For the Internal Audit
Sampling was always a compromise with time.
You test a sample to estimate a rate of error. It was never the goal — it was what a human-sized team could do. When the check runs on everything, your job changes from finding instances to designing the control.
What you are measured on
- Coverage, and how defensible the sampling basis is
- Findings that should have been caught by a control that existed on paper
- Whether management can evidence that controls operated
- Repeat findings across periods
Where the leak hits your number
By the time a sample finds it, the money has gone. The finding becomes a recommendation rather than a recovery.
What changes in your week
- Population testing rather than sampling — every transaction, with the result recorded
- An immutable trail of what was checked, what was found and who released it
- Control adherence as a measured number per step, not an assertion
- Exceptions with evidence attached, so testing them is reading rather than reconstructing
What you would ask in the first meeting
01
Can I test the agent itself?
02
Is the trail immutable, and can I read it after the fact?
03
Who can override a hold, and is that logged?
04
What does it do when it cannot decide?
Each agent enforces one stated rule, which is what makes it testable — you can put transactions through it and check the result. Overrides are named-user and logged. And a check that cannot decide raises a named question rather than passing quietly, which is the behaviour you would design if you were writing the control yourself.
Ninety days of invoices answers this better than a meeting.
One export, findings back within a working day, with the invoice attached to each.
$Check your savings→