Back to Glossary

Entry · Accounting

Continuous Auditing

Continuous auditing uses technology and frequent or ongoing tests to help auditors assess transactions, controls and risks closer to when activity occurs. Rules can flag duplicate payments, unusual access or transactions outside approval limits for review. It does not mean a human has independently audited every transaction in real time or that an annual audit disappears.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A periodic audit may sample past transactions after a quarter or year, whereas a continuous audit programme can run checks daily, weekly or after each data update and then ask an auditor to investigate exceptions. The Institute of Internal Auditors describes continuous auditing as technology-enabled ongoing assessment of risks and controls and distinguishes it from management's continuous monitoring.

Management owns day-to-day control operation and correction, while internal audit assesses whether those controls work and reports independently under its charter. Start with a risk and an assertion; for supplier payments, an audit team might test duplicate invoice numbers, payments to new bank accounts soon after a vendor change, or payments above the approval threshold.

Each rule needs a reliable source, clear scope and owner. Test it on known examples, then document what it catches and what it misses, since exact-match rules can miss modified invoices.

Data completeness is a major limitation: if a subsidiary's transactions are not in the feed, a clean dashboard says nothing about that subsidiary, and if timestamps or approval fields change in a system migration, false alerts may spike or a critical test may silently stop working. Reconcile the number and total value of records processed with the source, manage access to data and watch for failed jobs.

Preserve evidence so findings can be reproduced. Set thresholds to reflect the business, because a rule that flags every payment above $100 may swamp reviewers while one that flags only exceptionally large amounts can miss systematic small fraud.

Segment by supplier type, country or period when relevant, but keep rules explainable. Sampling and professional judgement still matter for risks not captured by structured data, such as pressure on staff or a misleading contract.

An exception is a prompt for investigation, not proof of fraud, since a legitimate urgent payment may look odd while a sophisticated abuse may fit the rule. Assign ownership, record triage decisions, escalate serious findings and verify that fixes actually occur.

Track both false positives and true issues so the team improves thresholds, and do not close an alert merely because the volume makes a dashboard look bad. ISACA's retail-lending example combines rule-based assurance with monitoring outcomes, and it is a use case, not a requirement for machine learning.

Small teams can begin with a few repeatable high-risk checks and expand as data improves, but testing every transaction for one rule does not guarantee sound controls or prevent fraud. Explain which records, dates, tests and gaps the work covered, because external audits and formal opinions retain their own scope; for owners, ask what is tested, who investigates and what gets fixed, since frequent checks help only if someone owns the findings and data remains trustworthy.

In practice

Real-world examples.

1

Example

Internal audit checks new supplier bank details against the first payments made after each change and reviews flagged cases weekly. A payment to an account changed only two days earlier is escalated to the payables manager for confirmation. The supplier confirms the change by phone using a number already on file, and the case is closed with a note.

2

Example

A system scans expense claims daily for duplicate receipts, and an auditor tests alert accuracy and follows up with management. In a sample of 40 alerts she finds that 30 are genuine duplicates and 10 are separate purchases from the same shop. She asks the team to refine the rule so that reviewers spend their time on likelier problems.

3

Example

A monthly audit dashboard shows no exceptions, but the team discovers one branch's data feed failed and withdraws assurance for that branch. The clean result had simply reflected missing data. The branch is retested once the feed is repaired.

Formula

Calculation

Exception rate = Flagged transactions / Transactions actually tested x 100 Worked example. A fictional weekly payment test processes 12,000 transactions and flags 60. The exception rate is 60 / 12,000 x 100 = 0.5%. This is not a fraud rate, because some alerts may be legitimate and untested risks may remain. Workload check. If each flag takes a reviewer 20 minutes to triage, 60 flags need 60 x 20 = 1,200 minutes, or 20 hours, of review time. If the team tightens the rule so only 36 of the same 12,000 transactions are flagged, the exception rate falls to 0.3% and the review time to 12 hours, but the team must also check that the tighter rule has not started to miss real problems. Report the population, period and rule alongside the percentage.

Case study

Seen in the real world.

This illustrative and entirely fictional example follows Crescent Supplies, an invented distributor. Its internal audit team ran a weekly duplicate-payment rule over headquarters data. The rate fell, and managers assumed the control problem was solved. An auditor reconciled processed records to the ledger and found a branch's invoices had stopped feeding the test after a software update.

The team restored the data, documented the gap in coverage and retested the period. Several exceptions required review, but none was automatically called fraud. Management corrected one weak supplier-approval process and the audit team checked the next cycle. The case shows why a clean alert count without completeness checks can be misleading.

Crescent then added a standing completeness check to the weekly run. Each branch's record count and total value is compared with the ledger before the duplicate-payment rule runs, and the audit lead is alerted if any branch is missing or more than a small tolerance out. The check takes minutes to review and protects the credibility of every later result.

Watch out

Common mistakes.

  • Calling management's automated monitoring an independent audit without assessing roles and scope.
  • Treating every flag as fraud or zero flags as proof that all transactions are sound.
  • Failing to reconcile source data, assign alert owners and document follow-up.

Questions

People also ask.

Does continuous auditing replace an annual audit?

No. It adds frequent assurance tests within a defined scope; other audit duties remain.

Must tests run every second?

No. The frequency should fit the risk and data, whether event-driven, daily or weekly.

Is the exception rate the fraud rate?

No. It measures rule-based flags among tested records, not confirmed misconduct.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.