Finance operations

How to set up continuous control testing in finance.

How to move finance controls from year-end sampling to continuous testing: pick the controls, define the test, set thresholds and route exceptions.

Continuous control testing checks every relevant transaction against a control as it happens, rather than sampling at period-end. To set it up, pick the controls where quiet failures cost the most, write each one as a precise test, connect to the data read-only, and give every exception an owner. Keep the evidence so auditors can rely on it.

Sampling finds problems months after they happened. By then the duplicate payment has cleared and the supplier's bank details were changed three payment runs ago.

Step 1: Pick controls that fail quietly and cost real money

Good first candidates:

  • Duplicate payments: same supplier, amount and invoice number, or near matches
  • Supplier bank detail changes: every change verified by an independent call-back before the next payment
  • Segregation of duties: no one can both create a supplier and approve its payments
  • Unusual journal entries: entries posted at odd times, by unusual users or just under approval limits

Step 2: Write each control as a test

Turn the control into a rule a machine can check. "Bank details are verified" becomes: "for every bank detail change, a call-back record exists before the next payment to that supplier." If you cannot write the test precisely, the control is not well defined yet.

Step 3: Connect to the data, read-only

The tests need read access to the ERP, the supplier master and the payment files. They do not need write access. Keeping the testing layer read-only keeps it independent from the processes it checks.

Step 4: Set thresholds and owners

Decide what counts as an exception and who resolves it. A duplicate payment candidate goes to accounts payable. A segregation of duties conflict goes to the system owner. Set a target time to clear each exception type and report exceptions by age.

Step 5: Keep the evidence for audit

For every test run, keep what was tested, the rule applied, the result, and how each exception was resolved and by whom. That record is what lets your auditors rely on the control rather than retesting it.

Where AI agents fit

Agents are useful at the edges of these tests: reading supporting documents, checking whether a call-back note exists, and preparing each exception with its evidence. ETT Group has automated finance audit testing for clients, and our finance operations service runs continuous checks with every result held in the Evidence File.

Common questions.

What is continuous control testing?

It is testing a control against every transaction as it happens, instead of sampling a few transactions at quarter-end or year-end. Exceptions are raised while they can still be fixed.

Which controls should be tested first?

Controls where a failure is expensive and hard to spot: duplicate payments, supplier bank detail changes, segregation of duties in the ERP, and journal entries posted outside normal patterns.

Want this run for you.

Agentic MSP runs back-office work with governed AI agents and bills only for verified outcomes.