API Query Hub
Client stories
What controllers and internal auditors say after a financial audit of their expense management applications — including the awkward bits.
We asked for a full audit of our main expense application after a messy year of card migrations. The sample pulled out weekend approvals that never hit the secondary reviewer. The letter was blunt about our threshold settings — which we needed, even if it stung.
The sampling review between our annual cycles caught a cluster of split taxi claims that our policy technically allowed. I would have preferred a faster turnaround on the draft memo, but the exception log was tidy enough to hand straight to AP.
Their policy-and-configuration assessment showed that our written entertainment limit and the application’s dropdown limit had drifted by nearly a third. No drama, just a gap matrix our administrators could fix before peak travel season.
Extended story: hospitality group, multi-entity claims
A regional hospitality group running three legal entities through one expense application asked us to examine a twelve-month population after a new per diem schedule. Fieldwork combined four days at their Pathum Wan office with remote extract testing.
We found that property-level managers could still select the old per diem category for international trips, and that card feed postings for two properties bypassed the claim match step when the feed arrived after month-end close. The management letter ranked the card-feed timing issue highest because it affected ledger completeness, not only policy optics.
Remediation sat with the client’s AP lead and application administrator. We were not asked to implement changes — and would have declined if we had been, to keep the next year’s audit independent.
Extended story: manufacturing controller after a tool switch
Six months after moving travel claims into a new application, a manufacturing controller wanted comfort before the audit committee pack. Our full application audit walked a claim from mobile receipt capture through to the ERP batch.
The awkward finding: duplicate mileage entries were possible when staff submitted both a card charge and a reimbursement for the same journey, because the match rule only looked at merchant name, not date-plus-amount. The controller already suspected something; we gave her the sample evidence to take upstairs.