API Query Hub
How an engagement runs
From scoping workshop to management letter — the practical sequence of a financial audit of expense management applications.
Why we publish the sequence
Controllers deserve to know what the next eight weeks look like before they open access to claim data. This page describes how API Query Hub runs a typical full financial audit of expense management applications. Sampling reviews and configuration assessments follow a shorter version of the same path.
1. Scoping workshop
We confirm applications, entities, review period, and known pressure points. You leave with a draft population list and a list of access we will need (read-only extracts, policy PDFs, organisation chart for approvers).
2. Engagement letter
Scope, exclusions, fee, deposit, and fieldwork window are written down. Work does not start until the letter is signed and the deposit clears.
3. Access and sample design
We size the sample by claim type, amount band, and geography. Your AP contact receives a dated request list so extract pulls are not a surprise.
4. Fieldwork
Walkthroughs of live claim cycles, testing of selected items, and interviews with approvers. Site days in Bangkok are scheduled; remote testing continues between visits.
5. Draft findings
We share a draft with your finance lead to correct factual errors — not to negotiate ratings. New evidence can adjust a finding; unexplained disagreement is noted.
6. Management letter
Final letter, sample appendix, and a short briefing if requested. Remediaton belongs to your team; we remain available for clarification questions for thirty days after delivery.
What we need from you
- Named contact in finance and in application administration
- Population extract for the agreed period
- Current expense, travel, and card policies
- Timely access to receipt evidence for sampled claims
Natural next actions
Browse audit scopes or request an estimate with the applications you run and the period you want examined.