Notebook and charts prepared for a structured review

Approach

From scoping letter to findings workshop — the sequence we use when auditing treasury control applications.

Why a defined sequence

Treasury applications sit close to cash movement. An unstructured review wastes floor time and leaves findings hard to defend. Our approach keeps each stage tied to named applications and control questions.

  1. Scoping letter We agree which applications, entities, and payment corridors are in scope, what evidence we need, and which weeks fieldwork will occupy. The letter states exclusions in plain language.
  2. Document intake Control matrices, entitlement extracts, recent reconciliation exception reports, and change logs arrive before we sit with operators. Missing items are logged early so they do not surface as surprises in week three.
  3. Floor walkthroughs We observe payment initiation, approval, and release with the people who perform those steps. Screenshots and sample references are taken with client permission.
  4. Control testing Dual authorization, segregation of duties, cut-offs, and override paths are tested against the matrix. Findings are graded by severity and by how easily an unauthorised change could move cash.
  5. Validation Draft findings return to treasury operations for factual correction before the report freezes. Disagreements on severity can be noted; disagreements on observed facts are resolved with evidence.
  6. Closing workshop and report We walk prioritised findings with the agreed audience and deliver a client-owned report suitable for internal audit and, where requested, the board.

What we need from you

A named liaison, timely access to read-only environments, and honesty about known weak spots. Surprises during fieldwork slow everyone down.

Natural next step

If this sequence matches how your organisation prefers to work, browse engagement types or request a scoping call.