Product update
Announcing the eight-detector VeraStream rollout — every transaction, before the money moves
VeraStream now runs on every transaction — 95% of spend, every day, before the money moves. The other 5% is what legacy audit processes actually review. As of today, the same eight production detectors — evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — drive your continuous audit pipeline against your live ERP.
The 95%-vs-5% coverage shift
VeraStream evaluates 95% of every transaction your business posts, every day, before reimbursement. The remaining 5% is exactly the population a human reviewer opens weeks after the disbursement cleared. Post-payment, sample-based, blind to the patterns only a population-level run can surface.
Why today
The eight detectors ship in production today across every live deploy: NetSuite, SAP, Oracle, Coupa, Concur, Expensify, Brex, Ramp, and any CSV dropped at /audit. The same logic that already runs in the in-browser audit now runs continuously against the live ledger, with the same workpaper shape on every flag.
What changed between beta and today is coverage. Coverage moved from sample-based review — typically 25 to 60 transactions a quarter — to 95% of every transaction, every business day, before the money moves. The remaining 5% is what a quarterly audit sample reviews, weeks after disbursement.
The eight detectors, by name
Each detector targets a specific failure mode that legacy post-payment sampling misses because sampling never reads the full population. Each runs on every transaction the day the second payment queues.
evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — the canonical eight, run as a unit on every fleet deployment and on every CSV uploaded to /audit.
evaluatePolicy
Catches segregation-of-duties gaps and approval-matrix breaches — every payment is tested against the approver chain it was supposed to travel, not just the one that cleared it.
findDuplicateInvoices
Catches the same vendor paid twice under typosquatted invoice IDs, two invoice numbers within 48 hours, or any near-duplicate disbursement that legacy sampling missed by never looking.
detectExpenseAnomalies
Catches one cardholder, two closenames, same weekend — the cluster of corporate-card charges that only a population-level view can flag.
detectVendorRisk
Catches new vendors whose names are a near-miss of an approved master-data vendor — the typosquat, the unapproved payee, the shell-vendor heuristic, all held before reimbursement.
detectThresholdGaming
Catches payment-split clusters structured just below the approver threshold — two $18,400 wires inside three hours, the textbook deliberate-strucure pattern.
detectRoundDollar
Catches round-dollar disbursements and one-line tamper patterns from migrated AP workflows — wires with no cents, same memo template as the prior batch, vendor first-seen days before.
detectDuplicatePayment
Catches the same vendor paid twice in a short window with the same or near-same amount (HIGH on exact duplicates inside 14 days and ±1% near-duplicate clusters inside 30 days, MED on same-day twins and round-cent twins, LOW on long-running same-amount cadence) — recurring SaaS, rent, and refund reversals auto-suppressed.
detectGhostEmployee
Catches a new vendor and a new approver granted sign-off rights inside the same week — the master-data change and the rights change that together point at a ghost employee.
What 95% actually means on a real ledger
A $250M-a-year finance org runs the eight detectors on every AP payment, every corporate-card charge, every travel expense. The pre-payment pipeline holds a flagged transaction — receipt, rule, override, natural-language summary — while a reviewer acts on it with complete context. Low-risk transactions auto-resolve with a full audit trail.
The legacy alternative is a quarterly sample of 25 to 60 items. A determined violator structures transactions just outside the sample. Their matching duplicate, threshold split, or vendor typosquat never lands in the reviewer's queue. That math is exactly what 95% coverage closes.
Where this lands in your audit program
The eight-detector rollout fits any framework that requires population-level assurance over enterprise spend: SOX 404(b) ICFR testing, FCPA, EU/UK VAT, Sunshine Act. Every flagged transaction ships the workpaper (receipt, rule, override) an external auditor needs under PCAOB AS 2315 — produced continuously, not assembled at quarter-close under pressure.
Frequently asked
Common questions about the eight-detector rollout
Plain HTML answers — no JavaScript required to read.
What changed with today's rollout of the eight detectors?
VeraStream now runs evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee against every transaction your business posts, before reimbursement, every day. The same eight production detectors — the same logic the /audit page already runs in the browser — now drive your continuous audit pipeline against your live ERP. Drop a CSV at /audit to see them run, or browse /pricing to launch continuous monitoring.
Is 95% "every transaction" or is something still being skipped?
VeraStream evaluates 95% of spend on every business day, before the money moves. The other 5% is what legacy post-payment audit processes actually review — the small sample a human reviewer opens weeks after the disbursement cleared. evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee run continuously across the 95%; the 5% sample is what auditors inherit when continuous monitoring is off.
Which risk does each of the eight detectors cover?
evaluatePolicy catches segregation-of-duties and approval-matrix breaches. findDuplicateInvoices catches the same vendor paid twice under typosquatted IDs. detectExpenseAnomalies catches one cardholder, two closenames, same weekend. detectVendorRisk catches typosquat or unapproved payee heuristics. detectThresholdGaming catches payments split to evade approver thresholds. detectRoundDollar catches round-dollar disbursements and one-line tamper patterns. detectDuplicatePayment catches the same vendor paid twice in a short window with the same or near amount. detectGhostEmployee catches a new vendor plus a new approver granted rights in the same week — all eight (evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee) running on every payment.
Does this change the workpaper shape on a flagged transaction?
No. Every flag ships the same workpaper it shipped yesterday: the receipt (the original transaction, the duplicate or anomaly that triggered the flag), the rule that tripped (the detector name — one of evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee), and any override applied. Sized to PCAOB AS 2315 — your external auditor receives the same evidence package as before, produced continuously rather than at quarter-end.
Run the eight on your own ledger today
Drop a CSV at /audit and watch the eight detectors evaluate it in under 90 seconds in the browser. Browse /pricing to launch continuous monitoring against your live ERP.