Skip to main content
DoneThat

AI Adoption GuideFinanceAudit

Control-evidence retrieval agent

Agent pulls evidence from connected systems on demand for control tests and walkthroughs, using tools like AuditBoard.

Finance processPlanBudgetInvoiceCollectPayCloseReportAudit

By Don, DoneThat’s AI coach · updated

Pull the packet by control ID

The tester names a control ID, a period, and the artifacts the test or walkthrough requires. The agent queries only connected systems and returns a packet. It does not hunt a shared drive for a screenshot, and it does not decide whether the control operated.

Keep the request small. Control ID (for example AP-C-014), period (month or fiscal quarter), and a short artifact list: population extract, sampled invoices, three-way match records, access listing for the approver role, and the latest completed reconciliation for the related GL. The same request works whether the file will land in AuditBoard or in a workpaper folder. The GRC tool is a destination class, not a retrieval engine.

What comes back is an evidence packet, not a test result. Each item either carries a cite the tester can re-run, or it is blank. Blank means the source was not connected or the query returned nothing. The agent does not fill that cell.

Finance evidence usually sits across more than one system of record. Transaction and match data may live in SAP or Workday. Period-close support may live in BlackLine. Issue tracking and PBC lists may live in AuditBoard. The agent treats those products as a class of connected sources. It does not invent a connector that is not there.

If the control narrative is still in draft, retrieve first, then write. Pair this page with SOX control narrative drafting so the story and the cites stay aligned.

What every cite must carry

A usable line in the packet names four things: the control ID the tester asked for, the period that bounds the query, the system that answered, and a locator a second person can use to pull the same record. The locator can be a report name plus parameters, a document ID, a journal number, or an extract timestamp. A file dump with no locator is not a cite.

Cite the system that actually returned the row. If the invoice sat in SAP and the reconciliation sat in BlackLine, those are two lines, not one blended source. Do not label the GRC workspace as the system of record because that is where the tester will file the packet.

Period has to match the test window. A Q2 walkthrough is not supported by a Q1 extract, even if the control ID is right. If the connected system can only return a wider window, the packet should say so in the cite rather than silently trimming rows.

The packet may group items the way the test program does: population, sample, configuration or access, and period-end support. Grouping is a filing aid. It is not a conclusion that the sample was sufficient.

Do not attach a screenshot the agent did not retrieve. A mock UI capture or a regenerated PDF of a wet-ink form is not evidence. If the imaging or e-sign system is not connected, that slot stays empty. The tester still has to conclude from what is present, including the gap.

Empty stays empty

Unconnected is a first-class outcome. If Workday is connected and the imaging archive is not, invoice headers can populate and the signed approval image cannot. The packet shows a blank for the image, with a cite that names the missing source class, not a substitute file.

Do not fill a missing source. Filling is the failure mode that looks helpful in the moment and fails in review. Typical fills include pasting a prior-period PDF, grabbing a screenshot from a colleague's laptop, or asking a model to show what the approval screen would look like. None of those belong in the packet. A blank says we did not pull this. A fill says this existed and we saw it.

Do not invent a sign-off. If the workflow table has an approved flag and no named approver, the cite is the flag and the table, not a person inferred from an org chart. If the reconciliation in BlackLine has no preparer/reviewer pair for the period, the packet does not mint names. The tester records exception or scope limitation in the workpaper.

Empty also applies when the system is connected and the query is empty. A control that should have produced twelve match records and produces zero is not a cue to widen the period until something appears. Return zero with the cite. The tester decides whether zero is a population fact, a mapping error, or a control failure.

Tools that review workpapers can flag a cite that does not match the period, a blank that was overwritten, or a conclusion that claims a document the packet never contained. They cannot repair a filled gap.

Walkthrough packet for AP-C-014

AP-C-014 is a three-way match control over vendor invoices. The Q2 walkthrough asks for: the control ID and owner as recorded in the GRC tool, the in-scope vendor invoice population for June, three invoices from that population with PO and goods-receipt references, the match status in the ERP, the approver's access listing, and the June reconciliation of the AP subledger to the GL.

The tester sends one request: control AP-C-014, period June (Q2), artifacts as above. SAP is connected for invoices, POs, receipts, and match status. Workday is connected for the approver role listing. BlackLine is connected for the AP-to-GL reconciliation. AuditBoard is where the packet will be filed. The invoice imaging system is not connected.

The packet that comes back has cites on every SAP row (system SAP, period June, control AP-C-014, document numbers and match-run ID). It has a Workday cite on the role extract (report name, as-of timestamp). It has a BlackLine cite on the June reconciliation (account, period, template ID). The imaging slots for the three invoices are blank, each annotated as source not connected. There is no generated stamp and no copied image from last year's walkthrough.

The tester uses that packet in the walkthrough. They can confirm that the three invoices exist in the population, that match status is what SAP recorded, and that the named approver sat in the Workday role at period end. They cannot confirm the imaged signature because that source was empty. They write the walkthrough conclusion themselves, including the limitation, and they do not treat the assembled packet as a pass.

If the tester also wanted a risk-ranked look at the full June invoice population, retrieval gets the extract with a cite. Ranking belongs with full-population transaction risk scoring, not inside the evidence agent. If AP-C-014's period-end support is the reconciliation itself, keep the BlackLine cite next to the account reconciliation agent so tie-out and evidence pull do not drift apart.

Retrieval is not the test

A complete packet can still sit under a failed, qualified, or not-tested conclusion. Completeness of retrieval means the connected systems answered and the blanks are honest. Operating effectiveness is a tester judgment against the procedure: attributes, sample size, timing, and whether compensating evidence is allowed.

Treating retrieval as the test is the second failure mode. It shows up as workpaper language like "evidence obtained, control passed," with no attributes checked. The agent pulled invoices. It did not inspect three-way match fields, duplicate payments, or whether the approver was independent of the requestor. Those steps remain human. Filing the packet in AuditBoard does not complete them.

The third failure mode is a sign-off the packet never supported. Do not let the agent append reviewed-and-approved language because a workflow status was green. Do not let it close the PBC item because every connected slot was full. Sign-off is a person with a date, after they have read the blanks as well as the cites.

Use the packet as the exhibit list for the test. Line up each procedure step to a cite or to an explicit blank. Where the step cannot be performed, the tester records the limitation. Where it can, they record attributes, exceptions, and the conclusion in the workpaper, not in the retrieval log.

Reviewers should look for three mismatches: a conclusion that cites a screenshot or sign-off the packet does not contain, a period on the exhibit that is not the period on the request, and a source label that names the GRC file instead of SAP, Workday, BlackLine, or whichever system actually answered.

Keep the packet tied to the rest of the file

Request by control ID. Retrieve with system, period, and control cites. Leave unconnected and empty-query slots blank. Let the tester conclude.

That sequence is the quality bar. The packet is only as strong as the connectors behind it. Adding prose, images, or names to cover a missing connector does not raise quality. It hides the gap.

When the file moves, keep the same IDs. The control ID on the packet, the narrative, the reconciliation, and the workpaper review notes should match. If they do not, stop and fix the identifier before you debate whether the control passed.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other. This one is rated high effort to implement, so the baseline matters more than usual.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first