Continuous controls
Continuous controls in the organisation: catching what falls between departments
The expensive failures in an organisation almost never sit inside one department. They sit in the seam between two departments or more, in a place where nobody is defined as responsible: procurement assumed finance had checked, finance assumed procurement had approved, and nobody cross-checked. Continuous controls are a cross-check that runs on every transaction, every day, not on a sample once a year.
The moment someone calls us: duplicate payments and changed bank details, found too late
It is almost always the same moment: somebody found something too late. An invoice that arrived twice and was paid twice. A transfer that went out to a bank account quietly changed a month earlier. A customer who keeps buying well beyond the credit limit approved for them. A contract signed with an indexation clause that nobody updated for three years.
In every one of these cases, looking back, it turns out that the information existed. It simply sat in two different systems, and nobody cross-checked between them on the day it happened.
Why do the failures sit in the seam between departments?
An organisation is divided into departments, and every department has someone responsible for what happens inside it. Nobody is in charge of the seam between two departments. It appears in nobody's job description, so each side assumes in good faith that the other side is handling it.
These are a few seams that recur in almost every organisation:
- Procurement and finance. Procurement knows the supplier, and the finance department makes the payment. A change in the supplier's bank details looks to procurement like a technical update, and to finance like data that arrived already approved.
- HR, payroll and IT. An employee leaves. The file is closed in HR, but payroll is not always updated the same month, and access to the systems is almost never closed the same day.
- Sales and billing. Sales closed a deal with special terms, and billing works from what appears in the system. The gap between the two is revenue that was never collected.
- Operations and finance. The service keeps being delivered after the contract has ended, because the people delivering it do not know that it ended.
Internal audit is organised by department and by annual plan as well, so it inherits exactly the same blind spot. That is not a weaker audit. It is structure.
What cannot be sampled: the invoice never issued, the indexation never applied
A transaction that was carried out has a record. It can be sampled, checked and commented on. An omission has no record at all, so there is nothing to sample, and that is why it is almost never caught:
- A service that was delivered and never invoiced.
- An indexation clause, a CPI adjustment or a contractual price increase not applied on time. Very common, and it quietly accumulates into large sums.
- A contract that ended while the service continued without billing.
- A bank reconciliation opened and not closed for months.
- A licence, insurance policy or certification that expired and was not renewed.
Continuous controls work the other way round here: they check what should have happened and compare it with what actually happened. The gap is the finding.
Payments and procurement controls: money that went out and should not have
These are the controls that can run on every transaction, not on a sample:
- A change in a supplier's bank details. Every change is compared with the history and flagged for re-verification before the next payment. This is the most common fraud vector, and it looks like a routine master data update.
- A duplicate invoice. Same supplier, a close amount, a similar invoice number, within a time window. At a volume of thousands of invoices a month it gets swallowed.
- The same invoice through two channels. Paid by transfer and also by cheque, or through two companies in the group.
- Order splitting. Two orders of 49,000 instead of one of 98,000, to pass under the approval threshold. Each order on its own is perfectly valid, and only the pattern gives it away.
- A supplier who is actually an employee. A cross-check of ID number or company registration number, address, phone and bank account between the supplier file and the employee file.
- A supplier opened and used immediately. A new supplier that was paid too soon after being set up.
- A payment to a supplier not on the approved list, or to a supplier marked inactive.
Revenue and billing controls: money that came in below what was agreed
- A deal that was never billed. Recorded in sales or in operations, with no invoice created for it.
- Indexation that was never applied. A contract with a CPI clause or an annual increase that was never actually implemented.
- A price that does not match. A price on an order that does not match the price list or that customer's specific agreement.
- A discount above authority, and a discount that creeps. Not only a one-off discount beyond the approver's authority, but also a discount that rises gradually for the same customer over a year. No single event looks like an exception.
- Exceeding a credit limit, and also a limit that was raised without approval at the required level.
- A contract that ended while the service continues without billing.
People and access rights: leavers, segregation of duties and expired certifications
Here the cross-check is between three sources that are almost never checked together:
- An employee who has left and is still paid. A cross-check between HR and payroll.
- An employee who has left and still has access to the systems. A cross-check between HR and the user lists. This is the exposure that is checked the least and is the easiest to check.
- Segregation of duties. The same person sets up a supplier and also approves its payment, or enters an order and also approves the receipt. This is the heart of internal audit, and it is exactly the kind of rule that can run continuously instead of once a year.
- Certification, insurance or licence expiry. In some industries an expired certification is both a safety risk and a regulatory exposure. At Metal Stone this is a control that was actually built: a real-time alert on training and refresher courses approaching their expiry.
- An unusual pattern of hours against that employee's history and the role's.
Investments and treasury: financial covenants, fees, policy limits and concentration
In this area the gap between what is checked and what can be checked is the widest, because the check requires a cross-check between a policy document, an agreement and a transaction file. These are the controls that recur:
- Financial covenants on loans. Monitoring the ratios against the commitment in the agreement, with an alert before the ratio is breached and not in the following quarter's report. That is the practical difference between a control and reporting.
