Layer8 Tech Group Exit Readiness Assessment
Garrison Professional Advisors 2026-08-03

Prepared by: Layer8TechGroup  ·  Framework: 10 Technology Fixes — Tier 1  ·  Documents Ingested: cached collection (previously ingested)

Overall Score
3.6/10
5-domain blend
Buyer Discount Risk
0.5 – 0.8×
Revenue · Main Street
EBITDA
$254,200
most recent FY
Vertical
Accounting
accounting

Assessment Scores — 8-Domain Profile

Diligence Risk
3.9/10NEEDS WORK
Owner Risk
3.2/10CRITICAL RISK
Customer Quality
5.0/10NEEDS WORK
Financial Readiness
2.8/10CRITICAL RISK
Operational Scalability
3.5/10NEEDS WORK
Technology & Systems Maturity
3.1/10CRITICAL RISK
Legal & Regulatory Compliance
4.0/10NEEDS WORK
Human Capital & Key Employee Risk
3.0/10CRITICAL RISK
Value Recovery RoadmapTotal Recoverable Value: $38,130
Prioritized by estimated recovery value  ·  8 scored domains  ·  90-day remediation timeline
DomainLayer8 ServiceDeal ImpactValue at RiskEst. TimelineTypical InvestmentEst. ROI
OROwner Risk
Succession Planning & Knowledge Capture Sprint+2%$6,101⏱ 8–10 wks$6,000 – $10,000~1x
LCLegal & Regulatory Compliance
Legal Compliance Audit & Contract Review+2%$5,720⏱ 6–8 wks$3,500 – $6,500Reduces deal risk and supports clean diligence — unresolved legal gaps are the #…
DRDiligence Risk
Security Hardening & Data Room Preparation+2%$5,338⏱ 6–8 wks$4,500 – $7,500~1x
CQCustomer Quality
Contract Audit & CRM Implementation+2%$5,338⏱ 8–10 wks$5,000 – $9,000~1x
HCHuman Capital & Key Employee Risk
Key Employee Retention & Documentation Sprint+2%$5,338⏱ 8–10 wks$5,000 – $9,000Key employee retention is a direct deal risk — buyers model post-close talent lo…
FRFinancial Readiness
Books Cleanup & Add-Back Schedule+2%$4,194⏱ 6–8 wks$4,000 – $7,000~1x
OSOperational Scalability
Process Documentation & Systems Audit+1%$3,050⏱ 10+ wks$6,500 – $11,000~0.5x
TMTechnology & Systems Maturity
Technology Infrastructure Audit & Modernization Plan+1%$3,050⏱ 8–12 wks$5,000 – $9,000Technology gaps are an increasingly standalone underwriting factor — buyers mode…
TOTAL$38,130$39,500 – $69,000~0.5x
⚠ Targeted Remediation Only
At this business size and valuation basis, the cost of full-roadmap remediation approaches or exceeds the recoverable valuation uplift. Prioritize Quick Win items and focus on the top 2 domains by value at risk.
Quick Win items only — prioritize the top 2 domains by value at risk.

Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.

Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.

Ready to recover this value before you list?
Layer8 Tech Group delivers these services for businesses preparing for acquisition.
Schedule a Discovery Call →

Valuation Impact Analysis

Main Street  ·  Revenue Accounting businesses in this size range typically trade at 0.5–0.8× Revenue — CPA and accounting firms trade on revenue multiples due to high owner compensation normalization complexity. Client retention and engagement letter transferability are the primary drivers.
Score-adjusted range   (Exit Readiness 3.6/10 — Main Street — lower range)
EBITDA (most recent FY): $254,200 (AI-extracted)
Material Gaps
High — significant discount likely
Scenario Score-Adjusted Range Implied Value (Revenue)
Current (as-is) 0.5×–0.8× Revenue $127,100 – $203,360
Post-Remediation (5.6/10 est.) 0.5×–0.8× Revenue $127,100 – $203,360

Implementing the recommended priority fixes over 90 days could add an estimated ~$0 to the transaction value — a potential 0% lift on the same underlying business.

