Skip to main content
DoneThat

AI Adoption GuideFinanceBudget

Budget anomaly flagging

ML detects line items deviating from prior-period patterns and seasonality, using tools like Datarails or Vena Copilot.

Finance processPlanBudgetInvoiceCollectPayCloseReportAudit

By Don, DoneThat’s AI coach · updated

What a usable flag has to name

A budget anomaly flag earns a place in the packet when it names three things in one place: the line item, the prior periods used as the baseline, and the pattern those periods were treated as. A cost-center owner can then explain the line, or FP&A can drop the flag. A number with no cite is not a flag. It is a nudge that cannot be audited.

The job is quality on an existing budget, not a rewrite of it. The system does not invent a variance percent. If history is too thin to support a pattern, the output stays empty. FP&A still owns the budget.

This check sits next to other budget quality work. A zero-based budget challenger asks whether a line should exist at all. A variance report with driver attribution explains a gap after the period closes. Anomaly flagging happens while the budget is still being built, and it only speaks when the history is thick enough to justify the sentence.

Freeze prior actuals before the model looks

Lock the actuals the model is allowed to see, then freeze them. Use closed periods only. Do not let in-flight actuals, restatements, or the current draft budget leak into the baseline. If the baseline moves while reviewers are arguing a flag, the cite is already stale.

Record the freeze as part of the flag: which ledger, which entity, which periods, which mapping of accounts to budget lines. When a mapping change splits or merges a line, treat that as a break in history, not as a seasonal swing. The model should see the same line the owner will see in the packet.

Platforms that already hold the budget and the actuals, including Datarails, Vena, Anaplan, and Workday, are a class of places this freeze can live. They are not a second budget owner. They do not accept the flag. They can surface a deviation against the frozen series. FP&A still decides whether the line stays, moves, or needs a note.

Do not invent seasonality in the freeze. Seasonality is a pattern you can point at in the frozen series: the same months, the same peak, the same trough, across enough years that a reviewer can see it without a model. If you only have a handful of months, you do not have seasonality. You have a short series. Flagging against an invented seasonal shape is a failure mode that looks sophisticated and wastes the owner's time.

Flag the deviation with the cite attached

Run the comparison only after the freeze. For each budget line, ask whether the proposed amount, or the recent actuals feeding the proposal, departs from the pattern in the frozen series. If it does, write the flag as a cite, not as a score.

The cite should be readable in one pass: line name and account, the prior periods compared, and the pattern used (level, trend, or a seasonal shape that is visible in those periods). If the model cannot name the pattern in words an owner would recognize, do not ship the flag.

Leave the cell empty when history is thin. A new cost center with no closed actuals is the usual case. There is nothing to compare. Flagging it as an anomaly pretends the absence of history is a signal. It is not. Route that line to a different check if the question is whether the spend should exist, or how it should be classified, rather than whether it broke a pattern.

Do not fill the empty with a made-up variance percent. Percent of what: of last year, of a seasonal index you invented, of a peer line the mapping does not support? If you cannot cite the denominator, you do not have a variance. You have a guess.

A facilities line that broke its own calendar

Take a facilities line that, in the frozen actuals, is high in the same two months each year (maintenance windows) and otherwise sits in a narrow band. The draft budget for the coming year is flat across all twelve months at a level that matches the quiet months, not the maintenance months.

The flag names the line, names the closed years and months used, and names the pattern: a two-month seasonal peak visible in those periods, not a generic seasonality label. It does not say the line is over or under by a percent. It says the draft does not follow the pattern the actuals show.

The facilities owner can then explain. Maybe the maintenance window moved to a vendor contract that is now in another line. Maybe the work was capitalized and should go through a capex vs opex classifier before it is treated as run-rate. Maybe the peak is real and the draft is incomplete. The flag did not decide. It cited.

That is the whole example. No savings figure, no model accuracy claim. The value is that the packet contains a sentence a reviewer can check against the same actuals.

Owner explains, then FP&A accepts

Send the flag to the line owner with the cite intact. The owner writes an explanation against that cite: reclass, one-time, timing, volume, or that the pattern still holds and the draft is wrong. The explanation attaches to the line, not to a dashboard tile.

FP&A accepts or rejects the flag as a quality item on the budget. Accepting means the explanation is sufficient, or the draft is updated, or a note stays on the line. It does not mean the amount is cut. Treating the flag as a cut is a failure mode that turns a quality check into a savings target. A line can be anomalous and still correct: a new lease, a stepped contract, a hiring plan that has no prior-year twin. Cutting on the flag punishes the owner for having a cite.

If the owner cannot explain and the pattern still holds, FP&A can send the line back. That is still ownership of the budget, not automation of it. Related spend questions, such as whether a vendor line is out of family with similar vendors, belong on a vendor spend benchmark, not on this flag.

After close, the same line may show up again when you write a variance report with driver attribution. That report explains what happened. This page is only about whether the budget, as submitted, broke a pattern the actuals already showed.

Empty stays empty, and the budget stays with FP&A

Refuse flags with no line, no periods, or no named pattern. Refuse flags on new cost centers and other thin history. Refuse seasonal claims that are not visible in the frozen series. Refuse variance percents the system invented to look complete. Refuse any workflow where the flag auto-reduces the budget.

The owner explains. FP&A accepts. The packet either contains a cite a reviewer can check, or it contains nothing. Both are valid. Silence is the correct output when the history cannot support the sentence.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first