David S. Marshall, MBA, CISA, CFE
Internal Audit, Cybersecurity, Internal Control and Fraud Expert
David S. Marshall is an experienced auditor, consultant, security professional, fraud examiner and CPE instructor with more than 30 years of professional experience.
He is the founder and Chief Executive Officer of Infotech Global Audit and Security, Inc., a consulting firm specializing in internal auditing, cybersecurity, physical security, regulatory compliance, enterprise risk management, internal controls, and fraud prevention and detection.
David is also a co-founder and co-CEO of Corporate Compliance Seminars. Since CCS was established in 2004, he has helped develop and deliver practical Continuing Professional Education programs for internal auditors, external auditors, accountants, compliance professionals, information-technology professionals, fraud examiners, corporate executives, boards of directors and audit committees.
Throughout his career, David has managed and performed hundreds of audits, security assessments, fraud investigations and Sarbanes-Oxley compliance projects. He has also trained thousands of professionals through webinars, in-person seminars, conferences and customized organizational programs.
Professional Credentials
David holds an advanced business degree and respected professional certifications in information-systems auditing and fraud examination:
-
Master of Business Administration — MBA
-
Certified Information Systems Auditor — CISA
-
Certified Fraud Examiner — CFE
This combination of business, audit, technology and fraud expertise allows him to address risks that cross organizational boundaries and cannot be evaluated effectively by examining one department in isolation.
More Than 30 Years of Professional Experience
David’s career encompasses internal auditing, information-technology auditing, management consulting, systems implementation, cybersecurity, regulatory compliance, fraud investigation, risk management and professional education.
His professional experience includes work as a:
-
Internal auditor
-
Information-technology auditor
-
Management consultant
-
Fraud examiner
-
Security assessor
-
Financial-systems analyst
-
Enterprise-software implementer
-
Internal-control specialist
-
Risk-management consultant
-
Audit peer reviewer
-
Corporate executive
-
Business owner
-
CPE course developer
-
Professional instructor
This broad experience helps David connect business objectives with the financial, operational, technological, security and compliance risks that can prevent organizations from achieving them.
Founder and CEO of Infotech Global Audit and Security
David founded Infotech Global Audit and Security, Inc. to help organizations evaluate and improve their internal audit, cybersecurity, compliance, risk-management and fraud-prevention programs.
The firm’s areas of practice include:
-
Internal auditing
-
Information-technology auditing
-
Cybersecurity assessments
-
Physical security
-
Internal-control evaluations
-
Regulatory compliance
-
Enterprise risk management
-
Fraud-risk assessments
-
Fraud investigations
-
Sarbanes-Oxley compliance
-
Policy and procedure development
-
Audit quality assessments
-
Security awareness
-
Professional training
Infotech Global’s approach begins with organizational objectives, identifies the risks that threaten those objectives and evaluates whether the organization’s controls reduce those risks to an acceptable level.
Co-Founder of Corporate Compliance Seminars
David co-founded Corporate Compliance Seminars with John C. Blackshire, Jr. to provide practical, instructor-led CPE for auditing, accounting, compliance and technology professionals in 2004 during the implementation of SOX.
CCS is registered with the National Association of State Boards of Accountancy as a sponsor of Continuing Professional Education on the National Registry of CPE Sponsors.
David has played a central role in developing CCS programs covering:
-
Internal auditing
-
Information-technology auditing
-
Cybersecurity
-
Internal controls
-
Sarbanes-Oxley compliance
-
COSO
-
Fraud prevention and detection
-
Audit committee governance
-
Enterprise risk management
-
SOC examinations
-
Audit report writing
-
Audit quality
-
Continuous auditing
-
Project management
-
ISO management systems
-
NIST cybersecurity guidance
His programs are designed to give participants knowledge and methods they can apply immediately rather than simply repeating the language of professional standards.
Big Four Consulting and Auditing Experience
Before establishing Infotech Global and Corporate Compliance Seminars, David served as a Senior Manager in the management-consulting and auditing practices of a Big Four public accounting firm, PriceWaterHouse.
