Order-to-cash is the cycle the organization exists to run, and it is audited in fragments. Revenue recognition gets the accounting attention, receivables get the credit and collections attention, and the pieces in between, the order, the price, the delivery, the invoice, the credit memo, the cash application, get whatever attention is left, which is usually none. The receivables guide covers the back half of the cycle from invoice to cash and the revenue recognition guide covers the accounting, and each is worth running on its own. This guide is the integrated version: order-to-cash as one chain, from the customer record that decides who may buy on credit to the write-off that decides who never paid, with the handoffs between sales, operations, billing and finance tested as handoffs rather than as somebody else’s problem.
The integrated audit finds a different class of problem from the fragment audits. A revenue test confirms the invoice was recorded in the right period; it does not ask whether the price on it was authorized. A collections test ages the receivable; it does not ask whether the credit memo that cleared last month’s balance had a return behind it. A cash test reconciles the bank; it does not ask whether the receipt was applied to the customer who paid or to the customer whose invoice was oldest. The ACFE’s Occupational Fraud 2026 report puts asset misappropriation in 90 percent of its 2,402 cases, and the revenue-side schemes, skimming, lapping, credit memo fraud and unauthorized discounts, all live in the handoffs this guide tests. It covers the terrain and the six handoffs, a cross-stage risk map, a twelve-control starter matrix, sizing, a 14-test program, the analytics that join the stages, MidState Beverage’s order-to-cash engagement with every test’s result, the findings that recur with wording that lands, and the scoping variants for route and cash businesses, subscription models, project revenue and marketplaces.
In this guide
- Know the terrain: the chain and its six handoffs
- The integrated risk map
- The starter RCM for the chain: twelve controls
- Sizing and sequencing the engagement
- The 14-test program
- Analytics across the chain
- Worked example: MidState Beverage’s order-to-cash audit
- The findings that recur, and wording that lands
- Scoping variants: route and cash businesses, subscriptions, projects, marketplaces
- Where to go next
Know the terrain: the chain and its six handoffs
Order-to-cash runs through seven links: the customer master and the credit decision; the order and its price; fulfillment, whether a shipment, a delivery or a service performed; the invoice; cash receipt and its application to the account; credits, returns and adjustments; and collections, the allowance and the write-off. Sales owns the first two, operations the third, billing the fourth, treasury or cash application the fifth, and finance the last two, with customer service touching all of them. As in procure-to-pay, each function’s controls assume the previous function did its job: billing invoices what operations says was delivered, cash application posts what treasury says arrived, collections chases what billing says is owed. The integrated audit tests the assumptions.
| Handoff | What the receiving function assumes | What breaks there | The integrated test |
|---|---|---|---|
| 1. Customer master and credit to order | Sales assumes the customer may buy on the terms in the order | Orders shipped over credit limit with holds released by the wrong person; customers created and credited by the same rep; terms changed without approval | Join orders to the credit file for the year; test every released hold for the releaser’s authority; creator-approver overlap on the customer master |
| 2. Order to price | Billing assumes the price on the order was authorized | Off-list pricing and discounts entered by reps with no approval; promotional prices left running after the promotion | Invoice unit prices against the price file and the approved deal sheet, by rep and customer |
| 3. Order to fulfillment | Billing assumes what operations recorded was delivered as recorded | Short deliveries invoiced in full; proof of delivery missing; services invoiced before performance | Match delivery evidence to invoices at line level for a sample; profile missing proof of delivery by site |
| 4. Invoice to cash application | Finance assumes receipts were applied to the customer who paid | Lapping, misapplication, unapplied cash used to hide shortages, receipts held in suspense | Age unapplied and on-account cash; run the lapping pattern; reconcile receipts to the bank at the deposit level |
| 5. Invoice to credit and adjustment | Collections assumes a credit memo reflects a return, a pricing error or an authorized concession | Credits with no return behind them; credits approved by the issuing rep; adjustments used to clear balances quietly | Join credit memos to return receipts and pricing claims; test approver identity for the full population |
| 6. Receivable to allowance and write-off | The controller assumes the allowance reflects the aging and write-offs were approved | Allowance formulas untouched for years; write-offs below the approval level; write-offs to customers still buying | Re-perform the allowance from the aging; test write-off approvals in full; join write-offs to subsequent orders |
The integrated risk map
The fragment guides carry their own risk maps, and their risks remain in scope. The eight below are the ones that only appear when the cycle is looked at as one, and they are the rows the integrated engagement’s risk and control matrix is built around.