↑ What drives higher multiples

  • High client retention >90%
  • Engagement letters assignable
  • Staff CPA capacity beyond owner
  • Seasonal workflow documented

↓ What buyers will flag

  • Owner performs all technical work
  • Client relationships not transferable
  • No engagement letter documentation

Domain Detail & Findings

Diligence Risk3.9/10  NEEDS WORK (14% blend)
Deal Impact: Documentation gaps will extend diligence and require owner availability — expect timeline delays and buyer leverage.
IDCriterion & FindingScoreRatingBar
fix_01Documented Processes & SOPs
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The company has minimal formal documentation of core processes. The customer onboarding SOP exists only as informal notes marked "[PERSON]'s notes — needs to be formalized" with a personal checklist that is not official, and the onboarding program is explicitly described as "partially documented" with "no documented onboarding checklist or milestone review" and training occurring primarily through learning by doing. Critical process knowledge remains concentrated in key individuals, as evidenced by the owner's required involvement in all hiring decisions and new hire orientations, creating significant operational risk for exit readiness.
3/10CRITICAL RISK
fix_02Cybersecurity Posture
GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
The company has significant cybersecurity gaps that place it below acceptable threshold for sale readiness. Critical issues include MFA not enforced for 3 of 5 staff members with access to client financial data, no EDR solution deployed (Windows Defender only), client tax files stored on unencrypted local drives containing SSNs and EINs, all staff sharing a single QuickBooks login with no audit trail, and backup strategy limited to local external drives with no offsite or cloud backup. While the assessment identifies these gaps as "fast and cheap to remediate" at under $2,000 total cost, they currently represent a MEDIUM overall risk rating that exceeds acceptable thresholds for the transaction process.
4/10NEEDS WORK
fix_03Owner Dependency
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The owner ([PERSON]) is the single point of failure across the business — he holds direct relationships with 48 of 67 clients (72% of revenue), manages all hiring and onboarding decisions, sets compensation and raises at his discretion, and provides direct guidance on all new hire orientations with no formal handoff process documented. The firm has not operated without the owner for an extended period in the past 3 years, and while one Senior CPA ([PERSON]) can handle 19 clients independently, he "has not been formally introduced as backup for Garrison's top accounts," with no documented succession plan for any key role.
2/10CRITICAL RISK
fix_04Revenue Quality & Concentration
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The company demonstrates strong revenue quality with 78% recurring revenue derived from tax preparation and bookkeeping retainers, exceeding the 50-70% threshold for this score band. Revenue concentration is excellent with 67 active client relationships and no client exceeding 3% of total revenue (largest client at $19,200 / 2.3%), well below the 15% concentration limit. However, the firm lacks documented renewal rates and formal multi-year contract tracking, preventing a higher score despite the presence of engagement letters and retainer agreements.
8/10STRONG
fix_05Customer Contracts
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
Customer contracts lack standardization and formal documentation infrastructure—engagement letters are sent via email from Outlook drafts rather than through formal systems like DocuSign, and there is no centralized contract repository or renewal tracking mechanism documented. The onboarding SOP notes indicate informal processes ("I keep a personal list but nothing formal"), with no evidence of change-of-control or assignment clauses in customer agreements, and no documented contract renewal rate or tracking system in place. Additionally, the managing partner holds direct relationships with 72% of clients by revenue, creating substantial transfer risk that is not mitigated by formal, transferable contract documentation.
3/10CRITICAL RISK
fix_06IT Infrastructure & Asset Documentation
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated
The company lacks a comprehensive IT asset inventory and system documentation. The cybersecurity assessment identifies critical gaps including unencrypted local drives storing client tax files, no endpoint detection and response (EDR) protection, consumer-grade networking equipment with no formal firewall policy, and backup systems that are incomplete and largely undocumented (e.g., Drake Tax files backed up to owner's personal iCloud, external drive backups kept in-office with no offsite copy). While basic systems like QuickBooks Online and Canopy are in use, there is no evidence of formal asset lifecycle tracking, current patch management documentation, or any disaster recovery testing.
3/10CRITICAL RISK
fix_07CRM & Pipeline Documentation
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
The company uses Canopy Practice Management with individual logins for client management and mentions an "active pipeline of $185K with $92K weighted value" in the CIM, indicating some pipeline documentation exists. However, the retrieved documents provide no evidence of consistent pipeline discipline, forecast validation, or stage tracking—only a single mention of pipeline value with no supporting detail on how opportunities are managed, tracked, or forecasted against actuals.
4/10NEEDS WORK
fix_08Key Employee Risks
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The firm has severe key employee risks with multiple single points of failure beyond the owner. The Managing Partner holds direct relationships with 48 of 67 clients (72% of revenue) with no documented succession plan, and the Senior CPA ([PERSON]) is the sole resource for bookkeeping administration with "none identified" as backup. While the Senior CPA has onboarded two associates, there is no formal handoff process documented, no cross-training program, onboarding is primarily "learning by doing alongside managing partner," and the firm has not operated without the Managing Partner for an extended period in the past 3 years, creating critical business continuity risk.
3/10CRITICAL RISK
fix_09Financial Trajectory & EBITDA Quality