This experience exposed him to complex organizations, large financial systems, demanding client environments and multidisciplinary audit and consulting assignments.
His Big Four background contributes to his understanding of:
-
Audit planning
-
Engagement management
-
Financial systems
-
Business-process analysis
-
Technology implementation
-
Internal controls
-
Client communication
-
Project management
-
Quality assurance
-
Risk assessment
-
Consulting methodologies
-
Professional documentation
David uses that experience to help organizations develop audit and compliance programs that are both technically sound and operationally practical.
Aerospace, Defense and Government Experience
David also led an internal audit, information-technology and compliance practice for a worldwide U.S. aerospace and defense corporation.
In that role, he worked within a highly technical and regulated operating environment where security, documentation, contract requirements, systems reliability and internal controls were essential.
His aerospace and defense experience included work involving:
-
Internal auditing
-
Information systems
-
Regulatory compliance
-
Government-contract requirements
-
Security
-
Classified projects
-
Business processes
-
Financial systems
-
Technology risk
-
Operational controls
David previously held a U.S. Department of Defense security clearance and worked on classified government projects. This experience strengthened his understanding of security, confidentiality, controlled information and the need for disciplined processes.
Internal Audit Expertise
David has managed and performed internal audits across financial, operational, compliance and technology environments.
His internal audit expertise includes:
-
Risk-based audit planning
-
Audit universe development
-
Engagement scoping
-
Audit objectives
-
Risk and control matrices
-
Internal-control testing
-
Audit fieldwork
-
Workpaper documentation
-
Audit evidence
-
Root-cause analysis
-
Audit findings
-
Corrective-action recommendations
-
Audit report writing
-
Management responses
-
Follow-up reviews
-
Audit committee communications
-
Quality assurance and improvement programs
-
Internal audit peer reviews
David’s instruction emphasizes that internal audit must do more than identify exceptions. Auditors must understand organizational objectives, evaluate the risks threatening those objectives and determine whether management’s controls are properly designed and operating effectively.
Internal Audit Quality Assessments
David has performed external reviews and peer assessments of internal audit organizations.
These reviews examine whether an internal audit function conforms with applicable professional standards and whether it uses practices that support quality, independence and organizational value.
Assessment areas may include:
-
Internal audit charter
-
Organizational independence
-
Audit committee oversight
-
Risk assessment
-
Audit planning
-
Staff competence
-
Engagement supervision
-
Workpaper quality
-
Audit evidence
-
Reporting practices
-
Corrective-action monitoring
-
Continuing professional education
-
Quality assurance
-
Performance measurements
-
Stakeholder expectations
David performed an external peer review of the Riverside County Auditor-Controller’s internal audit operation. The review concluded that the function generally conformed with the Institute of Internal Auditors’ professional standards—the highest rating available under the assessment framework.
The Internal Auditing Training Series
David developed the CCS Internal Auditing series to build auditor competence from the entry level through advanced audit leadership.
The series addresses:
-
Internal audit fundamentals
-
Audit standards
-
Auditor responsibilities
-
Risk assessment
-
Audit planning
-
Engagement development
-
Internal controls
-
Audit testing
-
Interviewing
-
Evidence collection
-
Workpaper documentation
-
Findings development
-
Root-cause analysis
-
Audit reporting
-
Corrective-action follow-up
-
Audit management
-
Audit quality
-
Audit committee relationships
His courses help new auditors establish sound methods while giving experienced professionals opportunities to challenge and improve established practices.
The Art of Internal Audit Report Writing
An audit’s value can be lost if its results are not communicated clearly.
David’s audit-report-writing instruction helps professionals convert extensive fieldwork into concise, persuasive reports that decision-makers can understand and act upon.
