5,000 – $9,000 | |
| TOTAL | — | $38,130 | — | $39,500 – $69,000 | ~0.5x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (Revenue) |
|---|---|---|
| Current (as-is) | 0.5×–0.8× Revenue | $127,100 – $203,360 |
| Post-Remediation (5.6/10 est.) | 0.5×–0.8× Revenue | $127,100 – $203,360 |
Implementing the recommended priority fixes over 90 days could add an estimated ~$0 to the transaction value — a potential 0% lift on the same underlying business.
↑ What drives higher multiples
- High client retention >90%
- Engagement letters assignable
- Staff CPA capacity beyond owner
- Seasonal workflow documented
↓ What buyers will flag
- Owner performs all technical work
- Client relationships not transferable
- No engagement letter documentation
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company has minimal formal documentation of core processes. The customer onboarding SOP exists only as informal notes marked "[PERSON]'s notes — needs to be formalized" with a personal checklist that is not official, and the onboarding program is explicitly described as "partially documented" with "no documented onboarding checklist or milestone review" and training occurring primarily through learning by doing. Critical process knowledge remains concentrated in key individuals, as evidenced by the owner's required involvement in all hiring decisions and new hire orientations, creating significant operational risk for exit readiness. | 3/10 | CRITICAL RISK | |
| fix_02 | Cybersecurity Posture GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company has significant cybersecurity gaps that place it below acceptable threshold for sale readiness. Critical issues include MFA not enforced for 3 of 5 staff members with access to client financial data, no EDR solution deployed (Windows Defender only), client tax files stored on unencrypted local drives containing SSNs and EINs, all staff sharing a single QuickBooks login with no audit trail, and backup strategy limited to local external drives with no offsite or cloud backup. While the assessment identifies these gaps as "fast and cheap to remediate" at under $2,000 total cost, they currently represent a MEDIUM overall risk rating that exceeds acceptable thresholds for the transaction process. | 4/10 | NEEDS WORK | |
| fix_03 | Owner Dependency GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The owner ([PERSON]) is the single point of failure across the business — he holds direct relationships with 48 of 67 clients (72% of revenue), manages all hiring and onboarding decisions, sets compensation and raises at his discretion, and provides direct guidance on all new hire orientations with no formal handoff process documented. The firm has not operated without the owner for an extended period in the past 3 years, and while one Senior CPA ([PERSON]) can handle 19 clients independently, he "has not been formally introduced as backup for Garrison's top accounts," with no documented succession plan for any key role. | 2/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company demonstrates strong revenue quality with 78% recurring revenue derived from tax preparation and bookkeeping retainers, exceeding the 50-70% threshold for this score band. Revenue concentration is excellent with 67 active client relationships and no client exceeding 3% of total revenue (largest client at $19,200 / 2.3%), well below the 15% concentration limit. However, the firm lacks documented renewal rates and formal multi-year contract tracking, preventing a higher score despite the presence of engagement letters and retainer agreements. | 8/10 | STRONG | |
| fix_05 | Customer Contracts GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated Customer contracts lack standardization and formal documentation infrastructure—engagement letters are sent via email from Outlook drafts rather than through formal systems like DocuSign, and there is no centralized contract repository or renewal tracking mechanism documented. The onboarding SOP notes indicate informal processes ("I keep a personal list but nothing formal"), with no evidence of change-of-control or assignment clauses in customer agreements, and no documented contract renewal rate or tracking system in place. Additionally, the managing partner holds direct relationships with 72% of clients by revenue, creating substantial transfer risk that is not mitigated by formal, transferable contract documentation. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company lacks a comprehensive IT asset inventory and system documentation. The cybersecurity assessment identifies critical gaps including unencrypted local drives storing client tax files, no endpoint detection and response (EDR) protection, consumer-grade networking equipment with no formal firewall policy, and backup systems that are incomplete and largely undocumented (e.g., Drake Tax files backed up to owner's personal iCloud, external drive backups kept in-office with no offsite copy). While basic systems like QuickBooks Online and Canopy are in use, there is no evidence of formal asset lifecycle tracking, current patch management documentation, or any disaster recovery testing. | 3/10 | CRITICAL RISK | |
| fix_07 | CRM & Pipeline Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company uses Canopy Practice Management with individual logins for client management and mentions an "active pipeline of $185K with $92K weighted value" in the CIM, indicating some pipeline documentation exists. However, the retrieved documents provide no evidence of consistent pipeline discipline, forecast validation, or stage tracking—only a single mention of pipeline value with no supporting detail on how opportunities are managed, tracked, or forecasted against actuals. | 4/10 | NEEDS WORK | |