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_CIM.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The company reports $820K in [DATE_TIME] revenue with a 31% EBITDA margin ($254K) and normalized EBITDA of $298K after add-backs, demonstrating reasonable profitability, but the documents do not provide audited or reviewed financial statements, multi-year comparative financials, or detailed documentation of the add-backs beyond the summary figures in the CIM. The absence of formal financial review documentation, combined with lack of historical growth trajectory data across multiple years, places the firm in the compiled financials category with reasonable margins but insufficient third-party validation for a higher exit-readiness score.
6/10ADEQUATE
fix_10Data Room Readiness
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated
The company lacks an organized data room and has not prepared key documents for due diligence. While a Confidential Information Memorandum (CIM) exists, the internal documents reveal significant gaps: the customer onboarding process is informal with notes stating "needs to be formalized" and no checklist, engagement letters are stored in Outlook drafts rather than in a centralized repository, and critical cybersecurity and operational documents appear scattered across multiple internal files rather than consolidated. The absence of version control, formal document organization structure, and any evidence of a dedicated data room accessible to advisors indicates the company would require substantial cleanup before buyer review.
3/10CRITICAL RISK
Owner Risk3.2/10  CRITICAL RISK (16% blend)
Deal Impact: Critical owner dependency — high probability of deal restructuring, escrow requirement, or significant price reduction.
IDCriterion & FindingScoreRatingBar
owr_01Succession Readiness
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
No formal succession plan exists for Garrison Professional Advisors. The owner ([PERSON]) is the primary contact for 72% of client relationships by revenue, manages all staff supervision and hiring decisions, and "the firm has not operated without [PERSON] for [DATE_TIME] in the past 3 years," with documentation explicitly stating "No documented succession plan for any key role" and "No cross-training program." While a senior CPA ([PERSON]) has onboarded two associates and holds relationships with 19 clients, this represents only informal readiness with no formal handoff protocols, documented backup arrangements, or prepared transition plan.
2/10CRITICAL RISK
owr_02Institutional Knowledge Capture
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company has minimal institutional knowledge documentation with critical processes remaining in individual heads. The client onboarding SOP is explicitly noted as "[PERSON]'s notes — needs to be formalized" with a personal checklist that is not formally documented, and onboarding relies primarily on "learning by doing alongside managing partner" with no documented checklist or milestone review. The owner is involved in all new hire orientations with no formal handoff process, and 72% of client relationships by revenue are controlled by the owner with no documented succession plan or cross-training program across any key role.
3/10CRITICAL RISK
owr_03Management Team Depth
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The Senior CPA ([PERSON]) has independently handled 19 clients (28% of revenue) and onboarded two associates, but the owner ([PERSON]) remains the primary contact for 72% of client relationships and is required for all new hire orientations, key decisions, and staff supervision with no documented succession plan or cross-training program. The firm has not operated without the owner for an extended period in the past 3 years, and the documents explicitly state that "if [PERSON] were absent for an extended period, [PERSON] could handle routine returns but client relationship continuity would be at risk," indicating the business cannot reliably operate independently for 60+ days.
4/10NEEDS WORK
owr_04Key Person Concentration Beyond Owner
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The firm has significant key person concentration beyond the owner, with one Senior CPA ([PERSON]) at $82,000 salary who appears deeply embedded in client relationships and tax return reviews, and a Bookkeeper/Admin ([PERSON]) at $58,000 who manages client onboarding, QuickBooks access, and document organization—roles documented as lacking formal procedures or backup coverage. The onboarding SOP explicitly notes that critical processes are managed by named individuals with "nothing formal" documented, training is "primarily learning by doing alongside managing partner," and the owner "must be involved in all new hire orientations," indicating no cross-trained backup for these key roles and a 62% new-hire retention rate suggesting instability in replacing departing staff.
4/10NEEDS WORK
Customer Quality5.0/10  NEEDS WORK (14% blend)
Deal Impact: Customer concentration or churn risk increases buyer discount risk — expect sensitivity analysis and possible escrow.
IDCriterion & FindingScoreRatingBar
cq_01Top Customer Concentration
GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_CIM.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated
The company demonstrates excellent customer diversification with no single customer concentration risk. The largest customer represents only 2.3% of revenue ($19,200), the top 5 customers combined represent approximately 10% of revenue, and the firm serves 67 active client relationships with an average client value of $12,200, explicitly noted in the CIM as "low concentration." This well-distributed customer base across SMB owners, real estate investors, and professional services verticals significantly mitigates revenue vulnerability typical in professional services firms.
9/10STRONG
cq_02Revenue Predictability & Recurring Mix
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
Garrison Professional Advisors demonstrates strong revenue predictability with 78% recurring revenue from tax preparation and bookkeeping retainers under engagement letters and retainer agreements, averaging $12,200 per client across 67 active client relationships. However, the documents do not provide documented renewal rates, retention tracking data, or explicit contract terms (annual vs. multi-year), which prevents a higher score; the firm's reliance on the managing partner for 72% of client relationships by revenue also introduces concentration risk that could impact renewal predictability in an ownership transition.
7/10ADEQUATE
cq_03Contract Transferability
