Accounting Intelligence (ACCTINT): Intelligence Discipline Guide
Financial statements are an argument, not a record. Accounting intelligence is the discipline of testing whether the argument actually holds.
Financial statements are an argument, not a record. Accounting intelligence is the discipline of testing whether the argument actually holds.
What Accounting Intelligence is as a discipline
Accounting intelligence is the structured analysis of financial statements, disclosures and accounting policy to assess an entity true condition and detect manipulation. It works from filed accounts, meaning balance sheet, income statement, cash flow statement, notes and auditor reports, together with segment data, related-party disclosure, restatements and management commentary. Techniques include ratio and trend analysis, reconciliation of earnings to cash, accrual quality assessment, revenue recognition scrutiny, and digit and distribution testing. The purpose is to locate where reported performance and economic reality diverge, and to explain why.
Sub-methods include forensic accounting on suspected fraud, credit analysis of counterparty solvency, quality-of-earnings review during due diligence, and comparative benchmarking against peers and sector norms. Maturity runs from reading the statements, to systematic quantitative screening across a portfolio, to integrated analysis combining filings with corporate registry, litigation, procurement and supply-chain evidence. In practice the notes and the auditor report carry far more information than the headline figures they accompany.
Why it matters
This discipline answers whether an entity is what its numbers claim. It is the only method that can detect fraud, distress or manipulation from primary documents before an incident, a default or an enforcement action makes the problem public. In counterparty and supplier risk it identifies fragility that no credit score reflects. In investigations it exposes circular revenue, undisclosed related-party transfers and asset overstatement, which are the mechanics through which value is misappropriated and obligations concealed.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Sustained divergence between reported net income and operating cash flow across several periods, the classic accrual quality warning
- Receivables and inventory growing materially faster than revenue, indicating channel stuffing, collection failure or obsolete stock
- Revenue recognition policy changes, unusual contract terms, or a shift toward bill-and-hold and long-dated performance obligations
- Related-party transactions, loans to directors and off-balance-sheet vehicles disclosed only in the notes rather than the face statements
- Auditor changes, resignations, qualified opinions, going-concern paragraphs and disclosed material weaknesses in internal control
- Restatements, late filings and repeated non-standard adjustments that consistently move reported results in a favourable direction
- Margin and expense ratios deviating from sector peers without any operational explanation appearing in the disclosures
- Digit distribution and rounding anomalies, and reported figures clustered just above covenant, bonus or classification thresholds
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- SEC EDGAR — Full text of US filings including annual and quarterly reports, proxy statements and auditor opinions, free
- SEC Financial Statement Data Sets — Structured XBRL data enabling bulk ratio and trend screening across thousands of filers at once
- Companies House (UK) — Filed statutory accounts, charges, officers and filing history for UK entities, downloadable without charge
- GLEIF — Legal Entity Identifier records mapping entities to parents, supporting consolidation and group-level analysis
- OpenCorporates — Cross-jurisdiction registry aggregation used to identify affiliates, subsidiaries and probable related parties
- PCAOB inspection reports — Audit quality findings and registration status for the firm that signed the accounts in question
- National registry portals — Bundesanzeiger, Registro Mercantil and ASIC publish statutory accounts outside the Anglo-American systems
- Court and insolvency records — Litigation, liens and administration filings that can directly contradict a going-concern presentation
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Assemble primary documents — Collect several years of filed accounts with notes, auditor reports and proxy disclosure. Never analyse a single period in isolation.
- Normalise the figures — Restate for policy changes, acquisitions, currency and non-recurring items so that periods and peers become genuinely comparable.
- Screen quantitatively — Run ratio, trend and accrual tests, flagging divergence from sector peers and from the entity own historical behaviour.
- Read the notes — Most material disclosure sits in related-party notes, contingencies, subsequent events and internal control weakness statements.
- Reconcile to cash — Trace reported earnings through to operating cash flow and financing activity, because cash is the hardest number to manufacture.
- Corroborate externally — Test the reported story against registry filings, court records, procurement awards, headcount and observable physical operations.
- Report with the working shown — State the anomaly, the supporting evidence, the benign explanations considered and rejected, and your confidence in the conclusion.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
Operates on these data points
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Corporate Filing — A regulatory or corporate filing (SEC, Companies House, court).
