Aisha Rahman
Engagement partner
Leads application-finance audits for banks and payment firms in the Klang Valley. Former internal audit manager focused on financial-crime operations.
Methodology
The work is sequential on purpose. We do not start with a dashboard tour. We start with the financial events the application is allowed to create, then we test whether those events can be found in the ledger and the bank.
We name the application (including modules actually in use), the legal entity, the period, and the financial events in scope: recoveries, write-offs, refunds, holds, releases, fees, vendor charges, and any provision inputs stored on the case. Out of scope is written down too — alert-performance tuning, model validation, and statutory audit of the entity are not this engagement unless the letter says otherwise.
Access is agreed here: extracts with stable identifiers, a read-only walkthrough environment or recorded screen-share, GL dumps, and a small set of bank statements. If a vendor hosts the application, the client introduces us; we do not scrape or bypass access controls.
Two or three walkthroughs produce narratives in plain English: what happens to money when an investigator marks a case recovered, when a hold is placed, when a fee is charged to a business unit. Each narrative names the control owner in finance and in financial-crime operations. Screenshots are attachments, not the story.
Populations are amounts, not alerts. We stratify by value and by event type, include reversals, and match a sample through application extract, case evidence, journal, and bank or clearing movement. Breaks are aged and assigned before anyone calls them a system defect.
Exceptions are graded by financial effect and by whether the audit trail survived. A missing posting with cash still in suspense is a different finding from an overwritten amount with no history. The grading table is the spine of the management letter.
You receive a scoping memo, narratives, sample sheets, the exception log, and a short letter finance can take to the audit committee. A closing meeting is held in Kuala Lumpur or by video. We do not post journals. We do not remain on retainer unless a follow-on letter is signed.
Who does which hour
Engagement partner
Leads application-finance audits for banks and payment firms in the Klang Valley. Former internal audit manager focused on financial-crime operations.
Application-finance specialist
Traces how case values, recoveries, and fees move from the fraud-monitoring application into ledgers, suspense accounts, and bank statements.
Sampling and evidence lead
Designs sample frames across alerts, cases, and postings, and prepares the workpapers that sit behind the management letter.
Write to the Kuala Lumpur desk with the application name, the entity, and the period. We reply with a scoping call, then a letter. Fees on this site are informational ranges, not a checkout.