Skip to the guide

Continuous Audit & Anomaly Detection — User Guide

Case 04 · Internal Audit · Rutherford Advisory Group
Case 04 · Internal Audit

What decision does this actually settle?

Rutherford Advisory Group is a fictional $285M professional-services firm generating 18,600 card and expense transactions a month. A four-person audit team can inspect about 5% of them after the quarter closes — enough to find a bad receipt, not enough to connect three sub-$1,000 charges made eleven minutes apart. The model doesn't decide that anyone committed fraud. It screens all 18,600, links the transactions that only look separate, and holds the high-confidence ones before the card settles.

Who uses itInternal audit, corporate card program owners, controllers
WhenPre-settlement, continuously — not a quarterly sample
Playbook versionExpense & Card Playbook — v2026.8
Quick start

From a live feed to a held transaction

Compare the two modes first

Traditional 5% sample (post-quarter, ~45-day lag) versus 100% continuous screening (pre-authorization, human review) — the toggle above the workbench is the whole argument in one control.

Inject the next event

Feeds a new transaction into the stream, scored against policy, timing, merchant, and behavioral context as it arrives.

Filter by status

All / Held / Review / Cleared, or jump straight to the two patterns the case brief walks through: Split purchase and Duplicate.

Open a flagged transaction, e.g. MetroTech Store TXN-88214

Shows the linked events — same amount, same eleven-minute window, or a receipt hash matching one already on file.

Send to reviewer or keep the simulated hold

A hold pauses settlement, it doesn't accuse anyone. Fraud determination and any employee action stay with a person.

Screen map

What each part of the workbench is for

AreaWhat it showsWhere the decision happens
Mode bar5% quarterly sample vs. 100% continuous screening, side by side.Sets the frame for everything below — this is the case's core argument, not a filter.
Feed panelThe live transaction stream with status and pattern filters.Pick which flagged event to open.
Detail panelThe linked transactions behind one flag, with amounts, timestamps, and receipt evidence.Send to reviewer or keep the hold — nothing here is a fraud finding.
Download audit packetExports held and reviewed items with their linked evidence.Hand this to the person who makes the fraud determination.
Reading the output

Three numbers, in order of usefulness

MetricWhat it meansWhat to do about it
Transactions reviewed5% under quarterly sampling — the baseline this case exists to change.Compare it against 100% continuous screening in the mode bar, not against an assumed "good enough" rate.
Monthly spend$2.85M across 620 cardholders and 18,600 transactions.Use it to size the audit team's actual coverage gap, not just the transaction count.
Confidence scoreHow strongly linked events match a known pattern — split purchase, duplicate receipt, prohibited merchant.High confidence is a reason to hold before settlement; it is not a verdict.
Use cases

Three questions this actually settles

"A $2,940 purchase turns into three $980 charges, each under the $1,000 approval threshold. Does anyone catch that?"

Individually each charge looks ordinary. The model links them by cardholder, amount pattern, and an eleven-minute window — which a quarterly sample would never see together.

"The same hotel receipt shows up in a card reconciliation and an expense report under two different filenames. Is that duplicate reimbursement?"

The receipt image hash matches even when the filename doesn't — that's what the Duplicate filter is built to catch.

"By the time the quarterly sample finds a bad receipt, is recovery even still possible?"

Compare the held-before-settlement flow against the post-quarter, ~45-day-lag baseline in the mode bar — that gap is the actual cost of sampling.

Pitfalls

Where this breaks if you push it too far

A held transaction is a review priority, not proof of fraud. Treating a hold as a finding before a person reviews it is exactly the failure mode this model is built to avoid.
Pattern linking is only as good as the behavioral history it has. A genuinely new employee or a first-time vendor will generate more false positives until the history builds up.
Inputs & outputs

What goes in, what comes out

Detail
InputA pre-loaded illustrative transaction stream for 620 cardholders — no payment system connection.
Agent outputPattern grouping, anomaly score, a temporary-hold recommendation.
Stays with a personFraud determination, employee action, recovery, card suspension.