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The documents provide no evidence of engagement letters containing assignment or change-of-control clauses; the onboarding SOP notes that engagement letters are sent via email from an Outlook template but require formalization, with no mention of transferability language. Client relationships are personality-dependent and concentrated with the owner ([PERSON] identified as primary contact for 72% of client relationships by revenue), and the documents explicitly state "no documented succession plan for any key role" and that the firm has not operated without the owner in the past 3 years, indicating contracts cannot be transferred without individual customer consent and relationship continuity is at material risk.
2/10CRITICAL RISK
cq_04Churn Rate & Retention Metrics
GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv — High confidence — multiple documents corroborated
The documents contain no evidence of tracked churn rate, retention metrics, or formal retention programs. The onboarding process documentation (excerpt [1]) focuses only on initial client setup with informal, undocumented procedures ("I keep a personal list but nothing formal"), and there is no mention of customer retention tracking, analysis, or recovery initiatives. The only retention-related data present concerns employee turnover (new-hire 62% retention over an unspecified period in excerpt [3]), not customer churn, indicating the company has not established systematic customer retention measurement or strategy.
2/10CRITICAL RISK
Financial Readiness2.8/10  CRITICAL RISK (11% blend)
Deal Impact: Financial readiness is a deal blocker — books must be restructured before any formal sale process can begin.
IDCriterion & FindingScoreRatingBar
fr_01Books Quality & CPA Relationship
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
The company maintains internally prepared financial records with no evidence of audited, reviewed, or compiled financial statements from a qualified CPA firm. The CIM and internal documents reference the firm's own tax and bookkeeping practices but contain no indication of professional financial statement preparation, audit relationships, or GAAP-compliant reporting; additionally, significant cybersecurity gaps including unencrypted client tax files, shared QuickBooks credentials with no audit trail, and lack of formal financial controls create material risks that would require substantial remediation before diligence readiness.
3/10CRITICAL RISK
fr_02Add-Back Documentation
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
The CIM mentions "Normalized EBITDA of $298K after add-backs" but provides no supporting schedule, documentation, or methodology for these adjustments. The HC Profile document identifies the managing partner draw of $195,000 with a normalized add-back value of $148,000, but this single adjustment lacks detailed calculation or verification support, and no formal add-back schedule separating personal versus business expenses is evident in any retrieved documents. A buyer's accountant would have insufficient documentation to independently verify the $44,000 difference between reported and normalized EBITDA.
3/10CRITICAL RISK
fr_03Revenue Recognition & Consistency
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no formal revenue recognition policy, no documentation of GAAP compliance procedures, and no evidence of deferred revenue tracking or audit oversight. The onboarding SOP references informal processes ("needs to be formalized," "personal list but nothing formal") and lacks any structured revenue documentation or consistency controls. No audit trail, revenue recognition standards, or period-to-period policy documentation are evident in any of the provided materials, presenting significant restatement risk during due diligence.
2/10CRITICAL RISK
fr_04Three-Year Financial Trend
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
The retrieved documents contain a CIM showing $820K in revenue with 31% EBITDA margin (~$254K EBITDA) for one fiscal year, but provide no multi-year financial statements, historical revenue trends, or EBITDA comparability data needed to assess a three-year trend. Without access to prior-year P&Ls or tax returns showing year-over-year growth rates, CAGR calculation, or margin trajectory, the financial trend assessment cannot be completed; the single-year snapshot alone is insufficient to demonstrate consistent growth or margin stability over three years.
3/10CRITICAL RISK
Operational Scalability3.5/10  NEEDS WORK (8% blend)
Deal Impact: Technology or process gaps require post-close investment — buyers will model remediation cost into their offer.
IDCriterion & FindingScoreRatingBar
ops_01Process Documentation & Repeatability
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company has minimal formal process documentation with heavy reliance on specific individuals. The customer onboarding SOP document explicitly states it is "[PERSON]'s notes — needs to be formalized" and notes that "I keep a personal list but nothing formal" for onboarding checklists. The onboarding program is "partially documented" with training "primarily learning by doing alongside managing partner; no formal program" and "no documented onboarding checklist or milestone review," making new staff dependent on direct owner guidance for execution of core workflows.
3/10CRITICAL RISK
ops_02Technology & Systems Scalability
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The company's technology stack relies on a mix of cloud-based systems (QuickBooks Online, Canopy) and locally-installed legacy software (Drake Tax on unencrypted drives), with critical infrastructure gaps that would require material modernization to support 3x growth. The cybersecurity assessment identifies HIGH-risk issues including shared QuickBooks credentials across 67 client accounts with no audit trail, unencrypted local storage of sensitive tax files containing SSNs and EINs, and missing multi-factor authentication for 60% of staff—all indicating systems are fragile and underdocumented. Additionally, onboarding processes are informal and owner-dependent ("learning by doing"), with no formal documentation or scalable procedures, meaning growth would require significant architectural and operational rework beyond simple infrastructure investment.
4/10NEEDS WORK
ops_03Vendor & Supplier Concentration
GPA_Cybersecurity_Assessment.txt · GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated
