Financial Audit Management & Pre-IPO Compliance3 min readUpdated September 2026

Reconciling Customer Funds Before You Pick an Audit Platform

A payments or embedded finance company carries a reconciliation no SaaS peer has to think about: customer funds sitting in a settlement or escrow account that must tie to the ledger, to the penny, every single day, not just at month end.

Get that process right before you decide between FloQast and AuditBoard, because it changes which one you need first.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

How do you nail down the daily float reconciliation?

Before either tool matters, your team needs a daily process that ties the balance in your settlement or escrow account to what your ledger says customers are owed, with a documented explanation for every variance.

This reconciliation happens far more often than a typical monthly close cadence, and it's the control most examiners and auditors test first, because a break here means customer funds and company funds have gotten mixed up somewhere in the pipeline.

Step Two: Separate Regulatory Reporting From Financial Close

Money transmitter licenses and state-level regulatory filings run on their own calendar and their own definitions of what counts as customer funds, which don't always match GAAP close timing.

Keep these as separate workstreams even though they draw on the same underlying data, because conflating them is how a fintech ends up missing a filing deadline while focused on closing the books, or the other way around.

Step Three: Map Where SOX and Security Controls Actually Overlap

Access controls over who can move customer funds, change settlement account details, or approve a payout often satisfy both a security requirement and a SOX financial reporting control at the same time.

Map that overlap explicitly instead of maintaining two separate control lists for the same access review, since a GRC platform is built to hold one control with multiple compliance frameworks mapped to it rather than duplicating the work.

Step Four: Decide Who Owns Testing Once Controls Are Documented

Documenting a control and testing it on a schedule are different jobs, and fintechs sometimes stop at documentation because nobody owns the testing calendar.

This is where AuditBoard earns its keep for a payments company specifically: the customer-funds handling controls that examiners and auditors both care about need periodic, evidenced testing, not just a policy document that hasn't been reviewed since it was written.

How do you sequence the purchase around your renewal or audit date?

If your daily float reconciliation is still a manual spreadsheet exercise, fix that with close management software first, since it's the control most likely to generate a finding in the meantime.

If float reconciliation is already solid and your gap is testing and evidencing the access and change controls around customer funds, prioritize a GRC platform ahead of your next license renewal or SOX walkthrough, since regulators and auditors will ask for that evidence on their timeline, not yours.

A Worked Example: Tracing a Small Float Break

Picture a payments company whose daily float reconciliation comes up a few cents short on a Tuesday. On its own, a break that small looks trivial, and it's tempting to plug it and move on. The problem is that a small unexplained variance is often the visible edge of a larger issue: a failed transaction that retried and posted twice, a fee calculated on the wrong side of the ledger, or a settlement file that arrived with one record missing.

Treating every variance, regardless of size, as something that needs a documented root cause rather than a plug is the discipline examiners and auditors actually test for. A reconciliation template that requires an explanation field before it can be marked complete forces that habit, and it's exactly the kind of control close management software enforces well: no sign-off without a stated reason for every open item.

Once the root cause is found, the harder question is whether it's a one-time processing error or a pattern. If the same kind of break shows up for several months running, that's no longer a close-process issue, it's a control gap in how transactions post or how a settlement file gets validated on the way in, and it belongs in front of whoever owns testing for access and change controls over the payment pipeline. That's the handoff point between close software, which caught the pattern, and a GRC platform, which documents and tests the fix.

This matters even more for a fintech running multiple settlement rails at once, ACH, card networks, and instant payment rails, each with its own timing quirks and file formats. A break that's routine on one rail can be a genuine incident on another, so keep the investigation playbook rail-specific rather than assuming what worked for one settlement break applies to the next.

In order, the sequence looks like this:

  1. Reconcile the settlement or escrow account to the ledger every business day, not only at month end.
  2. Keep regulatory reporting separate from the financial close.
  3. Map each control once and tie it to both SOX and security frameworks, especially access and change management over systems that touch customer funds.
  4. Assign an owner for testing once controls are documented.
  5. Time the purchase around your renewal or audit date.
Executive Capability Standard

What Good Looks Like

A fintech's close and controls are in good shape when the daily float reconciliation ties to the penny with a documented variance explanation, and the access controls governing customer funds are both mapped to every framework that requires them and tested on a set schedule.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Confirm exactly which state money transmitter licenses and which financial reporting frameworks apply to your specific payment flows, since this varies by product structure.
2. Do Manually:Build a daily, not monthly, template for reconciling the settlement or escrow balance to the ledger, with a required explanation field for any variance.
3. Delegate:Assign one person to own the daily float reconciliation and a separate person to review it, so the same individual never prepares and approves the same check.
4. Automate:Deploy FloQast for the close-level reconciliations feeding into your ledger, and AuditBoard once you need to test and evidence access controls across multiple frameworks at once.
5. Buy:Engage outside counsel or a compliance advisor to confirm your money transmitter obligations before you design controls around the wrong regulatory framework.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does general security compliance cover what a SOX audit needs for a fintech?

No. Security compliance work addresses trust controls that partners and customers care about. SOX 404 addresses internal control over financial reporting specifically, including controls over how customer funds are reconciled and reported to the extent they affect your financial statements, and it matters once you're public or preparing for a filing regardless of your other certifications.

How often should float reconciliation happen for a payments company?

Daily, not monthly. Customer funds sitting in a settlement or escrow account need to tie to the ledger every business day, since a mismatch that sits unnoticed for weeks is far harder to explain to an examiner or auditor than one caught the next morning.

Can one control satisfy both security and SOX requirements?

Often, yes, particularly for access and change management controls over systems that touch customer funds or payment data. Map the control once and tie it to both frameworks in whatever system tracks your controls, rather than documenting and testing it twice.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides