Methodology

The working method behind an origination application audit

This page is the practice’s method, not a product tour. It is what we do when instructed to audit a loan origination application as a financial record. If the method does not fit the book you run, say so at scoping — we will not stretch a sample to cover a story.

Reviewers comparing origination decision logs with paper files during fieldwork

Population and sample

We ask for a listing of applications opened, approved, declined, withdrawn, and disbursed in the named period. That listing is the population. We draw the sample. Approvals alone are never the population. Where Islamic and conventional products share an origination application, we treat them as two populations unless the engagement letter says otherwise.

Sample size is set in writing against the size of the book and the controls in scope. We do not promise statistical extrapolation unless that work is separately instructed and the data can support it. Unresolved files stay unresolved; they are not replaced with cleaner ones.

File tracing

Each sampled file is traced from intake to the last status the origination application shows. We read generated letters, fee quotes, and special conditions. We test whether holds stop the next step. We compare imaged evidence with the fields the application stored. A walk-through of one live file on the operations floor is part of every full control audit.

Decisioning and dual control

Where decisioning is in scope, we sample automated outcomes and manual overrides. We look for the rule, the reason recorded at the time, the authoriser, and whether later edits were locked. Maker-checker is tested against timestamps and access listings, not against an organisation chart.

Calculation, when instructed

Recalculation starts from the written product sheet, not from the screen. Instalments, fees, and origination illustrations are rebuilt, then compared with what the application printed. Islamic rebate illustrations are worksheeted on their own terms. Differences are attached to file references. Small systematic differences are still findings.

Disbursement tie-out

When posting integrity is in scope, we follow final approval to the disbursement instruction and the reference that finance should recognise. Payee changes after approval, and files released while a hold was open, are listed. We do not assume a core-system posting that we have not seen.

Reporting

The findings paper names the control, the file, and the money or customer impact. The management letter is written so it can be tabled. Residual risks are owned and dated. We hold a closing meeting. We do not reopen the sample to soften wording.