The company exhibits significant vendor concentration risk, with critical dependencies on a small number of platforms that lack formal alternatives or documented SLAs. The firm relies heavily on Drake Tax (locally installed with unencrypted storage), Canopy (practice management with individual logins but no MFA), and QuickBooks Online (all staff sharing one admin login with no audit trail), and the cybersecurity assessment identifies no documented vendor alternatives or formal service level agreements for any of these critical systems. Additionally, the onboarding process and operational procedures are undocumented and heavily dependent on the owner's personal involvement, creating de facto single-source dependencies that extend beyond traditional vendor relationships into key service delivery.
4/10NEEDS WORK
ops_04Financial Controls & Reporting Cadence
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The company lacks formal financial close processes and documented controls. The retrieved documents contain no evidence of monthly financial close timelines, budget vs. actual reviews, or a CFO/Controller overseeing financial reporting; instead, they reveal ad-hoc processes such as a bookkeeper managing accounts with informal controls, a managing partner setting compensation "at his discretion with no documented formula," and onboarding procedures that are "partially documented" with "no formal program." The cybersecurity assessment notes "no formal data retention or destruction policy" and indicates financial data management relies on personal judgment rather than documented procedures, suggesting the firm's own financial controls mirror the informal practices observed in client work.
3/10CRITICAL RISK
Technology & Systems Maturity3.1/10  CRITICAL RISK (8% blend)
Deal Impact: Technology infrastructure is a deal risk — undocumented systems, personal dependencies, or technical debt will trigger buyer discount.
IDCriterion & FindingScoreRatingBar
tm_01Core Systems Documentation & Ownership
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
Core business systems lack formal documentation and exhibit significant personal account dependencies that create exit risk. The onboarding SOP is described as "[PERSON]'s notes — needs to be formalized" with the owner maintaining personal informal checklists; critical systems like Drake Tax files are backed up to the owner's personal iCloud account, and all staff access 67 client QuickBooks accounts through a single shared login with no audit trail. Additionally, the cybersecurity assessment identifies that the owner's laptop is used for both personal and business activities, and the owner must be directly involved in all new hire orientations and hiring decisions, indicating substantial key-person dependencies rather than transferable, entity-owned systems and processes.
3/10CRITICAL RISK
tm_02Cybersecurity & Data Protection Posture
GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt · GPA_CRM_Pipeline.csv · GPA_IT_Asset_Inventory.csv — High confidence — multiple documents corroborated
The firm has critical cybersecurity gaps that fall well below exit-readiness standards. While MFA is partially deployed (only 2 of 5 staff enabled), there is no EDR protection beyond Windows Defender, no tested incident response plan, no cyber insurance mentioned, and no vendor security review documentation. The assessment identifies multiple HIGH-risk gaps including unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail, local-only backups with no offsite copy, and a consumer-grade router with no network segmentation—creating unacceptable vulnerability for a firm holding sensitive financial data for 67 clients.
3/10CRITICAL RISK
tm_03Data Integrity & Business Intelligence
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
Data integrity and accessibility are severely compromised by individual dependencies and fragmented systems. Critical operational data lacks formal documentation—client onboarding relies on [PERSON]'s personal checklist rather than formalized processes, new hire retention tracking is ad-hoc, compensation decisions are made "at [PERSON]'s discretion [DATE_TIME] with no documented formula," and client tax files are stored on unencrypted local drives with "no audit trail of individual staff access to client data" due to shared QuickBooks credentials. The cybersecurity assessment identifies that "all staff access 67 client QuickBooks accounts via one login" and "Drake Tax data [is] backed up to owner's personal iCloud," creating both data integrity risks and complete operational dependency on the managing partner.
3/10CRITICAL RISK
tm_04Technology Vendor & Subscription Management
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt — High confidence — multiple documents corroborated
Technology vendor relationships are largely undocumented and contain critical personal subscription dependencies that create significant transfer risk. The cybersecurity assessment reveals that Drake Tax data is "backed up to owner's personal iCloud" and client tax files are stored on unencrypted local drives with no formal data retention policy, while the onboarding documentation shows key processes (engagement letters, client setup in Canopy, QuickBooks access) are managed ad-hoc by the owner with "nothing formal" documented. Additionally, the firm lacks formal documentation of vendor contracts, renewal dates, and transferability terms for critical tools including Canopy, Drake Tax, QuickBooks Online, and Tax Dome, creating substantial risk for an acquiring entity.
3/10CRITICAL RISK
tm_05Technical Debt & Modernization Risk
GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_Financials.csv · GPA_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated
The company operates on a mixed and aging technology stack with material technical debt requiring post-close investment. Critical gaps include unencrypted local storage of client tax files containing SSNs and EINs, shared QuickBooks credentials across all staff with no audit trail, absence of EDR protection despite high ransomware risk to accounting firms, and no offsite cloud backup for tax files. While the cybersecurity assessment acknowledges these gaps are "fast and cheap to remediate" with estimated costs under $2,000, the presence of unsupported security controls (consumer-grade router, Windows Defender only, no MFA enforcement, no disk encryption) and the reliance on legacy Drake Tax local installation represent significant inherited risk for a buyer.
4/10NEEDS WORK
▲ Layer8's primary practice area. Technology & Systems Maturity is where Layer8 delivers directly — not just identifies gaps. Where this domain shows deficiencies, remediation is available immediately through Layer8 engagements.
Legal & Regulatory Compliance4.0/10  NEEDS WORK (15% blend)
Deal Impact: Compliance gaps will surface in diligence — expect buyer requests, timeline extension, and potential price adjustment.
IDCriterion & FindingScoreRatingBar