Topics include:
-
Writing clear audit objectives
-
Using AI in the development of reports
-
Explaining conditions
-
Establishing criteria
-
Identifying root causes
-
Describing consequences
-
Evaluating risk
-
Developing corrective actions
-
Avoiding vague language
-
Removing unnecessary detail
-
Presenting complex findings
-
Addressing management disagreement
-
Writing executive summaries
-
Communicating with audit committees
-
Monitoring corrective actions
The objective is not to produce a longer report. It is to produce a report that makes the risk, cause and required action unmistakable.
Information-Technology Auditing
As a Certified Information Systems Auditor, David brings extensive technology-audit experience to his consulting and training.
His IT audit expertise includes:
-
IT general controls
-
Logical access
-
User provisioning and termination
-
Privileged access
-
Change management
-
System development
-
Computer operations
-
Backup and recovery
-
Business continuity
-
Disaster recovery
-
Network security
-
Cloud computing
-
Third-party technology
-
Data integrity
-
System interfaces
-
Cybersecurity
-
IT governance
-
Technology risk assessment
David helps auditors understand that technology is not a separate technical universe. Nearly every significant financial, operational and compliance process depends on information systems.
IT General Controls
Weak IT general controls can undermine otherwise well-designed financial and operational controls.
David’s ITGC training addresses controls over:
-
User access
-
Administrator privileges
-
Passwords and authentication
-
Segregation of duties
-
System changes
-
Program development
-
Data conversion
-
System operations
-
Batch processing
-
Interface monitoring
-
Incident management
-
Backup procedures
-
Recovery testing
-
Vendor management
-
Cloud services
-
System configuration
His programs help financial auditors understand technology risks and help IT auditors connect technical findings with business and financial consequences.
Cybersecurity and Information Security
David has extensive experience evaluating cybersecurity programs, information-security controls and technology risks.
His cybersecurity training covers:
-
Cybersecurity governance
-
Information-security policies
-
Asset identification
-
Risk assessment
-
Identity and access management
-
Data protection
-
Network security
-
Vulnerability management
-
Security monitoring
-
Incident response
-
Business continuity
-
Disaster recovery
-
Ransomware
-
Social engineering
-
Third-party risk
-
Cloud security
-
Security awareness
-
Board reporting
-
Cybersecurity auditing
He helps participants distinguish between purchasing security products and operating an effective cybersecurity program.
Technology alone cannot compensate for weak governance, unclear ownership, inadequate monitoring or poor employee behavior.
NIST Cybersecurity Framework
David provides instruction on the NIST Cybersecurity Framework and its application to cybersecurity governance and risk management.
His training examines the CSF functions:
-
Govern
-
Identify
-
Protect
-
Detect
-
Respond
-
Recover
Participants learn how the framework can be used to evaluate current cybersecurity capabilities, identify gaps, prioritize improvement activities and communicate cyber risk to executive management and the board.
Sarbanes-Oxley Compliance
Since the Sarbanes-Oxley Act was enacted in 2002, David has helped dozens of organizations design, implement, assess and improve their SOX compliance programs.
His SOX experience includes:
-
Compliance project management
-
Process documentation
-
Risk assessment
-
Financial-reporting risks
-
Key-control identification
-
Entity-level controls
-
IT general controls
-
Security policies
-
Control testing
-
Deficiency evaluation
-
Remediation
-
Management reporting
-
External-auditor coordination
-
Sustainable compliance
-
Program improvement
David’s instruction stresses that SOX compliance should not become a documentation exercise disconnected from the business. A sustainable program must focus on material financial-reporting risks and the controls that actually address them.
COSO Internal Control Framework
David is an authority on designing, implementing and assessing internal controls using the COSO Internal Control—Integrated Framework.
His COSO instruction addresses:
-
Control environment
-
Risk assessment
-
Control activities
-
Information and communication
-
Monitoring activities
-
COSO principles
-
Points of focus
-
Entity-level controls
-
Process-level controls
-
Control design
-
Operating effectiveness
-
Control deficiencies
-
Management responsibility
-
Board oversight
-
Continuous improvement
Participants learn how to connect objectives, risks and controls rather than treating the COSO framework as a collection of isolated requirements.