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
Related disciplines
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Cryptocurrency Intelligence — Tracing Value on Public Ledgers
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Financial Intelligence — Following Value Through the Financial System
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
Inside the platform: where Accounting Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=ACCTINT— Discipline hubsource-catalog.php?disc=ACCTINT— Source catalogue filtered to this disciplinesearch.php— Person / Name profilesanctions.php— Sanction / Watchlist Entry profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Export STIX/MISP
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Assemble primary documents is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Screen quantitatively turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report with the working shown feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Accounting Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts practise accounting intelligence mainly against the industrial base rather than against manoeuvre units. The authority is contractual and commercial: audited accounts, cost and pricing data submitted under acquisition regulation, and open filings from prime contractors and their lower tiers. The analyst tests whether a supplier can actually sustain a production rate, whether working capital supports a surge, and whether a foreign parent introduces control risk. Output feeds acquisition risk boards, industrial base assessments and sustainment planning, and occasionally force protection where a local contractor is failing. Constraint: commercial judgements circulated to programme staff must rest on releasable filed data, not on classified reporting, or the finding cannot be acted on.
🕵 National intelligence
National intelligence services treat filed accounts as a validated, attributable open source that can be fused with collection that cannot be shown. Requirements typically concern proliferation financing, sanctions circumvention, state-linked commercial fronts and strategic industry health. The practitioner works consolidated statements, segment notes, related-party disclosure and auditor opinions, then compares the declared picture against trade, shipping and signals-derived reporting to identify the gap that needs explaining. Products are usually assessed judgements with source-reliability grading rather than raw extracts. Handling matters: the underlying filings are unclassified, so the classification attaches to the analytic conclusion and to any collateral corroboration, and tearlines are written so the open finding can be passed to partners.
👮 Law enforcement
Investigators use accounting intelligence to build the evidential spine of fraud, corruption and money laundering cases. Filed accounts and registry documents are obtained as public records or under production order; internal ledgers, journals and audit working papers require a warrant, production order or mutual legal assistance request. Everything is exhibited with continuity: who obtained it, when, from which registry, and the hash of the retrieved file. Analysis is directed at provable propositions such as false accounting, concealment of a deficiency, or a transaction with no commercial rationale. The output supports charging by tying a specific person to a specific entry, and expert accounting evidence is normally required to put the reconstruction before a court.
🔍 Private investigation and corporate security
Corporate and private practitioners use accounting intelligence for pre-transaction due diligence, counterparty credit risk, insider fraud triage and litigation support. The lawful base is filed accounts, credit agency data, court records, and material supplied under a contractual right to audit. A private actor may not obtain bank records, tax filings or internal ledgers by pretext, deception or paid access to an insider, and may not run covert surveillance on the finance team. In practice the value comes from disciplined ratio work, comparison against filed peers and identification of disclosure that has quietly changed year on year. Findings are written as risk statements with stated confidence, not as accusations of fraud.
📰 Journalism and OSINT media
Journalists practise accounting intelligence to substantiate stories about failing companies, extraction of value, hidden ownership and public-money misuse. The standard is that every figure quoted is traceable to a named filing with a date, and that the interpretation has been tested with an independent accountant who is willing to be cited or at least to correct an error. Leaked internal accounts must be authenticated against filed figures before use, and the leak route protected. Statistical red flags such as an unusual accrual pattern are indicative, never conclusive, and must be published as such. The company gets a specific, itemised right of reply, and any correction offered on the numbers is published.
🌍 NGO, humanitarian and human rights
NGO and accountability practitioners use accounting intelligence to trace public funds, expose asset stripping, and document the financial architecture of harm, for example a contractor profiting from forced labour or an extractive project understating remediation liabilities. The discipline is applied to filed accounts, procurement records and donor reporting, and the output is intended for regulators, courts and coalitions rather than for confrontation. Do-no-harm applies to the people who gave you documents: publication timing and detail can identify an internal source in a small finance function. Where a state actor is implicated, staff exposure is a live risk and legal review before publication is standard. Preserve originals for later accountability processes.
🎓 University and research
Researchers apply accounting intelligence as empirical method: accrual quality models, earnings management detection, digit-distribution tests and going-concern prediction, run over panels of filings rather than single entities. Reproducibility depends on documenting the extraction pipeline from the registry or filing archive, the exact taxonomy or line-item mapping used, and every exclusion rule, since restatements and taxonomy changes silently break comparability. Ethics review is usually light for public filings but becomes substantive where the design names living individuals as suspected manipulators. Publish code and the identifier list rather than redistributing licensed vendor data, and cite the filing archive and retrieval date because filings are amended in place.