lc_01Business Licenses & Permits
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of business licenses, permits, or their transferability status. The company is a CPA firm handling sensitive client financial data for 67 clients, yet there is no documentation addressing state CPA licenses, firm licenses, or change-of-control transferability with counsel. This represents a material compliance gap for an accounting services firm operating without documented proof of required professional licensure.
2/10CRITICAL RISK
lc_02Contract Change-of-Control Provisions
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence that key vendor, customer, or lease agreements have been reviewed by counsel for assignment clauses or change-of-control provisions. The customer onboarding documentation shows engagement letters are sent via email template but makes no mention of change-of-control language, and there is no record of legal review of these or other material contracts. The only contract-related activity documented is informal client onboarding procedures that lack any change-of-control analysis, presenting material deal risk for the transaction.
2/10CRITICAL RISK
lc_03Employment Law Compliance
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company maintains all staff on W-2 employment and compensation is benchmarked against AICPA surveys with salaries at or near market rates for senior roles; however, compensation structure presents material risk, as the managing partner's S-corp owner compensation ($195,000 distribution) "requires restructuring" and raises are set "at [the owner's] discretion [with] no documented formula." Additionally, while the documents confirm standard employment practices and no open legal matters are mentioned, there is no explicit evidence of current I-9 documentation, formal non-compete agreements, or documented employment policies, creating documentation gaps typical of a small firm lacking formalized HR infrastructure.
6/10ADEQUATE
lc_04Intellectual Property Ownership
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt — High confidence — multiple documents corroborated
IP ownership is ambiguous and largely undocumented. While the company operates as a licensed CPA firm (Garrison Professional Advisors LLC) with established client relationships, the documents reveal critical gaps: client data and tax files are stored on unencrypted local drives with shared credentials across staff, there is no formal IP assignment documentation, and key processes (like client onboarding) exist only in informal notes rather than as formally owned company assets. The cybersecurity assessment notes "no formal data retention or destruction policy" and identifies that client financial data containing SSNs and EINs is accessible to all staff without individual audit trails, creating ambiguity around data ownership and control rather than clean entity ownership.
4/10NEEDS WORK
lc_05Litigation & Contingent Liability
GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_CIM.txt · GPA_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated
The company has no disclosed active litigation or contingent liabilities; however, the cybersecurity assessment identifies multiple material security gaps involving unencrypted client tax files containing SSNs and EINs, shared QuickBooks credentials with no audit trail, and lack of MFA for 3 of 5 staff members—creating meaningful exposure to potential regulatory claims, client data breach liability, and professional liability before sale. These gaps are characterized as "MEDIUM" overall risk and "above acceptable threshold for sale process," though estimated remediation costs are under $2,000 and described as "fast and cheap to remediate."
6/10ADEQUATE
Human Capital & Key Employee Risk3.0/10  CRITICAL RISK (14% blend)
Deal Impact: Key employee dependency is a deal risk -- high probability of post-close talent loss will trigger buyer discount or escrow requirement.
IDCriterion & FindingScoreRatingBar
hc_01Employee Documentation & Compensation
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
While compensation is benchmarked to AICPA market surveys with documented salaries for all staff ($42,000–$82,000 range), employee roles and responsibilities lack formal documentation. The onboarding process is "partially documented" with no formal checklist, training is "primarily learning by doing," and critically, there is "no documented succession plan for any key role" with the managing partner holding 72% of client relationships by revenue and no formal handoff process documented for onboarding. Key operational procedures like client onboarding exist only in personal notes marked "needs to be formalized," indicating heavy reliance on informal, owner-dependent knowledge rather than systematized role documentation.
4/10NEEDS WORK
hc_02Retention Agreements & Non-Competes
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Financials.csv · GPA_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
There is no evidence in the retrieved documents of non-compete or retention agreements in place for any key employees. The HC Profile explicitly states "No retention bonuses in place" and notes that associate compensation is "slightly below market, which partially explains typical associate turnover" with only 62% new-hire retention over the period reviewed. The firm has critical key-person risk with the managing partner holding 72% of client relationships by revenue and no documented succession plan or cross-training for any role, creating significant flight risk for key staff post-acquisition.
2/10CRITICAL RISK
hc_03Bench Depth & Succession
GPA_HC_Profile.txt · GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_Financials.csv — High confidence — multiple documents corroborated
The firm has severe bench depth deficiencies with multiple critical single points of failure centered on the managing partner. All hiring decisions require owner approval with no delegated authority, new client onboarding is entirely managed by the owner (who "meets with them," sets them up in systems, and "reviews everything before any return is filed"), and the onboarding process relies on "learning by doing alongside managing partner" with no formal program. Additionally, the owner's involvement is explicitly required in all new hire orientations, and key operational processes like client onboarding lack formalization, existing only as the owner's personal notes—indicating no documented procedures other staff can execute independently.
3/10CRITICAL RISK
▲ Automation Maturity IndexScored separately — excluded from overall score and buyer discount risk band
1.7/10MANUAL (raw: 1/9)