- Fees against the agreement. Management, custody and brokerage fees checked line by line against what was agreed. This drains substantial sums over time and is rarely checked.
- A breach of the investment policy. The actual asset allocation against the ranges the board or the investment committee approved.
- Concentration. Exposure to a single issuer, a single bank or a single sector above the ceiling that was set.
- Foreign currency exposure against the hedging policy. The actual exposure after hedging, against what the policy allows.
- Forecast cash flow against known commitments, with an alert several days ahead and not on the payment day.
- Automatic renewal on poor terms. A deposit or a loan that rolls over for another period at a worse rate, without anyone having examined an alternative.
- Return against a benchmark set in advance, not against a feeling.
Gaps between systems: sales, the books, inventory and the bank
- A gap between the sales system and the accounting system.
- A gap between physical inventory and inventory in the system, an inventory movement without a document, and negative inventory.
- Bank reconciliation items opened and not closed within the time set.
- A gap between what was reported to the authorities and the books.
Regulation and deadlines: VAT, advance tax payments, licences and insurance policies
This category is technically simple and expensive when missed: VAT reporting dates, advance tax payments and withholdings, renewal of licences and standards, the validity of insurance policies, and filing deadlines and limitation periods. All of them are known in advance, and all of them live today in one person's calendar.
How is one control built on your historical data, and why start with one?
We do not build twenty controls. We choose one, the one with the largest exposure or the one that has already hurt you in practice, and run it on your historical data. That result does two things at once. It shows how many cases the control would have found in the past year. That both proves whether it is worth the investment and sets the expected volume and who it goes to.
A control that would have produced dozens of cases a day is recalibrated before it goes live. A control that found nothing in a whole year is a candidate not to be built, and that is a legitimate answer we give you.
What do we not say?
We do not promise you will miss nothing. A control checks what it knows how to check, on the data it is given access to, and by the rules defined for it. If a particular piece of data is not accessible in your system, the control that depends on it will not be built, and that is said at the measurement stage, not after it.
What does change is the coverage and the timing: instead of a sample after the fact, every transaction, at the frequency you set. A person decides what to do with each case, and professional judgement and responsibility stay with you.
And if your question is what will be written about one unit in an audit report, and how to stop a finding recurring next year, that is a separate subject: Unit controls and audit in the organisation.
Where do you start?
With the case that has already happened to you. If there was a duplicate invoice, if a contract that was never updated came to light, if a supplier changed bank details and somebody noticed by chance, that is the first control. If nothing has happened yet, we start with the seam that worries you most.
- Email: info@tagula.ai
- Phone and WhatsApp: 054-650-4053
Frequently asked questions
What is the difference between this and the internal audit we already have?
Internal audit checks a sample, after the fact, according to an annual plan. Continuous controls run the same rules on every transaction, at the frequency you set. The two do not compete: audit defines what is important to check and interprets the findings, and automation is what makes it possible to check everything instead of a sample. In many cases the controls that are built are exactly the ones already in the audit plan, except that they run every day.
We already get exception reports from the system. How is this different?
An exception report from one system looks at what happens inside that system. Most of the expensive failures are not there. They sit in the seam between two systems that do not talk: a supplier whose details match an employee, an employee who has left and is still paid, an order split to pass under an approval threshold. No single system sees it, because each one holds only half the picture.
Which category of failure is the hardest to catch?
What did not happen. A transaction that was carried out has a record, so it can be sampled and checked. An invoice that was never issued, a contractual indexation that was never applied, or a contract that ended while the service continued without billing has no record at all, so there is nothing to sample. A continuous process checks what should have happened against what actually happened, and that is the difference.
How many alerts will we get a day?
That is set at the measurement stage, before anything is built. We check how many cases each control would have found in the past year on your real data. That way the expected volume, and who it goes to, are known in advance. A control that would have produced dozens of cases a day is recalibrated or not built.
Does this replace a controller or an accountant?
No. The system cross-checks, filters and presents an organised case with all of its context. The decision on what to do with the case, and the professional judgement and responsibility, stay with the person. What changes is that they receive the case on the day it happened instead of finding it next quarter, and that they spend their time on handling it rather than on gathering it.
What data do we need to give you for this to work?
Read access to the sources the control has to see, and no wider than that. A payments control needs suppliers, invoices and bank transactions. An access control needs the list of employees and the list of users in the systems. What data enters the process is set at the measurement stage, together with you, and whatever is binding about it is set in a written agreement.
What happens when a system does not allow access to the data?
That is checked against the system itself before anything is promised, in the version and with the permissions you have. Some systems have a proper interface, some allow only file exports or scheduled reports, and there are operations the vendor has not opened to external access. A control that relies on data that cannot be exported will not be built, and that is said at the measurement stage, not after it.
Where do we start when there are dozens of possible controls?
Not with dozens. We choose one, the one with the largest exposure or the one that has already hurt you in practice, and run it on the historical data to see what it would have found. That result is both the proof that it is worth it and the basis for deciding what the next control is.
This page is general information about how we work. It is not an offer, an undertaking, or a promise of any result. Binding arrangements, including the scope of the service and the handling of data, are set out in a written agreement. See the Terms of use.