
A licensed CPA firm built for
small teams who want a real CPA in the room.
The Story
Founder note — Disha Shah, CPA

I've spent my career on both sides of the audit.
I started in audit at KPMG and went on to lead the SOC 2, ISO 27001, and ISO 42001 programs in-house at Abnormal AI. Vigil Assurance is the deliberate, small book of clients where those two perspectives meet.
The pattern I kept seeing was the same. Small teams come to compliance late, usually under pressure from an enterprise prospect or a security questionnaire they cannot ignore. They hire a generalist firm, the audit drags, the report gets flagged in procurement...and they end up paying twice: once for the firm that did not understand their stack, and again for the one that finishes the job.
The realization was simple. This segment is genuinely underserved. With the right process, the right tooling, and a deliberate book of clients, a single licensed CPA can deliver attestation work at a price that makes sense for small teams, without cutting quality. The work is technical, repeatable, and best done by someone who has actually run the controls being tested.
Credentials, Briefly
The licenses, memberships, and experience behind the work.
Licensed Certified Public Accountant
State of Illinois
AICPA and ICPAS
Member in Good Standing
AICPA Peer Review Program
Enrolled
ISO 42001 Lead Implementer AI Management Systems
BSI Group
Audited the enterprises asking you for SOC 2. Built the GRC program at a startup just like yours.
Why we built Vigil
Vigil means to keep watch.
That's what good assurance work actually is. Not a once-a-year exercise. Not a checkbox. A steady, attentive presence that helps you build the right controls now so the audits that come later are routine, not crises. Our clients don't see audit as something to survive. They see it as something they get done well, the first time, with a CPA who treats them like a peer.
What that means in practice:
- No account managers learning on your engagement.
- No senior hours billed at partner rates.
- No surprise scope changes halfway through.
Working Together
A 30-minute scoping call is the right place to start.
If we're a good fit, we'll send a proposal within 48 hours.
If we're not, we'll tell you who is.
Get in touch now
Tell us what your customers are asking for and where you are now. We will tell you what you actually need, and what you don't.
Write Email