| fix_08 | Key Employee Risks GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The firm has severe key employee risks with multiple single points of failure beyond the owner. The Managing Partner holds direct relationships with 48 of 67 clients (72% of revenue) with no documented succession plan, and the Senior CPA ([PERSON]) is the sole resource for bookkeeping administration with "none identified" as backup. While the Senior CPA has onboarded two associates, there is no formal handoff process documented, no cross-training program, onboarding is primarily "learning by doing alongside managing partner," and the firm has not operated without the Managing Partner for an extended period in the past 3 years, creating critical business continuity risk. | 3/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company reports $820K in [DATE_TIME] revenue with a 31% EBITDA margin ($254K) and normalized EBITDA of $298K after add-backs, demonstrating reasonable profitability, but the documents do not provide audited or reviewed financial statements, multi-year comparative financials, or detailed documentation of the add-backs beyond the summary figures in the CIM. The absence of formal financial review documentation, combined with lack of historical growth trajectory data across multiple years, places the firm in the compiled financials category with reasonable margins but insufficient third-party validation for a higher exit-readiness score. | 6/10 | ADEQUATE | |
| fix_10 | Data Room Readiness GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company lacks an organized data room and has not prepared key documents for due diligence. While a Confidential Information Memorandum (CIM) exists, the internal documents reveal significant gaps: the customer onboarding process is informal with notes stating "needs to be formalized" and no checklist, engagement letters are stored in Outlook drafts rather than in a centralized repository, and critical cybersecurity and operational documents appear scattered across multiple internal files rather than consolidated. The absence of version control, formal document organization structure, and any evidence of a dedicated data room accessible to advisors indicates the company would require substantial cleanup before buyer review. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated No formal succession plan exists for Garrison Professional Advisors. The owner ([PERSON]) is the primary contact for 72% of client relationships by revenue, manages all staff supervision and hiring decisions, and "the firm has not operated without [PERSON] for [DATE_TIME] in the past 3 years," with documentation explicitly stating "No documented succession plan for any key role" and "No cross-training program." While a senior CPA ([PERSON]) has onboarded two associates and holds relationships with 19 clients, this represents only informal readiness with no formal handoff protocols, documented backup arrangements, or prepared transition plan. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has minimal institutional knowledge documentation with critical processes remaining in individual heads. The client onboarding SOP is explicitly noted as "[PERSON]'s notes — needs to be formalized" with a personal checklist that is not formally documented, and onboarding relies primarily on "learning by doing alongside managing partner" with no documented checklist or milestone review. The owner is involved in all new hire orientations with no formal handoff process, and 72% of client relationships by revenue are controlled by the owner with no documented succession plan or cross-training program across any key role. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The Senior CPA ([PERSON]) has independently handled 19 clients (28% of revenue) and onboarded two associates, but the owner ([PERSON]) remains the primary contact for 72% of client relationships and is required for all new hire orientations, key decisions, and staff supervision with no documented succession plan or cross-training program. The firm has not operated without the owner for an extended period in the past 3 years, and the documents explicitly state that "if [PERSON] were absent for an extended period, [PERSON] could handle routine returns but client relationship continuity would be at risk," indicating the business cannot reliably operate independently for 60+ days. | 4/10 | NEEDS WORK | |
| owr_04 | Key Person Concentration Beyond Owner GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The firm has significant key person concentration beyond the owner, with one Senior CPA ([PERSON]) at $82,000 salary who appears deeply embedded in client relationships and tax return reviews, and a Bookkeeper/Admin ([PERSON]) at $58,000 who manages client onboarding, QuickBooks access, and document organization—roles documented as lacking formal procedures or backup coverage. The onboarding SOP explicitly notes that critical processes are managed by named individuals with "nothing formal" documented, training is "primarily learning by doing alongside managing partner," and the owner "must be involved in all new hire orientations," indicating no cross-trained backup for these key roles and a 62% new-hire retention rate suggesting instability in replacing departing staff. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The company demonstrates excellent customer diversification with no single customer concentration risk. The largest customer represents only 2.3% of revenue ($19,200), the top 5 customers combined represent approximately 10% of revenue, and the firm serves 67 active client relationships with an average client value of $12,200, explicitly noted in the CIM as "low concentration." This well-distributed customer base across SMB owners, real estate investors, and professional services verticals significantly mitigates revenue vulnerability typical in professional services firms. | 9/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated Garrison Professional Advisors demonstrates strong revenue predictability with 78% recurring revenue from tax preparation and bookkeeping retainers under engagement letters and retainer agreements, averaging $12,200 per client across 67 active client relationships. However, the documents do not provide documented renewal rates, retention tracking data, or explicit contract terms (annual vs. multi-year), which prevents a higher score; the firm's reliance on the managing partner for 72% of client relationships by revenue also introduces concentration risk that could impact renewal predictability in an ownership transition. