Checklist for Detecting Anomalous Transactions Before AI Audits
21/09/2026

The Myth of Clean Data vs. Deployment Reality
Many finance leaders believe that simply purchasing software will automatically catch every instance of tax compliance non-compliance. They assume data flows in from the ERP, algorithms process it, and their only job is to review the reports. Deployment reality proves this completely wrong. Financial data in Vietnamese enterprises, as well as in neighboring markets like Thailand and the Philippines, is often very "dirty." Invoice codes are inconsistent, partner names use varying abbreviations, and date formats (month-day-year) are mixed. If you do not clean the data first, the system will detect a mess rather than anomalous transaction findings with legal value. We once deployed a project for a major distribution group where 20% of input data had formatting errors. The result was continuous false alarms, causing the audit department to lose trust in the system within the first week. The lesson is: do not start with algorithms; start with data cleaning processes. This is the foundation of any effective AI audit system.

Key Technical Decisions to Make from the Start
When building the system, you are not just a user but a technical decision-maker. Below are the critical forks in the road you must choose, each accompanied by a clear trade-off.
- Static or dynamic alert thresholds? Static thresholds (e.g., alerting on all transactions over 100 million) are easy to set up but are easily ignored due to repetitive alerts. Dynamic thresholds are based on the historical behavior of specific partners. This method is more accurate, detecting clusters of small transactions, but requires at least six months of historical data for the model to learn what is "normal." If your company has recently undergone digital transformation, accept static thresholds for the first three months, then switch to dynamic.
- How to handle missing data? In multinational supply chains, data from factories in Mexico or warehouses in Indonesia often lacks address or tax code fields. You can remove these rows, but you will lose about one-third of your data. Alternatively, you can impute based on related data. Imputation is riskier as it can create false patterns, but it helps retain the overall picture. For legal audit purposes, we often recommend the removal method with a note on the reason, to ensure transparency when facing tax authorities.
- System execution frequency: real-time or batch? Real-time execution helps block transactions immediately but requires robust cloud infrastructure and high costs. Nightly batch execution is cheaper and sufficient for most post-event audit cases. For large manufacturing enterprises in industries like beer or instant noodles that AIVISION has supported, nightly batch execution is sufficient to catch abnormal trends before month-end reporting.
- Who handles the alerts? This is the most important organizational decision. If alerts are assigned to accountants, they will be overwhelmed by the volume. If assigned to internal audit, the response speed will be slow. The most effective approach is to create a small dedicated team, consisting of one IT specialist and one finance specialist, using a centralized dashboard. They do not need to process every alert, but focus only on high-risk cases. This reduces pressure and increases the accuracy of the response.
Common Questions from Clients
During consulting, we often receive these three questions from CFOs and Finance Directors. Here are the straightforward answers, without beating around the bush.
Can the system replace human auditors?
No. The system only performs repetitive tasks: comparison, reconciliation, and pattern searching. Human auditors are the ones who make the final judgment, assess the business context, and decide whether a violation has occurred. AI is a support tool, not a judge. Expect it to save you time in data retrieval, not to replace professional expertise.
How long does it take to see practical results?
The average time from starting deployment to having the first reliable report is 3 to 4 months. One month for data cleaning, one month for model training, and two months for parallel testing with the old process for calibration. If someone promises you results in two weeks, be careful. They may be using a simple tool not deep enough for complex AI audit work.
Are annual maintenance costs high?
Initial costs lie in data integration and model customization. Annual maintenance costs are primarily cloud costs and model updates when tax regulations change. Compared to the cost of hiring additional manual audit staff, the system is usually about half the price after the first year. However, this figure depends heavily on your transaction volume. Enterprises with millions of transactions per month will see significantly clearer economic benefits compared to companies with only a few thousand transactions.
How to Use This Checklist in Meetings and Its Limitations
Do not let this checklist sit in a PDF file. Print it out or project it on the screen during your next meeting with the IT and Finance departments. Start by asking: "Which of the four decisions above are we at?" If not yet chosen, spend the first 15 minutes finalizing it. This helps everyone align expectations from the start, avoiding a situation where each side understands things differently. After finalizing, clearly assign a person responsible for each item. For example, IT is responsible for data cleaning, and Finance is responsible for defining initial alert thresholds.
However, I need to be direct about what the system has not yet solved. AI is good at detecting repetitive patterns, but it is weak in understanding one-off abnormal contexts. For example, a sudden large transaction due to a special contract may be flagged as high risk, even if it is completely legitimate. The system does not know that it is a strategic deal. Therefore, you need to add a manual "exception confirmation" step to the process, where the finance lead can mark special transactions so the system learns and does not alarm next time. Additionally, this system only works well when input data has minimum quality. If the enterprise is still using scattered Excel files and has no central ERP, deployment will face significant difficulties. You need to add a basic data standardization step first, or accept a simpler version, focusing only on a few main transaction types. There is no perfect solution, but there is a pragmatic approach. Start small, measure results, and expand gradually. This is how successful enterprises in this field have done it, from large corporations to regional distribution companies.
If you are weighing up a similar project, our team can help you scope it before you spend anything. See what we build or book a conversation.