Document

MindBridge memo to file template

XYZ Company
MindBridge risk assessment and journal entry testing

XYZ Company year-end

Use this template to produce a memo explaining how MindBridge is incorporated into your audit methodology.
This template is our recommendation and not intended for inclusion into your audit file. The datasets used in this template are dummy data sets and do not represent actual data.
If you have any questions about the use of this template, please contact your MindBridge customer success manager.

Overview of MindBridge

Used the MindBridge artificial intelligence (AI) audit platform to perform risk assessment and journal entry testing (JET) for the audit engagement in the current year.

The full general ledger (GL) download for and both interim and year-end GL downloads were imported into MindBridge for analysis.

MindBridge analyzes 100% of the transactions in client financial data to provide a transactional risk assessment. It uses 28 separate control points (business rules, statistical models, and machine learning algorithms) with individual weights, keywords, and trends to risk score each transaction. This enables MindBridge to evaluate the risk level of accounts, users, and transactions to provide the auditor with visibility into unusual transactions or anomalies within the data set.

See the sections on control points and settings for further explanation. While has the option to modify the weighting of individual control points, elected not to do so, which is consistent with the firm standard and aligned with the MindBridge recommendation based on industry best practices. If appropriate, may modify a control point weighting due to the nature of a business.

Has set the MindBridge materiality setting to zero to ensure that all data is analyzed and all anomalies identified regardless of thresholds.

The analysis workflow

The process of an AI-based workflow is as follows:

  1. Importing the entire GL for the years under review and importing the current year’s preliminary trial balance. If there were any audit adjustments in the prior year, a final prior-year trial balance would also need to be imported.
  2. MindBridge ensures that all imported documents net to “0” for accounting purposes.
  3. MindBridge validates the GL information for the year to ensure the population is complete.
  4. MindBridge takes the final prior year trial balance, adds the debits/credits in the accounts from the imported GL, and compares the calculated ending balances to the imported preliminary trial balance. If any errors are noted, the GL is deemed incomplete and a sufficient analysis will not be able to be performed. If the population is deemed complete, an analysis can be performed.
  5. MindBridge analyzes 100% of the data across entire transactions, identifying any unusual transactions by looking at the monetary flows between accounts and all credits and debits. This allows the auditor to better understand transaction details and identify any potential issues.

Refer to subsequent sections in this document for:

Security and privacy

MindBridge maintains compliance with the AICPA Security Organization Controls (SOC) and has completed its SOC 2 Type 2 certification against all five trust services criteria. With this certification, MindBridge clients are confident that an independent third party has validated that controls are in place for security, confidentiality, availability, processing integrity, and privacy of client data.

Received the most recent SOC 2 report from MindBridge dated 11/21/19, assessed the controls in place at MindBridge, and assessed the necessary controls that needed to be implemented at .

Notes that, per the report, there were no exceptions for the control testing that was performed and that the complementary user controls were properly implemented at .

Control point descriptions and weightings

Used the following control points and weightings to evaluate the risk level of accounts, users, and transactions during the analysis. These settings are consistent with the firm standard and aligned with the MindBridge recommendation based on industry best practices.

