Audit, segregation of duties and the controls you already have
What the sector will not let an agent do.
The reason finance automation projects stall is rarely accuracy. It is that nobody can explain the control environment afterwards. This is how each control survives the deployment.
- Segregation of duties
- The agent prepares and a person approves, which is the separation your auditors already expect between the person who enters and the person who authorises. The agent holds no approval authority, and the log records both sides of every transaction.
- An audit trail that stands up
- Every action is logged: what ran unattended, what waited for approval, who released it, what escalated and which version of the rules applied. The trail is built as the work happens rather than reconstructed when an auditor asks.
- Payment release and delegation of authority
- Nothing is paid by an agent. Payment release stays with a person under your existing delegation limits by default, and we would advise leaving it there permanently however accurate the matching becomes.
- Supplier fraud and changed bank details
- A change to a supplier's bank details is a stop condition, not a field to be updated. It is flagged, held and routed for out-of-band verification by a person, because that specific change is where the loss actually happens.
- Tax and statutory accuracy
- GST treatment, coding rules and statutory positions are captured during solution design and applied consistently, but the return is lodged by a person. The agent escalates what falls outside the rules rather than guessing at a treatment.
This is a description of how the deployment is built, not legal, financial
or compliance advice. Your own obligations should be confirmed with your
own advisers.
The security page
sets out hosting, model choice, retention and access in full.