Worked case study
VeraStream eight-detector rollout — from a 25-to-60 quarterly sample to 95% continuous coverage
A mid-market finance org switching from 25-to-60-line quarterly sample review to 95% continuous coverage on every business day.
Outcome: 95% of every transaction, every business day, before the wire clears — replacing the legacy 25-to-60-line quarterly sample that legacy review never had the runway to find.
The numbers, before and after
Three stats that frame the coverage shift
95%
of every transaction, every business day, before the wire clears.
25–60
transactions reviewed each quarter in the legacy sample queue.
47 days
from disbursement to the quarterly sample landing on a reviewer desk.
The 95%-vs-5% framing is the same shift surfaced on /how-it-works — every transaction evaluated daily, every wire held when one of the eight trips. The 25-to-60 quarterly sample and the 47-day lag are the legacy alternatives the rollout replaces.
The walkthrough
Before: sample-based review. After: 95% continuous coverage.
Before
Legacy review was a quarterly sample — typically 25 to 60 transactions per quarter, picked weeks after disbursement. A pattern that only surfaces in the missing 95% (duplicate invoice rings, threshold-gaming splits, vendor typosquats) was structurally guaranteed to be invisible to a reviewer staring at the 5% the queue was actually populated from.
After
Eight production detectors run on every transaction before the second payment queues. A 95% pre-payment coverage rate is the default — the remaining 5% is exactly the population legacy audit processes inherit, and exactly the population VeraStream no longer depends on. Hold before the wire clears; resolve with full workpaper; audit by exception.
Detector coverage on this rollout
The eight detectors that fired on this rollout
Every detector below runs continuously against the production ledger — the same canonical eight surfaced on /detectors and aggregated on /pricing: evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee. Adding a 9th detector is a single entry in the catalog at @/lib/business/detector-catalog; this list updates with no edits here.
Frequently asked
Six questions on this rollout
What the rollout covered, why 95% and not 100%, what survived of the legacy sample, whether the workpaper shape changed, which detectors led the holds, and whether the rollout replaces the external auditor. Plain HTML answers, no JavaScript required to read.
What did the eight-detector rollout cover on a real ledger?
Policy and segregation-of-duties evaluation, duplicate invoice detection, expense anomaly scoring, vendor risk and shell-vendor heuristics, threshold-gaming detection, round-dollar disbursement patterns, duplicate payment prevention, and ghost-employee / SOD breaks — eight rules on every transaction the day the queued payment batch submits, no slot left to the quarterly sample.
Why 95% coverage and not 100%?
95% is what VeraStream evaluates every business day, before the money moves. The remaining 5% is what legacy post-payment audit samples look at — a 25-to-60-row queue that lands on a reviewer desk about 47 days after disbursement. The rollout closes coverage on the 95%, which is exactly the population a sample-based reviewer never reads.
What happens to the legacy quarterly sample after rollout?
The 25-to-60-row quarterly sample keeps existing as an auditor-driven read; VeraStream simply no longer depends on it. The continuous pre-payment gate moves the same auditor workload from primary detection to corroboration — the auditor reviews VeraStream workpapers by exception, not blind samples.
Did the workpaper JSON change during the rollout?
No. Every flagged transaction produces the same three-part workpaper: the receipt (the original transaction that tripped the detector), the rule that tripped (the detector name + the spend signal), and any override applied. Sized to PCAOB AS 2315 — produced continuously rather than assembled under quarter-end pressure.
Which of the eight detectors led holds during the first 90 days?
detectDuplicatePayment and detectVendorRisk led the majority of holds in the first quarter — a duplicate-invoice ring tripping findDuplicateInvoices and a vendor typosquat ring tripping detectVendorRisk together recovered the largest single-day amount. detectExpenseAnomalies and detectThresholdGaming combined for the second tier of the hold queue.
Does the eight-detector rollout replace the external auditor?
No. The continuous coverage produces the same evidence package your external auditor signs off against under PCAOB AS 2315 — produced continuously rather than assembled under quarter-end pressure. The auditor’s workload moves from primary detection to corroboration: review the workpapers by exception, not blind samples.
Run the same on your ledger
Drop a CSV at /audit — or launch the eight continuously at /pricing.
The same eight VeraStream detectors run on your AP ledger at /audit — no signup, no sales call required to see first findings. Pick Continuous or Enterprise at /pricing to launch them continuously against your live ERP.