Control points: Defaults and explanations
Complex structure Description: The complex transaction structure control point flags transactions which have a complex structure. The control point distinguishes between large transactions with simple structure such as payroll and transactions with complex structure such as forward contracts, interest swaps, and other derivatives. Transactions with a complex structure have flows both into and out of the same account within the same transaction.
Type: Statistical
Weight: 1%
Two digit Benford Description: The two digit Benford law describes the number of times you would expect to see numbers starting with two specific digits in a naturally-occurring set of monetary values. The 2 digit Benford control point flags entries whose first two digits occur more or less than expected in the ledger. This could be a sign of unnatural or tampered data.
Type: Statistical
Weight: 5%
Cash expenditures Description: The cash expenditures control point flags transactions in which cash or cash-equivalent accounts are credited.
Type: Rules-Based
Weight: 10%
Cash to bad debt conversion Description: The cash to bad debt conversion control point flags transactions across which a cash account has been credited, and a bad debt expense account has been debited by the same amount.
Type: Rules-Based
Weight: 20%
Complex instrument Description: The complex transaction instrument control point flags transactions that appear to be based on a complex underlying financial instrument by identifying phrases in the memo field.
Type: Rules-Based
Weight: 1%
Text Indicators: fair value, guarantee, embedded derivative, net settlement, fix for fix, forward contract, swap, option, taps, callers, hedge, hedging, commodity, host contracts, forward option, re-commission, extinguishment, modifications, transaction costs
Duplicate Description: The duplicate transaction control point flags transactions which occur more than once in a ledger.
Type: Rules-Based
Weight: 5%
Empty text field Description: The empty text field point flags transactions which have blank memo fields for all entries.
Type: Rules-Based
Weight: 1%
End of period Description: The end of period control point flags transactions entered into the ledger within the 10 days before a fiscal period end.
Type: Rules-Based
Weight: 1%
End of year Description: The end of year control point flags transactions entered into the ledger within the 10 days before a fiscal year end.
Type: Rules-Based
Weight: 1%
High monetary value Description: The high monetary value control point flags transactions which are in the top 2% of all monetary values in the ledger.
Type: Rules-Based
Weight: 10%
Last 3 digits Description: The last 3 digit control point flags monetary values in the ledger which end in either 0.00 or 9.99. These monetary values are more likely to be entered manually than other monetary values.
Type: Rules-Based
Weight: 5%
Manual entry Description: The manual entry control point flags transactions which were entered manually into the general ledger. Ledger columns which indicate manual transactions should be entered below. If all entries were entered manually into the general ledger, then this control point's weight can be safely set to zero.
If manual entries are normal for this client, set the weight to 0. The control point will still be flagged but won't contribute to the overall score.
Type: Rules-Based
Weight: 10%
Text Indicators: source: gl, adj, m; OR type: JE, KZ, ZG
Material value Description: N/A
Type: Rules-Based
Weight: N/A
Reporting adjustment Description: The reporting adjustment control point flags end of period transactions which are reversed immediately in the next period, and which are separated by 20 days or less.
Type: Rules-Based
Weight: 1%
Reversal Description: The reversal control point flags transactions which are reversals of a previous transaction in the ledger.
Type: Rules-Based
Weight: 5%
Reversed Description: The reversed control point flags transactions which are reversed by a subsequent transaction in the ledger.
Type: Rules-Based
Weight: 5%
Sequence gap Description: The sequence gap control point flags transactions which are next to missing transaction IDs, based on the ledger's normal sequence of transaction IDs.
Type: Rules-Based
Weight: 1%
Start of period Description: The start of period control point flags transactions entered into the ledger within the 10 days after a fiscal period start.
Type: Rules-Based
Weight: 1%
Start of year Description: The start of year control point flags transactions entered into the ledger within 10 days after a fiscal year start.
Type: Rules-Based
Weight: 1%
Suspicious keyword Description: The suspicious keyword control point flags entries whose memo field contains keywords that are indicative of a ledger entry being outside of normal business processes.
Type: Rules-Based
Weight: 5%
Text Indicators: accrual, adjust*, alter*, request*, audit*, bonus*, bury, cancel*, capital, ceo, classif*, confidential, corr, correct*, cover*, director, ebit*, err*, estimate, fix, fraud*, gift, incentive, kite*, kiting, lease*, mis*, per, plug*, problem, reclass*, rectif*, reduc*, remov*, revers*, screen, switch, temporary, test, transfer,
Add keywords
Unbalanced debits and credits Description: The unbalanced debits and credits control point flags transactions whose credits and debits do not balance.
Type: Rules-Based
Weight: 5%
Weekend post Description: The weekend post control point flags transactions which were entered into the ledger on a weekend.
Type: Rules-Based
Weight: 5%
Zero entry Description: The zero entry control point flags journal entries whose credit and debit values are both $0.
Type: Rules-Based
Weight: 5%
Expert score Description: The expert score identifies monetary flows between account categories which were identified by domain experts as being of importance to audits. These flows either involve high-importance accounts, or are not a part of common business processes.
Type: Machine Learning
Weight: 10%
Flow analysis Description: The transaction flow analysis combines our three monetary flow results: outlier anomaly, rare flow, and expert score. Based on preliminary testing, a combination of these three scores is a strong indicator of transactions which are outside of normal business practices. We recommend that this control point be weighted higher than all other control points.
Type: Machine Learning
Weight: 80%
Outlier anomaly Description: The outlier anomaly control point flags monetary flows which are mathematically anomalous, based on the accounts, date, and amount of the monetary flow.
Type: Machine Learning
Weight: 5%
Rare flows Description: The rare monetary flows control point flags transactions where matching debits and credits occur between accounts that do not usually interact, based on the usual business processes within the ledger.
Type: Machine Learning
Weight: 10%
Unusual amount Description: The unusual amount control point flags monetary values which are statistically anomalous for the accounts in which they appear.
Type: Machine Learning
Weight: 5%

Control point settings

Used the following control point settings during the analysis. The phrase “IRC” was added as a suspicious keyword due to errors identified in the prior year by the predecessor auditor.

