Operating model

The evidence that
survives your audit.

Finance work moves through clear checkpoints, with evidence and authority attached.

  1. Signal

    A recurring task or a change in your books starts the work.

  2. Gather + check

    Relevant records come together. Gaps and conflicts surface.

  3. Prepare

    A proposed result, with the evidence behind it.

  4. Verify

    The proposal is checked against the rules and source records.

  5. Decide

    Proceed within recorded authority, or return to a person.

Human authorityApprove, narrow, return, or hold

Read-only or draft

A checked result, ready for your review.

Bounded action

Only the authorized action, followed by a check of what actually changed.

Exception Trace the return path

A source record is missing. The proposed result cannot pass verification.

  1. Back to Gather + check. Recover the missing record or resolve the conflict.
  2. Prepare and verify again. The revised proposal goes through the same checks and authority decision.
  3. Still unresolved? The work stays on hold for a person. It does not skip ahead.
After the decision
  1. OutcomeA verified output or an authorized action.
  2. ReadbackThe destination of record confirms the result.
  3. Operating recordEvidence, decisions, results, and open exceptions stay together.
Exceptions return to Gather + check for repair and reverification, or stay on hold for a person. Open Exception to follow an example.

Guarded autonomy

The record has to survive your audit.
A model's reasoning does not.

Delegating the work should not mean giving up the context, judgment, or visibility you need to stand behind it.

  1. Your process. Your boundaries.

    The starting point is your business context, the result you need, and clear limits on what the agent may do.

  2. Evidence before an answer

    Missing invoices and conflicting records are exceptions to resolve, not blanks for a model to fill.

  3. Decisions that stay yours

    Actions stay within the limits you authorize; anything outside them comes back to you.

  4. A second check, independent of the agent

    Night Auditor checks the work against source records, not the agent's account of what happened.

  5. Confirmation, not assumption

    The result is checked against the destination of record, so you can see what actually changed.

  6. Work you can evaluate

    Agent Grader evaluates the operating record, giving you a basis to judge the work beyond an agent saying it is done.

Four questions the record has to answer

  1. 01

    What was requested?

    The record names the work that was asked for, in the terms of your process.

  2. 02

    What evidence was it built from?

    The source records sit with the result. A missing invoice is an exception, not a blank the model fills.

  3. 03

    Who recorded the decision?

    Anything that posts, files, or pays waits on a named person. The permission to do otherwise does not exist.

  4. 04

    What actually changed?

    The result is checked against the destination of record. A model's account of the work is not that check.

Standards this is built to

  1. Generative AI internal control

    Mapped to COSO, Achieving Effective Internal Control Over Generative AI, 23 February 2026, guidance sections "AI capability types" and "Applying COSO to GenAI": bounded authority, source evidence, and independent readback against the guidance's five components and eight capability types.

    Bounded authority, source evidence, and independent readback.

  2. Electronic audit information

    Designed to satisfy AS 1105.10A and AS 2301.17, including the technology-assisted analysis amendments effective for audits of financial statements for fiscal years beginning on or after 15 December 2025: a complete source manifest, per-document digests, and independent readback preserve evidence of receiving, maintaining, and processing electronic information, with the auditor retaining the determination of whether substantive procedures alone are insufficient and controls testing is required.

    Complete source manifest, per-document digests, and independent readback, with the controls-testing determination retained by the auditor.

  3. Controls before an agent-run close

    Produces the evidence for Fulmore, "Before You Let the Agents Run the Close: Five Controls to Put in Writing First," CPA Practice Advisor practitioner guidance, 13 August 2026, sections 1 through 5: named ownership, replayable evidence, risk-scaled human sign-off, third-party assurance mapping, and monitoring with an exit threshold in the close operating record.

    Close-packet ownership, replayable evidence, risk-scaled sign-off, assurance mapping, and monitored exit thresholds.

Start with your process

Where does your close get stuck?

Tell us about the recurring work, the exceptions, and the decisions that still need you.

hello@nightworks.ai