Fintra reviews every transaction.
You only touch the exceptions.
Auditors test a sample, once a quarter. Fintra tests every control against your entire transaction population, continuously - and the moment one fails, it opens an exception with a tamper-evident receipt mapped to the exact SOX 404 control. Continuous controls, not a spreadsheet at year-end.
Controls fail quietly. You find out at the worst time.
A payment goes out with one signature instead of two. A journal entry books to the wrong period. A vendor's bank details change the week before a large run. In most companies none of this surfaces until an auditor pulls a sample months later - or a board meeting is on Monday and the books are three months behind. Sampling is blind to everything it did not sample.
Fintra flips it: the control runs against every transaction, continuously, so the exception is on someone's desk the same day - with the evidence already sealed.
Sampling
Tests ~25 of 2,400 items, once a quarter. A breach outside the sample is invisible.
Spreadsheet controls
A control matrix in Excel that nobody re-tests between audits.
Fintra continuous controls
Tests all 2,400, every day. Only the failures surface, each with a receipt.
Declare it once. It tests itself forever.
Every control is a full-population sweep on top of the same Control Tower governance and hash-chained evidence ledger that Fintra uses to govern live money movement. Steps 3 through 6 are real and recomputable - that honesty is the point.
Set a control once - a spend ceiling, a two-signature rule, a three-way match, segregation of duties. One of nine control kinds, built on the Control Tower that governs every money move.
Fintra tests it against the entire transaction population - not a sample - on every run, and again the moment new activity posts.
Passing items stay silent. Each failure opens an Exception ranked by financial exposure and routed to an owner.
The failure is written append-only to a per-org hash chain as a tamper-evident receipt - the same ledger the Control Tower verifies.
The receipt is linked to the exact SOX 404 control objective it violates, with its COSO component.
Recompute the chain end to end. An auditor can prove, through a time-boxed portal, that nothing was altered.
A COSO-mapped 404 program that tests itself.
Twenty canonical control objectives, mapped to the five COSO components. Thirteen run as live tests against real transaction populations today; the rest are the entity-level and attestation controls a human owns. We would rather show you the split than imply the whole thing is automated.
Control Environment
Segregation of duties · tone at the top · audit committee
Risk Assessment
Fraud risk assessment
Control Activities
Dual approval · 3-way match · JE review · period cutoff · bank recon · close checklist
Information & Communication
Audit-trail integrity
Monitoring
Management monitoring of exceptions
no single person initiates and approves
two signatures over the threshold
PO · receipt · invoice reconcile
order · fulfillment · invoice
material and manual entries reviewed
transactions land in the right period
ledger ties to the statement
every close step evidenced
changes approved and tested
The Exception Center
You are not running the tests - you are working the short list of what failed. Every exception carries its severity, financial exposure, the control it violated, an AI explanation, and a remediate-then-verify workflow. Recurring failures fold together and escalate. It is the one queue a controller actually opens.
- Ranked by financial exposure
- Fed by controls + fraud detectors + anomalies
- Remediate → verify, with an audit trail
- Recurrence-aware escalation
The auditor portal
Hand your external auditor a time-boxed, revocable, read-only window - no login to your production finance system, no hand-assembled PBC binder. The portal issues scoped, logged access to the mapped controls and their tamper-evident evidence; wiring every finance continuous-control finding into that same view is in progress.
- Time-boxed, revocable access tokens
- Full access log of every view
- Receipts mapped to the exact control
- Recompute the chain to prove integrity
A controller and an auditor that never sleep.
Run it as software, add a copilot, or let Fintra run it managed. Either way the controls are testing your books at 2 AM so no one has to - and the evidence is ready before the board meeting is. That is what peace of mind looks like when it is built into the system of record rather than bolted on after the close.
Honest scope
Of the 20 SOX 404 objectives, 13 map to control tests that run today against real transaction populations; the other 7 are entity-level or attestation controls a human signs off. A few control sources are still being wired - where a population is not yet connected, Fintra marks the control rather than reporting a pass, so it never fakes coverage. Continuous assurance complements your GRC stack and your external audit; it does not replace the auditor or issue an opinion. The population sweep, the seals, the hash chain, and the control map are real and recomputable today; surfacing every finance finding through the auditor portal, and lighting up the mapped framework control's status from it, is being wired.
Common questions
What is continuous controls monitoring?
Continuous controls monitoring tests a control against every transaction, all the time, instead of an auditor sampling a handful of items once a quarter. Fintra runs each control as a full-population sweep: it checks every payment, journal entry, or reconciliation against the rule, opens an exception only for the items that fail, and seals each failure as tamper-evident evidence mapped to the SOX 404 control it violates. The result is that a control breach is caught the moment it happens rather than discovered at year-end.
Does Fintra do SOX 404?
Fintra ships a SOX 404 control catalog of 20 COSO-mapped control objectives spanning the control environment, risk assessment, control activities, information and communication, and monitoring. Thirteen of them are wired to control tests that run continuously against real transaction populations - segregation of duties, dual approval, journal-entry review, AP and revenue three-way match, period cutoff, bank reconciliation, flux analysis, vendor bank-change review, the close checklist, change management, backup, and disaster recovery. The remaining seven are entity-level or attestation controls a human signs off. Fintra complements your external audit and SOX program; it does not replace the auditor.
How is this different from a GRC tool like Vanta or Drata?
GRC tools collect evidence after the fact - screenshots, policy attestations, and integration checks that confirm a control exists. Fintra tests the control itself against the live financial data and produces the evidence as a by-product of the test. Because every failing item is sealed into a hash-chained ledger and mapped to its control, an auditor can recompute the chain and prove nothing was altered. Fintra sits under your finance system where the money actually moves; it complements a GRC stack rather than duplicating it.
Can my external auditor use it?
Yes. Fintra includes an auditor portal that issues a time-boxed, revocable, read-only access token and logs every view. Your auditor sees the control, its continuous test results, and the tamper-evident receipt behind each exception, mapped to the SOX 404 control objective - without a login to your production finance system and without you assembling a PBC binder by hand.