Methodology

Audit methodology for reporting applications

How Data Layer Grid plans, samples, and reports when performing a financial audit of regulatory reporting applications.

Grounded in the return, not in abstract frameworks

Our methodology exists to support one offer: financial audit of regulatory reporting applications. We borrow structure from established assurance practice, then narrow every procedure to the pack, return, or schedule under review.

Phase 1 — Framing the application

We write a one-page engagement frame that names:

  • The supervisory recipient and return code or title
  • The reporting period and cut-off
  • Legal entity and consolidation perimeter
  • Materiality for quantitative slips and qualitative disclosure gaps
  • Known prior queries from the supervisor or internal audit

If the frame cannot be agreed, we pause rather than start open-ended fieldwork.

Phase 2 — Process walkthrough

Preparers walk us through how source extracts become the application. We note hand-offs, spreadsheet bridges, and where judgment enters (classification, netting, FX, or timing). Walkthroughs are evidenced with screenshots or worksheet versions dated to the period.

Phase 3 — Evidence and sampling

Sampling follows risk: large balances, volatile lines, heavy manual overlays, and areas with prior exceptions. For each sample we ask:

  1. Does the figure agree to an authoritative source?
  2. Was the transformation rule applied consistently?
  3. Did the named reviewer see the final number?
  4. Is supporting evidence retained in a retrievable place?

Failed samples expand within that schedule; they do not automatically expand the entire engagement.

Phase 4 — Reporting for filing calendars

Findings are drafted while the filing window is still open whenever the engagement timing allows. Severity language distinguishes:

  • Blocking — likely to misstate a supervisory total or breach a stated control
  • Significant — weak evidence or process gaps that should clear before the next cycle
  • Improvement — clarity or efficiency notes that do not threaten the current pack

Independence and access

We decline engagements where we previously prepared the same return schedules. Document rooms must allow read-only export of packs; chat screenshots alone are not accepted as a complete evidence trail.

Where to go next