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The documents provide no evidence of engagement letters containing assignment or change-of-control clauses; the onboarding SOP notes that engagement letters are sent via email from an Outlook template but require formalization, with no mention of transferability language. Client relationships are personality-dependent and concentrated with the owner ([PERSON] identified as primary contact for 72% of client relationships by revenue), and the documents explicitly state "no documented succession plan for any key role" and that the firm has not operated without the owner in the past 3 years, indicating contracts cannot be transferred without individual customer consent and relationship continuity is at material risk. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated The documents contain no evidence of tracked churn rate, retention metrics, or formal retention programs. The onboarding process documentation (excerpt [1]) focuses only on initial client setup with informal, undocumented procedures ("I keep a personal list but nothing formal"), and there is no mention of customer retention tracking, analysis, or recovery initiatives. The only retention-related data present concerns employee turnover (new-hire 62% retention over an unspecified period in excerpt [3]), not customer churn, indicating the company has not established systematic customer retention measurement or strategy. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The company maintains internally prepared financial records with no evidence of audited, reviewed, or compiled financial statements from a qualified CPA firm. The CIM and internal documents reference the firm's own tax and bookkeeping practices but contain no indication of professional financial statement preparation, audit relationships, or GAAP-compliant reporting; additionally, significant cybersecurity gaps including unencrypted client tax files, shared QuickBooks credentials with no audit trail, and lack of formal financial controls create material risks that would require substantial remediation before diligence readiness. | 3/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The CIM mentions "Normalized EBITDA of $298K after add-backs" but provides no supporting schedule, documentation, or methodology for these adjustments. The HC Profile document identifies the managing partner draw of $195,000 with a normalized add-back value of $148,000, but this single adjustment lacks detailed calculation or verification support, and no formal add-back schedule separating personal versus business expenses is evident in any retrieved documents. A buyer's accountant would have insufficient documentation to independently verify the $44,000 difference between reported and normalized EBITDA. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no formal revenue recognition policy, no documentation of GAAP compliance procedures, and no evidence of deferred revenue tracking or audit oversight. The onboarding SOP references informal processes ("needs to be formalized," "personal list but nothing formal") and lacks any structured revenue documentation or consistency controls. No audit trail, revenue recognition standards, or period-to-period policy documentation are evident in any of the provided materials, presenting significant restatement risk during due diligence. | 2/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain a CIM showing $820K in revenue with 31% EBITDA margin (~$254K EBITDA) for one fiscal year, but provide no multi-year financial statements, historical revenue trends, or EBITDA comparability data needed to assess a three-year trend. Without access to prior-year P&Ls or tax returns showing year-over-year growth rates, CAGR calculation, or margin trajectory, the financial trend assessment cannot be completed; the single-year snapshot alone is insufficient to demonstrate consistent growth or margin stability over three years. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has minimal formal process documentation with heavy reliance on specific individuals. The customer onboarding SOP document explicitly states it is "[PERSON]'s notes — needs to be formalized" and notes that "I keep a personal list but nothing formal" for onboarding checklists. The onboarding program is "partially documented" with training "primarily learning by doing alongside managing partner; no formal program" and "no documented onboarding checklist or milestone review," making new staff dependent on direct owner guidance for execution of core workflows. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company's technology stack relies on a mix of cloud-based systems (QuickBooks Online, Canopy) and locally-installed legacy software (Drake Tax on unencrypted drives), with critical infrastructure gaps that would require material modernization to support 3x growth. The cybersecurity assessment identifies HIGH-risk issues including shared QuickBooks credentials across 67 client accounts with no audit trail, unencrypted local storage of sensitive tax files containing SSNs and EINs, and missing multi-factor authentication for 60% of staff—all indicating systems are fragile and underdocumented. Additionally, onboarding processes are informal and owner-dependent ("learning by doing"), with no formal documentation or scalable procedures, meaning growth would require significant architectural and operational rework beyond simple infrastructure investment. | 4/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated The company exhibits significant vendor concentration risk, with critical dependencies on a small number of platforms that lack formal alternatives or documented SLAs. The firm relies heavily on Drake Tax (locally installed with unencrypted storage), Canopy (practice management with individual logins but no MFA), and QuickBooks Online (all staff sharing one admin login with no audit trail), and the cybersecurity assessment identifies no documented vendor alternatives or formal service level agreements for any of these critical systems. Additionally, the onboarding process and operational procedures are undocumented and heavily dependent on the owner's personal involvement, creating de facto single-source dependencies that extend beyond traditional vendor relationships into key service delivery. