Briefing
What a findings letter from this kind of engagement contains
Our letter is written for people who have to decide whether to keep relying on the application. It is not a dashboard and it is not a vendor scorecard.
Scope, access, and limits
The first pages say what we were asked to examine, which application and entities were in scope, what access we received, and what we could not see. If production logs were denied, the letter does not pretend we saw them. Limits are not buried in an appendix.
Exceptions with evidence
Each exception names the control, the sample item, what we expected, what we found, and why it matters to the ledger or to payment. We avoid colour-coded heat maps. Severity is described in sentences: this could duplicate a payment; this could misstate SST; this means the approval matrix is not operating.
Management comments are invited before the letter is final. We will include a disagreement. We will not rewrite a finding because it is inconvenient in a board pack.
What we suggest next
Recommendations are practical: close a role, change a tolerance, stop using a vendor category as a matching bypass, re-test in sixty days. We do not recommend a different invoice product. That would put us in a market we do not occupy.