Analysis Analyzed On Accounting period Aging report as at date Audit objectives Default suspicious keywords Suspicious keywords Default complex transaction keywords Complex transaction keywords Default manual entries Manual entries Control point weights System Default Weight Current Weight Last Modification By Reason For Deviation Date Setting Changed
Interim General Ledger Analysis (Complete) 2020-01-14T17:45:18.201Z Fiscal start month January 2019-12-31T00:00:00Z Expense accrual IRC callers callers Column name Inclusion tags Exclusion tags Column name Inclusion tags Exclusion tags Weekend Post 5 5
Fiscal start day 1 adjust* accrual commodity commodity source gl, adj, m source gl, adj, m Last 3 Digits 5 5
Frequency 1 alter* adjust* embedded derivative embedded derivative type JE, KZ, ZG type JE, KZ, ZG Manual Entry 10 10
Default currency CAD audit* alter* extinguishment extinguishment Reversal 5 5
Accounting package Microsoft Dynamics GP bonus* audit* fair value fair value Sequence Gap 1 1
Industry Manufacturing bury bonus* fix for fix fix for fix Zero Entry 5 5
High dollar top percentage 2% cancel* bury forward contract forward contract Rare Flows 10 10
Materiality amount 0.00 capital cancel* forward option forward option Unbalanced Debits and Credits 5 5
Old invoice day threshold 0 ceo capital guarantee guarantee Cash Expenditures 10 10
classif* ceo hedge hedge Cash to Bad Debt Conversion 20 20
confidential classif* hedging hedging Expert Score 10 10
corr confidential host contracts host contracts Reversed 5 5
correct* corr modifications modifications Start of Period 1 1
cover* correct* net settlement net settlement High Monetary Value 10 10
director cover* option option Material Value 0 0
ebit* director re-commission re-commission Suspicious Keyword 5 5
err* ebit* swap swap Start of Year 1 1
estimate err* taps taps Reporting Adjustment 1 1
fix estimate transaction costs transaction costs Complex Structure 1 1
fraud* fix Unusual Amount 5 5
gift fraud* Complex Instrument 1 1
incentive gift Duplicate 5 5
kite* incentive 2 Digit Benford 5 5
kiting kite* End of Year 1 1
lease* kiting Empty Text Field 1 1
mis* lease* Flow Analysis 80 80
per mis* Outlier Anomaly 5 5
plug* per End of Period 1 1
problem plug*
reclass* problem
rectif* reclass*
reduc* rectif*
remov* reduc*
request* remov*
revers* request*
screen revers*
switch screen
temporary switch
test temporary
transfer test
transfer

Risk grid data

Used the following risk assessments exported from MindBridge to create the risk grid in the “Risk Assessment & Analysis” tab.

Analysis and risk assessment

Performed the following steps for analysis and risk assessment.

Number $ value
High-risk transactions
Medium-risk transactions
Low-risk transactions
It is policy to select all high-risk transactions for testing. For medium-risk transactions, reviewed the results and noted the following composition:

Due to these results, selected medium-risk transactions for testing.

It is policy not to select low-risk transactions for testing based on the methods used by the underlying AI analysis technology. These transactions are considered part of the population when performing substantive procedures during the rest of the audit.

Procedures performed

Used MindBridge to support the preliminary risk assessment of inherent risk at . Details of this analysis are below.

1. Balance check

The first check that the auditor relied upon was D=C in the amount of for the YE . No issues were noted with unbalanced JEs.

2. Monthly risk assessment

The auditor checked the risk breakdown by month using MindBridge. The risk assessment generated of high-risk transactions, in transactions. Determined to test each high-risk transaction individually, as outlined in the next section.

3. The auditor reviewed details of the risk assessment using MindBridge, as seen below. As the rings move away from the center, the level to which accounts are aggregated becomes more detailed with aspects of those accounts further assessed.

[inner most ring = highest aggregation at the BS/IS summary level].

Notes that all accounts are assessed as low risk at or less. All the accounts not visible on the chart are also below .