Playbook: working Accounting Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Frame the accounting question
Establish precisely what is being tested before opening a single statement. Distinguish solvency and viability questions from manipulation questions and from ownership-of-value questions, because they use different evidence. Write the proposition in falsifiable terms, for example that reported revenue growth is not supported by cash conversion, or that the entity cannot meet obligations falling due within twelve months. Identify the decision the answer supports and the tolerance for error. A good output is a one-page terms of reference naming the entity, the reporting periods in scope, the comparators and the threshold at which a finding becomes reportable. Stop when the question can be answered with a yes, a no or a specified gap.
Phase 2 — Fix the reporting entity and perimeter
Determine which legal entity actually files, what it consolidates, and what sits outside the consolidation. Retrieve the group structure from the registry and the notes, and identify joint ventures, associates, special purpose entities and unconsolidated structured entities. Note the accounting framework and any change in it, the auditor, the reporting date and any change of year end. Perimeter errors are the commonest cause of wrong conclusions: comparing a consolidated group against a standalone subsidiary produces spurious findings. A good output is an entity map showing which numbers belong to which legal person. Stop when every material operating unit is placed inside or outside the perimeter.
Phase 3 — Assemble the primary filings
Pull the full filing set for at least five reporting periods: statements, notes, auditor report, directors report, and any interim accounts. Capture the original documents rather than a vendor summary, record the retrieval date, and hash the files. Collect restatements and prior-period adjustments separately, because they mark exactly where management previously got it wrong. Where an entity files in more than one jurisdiction, collect all versions and compare. A good output is a versioned document set with a manifest. Stop when you can reconstruct each headline figure from a filed document without recourse to a secondary source.
Phase 4 — Normalise and rebuild the series
Rebuild balance sheet, income statement and cash flow into a consistent multi-period series, adjusting for currency, acquisitions, disposals, discontinued operations and framework changes. Recalculate rather than transcribe, and reconcile opening to closing balances so nothing is unexplained. Every adjustment is logged with its rationale, because an unlogged normalisation is indistinguishable from an error. A good output is a workbook where each derived figure traces to a filed line item and every bridge closes to zero. Stop when the reconstructed series ties to the filings across all periods and the residual is nil or explained.
Phase 5 — Run the diagnostic screen
Apply the standard analytic battery: accrual ratio and cash conversion, days sales outstanding and inventory days against sector norms, gross margin stability, capitalisation of costs, revenue recognition policy shifts, related-party volume, and the composite scores such as the Beneish and Altman models used as screens rather than verdicts. Add digit-distribution testing where transaction-level data exists. The screen is designed to generate candidate anomalies, not conclusions. A good output is a ranked anomaly list with the specific line item and period each one attaches to. Stop when further tests stop producing new candidates rather than when the checklist is exhausted.
Phase 6 — Read the notes and the language
The notes carry the disclosure that the face of the statements hides. Read accounting policy notes for changes in estimate, revenue recognition and impairment triggers; read contingent liabilities, guarantees, covenant terms and going-concern statements; read the auditor report for emphasis of matter, key audit matters and any qualification. Compare the wording of the same note year on year, because quiet deletions and softened language are signals. Track auditor changes and resignations. A good output is a note-level diff across periods with each material change flagged. Stop when every material anomaly from the screen has a disclosure explanation or a documented absence of one.
Phase 7 — Corroborate against non-accounting evidence
Test the reported picture against evidence the entity does not control. Compare declared exports against customs statistics, headcount against filings and job postings, capacity against physical observation, and payment behaviour against court and enforcement records. Check directorships and related parties against corporate registries and beneficial ownership registers, and screen counterparties against sanctions and enforcement lists. Where reported activity has no observable footprint, that gap is the finding. A good output is a corroboration table listing each key claim, the independent evidence for or against it, and the residual uncertainty. Stop when the material claims are each supported or contradicted by an external source.
Phase 8 — Build the alternative explanation
For every anomaly, construct the benign explanation as carefully as the adverse one. A jump in receivables may be a genuine large contract with extended terms; a capitalisation change may follow a legitimate framework amendment. Seek the evidence that would distinguish the two and go and get it. This phase is what separates a defensible finding from an allegation. A good output is, for each anomaly, a stated adverse hypothesis, a stated benign hypothesis, the discriminating evidence, and a confidence judgement. Stop when no material anomaly remains with two equally supported explanations, or when the residual ambiguity is explicitly recorded.