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The company lacks formal financial close processes and documented controls. The retrieved documents contain no evidence of monthly financial close timelines, budget vs. actual reviews, or a CFO/Controller overseeing financial reporting; instead, they reveal ad-hoc processes such as a bookkeeper managing accounts with informal controls, a managing partner setting compensation "at his discretion with no documented formula," and onboarding procedures that are "partially documented" with "no formal program." The cybersecurity assessment notes "no formal data retention or destruction policy" and indicates financial data management relies on personal judgment rather than documented procedures, suggesting the firm's own financial controls mirror the informal practices observed in client work. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated Core business systems lack formal documentation and exhibit significant personal account dependencies that create exit risk. The onboarding SOP is described as "[PERSON]'s notes — needs to be formalized" with the owner maintaining personal informal checklists; critical systems like Drake Tax files are backed up to the owner's personal iCloud account, and all staff access 67 client QuickBooks accounts through a single shared login with no audit trail. Additionally, the cybersecurity assessment identifies that the owner's laptop is used for both personal and business activities, and the owner must be directly involved in all new hire orientations and hiring decisions, indicating substantial key-person dependencies rather than transferable, entity-owned systems and processes. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt · GPA_CRM_Pipeline.csv · GPA_IT_Asset_Inventory.csv — High confidence — multiple documents corroborated The firm has critical cybersecurity gaps that fall well below exit-readiness standards. While MFA is partially deployed (only 2 of 5 staff enabled), there is no EDR protection beyond Windows Defender, no tested incident response plan, no cyber insurance mentioned, and no vendor security review documentation. The assessment identifies multiple HIGH-risk gaps including unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail, local-only backups with no offsite copy, and a consumer-grade router with no network segmentation—creating unacceptable vulnerability for a firm holding sensitive financial data for 67 clients. | 3/10 | CRITICAL RISK | |
| tm_03 | Data Integrity & Business Intelligence GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated Data integrity and accessibility are severely compromised by individual dependencies and fragmented systems. Critical operational data lacks formal documentation—client onboarding relies on [PERSON]'s personal checklist rather than formalized processes, new hire retention tracking is ad-hoc, compensation decisions are made "at [PERSON]'s discretion [DATE_TIME] with no documented formula," and client tax files are stored on unencrypted local drives with "no audit trail of individual staff access to client data" due to shared QuickBooks credentials. The cybersecurity assessment identifies that "all staff access 67 client QuickBooks accounts via one login" and "Drake Tax data [is] backed up to owner's personal iCloud," creating both data integrity risks and complete operational dependency on the managing partner. | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated Technology vendor relationships are largely undocumented and contain critical personal subscription dependencies that create significant transfer risk. The cybersecurity assessment reveals that Drake Tax data is "backed up to owner's personal iCloud" and client tax files are stored on unencrypted local drives with no formal data retention policy, while the onboarding documentation shows key processes (engagement letters, client setup in Canopy, QuickBooks access) are managed ad-hoc by the owner with "nothing formal" documented. Additionally, the firm lacks formal documentation of vendor contracts, renewal dates, and transferability terms for critical tools including Canopy, Drake Tax, QuickBooks Online, and Tax Dome, creating substantial risk for an acquiring entity. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv · GPA_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated The company operates on a mixed and aging technology stack with material technical debt requiring post-close investment. Critical gaps include unencrypted local storage of client tax files containing SSNs and EINs, shared QuickBooks credentials across all staff with no audit trail, absence of EDR protection despite high ransomware risk to accounting firms, and no offsite cloud backup for tax files. While the cybersecurity assessment acknowledges these gaps are "fast and cheap to remediate" with estimated costs under $2,000, the presence of unsupported security controls (consumer-grade router, Windows Defender only, no MFA enforcement, no disk encryption) and the reliance on legacy Drake Tax local installation represent significant inherited risk for a buyer. