Briefing
An invoice export is not an audit trail
A spreadsheet dump from the invoice application can be sorted, filtered, and still fail to show who approved what, and when the record changed.
What the export usually contains
When a finance team is asked how invoices move through their application, the first reflex is to export a list. Vendor, invoice number, amount, tax code, status, payment date. That list is useful for sampling. It is not the trail.
The trail is the sequence of states: captured, matched, parked, released, approved, posted, paid — and the user identity attached to each change. Many exports flatten that sequence into a single status column that reflects only the last state.
What we ask to see instead
In Ipoh we sit with the application and open the history on a sample of invoices, including ones that were rejected and re-entered. If history is truncated after posting, that fact goes in the findings letter. If history exists only in a database table the AP team cannot read, we say the trail is not available to the people who own the process.
Statutory auditors sometimes receive the same export. Our job, when we are engaged, is to say whether that file can support a financial conclusion about the application. Often it cannot, and the work then moves to screens, logs, and document stores.