Methodology

How we audit a fraud-monitoring application as a set of books

The work is sequential on purpose. We do not start with a dashboard tour. We start with the financial events the application is allowed to create, then we test whether those events can be found in the ledger and the bank.

Small team reviewing documents together in a quiet office
Fieldwork is a walkthrough script, not a product workshop.

1. Scoping memo

We name the application (including modules actually in use), the legal entity, the period, and the financial events in scope: recoveries, write-offs, refunds, holds, releases, fees, vendor charges, and any provision inputs stored on the case. Out of scope is written down too — alert-performance tuning, model validation, and statutory audit of the entity are not this engagement unless the letter says otherwise.

Access is agreed here: extracts with stable identifiers, a read-only walkthrough environment or recorded screen-share, GL dumps, and a small set of bank statements. If a vendor hosts the application, the client introduces us; we do not scrape or bypass access controls.

2. Flow narratives

Two or three walkthroughs produce narratives in plain English: what happens to money when an investigator marks a case recovered, when a hold is placed, when a fee is charged to a business unit. Each narrative names the control owner in finance and in financial-crime operations. Screenshots are attachments, not the story.

3. Sample and match

Populations are amounts, not alerts. We stratify by value and by event type, include reversals, and match a sample through application extract, case evidence, journal, and bank or clearing movement. Breaks are aged and assigned before anyone calls them a system defect.

4. Exception grading

Exceptions are graded by financial effect and by whether the audit trail survived. A missing posting with cash still in suspense is a different finding from an overwritten amount with no history. The grading table is the spine of the management letter.

5. Closing file

You receive a scoping memo, narratives, sample sheets, the exception log, and a short letter finance can take to the audit committee. A closing meeting is held in Kuala Lumpur or by video. We do not post journals. We do not remain on retainer unless a follow-on letter is signed.

Who does which hour

Staffing on a typical file

Portrait of Aisha Rahman, engagement partner

Aisha Rahman

Engagement partner

Leads application-finance audits for banks and payment firms in the Klang Valley. Former internal audit manager focused on financial-crime operations.

Portrait of Lim Wei Jun, application-finance specialist

Lim Wei Jun

Application-finance specialist

Traces how case values, recoveries, and fees move from the fraud-monitoring application into ledgers, suspense accounts, and bank statements.

Portrait of Priya Nair, sampling and evidence lead

Priya Nair

Sampling and evidence lead

Designs sample frames across alerts, cases, and postings, and prepares the workpapers that sit behind the management letter.

If this is the file you need

Write to the Kuala Lumpur desk with the application name, the entity, and the period. We reply with a scoping call, then a letter. Fees on this site are informational ranges, not a checkout.

Open the desk form