Superseded scope notice. This document's v1 scope (4 finding types —
kiting,unsupported_manual_journal,restricted_cash,lapping— plus 5normal_checks, all liquide-middelen-specific) is superseded/expanded by the owner'sdata-audit-engine-requirements-source.md(2026-09-01). The authoritative, numbered requirements are now insrs.md, sequenced for delivery inroadmap.md. Persrs.md§3:unsupported_manual_journalmerged into the new SRS's general manual- journal-entry detection (DA-013); the 5-business-day cutoffnormal_checkmerged into the new configurable cut-off window (DA-035);kiting,restricted_cash, the bank-confirmation-letter extraction capability, and the IBANnormal_checkwere dropped — none has a corresponding row in the new MoSCoW table, since the new scope's Data-import section no longer lists bank-statement-PDF or bank-confirmation- DOCX ingestion as a requirement.lappingpartially merged into the new Debiteuren section's subsequent-receipts matching (DA-051 per the original numbering; note: in the currentsrs.mdDA-051 is the Memorial/Journal Entries Viewer — the subsequent-receipts matching requirement was assigned a different DA number), without carrying forward the specific cycle-detection algorithm below. The concrete EUR amounts and training-file references below remain valid and are reused as acceptance-criteria evidence throughoutsrs.md— only the finding-type framing around them is superseded.
V1 scope is defined entirely by what is evidenced in the training/ground-truth dataset
at /Users/sarkout/projects/prive/financial-audit/, specifically
09_verwachte_controlebevindingen.json (the ground-truth findings file) and
10_data_dictionary.json (field documentation). That JSON defines exactly two
categories of expected output:
expected_findings — 4 specific, typed findings (F-001 through F-004), one per
finding type: kiting, unsupported_manual_journal, restricted_cash, lapping.normal_checks — 5 standing checks that are not tied to a single flagged
instance in this dataset but describe procedures the tool must be capable of
running.Alongside these, the dataset includes a bank confirmation letter
(06_standaard_bankverklaring_voorbeeld.docx) whose stated purpose (per the data
dictionary) is "Extractie van saldi, faciliteiten, zekerheden en restricted cash" —
extraction of balances, facilities, securities/collateral, and restricted cash. This
extraction capability is in scope because it is the direct evidentiary source for
finding F-003 (restricted_cash) and for one of the normal_checks (bank confirmation
vs. bank account register comparison).
Everything else visible in the wider seed material — notably the 10-step methodology
in Document1.docx (risk analysis, cash counts, foreign-currency review, analytical
review of cash-flow trends, automated management-letter generation) — is explicitly
out of scope for v1. None of those steps has a corresponding ground-truth finding or
input file in this training set, so there is no acceptance bar to build or test against
yet. They are noted as a possible later phase, not a v1 commitment.
V1 is done when Athena, run against this exact training dataset, reproduces all 4
expected findings (F-001–F-004) with matching type, source_files, and
expected_detection field values, and correctly surfaces the facts needed for all 5
normal_checks. This dataset is the acceptance test, not just a design reference.
Finding type: kiting (ground truth: F-001, severity high)
01_auditfile_grootboek_bankmutaties.csv, or the
equivalent XAF XML 02_voorbeeld_auditfile_XAF.xml) — for booking_date,
document_date, manual_entry, source, debit/credit, and account.04_bankafschrift_rabobank_2025-12.pdf,
05_bankafschrift_ing_2025-12_en_2026-01.pdf) — for the actual bank-side value
dates and amounts of the same transfer.expected_detection):{
"finding_id": "string",
"type": "kiting",
"severity": "high",
"source_files": ["..."],
"logic": "human-readable explanation of the mismatch",
"expected_detection": {
"internal_transfer_amount": 0.0,
"outgoing_bank_date": "YYYY-MM-DD",
"incoming_book_date": "YYYY-MM-DD",
"incoming_bank_date": "YYYY-MM-DD",
"potential_overstatement_at_year_end": 0.0
}
}
Finding type: unsupported_manual_journal (ground truth: F-002, severity high)
manual_entry = true, source = manual) posted to a bank/cash GL account, dated at or near year-end, that has no
corresponding bank mutation to support it — i.e., it does not reconcile against the
bank statement or the bank reconciliation workpaper.manual_entry/source fields.07_bankreconciliatie_met_afwijking.xlsx) — to
confirm the entry is called out as a reconciling item without underlying bank
support ("Af: niet-geboekte handmatige correctie", tied to journal ID BNK-9003 in
the seed data).{
"finding_id": "string",
"type": "unsupported_manual_journal",