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of business licenses, permits, or their transferability status. The company is a CPA firm handling sensitive client financial data for 67 clients, yet there is no documentation addressing state CPA licenses, firm licenses, or change-of-control transferability with counsel. This represents a material compliance gap for an accounting services firm operating without documented proof of required professional licensure. | 2/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence that key vendor, customer, or lease agreements have been reviewed by counsel for assignment clauses or change-of-control provisions. The customer onboarding documentation shows engagement letters are sent via email template but makes no mention of change-of-control language, and there is no record of legal review of these or other material contracts. The only contract-related activity documented is informal client onboarding procedures that lack any change-of-control analysis, presenting material deal risk for the transaction. | 2/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company maintains all staff on W-2 employment and compensation is benchmarked against AICPA surveys with salaries at or near market rates for senior roles; however, compensation structure presents material risk, as the managing partner's S-corp owner compensation ($195,000 distribution) "requires restructuring" and raises are set "at [the owner's] discretion [with] no documented formula." Additionally, while the documents confirm standard employment practices and no open legal matters are mentioned, there is no explicit evidence of current I-9 documentation, formal non-compete agreements, or documented employment policies, creating documentation gaps typical of a small firm lacking formalized HR infrastructure. | 6/10 | ADEQUATE | |
| lc_04 | Intellectual Property Ownership GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated IP ownership is ambiguous and largely undocumented. While the company operates as a licensed CPA firm (Garrison Professional Advisors LLC) with established client relationships, the documents reveal critical gaps: client data and tax files are stored on unencrypted local drives with shared credentials across staff, there is no formal IP assignment documentation, and key processes (like client onboarding) exist only in informal notes rather than as formally owned company assets. The cybersecurity assessment notes "no formal data retention or destruction policy" and identifies that client financial data containing SSNs and EINs is accessible to all staff without individual audit trails, creating ambiguity around data ownership and control rather than clean entity ownership. | 4/10 | NEEDS WORK | |
| lc_05 | Litigation & Contingent Liability GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated The company has no disclosed active litigation or contingent liabilities; however, the cybersecurity assessment identifies multiple material security gaps involving unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail, and lack of MFA for 3 of 5 staff members—creating meaningful exposure to potential regulatory claims, client data breach liability, and professional liability before sale. These gaps are characterized as "MEDIUM" overall risk and "above acceptable threshold for sale process," though estimated remediation costs are under $2,000 and described as "fast and cheap to remediate." | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated While compensation is benchmarked to AICPA market surveys with documented salaries for all staff ($42,000–$82,000 range), employee roles and responsibilities lack formal documentation. The onboarding process is "partially documented" with no formal checklist, training is "primarily learning by doing," and critically, there is "no documented succession plan for any key role" with the managing partner holding 72% of client relationships by revenue and no formal handoff process documented for onboarding. Key operational procedures like client onboarding exist only in personal notes marked "needs to be formalized," indicating heavy reliance on informal, owner-dependent knowledge rather than systematized role documentation. | 4/10 | NEEDS WORK | |
| hc_02 | Retention Agreements & Non-Competes GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated There is no evidence in the retrieved documents of non-compete or retention agreements in place for any key employees. The HC Profile explicitly states "No retention bonuses in place" and notes that associate compensation is "slightly below market, which partially explains typical associate turnover" with only 62% new-hire retention over the period reviewed. The firm has critical key-person risk with the managing partner holding 72% of client relationships by revenue and no documented succession plan or cross-training for any role, creating significant flight risk for key staff post-acquisition. | 2/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated The firm has severe bench depth deficiencies with multiple critical single points of failure centered on the managing partner. All hiring decisions require owner approval with no delegated authority, new client onboarding is entirely managed by the owner (who "meets with them," sets them up in systems, and "reviews everything before any return is filed"), and the onboarding process relies on "learning by doing alongside managing partner" with no formal program. Additionally, the owner's involvement is explicitly required in all new hire orientations, and key operational processes like client onboarding lack formalization, existing only as the owner's personal notes—indicating no documented procedures other staff can execute independently. | 3/10 | CRITICAL RISK |