SSAE 18 and SOC Examinations
David developed CCS training addressing SSAE 18 and System and Organization Controls examinations.
His SOC-related instruction includes:
-
SOC 1 examinations
-
SOC 2 examinations
-
Service organizations
-
User entities
-
Complementary user-entity controls
-
Subservice organizations
-
System descriptions
-
Control objectives
-
Trust Services Criteria
-
Type 1 reports
-
Type 2 reports
-
Auditor testing
-
Report review
-
Vendor-risk management
His training helps organizations understand what a SOC report does—and does not—provide. Receiving a SOC report is not the same as evaluating whether the report covers the services, systems, risks and time period relevant to the user organization.
Fraud Prevention, Detection and Investigation
As a Certified Fraud Examiner, David has performed fraud-risk assessments and investigations and has trained professionals in fraud prevention and detection.
His fraud expertise includes:
-
Fraud-risk assessment
-
Occupational fraud
-
Financial-statement fraud
-
Asset misappropriation
-
Corruption
-
Procurement fraud
-
Vendor fraud
-
Payroll fraud
-
Expense fraud
-
Cyber-enabled fraud
-
Social engineering
-
Fraud red flags
-
Interviewing
-
Evidence preservation
-
Investigation planning
-
Fraud analytics
-
Corrective actions
David teaches auditors to incorporate fraud considerations throughout the engagement rather than treating fraud as a separate subject addressed only after a complaint is received.
“Frauditing”
David developed the concept and related training program known as “Frauditing”—the application of an investigative and fraud-focused mindset to auditing.
Frauditing encourages auditors to consider:
-
How a control could be bypassed
-
Who could override the process
-
What evidence could be manipulated
-
How collusion could defeat segregation of duties
-
Whether management explanations are independently supported
-
What unusual relationships exist
-
Whether data reveals suspicious patterns
-
How fraud might be concealed
-
Which incentives and pressures affect employees
-
Whether the organization responds appropriately to warning signs
This approach strengthens professional skepticism and helps auditors look beyond routine control testing.
Enterprise Risk Management
David’s enterprise risk-management instruction helps organizations connect strategic objectives with the risks that may prevent their achievement.
Topics include:
-
Governance
-
Strategic objectives
-
Risk identification
-
Risk assessment
-
Risk appetite
-
Risk tolerance
-
Risk responses
-
Control activities
-
Risk ownership
-
Key risk indicators
-
Emerging risks
-
Risk reporting
-
Board oversight
-
Internal audit’s role
-
Continuous monitoring
David emphasizes that management owns organizational risks. Internal audit evaluates and reports on risk-management effectiveness but should not assume management’s responsibilities.
Audit Committees and Governance
David has developed and delivered training for boards of directors and audit committees.
His governance instruction addresses:
-
Audit committee responsibilities
-
Financial-reporting oversight
-
Internal control
-
Fraud risk
-
Cybersecurity
-
Regulatory compliance
-
Enterprise risk management
-
Internal audit independence
-
External-auditor relationships
-
Whistleblower programs
-
Investigations
-
Executive sessions
-
Corrective-action monitoring
-
Committee reporting
-
Professional skepticism
His programs help committee members distinguish between receiving reports and exercising meaningful oversight.
ISO Management Systems
David’s audit, security, risk and internal-control experience provides a strong foundation for teaching ISO management-system standards.
His ISO-related programs include:
-
ISO 9001 quality management
-
ISO 27001 information-security management
-
ISO 31000 risk management
-
Management-system auditing
-
Risk-based thinking
-
Control implementation
-
Performance measurement
-
Corrective action
-
Continual improvement
David teaches ISO standards as operational management systems rather than certification paperwork. The objective is to build processes that help the organization manage risk, achieve objectives and improve performance.
Professional Leadership
David has served in leadership and advisory roles within the auditing, fraud and technology professions.
