Method

Six steps, one letter, no product pitch.

This is the sequence we use for a financial audit of an invoice processing application. It is also how matching reviews, SST coding tests, and pre-go-live work are shaped, with a narrower sample.

Person working through papers and a laptop at a desk
  1. Conversation and conflict check

    We ask which application, which legal entities, and why the examination is being requested now — a new system, a statutory-audit query, or a control incident. We check we are not already engaged by a vendor or an implementation partner on the same application. If we cannot be independent, we stop.

  2. Access and sampling plan

    We need production access or a supervised seat beside someone who has it, plus an invoice population for a defined period. The sampling plan is written before we open the first bill. Cancelled and reversed invoices belong in the population. If they are missing, that fact is recorded first.

  3. Walkthrough of the live application

    We sit with the people who capture, match, and approve invoices on a working morning. A recorded demo is not a substitute. We watch override buttons, parking reasons, shared logins, and the path from invoice to payment file. Observations from the queue sit beside the sample.

  4. Sample testing

    Each selected invoice is traced: document, matching, tax code, approval, posting, and, where in scope, payment. We compare what the application allowed with what policy and the approval matrix require. SST treatments are compared to the workbook that supports the return, not only to the setup screen.

  5. Exception discussion

    Draft exceptions go to the finance lead before the letter is final. We will include a disagreement. We will not drop a finding because it is awkward in a board pack. If access was refused for a test, the limitation stays in the front of the letter.

  6. Findings letter and close meeting

    You receive a letter, sampling worksheets, and an exception log. The close meeting is in Ipoh or at your premises. We say what we would re-test, and we will quote a follow-up examination if you want one. We do not recommend a competing invoice product.

What we will not do

We will not certify software. We will not sign SST returns. We will not implement configuration changes. We will not accept a sandbox as production. We will not start fieldwork without a written estimate in ringgit and a named scope.

Where the work happens

The practice is in Taman Tasek Baru, Ipoh. We travel across Peninsular Malaysia when the invoice volume and the live queue justify it. Remote follow-up is used after we have seen the process, not instead of seeing it.

Request a scoping conversation

Tell us the application, the entities, and whether this is a full audit or a narrower test. We reply from Ipoh during working hours.

Write to the practice

Or see the list of engagements.