Accounting firm revenue infrastructure is driven by client retention, referral network quality, and seasonal workflow management rather than high-velocity lead automation.

Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.

#Criterion & FindingScoreRatingBar
R01AI Voice / After-Hours Call Handling
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv
There is no evidence of AI voice agents or after-hours call handling automation in any of the retrieved documents; the firm's operations focus on manual client management, email-based communication, and in-person meetings with no mention of inbound call handling infrastructure. After-hours calls would default to voicemail or go unanswered, indicating zero automation maturity in this capability.
0/2MANUAL
R02CRM Presence & Workflow Automation
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_GL_Export.csv
The firm uses Canopy as a practice management system with individual logins for basic client management and document exchange, but workflow automation is minimal and dependent on the managing partner's manual oversight—new client onboarding relies on [PERSON]'s personal checklist rather than formalized automated workflows, and critical processes like engagement letter execution still use manual email and unsigned templates rather than DocuSign integration.
1/2PARTIAL
R0324/7 Lead Capture
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt
There is no evidence of after-hours or 24/7 lead capture capability; the retrieved documents focus on client onboarding, cybersecurity, and HR processes with no mention of a website contact form, chatbot, or automated lead routing system. Lead generation and capture mechanisms are entirely absent from the company's documented operations.
0/2MANUAL
R04SMS Appointment Reminders & Confirmations
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt
There is no evidence of any automated SMS appointment reminder or confirmation system in the retrieved documents; the company uses basic email-based engagement letters and manual client communication processes managed ad-hoc by staff members. The onboarding process described is entirely manual and owner-dependent, with no reference to SMS workflows, automated confirmations, or no-show follow-up sequences.
0/2MANUAL
R05Automated Review Solicitation
GPA_Customer_Onboarding_SOP.txt · GPA_HC_Profile.txt · GPA_Cybersecurity_Assessment.txt · GPA_GL_Export.csv
There is no evidence of any automated or manual post-service review solicitation process in the retrieved documents; reviews appear to be organic only with no systematic request mechanism in place. The onboarding SOP and operational practices document manual workflows but contain no mention of review requests, and no automation platform or trigger-based system is referenced.
0/2MANUAL
R06Smart Follow-Up Sequences
GPA_Customer_Onboarding_SOP.txt · GPA_Cybersecurity_Assessment.txt · GPA_HC_Profile.txt · GPA_CIM.txt
There is no evidence of automated follow-up sequences for leads or dormant clients in any of the retrieved documents. The onboarding process relies entirely on manual coordination by the managing partner and staff, with no mention of drip campaigns, automated email sequences, or systematic re-engagement workflows for unconverted prospects or inactive clients.
0/2MANUAL

