Continuous assurance

Fintra reviews every transaction. You only touch the exceptions.

Auditors test a sample, once a quarter. Fintra tests every control against your entire transaction population, continuously - and the moment one fails, it opens an exception with a tamper-evident receipt mapped to the exact SOX 404 control. Continuous controls, not a spreadsheet at year-end.

population · not sample·20 SOX 404 objectives·tamper-evident receipts·auditor portal
The 2 AM problem

Controls fail quietly. You find out at the worst time.

A payment goes out with one signature instead of two. A journal entry books to the wrong period. A vendor's bank details change the week before a large run. In most companies none of this surfaces until an auditor pulls a sample months later - or a board meeting is on Monday and the books are three months behind. Sampling is blind to everything it did not sample.

Fintra flips it: the control runs against every transaction, continuously, so the exception is on someone's desk the same day - with the evidence already sealed.

Sampling

Tests ~25 of 2,400 items, once a quarter. A breach outside the sample is invisible.

Spreadsheet controls

A control matrix in Excel that nobody re-tests between audits.

Fintra continuous controls

Tests all 2,400, every day. Only the failures surface, each with a receipt.

The continuous-controls loop

Declare it once. It tests itself forever.

Every control is a full-population sweep on top of the same Control Tower governance and hash-chained evidence ledger that Fintra uses to govern live money movement. Steps 3 through 6 are real and recomputable - that honesty is the point.

01
Declare

Set a control once - a spend ceiling, a two-signature rule, a three-way match, segregation of duties. One of nine control kinds, built on the Control Tower that governs every money move.

9 control kinds
02
Sweep

Fintra tests it against the entire transaction population - not a sample - on every run, and again the moment new activity posts.

population · not sample
03
Except

Passing items stay silent. Each failure opens an Exception ranked by financial exposure and routed to an owner.

ranked by exposure
04
Seal

The failure is written append-only to a per-org hash chain as a tamper-evident receipt - the same ledger the Control Tower verifies.

sha256 · chain-linked
05
Map

The receipt is linked to the exact SOX 404 control objective it violates, with its COSO component.

SOX-CA-02
06
Verify

Recompute the chain end to end. An auditor can prove, through a time-boxed portal, that nothing was altered.

chain intact ✓
SOX 404, continuously

A COSO-mapped 404 program that tests itself.

Twenty canonical control objectives, mapped to the five COSO components. Thirteen run as live tests against real transaction populations today; the rest are the entity-level and attestation controls a human owns. We would rather show you the split than imply the whole thing is automated.

Control Environment

3objectives
1 wired live

Segregation of duties · tone at the top · audit committee

Risk Assessment

1objective
0 wired live

Fraud risk assessment

Control Activities

14objectives
10 wired live

Dual approval · 3-way match · JE review · period cutoff · bank recon · close checklist

Information & Communication

1objective
0 wired live

Audit-trail integrity

Monitoring

1objective
1 wired live

Management monitoring of exceptions

Running live today
SOX-CE-03Segregation of duties

no single person initiates and approves

SOX-CA-02Dual approval on payments

two signatures over the threshold

SOX-CA-03AP three-way match

PO · receipt · invoice reconcile

SOX-CA-04Revenue three-way match

order · fulfillment · invoice

SOX-CA-01Journal-entry review

material and manual entries reviewed

SOX-CA-05Period cutoff

transactions land in the right period

SOX-CA-06Bank reconciliation

ledger ties to the statement

SOX-CA-10Close checklist

every close step evidenced

SOX-ITGC-01Change management

changes approved and tested

The Exception Center

You are not running the tests - you are working the short list of what failed. Every exception carries its severity, financial exposure, the control it violated, an AI explanation, and a remediate-then-verify workflow. Recurring failures fold together and escalate. It is the one queue a controller actually opens.

  • Ranked by financial exposure
  • Fed by controls + fraud detectors + anomalies
  • Remediate → verify, with an audit trail
  • Recurrence-aware escalation

The auditor portal

Hand your external auditor a time-boxed, revocable, read-only window - no login to your production finance system, no hand-assembled PBC binder. The portal issues scoped, logged access to the mapped controls and their tamper-evident evidence; wiring every finance continuous-control finding into that same view is in progress.

  • Time-boxed, revocable access tokens
  • Full access log of every view
  • Receipts mapped to the exact control
  • Recompute the chain to prove integrity

A controller and an auditor that never sleep.

Run it as software, add a copilot, or let Fintra run it managed. Either way the controls are testing your books at 2 AM so no one has to - and the evidence is ready before the board meeting is. That is what peace of mind looks like when it is built into the system of record rather than bolted on after the close.

Honest scope

Of the 20 SOX 404 objectives, 13 map to control tests that run today against real transaction populations; the other 7 are entity-level or attestation controls a human signs off. A few control sources are still being wired - where a population is not yet connected, Fintra marks the control rather than reporting a pass, so it never fakes coverage. Continuous assurance complements your GRC stack and your external audit; it does not replace the auditor or issue an opinion. The population sweep, the seals, the hash chain, and the control map are real and recomputable today; surfacing every finance finding through the auditor portal, and lighting up the mapped framework control's status from it, is being wired.

Common questions

What is continuous controls monitoring?

Continuous controls monitoring tests a control against every transaction, all the time, instead of an auditor sampling a handful of items once a quarter. Fintra runs each control as a full-population sweep: it checks every payment, journal entry, or reconciliation against the rule, opens an exception only for the items that fail, and seals each failure as tamper-evident evidence mapped to the SOX 404 control it violates. The result is that a control breach is caught the moment it happens rather than discovered at year-end.

Does Fintra do SOX 404?

Fintra ships a SOX 404 control catalog of 20 COSO-mapped control objectives spanning the control environment, risk assessment, control activities, information and communication, and monitoring. Thirteen of them are wired to control tests that run continuously against real transaction populations - segregation of duties, dual approval, journal-entry review, AP and revenue three-way match, period cutoff, bank reconciliation, flux analysis, vendor bank-change review, the close checklist, change management, backup, and disaster recovery. The remaining seven are entity-level or attestation controls a human signs off. Fintra complements your external audit and SOX program; it does not replace the auditor.

How is this different from a GRC tool like Vanta or Drata?

GRC tools collect evidence after the fact - screenshots, policy attestations, and integration checks that confirm a control exists. Fintra tests the control itself against the live financial data and produces the evidence as a by-product of the test. Because every failing item is sealed into a hash-chained ledger and mapped to its control, an auditor can recompute the chain and prove nothing was altered. Fintra sits under your finance system where the money actually moves; it complements a GRC stack rather than duplicating it.

Can my external auditor use it?

Yes. Fintra includes an auditor portal that issues a time-boxed, revocable, read-only access token and logs every view. Your auditor sees the control, its continuous test results, and the tamper-evident receipt behind each exception, mapped to the SOX 404 control objective - without a login to your production finance system and without you assembling a PBC binder by hand.