| # | Cross-stage risk | Why the fragment audits miss it | What it looks like in the data |
|---|---|---|---|
| R1 | Unauthorized pricing paid for by margin: discounts and off-list prices that never reached an approver and were invoiced, collected and recognized correctly | Revenue tests the period; receivables tests the collection; nobody tests the price | Invoice prices below the price file by rep and customer; discounts concentrated in a few reps; promotional prices outliving the promotion |
| R2 | Credit control theater: limits set, holds raised, holds released by the person who wants the sale | Credit is tested as a policy, not as a release log | Released holds by releaser; orders shipped over limit; limits raised the day before a large order |
| R3 | Credit memo as the universal solvent: returns, disputes, concessions and shortages all cleared through one document with one weak approval | Returns are tested in operations; credits in billing; the join is nobody’s | Credits with no return receipt or pricing claim; credits approved by the issuing rep; credits raised within days of a collection call |
| R4 | Cash application drift: receipts posted to the wrong account, held on account, or applied to the oldest invoice regardless of remittance | Cash is reconciled to the bank in total; application is tested by exception | Unapplied cash aging; postings that alternate between accounts; customers with chronic small differences |
| R5 | Delivery fiction: invoicing what the system says shipped when the customer received less, later, or nothing | Fulfillment is an operations audit; billing trusts the shipment record | Proof-of-delivery gaps by site; disputes and credits clustered on routes or carriers; invoices before performance for services |
| R6 | Rebate and trade promotion blindness: customer rebates accrued from memory, agreements unsigned, claims settled through credits | Rebates sit between sales and finance and are audited as an accrual, if at all | Accrual movements without agreements; claims paid above the agreement; year-end true-ups |
| R7 | Allowance and write-off as a lever: the allowance formula untouched, write-offs used to clean the aging before a review | The allowance is an estimate the external auditor tests; the write-off log is nobody’s | Write-offs below the approval level; write-offs to customers still ordering; allowance coverage moving against the aging |
| R8 | Cut-off and period drift: deliveries and services straddling period end, credits raised in the next period for this period’s sales | Revenue tests cut-off at year end and not at the quarter that mattered | Invoices dated after delivery by more than the standard; credits in the first week of the period against the last week’s invoices |
The starter RCM for the chain: twelve controls
Twelve controls hold the cycle together in most organizations. As with the procure-to-pay chain, they are not the fragment matrices stapled together but the shorter list that operates at a handoff or across several links. Build them in the RCM template, mark which exist, and treat a missing row as a design finding before testing a single invoice.
| Control | Stage or handoff | Risk | How to test it |
|---|---|---|---|
| Customer master maintained by a function independent of sales, with credit terms and limits set by credit and changed only through an approved request | Link 1 | R2, R3 | Creator against requester for new customers; every limit or term change in the year traced to an approval |
| Credit hold enforced in the system with release rights restricted to credit, logged, and reported | Handoff 1 | R2 | Full population of released holds against the release authority; orders shipped over limit listed and explained |
| Price file and deal sheets loaded to the system; off-list pricing requires approval routed by discount depth | Handoff 2 | R1 | Invoice prices against the price file for the year; approvals for every discount above the routing threshold |
| Fulfillment evidence captured at delivery (signature, scan, timestamp) and required before invoicing, with exceptions reported by site | Handoff 3 | R5 | Proof-of-delivery completeness profiled by site and route; a sample traced from evidence to invoice |
| Invoice generated from the fulfillment record, not from the order, with quantity and price taken from the record and the file | Handoff 3 | R1, R5 | Configuration inspected; a sample of invoices re-performed from the delivery record and the price file |
| Cash applied from the remittance to the invoices paid, by a function independent of billing and credit memo issue, with unapplied cash reviewed weekly and cleared within a set period | Handoff 4 | R4 | Unapplied cash aging inspected; a sample of applications re-performed from remittance; segregation tested from actual access |
| Credit memos supported by a return receipt, a pricing claim or an approved concession, approved by someone other than the issuing rep, with authority routed by amount | Handoff 5 | R3 | Full-population join of credits to returns and claims; approver against issuer for the year |
| Rebate and trade promotion agreements signed and loaded before accrual; accruals calculated from the agreement and settled against claims | Links 4 to 6 | R6 | Agreement population against the accrual schedule; a sample of settlements re-performed |
| Collections worked from the aging under a documented escalation, with disputes logged separately from credits | Link 7 | R3, R7 | Escalation evidence for a sample of overdue accounts; dispute log reconciled to credits |
| Allowance for doubtful accounts calculated from the aging and history under a documented method, reviewed and re-based annually | Link 7 | R7 | Re-perform the allowance from the aging; inspect the last re-basing |
