DocsControls

Continuous audit

All documentation pages

Test the full population on every cycle

  • Domain: Audit & Compliance
  • Moment: Before you sign
  • Customer: A commercial bank's internal audit function

Test every file in scope with the same versioned rules.

The situation

Internal audit plans a programme, draws a sample, and reads it by hand. Credit files, account opening packs, disbursement approvals. A reviewer opens each one against a checklist and writes down what is missing or wrong.

The sample size is set by how many files the team can read in the weeks available, then defended afterwards as statistically reasonable. Both are true at once.

The population grows every year. The team does not.

What breaks today

The sample is limited by capacity. The number of files reviewed depends on headcount and time. A problem concentrated in files outside the sample can remain hidden.

The finding arrives after the exposure. The error was made on a Tuesday. The cycle reports it a quarter later. By then the facility is drawn and the officer has made the same error several times more, because nobody told him.

Untested files can look clean in the report. Files outside the sample produce no findings, so a reader cannot tell which parts of the population were tested.

The test depends on reviewer judgement. A question such as "Is the documentation consistent with the stated purpose?" can produce different conclusions. The decision is difficult to repeat next year without a versioned rule and recorded reasoning.

Presence checks are done by eye. Signature on the page that requires it, stamp on the document that requires it, identification matching the applicant, collateral dated before the drawdown. This is the work a careful person does worst at the end of a long day, and it is most of the checklist.

What Manuel does

Reads the full population. Files can come from a document store, core system exports, a shared drive, or email. Intake is by SFTP, API, database read, delegated Microsoft 365 permissions, or an on-premise agent. The first run is read-only.

Turns each test into a rule that returns true or false. Is the signature present where it is required. Is the stamp on the document that requires it. Does the identification match the applicant. Is the approval inside the approver's limit. Every rule has an owner, an effective date and a version, so a file can be re-tested against the standard in force when it was reviewed.

Checks documents against business context. The set is tested against the stated purpose of the facility and the customer profile on record. A document describing an activity outside the approved purpose becomes a named exception.

Separates fixed checks from judgement. Lookups, date comparisons, limit checks, and presence tests run on every file. AI reads and classifies documents and helps investigate the remaining cases. Versioned rules determine the result.

Returns the result while it still matters. An exception names the failed test, document, page, and value, then routes to the branch owner. The test runs again after the file is corrected.

Keeps a record while it works. Every material action retains the actor, timestamp, reason, states before and after, and the records it touched. A reviewer can repeat the test later.

What the customer gets

Coverage stops being a sampling decision. Every file in scope is tested against every rule in scope, on every run. Audit stops being the last reader of a file and becomes the standing test on all of them.

Feedback moves to the front office. An exception routed to the person who can fix it, days after the file was created, changes behaviour. A report a year later does not.

The run creates the working paper. The test records its supporting evidence as it runs. Repeat issues become countable because the same tests cover the same population each cycle.

There is no measured before-and-after result for this control yet. Discovery measures how much of the checklist can use fixed rules, how much of the population carries an exception, the exception types, and current review time. These measures become the acceptance criteria.

What stays with your existing systems

Core banking stays the system of record. The document store stays. The audit management system, where you have one, stays. Manuel reads. It does not amend a file, does not touch a credit decision, and writes nothing back.

The opinion stays with audit. Manuel produces tested results and the evidence beneath them.

What a first scope looks like

Start with one product, one historical period, and one set of tests already written into the audit programme. The first run uses files in read-only mode.

We run the full population and compare our exceptions against what your team recorded by hand on its sample. What the sample also found tells you the rules are right. The files nobody opened tell you what sampling was costing you.


Related: Pre-reconciliation detection / Payment release control on high-risk disbursement / Management reporting certification