4. Assessed risk at both the "NTR Category" and the "Grouping Level 1" account grouping levels by month using pivot tables from the "Risk Grid Data" tab in MindBridge, noting that all groupings were deemed low risk. The NTR Categories are comparable to subgroupings at .

Conditional formatting coloring is similar to the above chart but the risk levels in red are below the moderate risk level of 40%, as noted above.

Account Grouping Level 1 by Month
Average of Average Risk
Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Grand Total
Unspecified assets 11% 10% 12% 11% 11% 12% 11% 11% 11% 12% 11% 11% 11%
Current assets 10% 14% 14% 14% 14% 14% 14% 15% 14% 15% 14% 15% 14%
Capital assets 11% 16% 17% 18% 17% 16% 19% 17% 17% 19% 18% 18% 17%
Current liabilities 18% 18% 19% 19% 20% 19% 19% 19% 19% 20% 20% 19% 19%
Unspecified equity 37% 37%
Paid-in capital 32% 34% 41% 30% 41% 38% 36%
Main business income 13% 12% 13% 12% 12% 12% 13% 12% 12% 13% 12% 16% 13%
Direct costs 12% 11% 12% 11% 12% 12% 12% 12% 11% 12% 12% 15% 12%
Operating expenses 18% 18% 17% 19% 18% 17% 19% 17% 18% 18% 18% 23% 18%
NTR Category by Month
Average of Average Risk
Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Grand Total
Accumulated amortization of other tangible capital assets (contra) 23% 20% 20% 22% 20% 20% 23% 20% 21% 22% 21% 21% 21%
Amortization expense for intangible assets 22% 20% 21% 22% 21% 20% 23% 21% 21% 22% 21% 28% 22%
Cost of materials 12% 11% 12% 11% 12% 12% 12% 12% 11% 12% 12% 15% 12%
Deductions and withholdings payable 15% 16% 15% 16% 16% 15% 16% 15% 15% 16% 17% 15% 16%
Domestic bank deposits 17% 18% 18% 18% 18% 17% 18% 18% 19% 18% 18% 18% 18%
Drawings (contra) 32% 34% 41% 30% 41% 38% 36%
Employers' portion of employee benefits 12% 13% 12% 13% 13% 12% 13% 12% 12% 13% 14% 14% 13%
Equipment 11% 10% 10% 10% 11% 9% 11% 11% 10% 11% 12% 12% 11%
Furniture and fixtures 0% 0%
Inventory of raw materials 16% 17% 17% 16% 17% 17% 17% 17% 17% 17% 18% 18% 17%
Site rental and related costs/fees 25% 23% 23% 26% 23% 23% 26% 21% 22% 23% 22% 29% 24%
Taxes payable 16% 16% 16% 17% 16% 16% 17% 16% 16% 17% 17% 16% 16%
Trade accounts payable 22% 25% 25% 22% 25% 25% 24% 25% 24% 25% 25% 26% 24%
Trade accounts receivable (A/R) 9% 13% 14% 14% 14% 14% 14% 15% 13% 14% 14% 14% 13%
Trade sales of goods and services 13% 12% 13% 12% 12% 12% 13% 12% 12% 13% 12% 16% 13%
Unspecified advertising/promotion 22% 21% 21% 23% 21% 21% 23% 21% 22% 23% 22% 31% 23%
Unspecified assets 11% 10% 12% 11% 11% 12% 11% 11% 11% 12% 11% 11% 11%
Unspecified equity 37% 37%
Unspecified salaries and wages 14% 13% 12% 14% 13% 12% 13% 12% 13% 13% 14% 15% 13%
Unspecified utilities 21% 21% 21% 22% 19% 18% 25% 19% 21% 22% 21% 28% 22%
Vehicles 0% 0%

5. [Optional] The auditor performed a detailed risk assessment at the user level, as seen below. The relative size of each box represents the amount of absolute dollars posted throughout the year by each user relative to other users. The colors represent the relative risk of each user (green is lower risk; red is higher risk).

The transactions posted by the high-risk user were reviewed and a sample included in the audit plan. The highest risk transactions were due to and it was concluded that there was no evidence of material misstatement.

Conclusion

See for conclusion on risk assessment based on the above and based on our understanding of the client and industry.

Audit plan and journal entry testing

Determined to select all high-risk entries identified by MindBridge for testing. The following entries were at high risk due to the MindBridge triggers listed in columns W – AY. These entries were included in the audit plan and requested the JE, reason for JE, and backup support from to analyze the entries and ensure they were appropriate.