"severity": "high",
"source_files": ["..."],
"logic": "explanation referencing the missing bank support",
"expected_detection": {
"journal_id": "string",
"amount": 0.0
}
}
BNK-9003 (EUR 25,000.00, dated 2025-12-31,
manual_entry=true, source=manual, user=directie), matching F-002 exactly.Finding type: restricted_cash (ground truth: F-003, severity medium)
03_saldibalans_voorbeeld.xlsx) — account 1120 "G-rekening",
classified under "Liquide middelen beperkt beschikbaar" with a control note
"Presentatie/toelichting beoordelen".06_standaard_bankverklaring_voorbeeld.docx) — the
"Geblokkeerde rekeningen" field stating "G-rekening EUR 32.500".{
"finding_id": "string",
"type": "restricted_cash",
"severity": "medium",
"source_files": ["..."],
"logic": "explanation of why the balance is restricted",
"expected_detection": {
"gl_account": "string",
"amount": 0.0
}
}
1120 (EUR 32,500.00) against
the bank confirmation letter's G-rekening line and reproduces F-003 with matching
account and amount.Finding type: lapping (ground truth: F-004, severity high)
08_debiteurenontvangsten_lapping_scenario.csv — per the data dictionary this file
carries customer, invoice, invoice_date, amount, bank_receipt_date,
bank_amount, applied_to_invoice, posting_date, and an exception narrative
column. The detection logic is: for each row, is applied_to_invoice an invoice
number that does NOT belong to customer, and does the applied invoice belong to a
customer whose own payment (received later) is in turn misapplied to a third
customer's older invoice — forming a cycle.{
"finding_id": "string",
"type": "lapping",
"severity": "high",
"source_files": ["08_debiteurenontvangsten_lapping_scenario.csv"],
"logic": "explanation of the misapplied-payment chain",
"expected_detection": {
"affected_customers": ["string", "..."],
"cycle_amount": 0.0
}
}
affected_customers list (Klant A,
Klant B, Klant C, Klant D) and cycle_amount (EUR 10,000.00 — uniform across
all 4 rows in this scenario).What it detects/extracts: Structured extraction of facility, guarantee,
collateral/security, and restriction facts from the free-text/tabular bank
confirmation letter, specifically the fields observed in
06_standaard_bankverklaring_voorbeeld.docx: Bank, entity, peildatum (reference
date), IBAN, Saldo, Kredietfaciliteit, Gebruikte kredietruimte, Bankgaranties,
Zekerheden, Geblokkeerde rekeningen, Bevoegde personen, Overige verplichtingen.
Inputs required: The bank confirmation letter (DOCX).
Output shape: A structured record per bank confirmation letter, e.g.:
{
"bank": "Rabobank",
"entity": "Demo Handelsmaatschappij B.V.",
"reference_date": "2025-12-31",
"iban": "NL91RABO0123456789",
"balance": 152340.25,
"credit_facility": 100000.0,
"credit_facility_used": 0.0,
"bank_guarantees": [{"amount": 25000.0, "beneficiary": "verhuurder"}],
"securities": ["Pandrecht op huidige en toekomstige vorderingen"],
"blocked_accounts": [{"description": "G-rekening", "amount": 32500.0}],
"authorized_persons": ["A. Directeur", "B. Controller"],
"other_obligations": null,
"source_file": "06_standaard_bankverklaring_voorbeeld.docx"
}
Feeds directly into Capability 3 (restricted cash) and into normal_check #3 below.
Done: All fields listed above are correctly extracted from the training letter, in particular the EUR 32,500 G-rekening figure (feeds F-003) and the EUR 25,000 bank guarantee (which has no corresponding ground-truth finding in this dataset but must still be extracted and surfaced, since it is explicitly named as an extraction target in the data dictionary).
normal_checksThese are standing procedures, not single flagged instances — each must run deterministically and produce a pass/exception result with supporting data, not a single finding record.
IBAN-formaat controleren (IBAN format validation)
NL91RABO0123456789 (Rabobank) and
NL20INGB0987654321 (ING).Bankafschrift-eindsaldo aansluiten met grootboek na correcties (bank statement ending balance reconciles with GL after corrections)
Eindsaldo, GL account balance from the trial
balance, and the bank reconciliation workpaper's adjusting items.07_bankreconciliatie_met_afwijking.xlsx — GL 1100 balance EUR 177,340.25 minus
the unsupported EUR 25,000 correction equals the Rabobank statement end balance
of EUR 152,340.25.Bankbevestiging vergelijken met bankrekeningregister (bank confirmation vs. bank account register comparison)
Negatieve banksaldi niet zonder meer salderen (do not net negative bank balances without justification)
Transacties vijf werkdagen voor en na balansdatum analyseren (analyze transactions in the 5 business days around balance sheet date)
Document1.docx) found alongside the training set, but with no
corresponding ground-truth finding or acceptance data in this training set.
Reacties