Review process
From flag list to signed-off memo
A predictable sequence so controllers know when to gather evidence, when to expect a draft, and when escalation decisions are theirs alone.
Intake and scoping
We confirm the flag source (bank, ERP, or internal checklist), the period, and approximate item count. You receive a short engagement note covering confidentiality, deliverables, and fee basis.
Evidence pack
You share the flag list plus statements, payment exports, contracts, and any prior explanations. We do not require access to live systems; exports and PDFs are enough for most batches.
Item classification
Each unusual transaction is read against supporting documents. Items land in one of three outcomes: cleared with rationale, needs more evidence, or recommended for escalation.
Draft memo
You review a draft suitable for internal audit packs. Comments usually focus on missing attachments or local context we could not see from the extracts alone.
Final memo and clarification
We issue the final memo and hold up to sixty minutes of clarification. Escalation decisions remain with your management; our role is to document the reasoning trail.