| Write-offs approved at a level set by amount, by someone outside sales and collections, with written-off customers blocked from further credit | Link 7 | R7 | Full population of write-offs against the approval matrix; written-off customers joined to subsequent orders |
| Cycle analytics run monthly with hits dispositioned, and period-end cut-off procedures at every quarter, not only at year end | Whole chain | R1 to R8 | Twelve months of monitoring output; cut-off tests at two quarter ends |
Sizing and sequencing the engagement
Order-to-cash volumes are large and the data is clean, which makes the integrated audit an analytics engagement with file work attached. The ranges assume a mid-sized organization with one billing system, a few thousand customers, a delivery or fulfillment record held in an operational system, and an auditor who can join five tables. What stretches it is fragmentation: multiple billing systems after an acquisition, a delivery record that lives on handheld devices or paper, and a rebate population managed in spreadsheets. Write the program to the five-element standard in the work program guide and record the stratification in the sampling memo; an order-to-cash sample drawn flat from millions of invoices tests the boring middle and nothing else.
| Phase | What happens | Hours |
|---|---|---|
| Planning and the boundary | The revenue recognition and receivables audits’ scope and findings read; the chain RCM drafted; pricing authority, credit policy and approval matrices listed as at each date | 30 |
| Walkthrough of the chain | One sale of each type (standard, promotional, over-limit release, returned, written-off) walked from customer record to ledger, at head office and at one site or depot | 30 |
| Data acquisition and joins | Customer master with change history, orders, price file and deal sheets, delivery records, invoices, receipts and applications, credit memos, returns, rebate agreements, aging and write-offs, joined on reconciled keys with completeness proofs | 50 to 70 |
| Chain analytics | The eight cross-stage analytics run on the full year; hits scored and triaged into sloppiness, control failure and possible fraud | 50 to 70 |
| Handoff and control tests | The 14-test program, aimed by the hits | 110 to 140 |
| Estimates and cut-off | Allowance re-performed; rebate accrual re-performed; cut-off at two quarter ends | 30 |
| Reporting | Findings written to the chain; base rates on every number; people-level items and any referral routed under the protocol | 40 to 50 |
| Total | 340 to 420 |
Sequence the walkthrough first, because the pricing authority and credit release rights you test have to be the ones in force at the sites; the analytics second, because they choose the files; and the estimates last, because the allowance and the rebate accrual are the two places where the chain’s leakage finally shows up as a number the board sees, and you want the transaction findings in hand before you argue about the estimate.
The 14-test program
| # | Test | Population and method | Risk |
|---|---|---|---|
| 1 | Walk the chain; reconcile the process as performed to the credit policy, pricing authority and approval matrices; redraw the RCM | One sale per type, head office and one site | All |
| 2 | Customer master integrity: creator against requester; limit and term changes traced to approvals; dormant customers reactivated | Full population of new records and changes | R2, R3 |
| 3 | Credit hold releases: releaser against authority; orders shipped over limit; limits raised within days of a large order | Full population | R2 |
| 4 | Pricing compliance: invoice unit prices against the price file and deal sheets; discounts above threshold traced to approval; promotions checked for end dates | Full year of invoice lines; sample 25 approvals | R1 |
| 5 | Fulfillment to invoice: proof of delivery profiled by site; a sample of invoices re-performed from the delivery record; service invoices tested for performance evidence | Full population profile; sample 40 | R5 |
| 6 | Cash application: unapplied and on-account cash aged; a sample of applications re-performed from remittances; the lapping pattern run | Full aging; sample 25; full population analytic | R4 |
| 7 | Credit memos: joined to return receipts and pricing claims; approver against issuer; credits within days of a collection contact | Full population | R3 |
| 8 | Rebates and trade promotions: agreement population against the accrual; settlements re-performed; claims above agreement | Full agreement population; sample 25 settlements | R6 |
| 9 | Collections discipline: escalation evidence for overdue accounts; dispute log against credits | Sample 25 overdue accounts; full dispute log | R3, R7 |
| 10 | Allowance: re-performed from the aging and loss history; method and last re-basing inspected | Full aging | R7 |
| 11 | Write-offs: full population against the approval matrix; written-off customers joined to subsequent orders | Full population | R7 |
| 12 | Cut-off at two quarter ends: deliveries and services around period end; credits in the first week against the prior week’s invoices | Two quarter ends, full window | R8 |
| 13 | Segregation from actual access: order, price, credit, cash application and credit memo rights by user | Access extract, full population | R1, R3, R4 |
| 14 | Monitoring and prior findings: twelve months of cycle analytics with dispositions; prior findings re-tested on the last quarter | Twelve months; all prior findings | R1 to R8 |
Analytics across the chain
The single-table receivables analytics, lapping signatures, credit memo concentration, write-off-then-receipt and the rest, are in the receivables guide and the fraud red flags library‘s revenue cycle. The eight joins below are the integrated engagement’s engine: each one crosses a handoff, and each is stated plainly enough to build in SQL or a spreadsheet.
