Document
MindBridge Memo to File Template
XYZ Company
MindBridge risk assessment and journal entry testing
XYZ Company Year-End
| Use this template to produce a memo explaining how MindBridge is incorporated into your audit methodology. This template is our recommendation and not intended for inclusion into your audit file. The datasets used in this template are dummy data sets and do not represent actual data. If you have any questions about the use of this template, please contact your MindBridge customer success manager. |
Overview of MindBridge
used the MindBridge artificial intelligence (AI) audit platform to perform risk assessment and journal entry testing (JET) for the
The full general ledger (GL) download for
MindBridge analyzes 100% of the transactions in client financial data to provide a transactional risk assessment. It uses 28 separate control points (business rules, statistical models, and machine learning algorithms) with individual weights, key words, and trends to risk score each transaction. This enables MindBridge to evaluate the risk level of accounts, users, and transactions to provide the auditor with visibility into unusual transactions or anomalies within the data set.
The Analysis Workflow
The process of an AI-based workflow is as follows:
- Importing the entire GL for the years under review and importing the current year’s preliminary trial balance. If there were any audit adjustments in the prior year, a final prior-year trial balance would also need to be imported.
- MindBridge ensures that all imported documents net to “0” for accounting purposes.
- MindBridge validates the GL information for the year to ensure the population is complete.
- MindBridge takes the final prior year trial balance, adds the debits/credits in the accounts from the imported GL, and compares the calculated ending balances to the imported preliminary trial balance. If any errors are noted, the GL is deemed incomplete and a sufficient analysis will not be able to be performed. If the population is deemed complete, an analysis can be performed.
- MindBridge analyses 100% of the data across entire transactions, identifying any usual transactions by looking at the monetary flows between accounts and all credits and debits. This allows the auditor to better understand transaction details and identify any potential issues.
Security and Privacy
MindBridge maintains compliance with the AICPA Security Organization Controls (SOC) and has completed its SOC 2 Type 2 certification against all five trust services criteria. With this certification, MindBridge clients are confident that an independent third party has validated that controls are in place for security, confidentiality, availability, processing integrity, and privacy of client data.
Control Point Descriptions and Weightings
used the following control points and weightings to evaluate the risk level of accounts, users, and transactions during the analysis. These settings are consistent with the firm standard and aligned with the MindBridge recommendation based on industry best practices.
| Control points: Defaults and explanations | ||
|---|---|---|
| Complex Structure | Description: Transactions with complex structure have flows both into and out of the same account within the same transaction. | Type: Statistical, Weight: 1% |
| Two Digit Benford | Description: Flags entries whose first two digits occur more or less than expected. | Type: Statistical, Weight: 5% |
| Cash Expenditures | Description: Flags transactions in which cash or cash-equivalent accounts are credited. | Type: Rules-Based, Weight: 10% |
| Cash to Bad Debt Conversion | Description: Flags transactions across which a cash account has been credited, and a bad debt expense account has been debited. | Type: Rules-Based, Weight: 20% |
| Duplicate | Description: Flags transactions which occur more than once in a ledger. | Type: Rules-Based, Weight: 5% |
| End of Period | Description: Flags transactions entered into the ledger within the 10 days before a fiscal period end. | Type: Rules-Based, Weight: 1% |
| High Monetary Value | Description: Flags transactions which are in the top 2% of all monetary values. | Type: Rules-Based, Weight: 10% |
| Unusual Amount | Description: Flags monetary values which are statistically anomalous for the accounts in which they appear. | Type: Machine Learning, Weight: 5% |
Further control points and their corresponding descriptions and weightings can be added as required.
Control Point Settings
used the following control point settings during the analysis. The phrase “IRC” was added as a suspicious keyword due to errors identified in the prior year by the predecessor auditor.
| Analysis | Analyzed On | Accounting period | Audit objectives | Default suspicious keywords | Current Weight | Reason For Deviation |
|---|---|---|---|---|---|---|
| Interim General Ledger Analysis (Complete) | 2020-01-14T17:45:18.201Z | Fiscal start month | January | Expense | ||
| Fiscal start day | 1 | |||||
| Frequency | 1 | |||||
| Default currency | CAD |
Further analysis of control point settings can be expanded.
Risk Grid Data
used the following risk assessments exported from MindBridge to create the risk grid in the “Risk Assessment & Analysis” tab.
Analysis and Risk Assessment
performed the following steps for analysis and risk assessment.
| High-risk transactions | Medium-risk transactions | Low-risk transactions |
|---|---|---|
It is policy to select all high-risk transactions for testing. For medium-risk transactions, reviewed the results.
Procedures Performed
used MindBridge to support the preliminary risk assessment of inherent risk at
1. Balance Check
The first check that the auditor relied upon was D=C in the amount of
2. Monthly Risk Assessment
The auditor checked the risk breakdown by month using MindBridge, determining to test each high-risk transaction individually.
3. Review of Risk Assessment
The auditor reviewed details of the risk assessment using MindBridge as seen below. As the rings move away from the center, the level to which accounts are aggregated becomes more detailed.
| Account Grouping Level 1 by Month | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Average of Average Risk | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Grand Total |
| Unspecified assets | 11% | 10% | 12% | 11% | 11% | 12% | 11% | 11% | 11% | 12% | 11% | 11% | 11% |
4. User Level Risk Assessment
The auditor performed a detailed risk assessment at the user level, reviewing transactions posted by the high-risk user.
Conclusion
See
Audit Plan and Journal Entry Testing
determined to select all high-risk entries identified by MindBridge for testing. The following entries were at high risk due to the MindBridge triggers as listed in columns W – AY.