Interpretation: Manual — buyer will underwrite operational risk, expect discount

CPA firm Automation Maturity scores are structurally lower by industry norm. Absence of AI voice, 24/7 capture, and aggressive review solicitation is standard for referral-based practices.

📈 Buyer Opportunity: A buyer who systematizes these automation gaps post-close would deploy a proven playbook: AI voice handling, CRM workflows, and follow-up sequences that collectively recover 15–25% of leads currently lost to slow response. This is a predictable, acquirable value-creation lever.
Layer8 delivers exactly this. Our 90-day Automation Sprint closes AI voice, CRM workflow, lead capture, and follow-up gaps — the same gaps that increase buyer discount risk. The work is defined, the timeline is fixed, and the ROI is measurable before you go to market.
► Operational Automation OpportunitiesVertical-specific — excluded from overall score
1.0/10MANUAL (raw: 1/10)

Vertical-specific operational automation gaps identified in Accounting Practice Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.

Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.

Automation OpportunityScoreStatusBarLayer8 Opportunity
Client Document Collection1/2PARTIAL
Document collection automation compresses the tax season intake window by 2-3 weeks and eliminates the most common source of extension filing and client frustration.
Engagement Letter & E-Signature0/2MANUAL
Engagement letter automation ensures 100% signed engagement coverage — a critical diligence item for buyers assessing client relationship transferability and E&O exposure.
Deadline & Filing Calendar0/2MANUAL
Deadline automation eliminates the most common source of penalty exposure and provides the workload visibility needed to staff engagements efficiently during peak season.
Recurring Invoice & Billing Automation0/2MANUAL
Billing automation converts the accounts receivable function from a partner time sink to a self-managing revenue stream — directly improving realization rates.
Client Communication & Seasonal Outreach0/2MANUAL
Automated seasonal outreach surfaces advisory opportunities the client didn't know to ask about and drives year-round engagement beyond the annual return.
These operational automation gaps represent post-close value creation opportunities for a buyer — and immediate efficiency gains for the current owner. Layer8 Tech Group delivers these implementations directly.

Top 3 Strengths

Top 3 Risks

Recommended Priority Fixes

Actions the company should take in the next 90 days to maximise exit readiness:

Fix 1
Weeks 1-4: Document & Formalize Customer Contracts Repository — Consolidate all engagement letters and retainer agreements into a centralized DocuSign or similar platform with version control; audit for missing change-of-control and assignment clauses; establish a tracked contract renewal schedule (spreadsheet minimum) with renewal dates and rates for all 67 clients to support revenue quality claims during due diligence.
Fix 2
Weeks 1-3: Implement Critical Cybersecurity Remediations — Enable MFA for all 5 staff members with financial data access; deploy endpoint detection and response (EDR) solution or upgrade from Windows Defender; encrypt local drives storing client tax files; establish individual QuickBooks logins with audit trail enabled; total cost under $2,000 per assessment, eliminating MEDIUM risk rating before buyer review.
Fix 3
Weeks 2-6: Formalize Key Process Documentation — Convert owner's onboarding notes into a standardized SOP with documented checklist and milestones; create written hiring and compensation decision frameworks that do not require owner sign-off; document the Senior CPA's client management process for the 19 independently-managed accounts to demonstrate knowledge transfer capability.
Fix 4
Weeks 3-8: Introduce & Transition Top Client Relationships — Formally introduce the Senior CPA as backup/co-manager to the Managing Partner's 10-15 largest accounts (representing ~25% of owner-dependent revenue); schedule joint client meetings with documented transition milestones; create a documented succession plan for each key role (owner, Senior CPA, bookkeeping admin) identifying backup resources and handoff protocols.
Fix 5
Weeks 1-6: Establish Data Room & Due Diligence Package — Organize a centralized data room with all customer contracts, financial statements, tax returns, employee records, IT asset inventory, and insurance policies; compile audited or reviewed financial statements for the past 2 years if available, or prepare detailed reconciliation of add-backs to normalized EBITDA ($298K); create an organization chart showing all roles, tenure, and client relationships to support buyer confidence in post-close continuity.

Compliance Notes

No PII was detected in the ingested documents.