Methodology
The working method behind an origination application audit
This page is the practice’s method, not a product tour. It is what we do when instructed to audit a loan origination application as a financial record. If the method does not fit the book you run, say so at scoping — we will not stretch a sample to cover a story.
Population and sample
We ask for a listing of applications opened, approved, declined, withdrawn, and disbursed in the named period. That listing is the population. We draw the sample. Approvals alone are never the population. Where Islamic and conventional products share an origination application, we treat them as two populations unless the engagement letter says otherwise.
Sample size is set in writing against the size of the book and the controls in scope. We do not promise statistical extrapolation unless that work is separately instructed and the data can support it. Unresolved files stay unresolved; they are not replaced with cleaner ones.
File tracing
Each sampled file is traced from intake to the last status the origination application shows. We read generated letters, fee quotes, and special conditions. We test whether holds stop the next step. We compare imaged evidence with the fields the application stored. A walk-through of one live file on the operations floor is part of every full control audit.
Decisioning and dual control
Where decisioning is in scope, we sample automated outcomes and manual overrides. We look for the rule, the reason recorded at the time, the authoriser, and whether later edits were locked. Maker-checker is tested against timestamps and access listings, not against an organisation chart.
Calculation, when instructed
Recalculation starts from the written product sheet, not from the screen. Instalments, fees, and origination illustrations are rebuilt, then compared with what the application printed. Islamic rebate illustrations are worksheeted on their own terms. Differences are attached to file references. Small systematic differences are still findings.
Disbursement tie-out
When posting integrity is in scope, we follow final approval to the disbursement instruction and the reference that finance should recognise. Payee changes after approval, and files released while a hold was open, are listed. We do not assume a core-system posting that we have not seen.
Reporting
The findings paper names the control, the file, and the money or customer impact. The management letter is written so it can be tabled. Residual risks are owned and dated. We hold a closing meeting. We do not reopen the sample to soften wording.