Accounting firm revenue infrastructure is driven by client retention, referral network quality, and seasonal workflow management rather than high-velocity lead automation.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv There is no evidence of AI voice agents or after-hours call handling automation in any of the retrieved documents; the firm's operations focus on manual client management, email-based communication, and in-person meetings with no mention of inbound call handling infrastructure. After-hours calls would default to voicemail or go unanswered, indicating zero automation maturity in this capability. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv The firm uses Canopy as a practice management system with individual logins for basic client management and document exchange, but workflow automation is minimal and dependent on the managing partner's manual oversight—new client onboarding relies on [PERSON]'s personal checklist rather than formalized automated workflows, and critical processes like engagement letter execution still use manual email and unsigned templates rather than DocuSign integration. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of after-hours or 24/7 lead capture capability; the retrieved documents focus on client onboarding, cybersecurity, and HR processes with no mention of a website contact form, chatbot, or automated lead routing system. Lead generation and capture mechanisms are entirely absent from the company's documented operations. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of any automated SMS appointment reminder or confirmation system in the retrieved documents; the company uses basic email-based engagement letters and manual client communication processes managed ad-hoc by staff members. The onboarding process described is entirely manual and owner-dependent, with no reference to SMS workflows, automated confirmations, or no-show follow-up sequences. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv There is no evidence of any automated or manual post-service review solicitation process in the retrieved documents; reviews appear to be organic only with no systematic request mechanism in place. The onboarding SOP and operational practices document manual workflows but contain no mention of review requests, and no automation platform or trigger-based system is referenced. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt There is no evidence of automated follow-up sequences for leads or dormant clients in any of the retrieved documents. The onboarding process relies entirely on manual coordination by the managing partner and staff, with no mention of drip campaigns, automated email sequences, or systematic re-engagement workflows for unconverted prospects or inactive clients. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
CPA firm Automation Maturity scores are structurally lower by industry norm. Absence of AI voice, 24/7 capture, and aggressive review solicitation is standard for referral-based practices.
Vertical-specific operational automation gaps identified in Accounting Practice Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Client Document Collection | 1/2 | PARTIAL | Document collection automation compresses the tax season intake window by 2-3 weeks and eliminates the most common source of extension filing and client frustration. | |
| Engagement Letter & E-Signature | 0/2 | MANUAL | Engagement letter automation ensures 100% signed engagement coverage — a critical diligence item for buyers assessing client relationship transferability and E&O exposure. | |
| Deadline & Filing Calendar | 0/2 | MANUAL | Deadline automation eliminates the most common source of penalty exposure and provides the workload visibility needed to staff engagements efficiently during peak season. | |
| Recurring Invoice & Billing Automation | 0/2 | MANUAL | Billing automation converts the accounts receivable function from a partner time sink to a self-managing revenue stream — directly improving realization rates. | |
| Client Communication & Seasonal Outreach | 0/2 | MANUAL | Automated seasonal outreach surfaces advisory opportunities the client didn't know to ask about and drives year-round engagement beyond the annual return. |
Top 3 Strengths
- Strong Revenue Quality & Diversification (8/10): 78% of revenue derives from recurring tax preparation and bookkeeping retainers, exceeding industry thresholds, with excellent client diversification across 67 active relationships where no single client exceeds 3% of revenue, significantly reducing buyer concentration risk.
- Solid Financial Performance: The firm generates $820K in revenue with a normalized EBITDA of $298K (36% margin after add-backs), demonstrating reasonable profitability and cash generation capability that supports valuation multiples typical for professional services exits.
- Core Technology Infrastructure in Place: The company uses modern practice management systems (Canopy) and accounting software (QuickBooks Online), providing a foundation for operational continuity post-acquisition and reducing buyer transition costs compared to legacy-dependent firms.
Top 3 Risks
- Extreme Owner Dependency (2/10) & No Succession Planning: The Managing Partner owns direct relationships with 72% of client revenue (48 of 67 clients), controls all hiring and compensation decisions, and has not operated without him for 3+ years, creating a critical single point of failure that buyers will discount heavily or condition on retention agreements that reduce seller proceeds.
- Critical Cybersecurity Gaps Below Transaction Threshold (4/10): The company stores unencrypted client tax files containing SSNs and EINs on local drives, lacks MFA for 60% of staff accessing financial data, maintains no EDR solution, and uses shared QuickBooks logins with no audit trail—these MEDIUM-rated security vulnerabilities will trigger buyer remediation demands and potential deal delay or renegotiation.
- Absent Process Documentation & Contract Infrastructure (3/10 each): Core operational processes exist only as informal owner notes with no formal SOPs, engagement letters are stored in Outlook drafts rather than a centralized system with no renewal tracking, and there is no evidence of change-of-control or assignment clauses in customer contracts, creating substantial transfer risk and buyer uncertainty around client retention post-close.
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.