Reconciling Customer Funds Before You Pick an Audit Platform
A payments or embedded finance company carries a reconciliation no SaaS peer has to think about: customer funds sitting in a settlement or escrow account that must tie to the ledger, to the penny, every single day, not just at month end.
Get that process right before you decide between FloQast and AuditBoard, because it changes which one you need first.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
How do you nail down the daily float reconciliation?
Before either tool matters, your team needs a daily process that ties the balance in your settlement or escrow account to what your ledger says customers are owed, with a documented explanation for every variance.
This reconciliation happens far more often than a typical monthly close cadence, and it's the control most examiners and auditors test first, because a break here means customer funds and company funds have gotten mixed up somewhere in the pipeline.
Step Two: Separate Regulatory Reporting From Financial Close
Money transmitter licenses and state-level regulatory filings run on their own calendar and their own definitions of what counts as customer funds, which don't always match GAAP close timing.
Keep these as separate workstreams even though they draw on the same underlying data, because conflating them is how a fintech ends up missing a filing deadline while focused on closing the books, or the other way around.
Step Three: Map Where SOX and Security Controls Actually Overlap
Access controls over who can move customer funds, change settlement account details, or approve a payout often satisfy both a security requirement and a SOX financial reporting control at the same time.
Map that overlap explicitly instead of maintaining two separate control lists for the same access review, since a GRC platform is built to hold one control with multiple compliance frameworks mapped to it rather than duplicating the work.
Step Four: Decide Who Owns Testing Once Controls Are Documented
Documenting a control and testing it on a schedule are different jobs, and fintechs sometimes stop at documentation because nobody owns the testing calendar.
This is where AuditBoard earns its keep for a payments company specifically: the customer-funds handling controls that examiners and auditors both care about need periodic, evidenced testing, not just a policy document that hasn't been reviewed since it was written.
How do you sequence the purchase around your renewal or audit date?
If your daily float reconciliation is still a manual spreadsheet exercise, fix that with close management software first, since it's the control most likely to generate a finding in the meantime.
If float reconciliation is already solid and your gap is testing and evidencing the access and change controls around customer funds, prioritize a GRC platform ahead of your next license renewal or SOX walkthrough, since regulators and auditors will ask for that evidence on their timeline, not yours.
A Worked Example: Tracing a Small Float Break
Picture a payments company whose daily float reconciliation comes up a few cents short on a Tuesday. On its own, a break that small looks trivial, and it's tempting to plug it and move on. The problem is that a small unexplained variance is often the visible edge of a larger issue: a failed transaction that retried and posted twice, a fee calculated on the wrong side of the ledger, or a settlement file that arrived with one record missing.
Treating every variance, regardless of size, as something that needs a documented root cause rather than a plug is the discipline examiners and auditors actually test for. A reconciliation template that requires an explanation field before it can be marked complete forces that habit, and it's exactly the kind of control close management software enforces well: no sign-off without a stated reason for every open item.
Once the root cause is found, the harder question is whether it's a one-time processing error or a pattern. If the same kind of break shows up for several months running, that's no longer a close-process issue, it's a control gap in how transactions post or how a settlement file gets validated on the way in, and it belongs in front of whoever owns testing for access and change controls over the payment pipeline. That's the handoff point between close software, which caught the pattern, and a GRC platform, which documents and tests the fix.
This matters even more for a fintech running multiple settlement rails at once, ACH, card networks, and instant payment rails, each with its own timing quirks and file formats. A break that's routine on one rail can be a genuine incident on another, so keep the investigation playbook rail-specific rather than assuming what worked for one settlement break applies to the next.
In order, the sequence looks like this:
- Reconcile the settlement or escrow account to the ledger every business day, not only at month end.
- Keep regulatory reporting separate from the financial close.
- Map each control once and tie it to both SOX and security frameworks, especially access and change management over systems that touch customer funds.
- Assign an owner for testing once controls are documented.
- Time the purchase around your renewal or audit date.
What Good Looks Like
A fintech's close and controls are in good shape when the daily float reconciliation ties to the penny with a documented variance explanation, and the access controls governing customer funds are both mapped to every framework that requires them and tested on a set schedule.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
An AP tool like BILL helps enforce approval layers over vendor and processor fee payments, which examiners sometimes review alongside customer funds controls.
A card platform like Ramp keeps operating expense controls separate and auditable from customer funds flows, which helps when an examiner or auditor wants to see the two are never commingled operationally.
Frequently Asked Questions
Does general security compliance cover what a SOX audit needs for a fintech?
No. Security compliance work addresses trust controls that partners and customers care about. SOX 404 addresses internal control over financial reporting specifically, including controls over how customer funds are reconciled and reported to the extent they affect your financial statements, and it matters once you're public or preparing for a filing regardless of your other certifications.
How often should float reconciliation happen for a payments company?
Daily, not monthly. Customer funds sitting in a settlement or escrow account need to tie to the ledger every business day, since a mismatch that sits unnoticed for weeks is far harder to explain to an examiner or auditor than one caught the next morning.
Can one control satisfy both security and SOX requirements?
Often, yes, particularly for access and change management controls over systems that touch customer funds or payment data. Map the control once and tie it to both frameworks in whatever system tracks your controls, rather than documenting and testing it twice.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
The Fintech Close: FloQast, BlackLine, and Settlement Reconciliation
Fintech and embedded finance platforms live or die on settlement reconciliation. Here's where FloQast and BlackLine fit and where each one falls short.
Cap Table Tools for a Fintech's Multi-Class Stock
How embedded finance and payments companies should weigh Pulley against Carta when preferred stock stacks, investor rights and audit scope multiply fast.
409A Valuation Platforms for Fintech and Embedded Finance Teams
Fintech and embedded finance companies face regulatory scrutiny that shapes their 409A. Here's how Carta and Shareworks handle that added complexity.
Fintech and Payments: Cube vs Mosaic for Take Rate Modeling
How Cube and Mosaic handle fintech unit economics: modeling take rate compression, interest on customer float, and sponsor bank fee structures.
Ramp vs Brex for Fintech and Embedded Finance Startups
How Ramp and Brex compare for fintech and embedded finance companies, where compliance and legal spend often rivals engineering as a cost center.
BILL vs Tipalti for Fintech and Embedded Finance Companies
Fintech and embedded finance companies face heavier vendor due diligence than most software firms. Here's how BILL and Tipalti compare for that workload.