Methodology
Audit methodology for reporting applications
How Data Layer Grid plans, samples, and reports when performing a financial audit of regulatory reporting applications.
Grounded in the return, not in abstract frameworks
Our methodology exists to support one offer: financial audit of regulatory reporting applications. We borrow structure from established assurance practice, then narrow every procedure to the pack, return, or schedule under review.
Phase 1 — Framing the application
We write a one-page engagement frame that names:
- The supervisory recipient and return code or title
- The reporting period and cut-off
- Legal entity and consolidation perimeter
- Materiality for quantitative slips and qualitative disclosure gaps
- Known prior queries from the supervisor or internal audit
If the frame cannot be agreed, we pause rather than start open-ended fieldwork.
Phase 2 — Process walkthrough
Preparers walk us through how source extracts become the application. We note hand-offs, spreadsheet bridges, and where judgment enters (classification, netting, FX, or timing). Walkthroughs are evidenced with screenshots or worksheet versions dated to the period.
Phase 3 — Evidence and sampling
Sampling follows risk: large balances, volatile lines, heavy manual overlays, and areas with prior exceptions. For each sample we ask:
- Does the figure agree to an authoritative source?
- Was the transformation rule applied consistently?
- Did the named reviewer see the final number?
- Is supporting evidence retained in a retrievable place?
Failed samples expand within that schedule; they do not automatically expand the entire engagement.
Phase 4 — Reporting for filing calendars
Findings are drafted while the filing window is still open whenever the engagement timing allows. Severity language distinguishes:
- Blocking — likely to misstate a supervisory total or breach a stated control
- Significant — weak evidence or process gaps that should clear before the next cycle
- Improvement — clarity or efficiency notes that do not threaten the current pack
Independence and access
We decline engagements where we previously prepared the same return schedules. Document rooms must allow read-only export of packs; chat screenshots alone are not accepted as a complete evidence trail.
Where to go next
- Review the flagship audit
- Check fee guidance
- Request an audit brief