Continuous control testing checks every relevant transaction against a control as it happens, rather than sampling at period-end. To set it up, pick the controls where quiet failures cost the most, write each one as a precise test, connect to the data read-only, and give every exception an owner. Keep the evidence so auditors can rely on it.
Sampling finds problems months after they happened. By then the duplicate payment has cleared and the supplier's bank details were changed three payment runs ago.
Step 1: Pick controls that fail quietly and cost real money
Good first candidates:
- Duplicate payments: same supplier, amount and invoice number, or near matches
- Supplier bank detail changes: every change verified by an independent call-back before the next payment
- Segregation of duties: no one can both create a supplier and approve its payments
- Unusual journal entries: entries posted at odd times, by unusual users or just under approval limits
Step 2: Write each control as a test
Turn the control into a rule a machine can check. "Bank details are verified" becomes: "for every bank detail change, a call-back record exists before the next payment to that supplier." If you cannot write the test precisely, the control is not well defined yet.
Step 3: Connect to the data, read-only
The tests need read access to the ERP, the supplier master and the payment files. They do not need write access. Keeping the testing layer read-only keeps it independent from the processes it checks.
Step 4: Set thresholds and owners
Decide what counts as an exception and who resolves it. A duplicate payment candidate goes to accounts payable. A segregation of duties conflict goes to the system owner. Set a target time to clear each exception type and report exceptions by age.
Step 5: Keep the evidence for audit
For every test run, keep what was tested, the rule applied, the result, and how each exception was resolved and by whom. That record is what lets your auditors rely on the control rather than retesting it.
Where AI agents fit
Agents are useful at the edges of these tests: reading supporting documents, checking whether a call-back note exists, and preparing each exception with its evidence. ETT Group has automated finance audit testing for clients, and our finance operations service runs continuous checks with every result held in the Evidence File.