| Analytic | Tables joined | Logic | A hit usually means |
|---|---|---|---|
| Price variance by rep | Invoice lines, price file, deal sheets, sales hierarchy | Invoiced unit price against the list or approved deal price on the date, summed by rep and customer | Unauthorized discounting; promotions left running; margin leakage with a name attached, handled under the proportionality rule |
| Hold release audit | Credit holds, releases, user list, orders | Every released hold with the releaser’s role and the order shipped afterward, against the limit | Credit control operating as theater; releases by sales or depot management |
| Limit-then-order | Customer master change log, orders | Credit limit increases within N days before an order exceeding the old limit | Limits raised to fit the sale rather than the risk |
| Credit-to-return join | Credit memos, return receipts, pricing claims, users | Credits with no matching return or claim; approver equal to issuer; credits within days of a collection contact | The universal solvent in use; concessions, disputes and shortages cleared without support |
| Delivery gap profile | Delivery records, invoices, sites, routes | Invoices with no proof of delivery, by site, route and driver; disputes and credits joined by route | Delivery fiction; a route or site where the evidence chain is broken |
| Application pattern | Receipts, applications, invoices, customers | Postings that alternate between accounts, receipts applied to the oldest invoice regardless of remittance, chronic small residuals | Lapping or systematic misapplication; every hit is a file to pull |
| Rebate agreement coverage | Rebate agreements, accruals, settlements, customers | Accrual and settlement activity for customers with no signed agreement on file; settlements above the agreement’s rate | Rebates managed from memory; an accrual that cannot be supported |
| Write-off-then-order | Write-offs, orders, credit holds | Customers written off who order again within N months, and whether a hold applied | Write-offs used to clean the aging; credit control not informed |
Worked example: MidState Beverage’s order-to-cash audit
MidState Beverage, the three-state drinks distributor used across this site, has twelve depots, three hundred routes, about 31 million dollars a year of cash and cheques collected by drivers, a 2013 ERP, two acquired distributors integrated for revenue but not for controls, and a six-person internal audit function. Its FY27 route cash audit had dealt with the depots’ handling of cash and found, among other things, the routing rule that let the user who entered a route-cash adjustment approve it. The FY28 plan added an order-to-cash engagement to look at everything that happens before and after the driver hands over the money: 2.6 million delivery invoices to 9,800 retail accounts, about 410 million dollars of revenue, 6,100 accounts on credit terms and the rest on delivery, 48,000 credit memos, and a rebate program with the larger retail chains. It was budgeted at 360 hours, ran to 380, and used the route cash and cash audits’ data as its first layer.