His experience has included:
-
Six years as President and Chairman of the Greater Chicago Chapter of the Association of Certified Fraud Examiners
-
Service on the ACFE Worldwide Advisory Council
-
Board service with the Chicago Chapter of ISACA
-
Service as Technology Committee Chair for an Institute of Internal Auditors International Conference
-
Service as Vice Chairman of the International Institute for Outsource Management
-
Contribution to the Outsource Management Body of Knowledge
-
Service on a university College of Business Administration advisory board
These roles reflect his long-term involvement in developing and supporting the audit, fraud-examination and information-systems professions.
Practical CPE Training
David’s training focuses on the problems professionals encounter in their actual work.
Participants learn how to:
-
Connect objectives, risks and controls
-
Plan risk-based audits
-
Evaluate control design
-
Test operating effectiveness
-
Audit information technology
-
Assess cybersecurity programs
-
recognize fraud risks
-
Write persuasive findings
-
Communicate with management
-
Evaluate corrective actions
-
Improve audit quality
-
Apply professional skepticism
-
Interpret professional frameworks
-
Convert compliance requirements into operational practices
His instruction encourages discussion, questions, case analysis and the exchange of real-world experiences.
Areas of Instruction
David’s CCS training subjects include:
-
Internal auditing
-
IT auditing
-
IT general controls
-
Cybersecurity
-
Information security
-
NIST Cybersecurity Framework
-
Internal control
-
COSO
-
Sarbanes-Oxley compliance
-
SSAE 18 and SOC examinations
-
Fraud prevention
-
Fraud detection
-
Fraud investigation
-
Fraud analytics
-
Audit report writing
-
Audit quality
-
Audit committee governance
-
Enterprise risk management
-
Continuous auditing
-
Project management
-
ISO 9001
-
ISO 27001
-
ISO 31000
-
Regulatory compliance
-
Risk-based auditing
Who Should Attend David Marshall’s CPE Events?
David’s programs are valuable for:
-
Chief audit executives
-
Internal audit directors
-
Internal auditors
-
IT auditors
-
External auditors
-
Certified Information Systems Auditors
-
Certified Fraud Examiners
-
CPAs and accounting professionals
-
Cybersecurity professionals
-
Information-security officers
-
Compliance professionals
-
Risk managers
-
Controllers
-
Chief financial officers
-
Audit committee members
-
Board members
-
Government auditors
-
SOX compliance professionals
-
Technology managers
-
Professionals responsible for internal controls
Why Attend a David Marshall CPE Event?
Participants benefit from an instructor with extensive experience across auditing, technology, security, fraud and compliance.
David brings:
-
More than 40 years of professional experience
-
Big Four auditing and consulting experience
-
Aerospace and defense experience
-
Hundreds of completed audits and assessments
-
Extensive Sarbanes-Oxley experience
-
Internal audit peer-review experience
-
Information-systems audit expertise
-
Cybersecurity and security-assessment experience
-
Fraud examination and investigation experience
-
Board and audit committee training experience
-
Development of numerous established CPE programs
-
Training delivered to thousands of professionals
His programs combine professional standards with the practical judgment required to apply them effectively.
Bring David Marshall’s Training to Your Organization
Corporate Compliance Seminars offers David Marshall’s programs through live webinars, in-person CPE events and customized onsite training.
Programs can be tailored to address your organization’s:
-
Internal audit function
-
Cybersecurity program
-
IT general controls
-
Fraud risks
-
Sarbanes-Oxley responsibilities
-
COSO framework
-
SOC report usage
-
Enterprise risk management
-
Audit committee responsibilities
-
Regulatory requirements
-
ISO management systems
-
Audit-reporting practices
-
Professional development needs
Contact Corporate Compliance Seminars to discuss a David Marshall webinar, in-person seminar or customized onsite training program.
Learn From Experience Across Audit, Technology and Fraud
Financial, operational, technology, fraud and compliance risks do not remain within departmental boundaries.
David S. Marshall gives professionals the practical knowledge needed to evaluate those interconnected risks, strengthen internal controls and help their organizations achieve their objectives securely, ethically and effectively.
















