About KGA Partners

Every engagement, led personally by the auditor

KGA Partners is a boutique IT audit and compliance consultancy based in Austin, Texas — built around one principle: assess honestly, report clearly, and never blur the line between advisor and implementer.

Sherif Kassem, CISA

Sherif founded KGA Partners after a career spanning IT operations, accounting, and audit — a combination that shows up in the way engagements are run: structured like an audit, but explained like a business conversation.

He works directly with every client. No handoffs, no account managers translating between you and the person actually doing the assessment.

  • CISA CertifiedCertified Information Systems Auditor
  • MBA + IT + AccountingA background built for reading both the controls and the balance sheet
  • Airbus, Capgemini, Texas state agenciesPrior experience across aerospace, consulting, and government
Our Independence Principle

We assess what's there. We never audit what we built.

If you can hand our recommendation to any IT provider and they can execute it without us in the room, we've done our job correctly.

Advising what to doYes — this is the engagement
Advising how, in detailCase by case
Doing the fix ourselvesNo
Auditing our own buildNever

We don't configure firewalls, set up MFA, deploy backup systems, tune SIEMs, or patch anything.

How We Work

A discovery-first process, every time

We never jump straight to evidence collection. Scope gets defined before anything gets requested.

01

Inquiry

You reach out via LinkedIn, Upwork, or referral.

02

Discovery call

We talk through your environment, your risk, and what's driving the need.

03

Requirement clarification

We pin down exactly what "done" looks like for this engagement.

04

Framework selection

NIST 800-53, CMMC Level 2, Texas DIR, or whatever your customer or regulator requires.

05

Scope definition

What's in, what's out, and how long it takes.

06

Proposal

A clear, written scope of work — no surprises later.

07

Evidence request

We tell you exactly what to gather, and why.

08

Assessment

Controls tested against the agreed framework.

09

Findings & recommendations

Gaps ranked by risk, with a prioritized path forward.

10

Final report

A document your team — or your next auditor — can actually use.

Ready to see where you stand?

Book a discovery call