| Test | What it found | Disposition |
|---|---|---|
| 1. Chain walkthrough | Head office and the ten legacy depots ran one process; the two acquired distributors’ depots still took orders on their old handhelds and settled routes on a spreadsheet, with credit memos raised by the depot office. | RCM redrawn with the acquired depots as a separate process |
| 2. Customer master | 240 customer records created in the year by sales representatives who could also raise credits against them; 61 limit changes with no approval record, all at the acquired depots. | Segregation inside finding 5; limits inside finding 3 |
| 3. Credit hold releases | 2,140 accounts exceeded their limit at some point in the year; 610 holds released, 388 by depot managers rather than credit; 61 orders shipped over limit with no release at all. | Finding, Medium: credit control theater |
| 4. Pricing compliance | 0.4 percent of invoice lines below the price file without an approved deal, 190,000 dollars of unapproved discounting concentrated in three representatives in one region; two promotions still invoicing at promotional prices five and seven weeks after their end dates. | Finding, Medium; the three representatives routed to sales management |
| 5. Credit memos | 48,000 credit memos; 2,300 approved by the issuing representative; 610 with no return receipt or pricing claim behind them, 410,000 dollars, concentrated in fourteen accounts served by two representatives. | Finding, High: credit memo control; the concentration referred under the protocol |
| 6. Fulfillment to invoice | Proof of delivery missing on 3 percent of invoices overall and 11 percent at two depots, both acquired; the sample re-performed from delivery records agreed in 38 of 40. | Finding, Low |
| 7. Cash application | 3,900 unapplied receipts older than thirty days, 1.2 million dollars; at one acquired depot the application pattern analytic found fourteen accounts whose postings alternated for five months, corroborated as a settlement clerk covering a 28,600-dollar shortfall with later customers’ payments. | Referred under the protocol on day six; substantiated; kept out of the report; finding, Low, on unapplied cash aging |
| 8. Rebates | 25 agreements sampled from the accrual schedule; 12 had no signed agreement on file; the accrual of 4.2 million dollars was understated by 310,000 dollars against the rates the chains had confirmed. | Finding, Medium: rebate agreements and accrual |
| 9. Collections | Escalation evidenced for 21 of 25 overdue accounts; the dispute log existed only at head office. | Observation |
| 10. Allowance | Formula unchanged since 2019; coverage of balances over ninety days had fallen from 52 to 38 percent while those balances grew from 1.9 to 2.9 million dollars. | Finding, Medium: allowance method |
| 11. Write-offs | 214 write-offs, 890,000 dollars; 31 approved below the required level, 140,000 dollars; nine written-off customers ordered again within six months without a hold. | Finding, Medium: write-off approvals and the credit block |
| 12. Cut-off | At the June and December quarter ends, 1,100 deliveries in the last two days invoiced in the next period, 410,000 dollars; credits in the first week of January against December invoices at the historical rate. | Finding, Low |
| 13. Segregation from access | Nineteen users at the acquired depots held order, credit memo and cash application rights together; none at the legacy depots. | Inside finding 5 |
| 14. Monitoring and prior findings | The route cash actions re-tested on the final quarter: the routing rule fixed and holding, no self-approved overrides; the three spreadsheet depots’ integration funded by the audit committee after the cash audit and scheduled; no order-to-cash analytics run by anyone before this engagement. | Route cash actions verified; monitoring pack recommended |
The report carried nine findings, one High, five Medium and three Low, an overall rating of Needs Improvement, and one referral handled outside it. The High finding was the credit memo control, and it was written as a control finding with numbers: 2,300 credits approved by their issuer and 610 unsupported credits worth 410,000 dollars, against 48,000 credits and 410 million dollars of revenue, which is 0.1 percent of revenue and 100 percent of the mechanism a diverted receipt would use. Three things about the engagement generalize. Almost every finding concentrated at the two acquired depots, which is what “integrated for revenue but not for controls” means when it is finally tested: the revenue was real, the process producing it was not the one the policy described. The lapping matter was small, found by an analytic that costs an hour, and would have been invisible to the cash audit, which reconciled the depot’s bank account correctly because the deposits were correct; the money moved between customers, not out of the bank, and only the application pattern showed it. And the allowance finding, the least dramatic in the report, was the one that reached the annual accounts: the external auditor had accepted a formula for six years because nobody had tested whether the aging it was applied to had changed shape.
The findings that recur, and wording that lands
Order-to-cash findings carry the same hazard as travel and expense findings: the data has names on it, and most of the names belong to people selling under pressure rather than stealing. Write the finding about the control, give every number its denominator, and route the people-level items through management or the protocol. The two below recur in most integrated engagements, in the five-Cs form.
Credit memo control. Condition: of 48,000 credit memos issued in the year, 2,300 were approved by the representative who issued them, and 610 credits totaling 410,000 dollars carried no return receipt, pricing claim or approved concession; the unsupported credits were concentrated in fourteen customer accounts served by two representatives at the acquired depots. Criteria: the credit policy requires every credit memo to be supported by a return, a claim or a documented concession, and approved by someone other than the issuer at a level set by amount. Cause: the acquired depots’ order system carried no approval routing for credits, and the migration that integrated their revenue into the ERP did not integrate the credit workflow. Consequence: 410,000 dollars of unsupported reductions in receivables, 0.1 percent of revenue, and a mechanism through which a diverted customer payment could be concealed indefinitely. Corrective action: management will route the acquired depots’ credits through the ERP workflow by the end of the quarter, block issuer approval system-wide, and review the fourteen accounts with the representatives’ management; internal audit will re-run the credit-to-return join monthly for two quarters.
