Tom Loring

Thomas J. Loring, CISA

Partner, Wipfli Advisory LLC

As a partner in Wipfli’s risk advisory services practice, Thomas Loring performs a variety of functions in internal controls, information technology (IT) and information security. He performs technology auditing in all areas of IT-related controls, including IT department organization and administration, daily operations, software change management, logical security and physical security. Tom regularly performs System and Organization Controls (SOC) 1 and SOC 2 examinations, IT general control reviews, information risk assessments and consulting for clients in a wide variety of industries, including financial institutions, third-party data processors, statement printers, data centers and more.

  • SOC 1 and SOC 2 examinations
  • Internal controls
  • Information security
  • Risk assessment

  • Certified Information Systems Auditor (CISA)
  • HITRUST Certified CSF Practitioner

  • Information Systems Audit and Control Association (ISACA) - Member

University of Southern Maine - Portland, Maine
  • Master of business administration degree
University of Maine - Orono, Maine
  • Bachelor of science degree in business administration with a concentration in accounting

Latest case studies, resources, and insights

  • People on digital technology.

    ARTICLE | RISK ADVISORY

    Technology risk management: How to modernize while successfully managing risk

    Businesses that move to the cloud, embrace big data or integrate AI face new technology risks. Learn about top risks, how to manage them and why doing so helps organizations create opportunities as well as avoid harms.

  • Two professionals reviewing data on a laptop during a business consulting meeting in a modern office.

    ARTICLE | AUDIT AND ASSURANCE

    Don’t cut corners on your SOC audit. You’ll risk harming your business.

    Many SOC audit providers offer cheap audits that can temporarily satisfy your customers but leave your business exposed to major risks. What does a better audit look like?

  • Understanding SOC exam exceptions and management letter comments

    ARTICLE | RISK ADVISORY

    Understanding SOC exam exceptions and management letter comments

    When completing a System and Organization Controls (SOC) examination, the results can generally fall into one of two categories: exceptions or management letter comments.