Fractional CFO resource
What to Audit in a Client’s Financial Stack in Week One
A CFO-focused financial-stack audit for week one: sources of truth, close, cash, billing, payables, payroll, reporting, access, controls, and handoffs.
A financial-stack audit is not a software shopping exercise. In the first week of a fractional CFO engagement, its purpose is to answer a more urgent question: can leadership get timely, reliable financial information from the current people, systems, and handoffs?
The audit should make the operating chain visible—from the transaction source to the ledger, close, forecast, KPI report, and management decision. It should also reveal where access, ownership, reconciliation, definitions, or manual work create risk. The output is a ranked list of facts, gaps, and next actions; it is not a verdict that every tool must be replaced.
Begin with the management questions
Ask the CEO and finance owner what they need to know routinely and what they cannot answer today. Typical questions include:
- How much cash is truly available and what will it look like over the next several weeks?
- Are the books closed on a predictable schedule, and what remains uncertain at close?
- Which KPIs guide decisions, and do the teams calculate them the same way?
- Which customers, products, channels, or projects are driving revenue and margin?
- Who can approve payments, change vendor or bank details, access payroll, or edit reported numbers?
These questions create the audit scope. A tool list without a decision context often becomes inventory rather than diagnosis.
Map the source-of-truth chain
For each critical financial output, identify where the underlying data originates, how it moves, who changes it, when it is reconciled, and where the final report is produced.
| Output | Primary source | Transformations / handoffs | Reconciliation owner | Consumer |
|---|---|---|---|---|
| Cash position | Bank or treasury data | Manual timing items and payment platforms | Finance owner | CEO / finance |
| Revenue and receivables | Billing, CRM, or ERP | Invoicing, credits, and collections notes | Accounting / sales ops | CEO / sales / finance |
| Payables and commitments | AP system, purchasing, or contracts | Approval workflow and payment batch | AP / operations | Finance / CEO |
| Payroll | Payroll provider or HRIS | Time, benefits, commissions, and tax filings | Payroll / HR | Finance / CEO |
| Management reporting | Ledger plus operational sources | Spreadsheets, BI tools, and KPI definitions | Finance | Leadership / board |
If the business cannot identify a primary source or reconciliation owner for a material output, record that as a finding. Do not fix it by silently choosing a spreadsheet as the new source of truth.
Audit cash and banking access first
Cash visibility is often the most time-sensitive topic. Confirm the accounts in use, authorized users, bank feeds or exports, payment platforms, restricted cash, debt facilities, and bank-reconciliation cadence. Ask whether the balance shown to leadership excludes pending payments, merchant holds, sweep activity, lockbox timing, or other material differences.
This work feeds a reliable 13-week cash-flow forecast. It also reveals basic control questions: who can initiate payments, who can approve them, who can change payment instructions, and whether access is reviewed when people or vendors change.
Review the close and reporting process
Document the close calendar and what happens at each step: transaction cutoff, reconciliations, accruals, revenue-recognition judgments where applicable, review, reporting, and sign-off. Ask what the team does when a close step is late or a balance is uncertain.
Then inspect the management reporting pack. Each KPI should have a written definition, source, owner, refresh date, and audience. If revenue, gross margin, active customers, bookings, cash, or another headline measure has multiple definitions across leadership, that is a management problem as well as a reporting problem.
Inspect billing, collections, payables, and payroll handoffs
The key risk is often between systems, not inside one. Review how a sale becomes an invoice, how a dispute becomes a collections task, how a purchase commitment becomes a payable, and how time or commission changes arrive in payroll. Capture the handoff owner and the normal timing.
Questions worth asking:
- Where do approvals live, and are they visible to accounting?
- How are credits, refunds, write-offs, and collections escalations documented?
- Which recurring vendor commitments do not appear in the AP aging?
- How are new vendors validated and bank-detail changes controlled?
- Who reconciles payroll registers and payroll-related liabilities to the ledger?
The goal is to find decisions and data that fall between roles—not to accuse the team of failure.
Assess access and change control
Make a simple access matrix for the systems that affect money or reporting. For each system, capture the business purpose, administrator, users with elevated access, approval roles, authentication method, and offboarding process. The audit should identify orphaned administrators, shared credentials, unrestricted export access, or a lack of separation between initiation and approval where material.
Technical controls should be evaluated with the appropriate internal, security, legal, and accounting advisers. The fractional CFO’s role is to surface the financial-operating exposure and ensure it has a named owner—not to represent a cybersecurity assessment as complete.
Turn observations into a week-one output
Organize findings into three columns:
- Immediate: affects cash, legal or contractual deadlines, a close or reporting deadline, or a material approval or access risk.
- Stabilize: blocks a repeatable cash, close, or reporting cadence but can be sequenced over the next 30–60 days.
- Improve: valuable longer-term work that should wait until the core operating rhythm is reliable.
For each finding, document the evidence, limitation, owner, next action, and target date. Avoid a score that implies precision the evidence does not support. A concise evidence-based findings list gives the CEO a better decision tool than a colorful but untraceable maturity rating.
Connect the audit to the first 90 days
The audit is an input to the first-90-days fractional CFO operating framework. It informs whether the first priority should be cash visibility, close stabilization, KPI definition, access cleanup, team ownership, or a more strategic finance project. It should also affect engagement scope; see how to price a fractional CFO retainer for a method that separates recurring leadership work from discrete remediation or implementation work.
Educational note
This is a finance-operating assessment, not an internal-control or security audit. Escalate specialized accounting, information-security, legal, tax, or compliance questions to appropriately qualified advisers.
Frequently asked questions
- Does a financial-stack audit mean replacing accounting software?
- No. The first question is whether the current system and process can produce timely, reliable information for the decisions at hand. Replacement may be a later option, but it should not be the assumed conclusion.
- How long should the audit take?
- The initial week-one view should be focused enough to identify risks, access gaps, and next questions. Deeper remediation, data cleanup, or system selection can take longer and should be separately planned.
- What is the most important system to review first?
- Start with the systems and handoffs that affect immediate cash, required filings or payroll, the current close, and leadership’s highest-priority decisions. The exact order depends on the client’s condition.
- Is this an internal-control or security audit?
- No. It is a finance-operating assessment. Escalate specialized accounting, information-security, legal, tax, or compliance questions to appropriately qualified advisers.