Allowance method. Condition: the allowance for doubtful accounts has been calculated with the same percentages by aging bucket since 2019; over that period balances older than ninety days have grown from 1.9 to 2.9 million dollars while the allowance’s coverage of them has fallen from 52 to 38 percent, and the method has not been re-based against actual loss history. Criteria: the accounting policy requires the allowance to reflect expected losses using current aging and historical experience, reviewed annually. Cause: the annual review was a sign-off on the formula’s output rather than a test of the formula against experience. Consequence: an allowance that is likely understated by an amount within the range of 300,000 to 450,000 dollars on the audit’s re-performance, and a receivables balance the audit committee is relying on with less support than it assumes. Corrective action: the controller will re-base the method on three years of write-off history by the year-end close and document the annual review as a re-performance; internal audit will observe the first re-basing.
Scoping variants: route and cash businesses, subscriptions, projects, marketplaces
Route and cash businesses, distributors, field services and retail, add a link to the chain between fulfillment and cash application: the settlement, where a driver or a store reconciles what was sold to what was collected. The settlement is where skimming lives, and the integrated audit treats it as handoff 3.5: settlement variances by driver, cash-sale ratios by route, and deposit lag by depositor are the analytics, and the cash and bank reconciliation guide covers the bank side. Subscription and software businesses move the risk from delivery to entitlement and from cash to deferred revenue: the handoffs that matter are contract-to-billing (is every active entitlement being billed, and at the contracted price), usage-to-invoice where pricing is metered, and billing-to-deferral, with the revenue recognition guide‘s five steps as the criteria. Project and construction revenue replaces delivery with progress: the handoff is between the project manager’s estimate of completion and the invoice, and the audit tests estimates-to-complete, change orders and retention rather than proof of delivery. Marketplaces and platforms carry a third party in the chain, the seller or the payment processor, and the integrated audit adds the settlement reconciliation between the platform’s records, the processor’s statements and the bank, with the processor’s SOC 1 report read the way the SOC 1 method describes. In every variant the discipline is the same: name the handoffs, test the assumptions, and write the findings to the chain.
Where to go next
Run the fragment audits for depth and the integrated audit for the handoffs, in the same rotation the procure-to-pay guide recommends for the other side of the business: the chain every year, one link in depth on top of it, chosen by the hits. Build the matrix from the twelve controls, walk the process at a site before trusting the policy, let the joins choose the files, and finish with the estimates, because the allowance and the rebate accrual are where the chain’s leakage reaches the accounts. When a hit clusters on a person, the first 48 hours protocol takes over; when the numbers themselves look managed, the financial statement fraud guide explains which of the five mechanisms is in play.
Related guides
- How to audit accounts receivable and collections — the back half of the cycle, with Brightwater’s worked engagement
- How to audit revenue recognition — the five steps, the assertions and the back-tests
- How to audit cash management and bank reconciliations — where the cash lands, with MidState’s 23 accounts
- How to audit inventory — the stock the orders draw down, with MidState’s twelve-depot count
- How to audit procure-to-pay end to end — the mirror-image integrated audit
- Financial statement fraud — the revenue mechanisms, with Pennine’s quarterly program
- The ACFE fraud tree explained — skimming, lapping and the receivables schemes in context
- When internal audit finds fraud: the first 48 hours — the protocol the lapping referral followed
- The fraud red flags library — the revenue cycle’s indicators, organized for triage
- How to run a fraud risk assessment — where the order-to-cash schemes sit in MidState’s register
- The risk and control matrix template — where the chain matrix lives
- Writing the audit work program — the five-element procedure standard the 14 tests follow
- The sampling memo template — recording the stratification decisions
- Segregation of duties beyond the ERP — order, credit, cash and credit memo rights kept apart
- How to review a SOC 1 report — the processor’s assumed controls in a marketplace
- The 5 C’s of audit findings — the form the two findings above are written in
- The finding and issue log template — tracking nine findings across sales, operations and finance
- Fieldwork and testing guides and internal controls guides — the full collections
Leave a Reply