Phase 9 — Grade and write the assessment
Write the finding as an assessed judgement with explicit confidence and explicit sourcing, separating what the filings state, what you calculated, and what you infer. Quantify materiality so the reader knows whether a finding changes the decision. Include what would change the assessment, which is what makes the product reviewable. For evidential use, produce a schedule tying each conclusion to an exhibited document and page. A good output is short, decision-facing and survives an adversarial read by the entity accountants. Stop when a competent reviewer can reproduce every number from the appendix without asking you a question.
Phase 10 — Maintain and re-test
Accounting intelligence decays with each new filing. Set a monitoring trigger on new filings, auditor changes, restatements, covenant events, late filing and enforcement actions against the entity or its officers. Re-run the diagnostic screen on each new period rather than assuming the prior conclusion holds, and specifically re-test any finding that was marginal. Record whether previous judgements proved right, because calibration is the only way the capability improves. A good output is a standing watch list with defined trigger events and a short revision log per entity. Stop maintaining only when the decision the analysis supported has been closed out.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| SEC EDGAR | Open | Full text and structured filings for issuers registered in the United States, including annual and quarterly reports, ownership and event disclosures. | Primary source for multi-period statement reconstruction, restatement history, auditor changes and related-party disclosure on US-listed entities. |
| Companies House | Open | United Kingdom statutory registry holding filed accounts, officer appointments, charges, and persons with significant control declarations. | Retrieval of filed accounts and group structure for UK entities, plus late-filing and strike-off signals that indicate distress. |
| GLEIF Legal Entity Identifier data | Open | Global register of legal entity identifiers with parent and ultimate parent relationship records maintained under a common data standard. | Fixes the reporting perimeter by resolving which legal entity files and which parent consolidates it across jurisdictions. |
| OpenCorporates | Registration | Aggregated company registry records from many jurisdictions with officer, filing and status data normalised into a common schema. | Rapid perimeter mapping and identification of unconsolidated affiliates and common officers across borders. |
| IFRS Foundation standards | Open | The authoritative text and amendment history of international financial reporting standards and interpretations. | Establishes whether an apparent policy change is a permitted framework amendment or a discretionary management choice. |
| PCAOB | Open | Audit inspection reports, enforcement actions and auditing standards for firms auditing US-listed issuers. | Assesses auditor quality and identifies firms with inspection findings relevant to reliance on the audit opinion. |
| OpenSanctions | Open | Consolidated sanctions, politically exposed person and enforcement datasets with entity resolution across source lists. | Screens directors, shareholders and counterparties surfaced in related-party notes against designation and enforcement data. |
| OCCRP Aleph | Registration | Searchable archive of leaks, registries, court filings and procurement records assembled for investigative research. | Corroborates related-party relationships and finds counterparty records that never appear in filed accounts. |
| UN Comtrade | Registration | Official bilateral merchandise trade statistics reported by national customs authorities at commodity code level. | Tests declared export or import revenue against reported trade flows for the same period and corridor. |
| FRED | Open | Economic time series covering prices, rates, output, credit conditions and sector activity from official statistical sources. | Supplies the macro baseline against which a reported margin or volume trend is judged plausible or anomalous. |
| Financial Reporting Council | Open | United Kingdom audit and reporting regulator publishing enforcement decisions, audit quality reviews and corporate reporting reviews. | Identifies entities and auditors already subject to regulatory challenge over the reporting periods under examination. |
| ESMA | Open | European securities regulator publishing enforcement decisions on financial reporting and common enforcement priorities. | Provides the supervisory view of which disclosure areas are being challenged across European issuers in a given year. |
| Association of Certified Fraud Examiners | Registration | Practitioner body publishing occupational fraud research, detection method effectiveness data and investigative methodology. | Calibrates expectations about which manipulation schemes are actually common and how they are typically detected. |
| World Bank open data | Open | Country-level economic, sector and governance indicators compiled from national and international statistical systems. | Benchmarks entity performance against the operating environment in jurisdictions with thin peer sets. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Accounting Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- XBRL structured filing extractors — Pull tagged line items directly from filings for multi-period series building. Limitation: tag choices vary by preparer, so mappings need manual validation before comparison.
- Spreadsheet reconstruction models — Rebuild statements with explicit bridges and reconciliations that a reviewer can audit. Limitation: fragile at scale and prone to silent formula error without cell-level testing.
- Python pandas with statement mapping libraries — Scripted normalisation and ratio computation across large filing panels. Limitation: quality depends entirely on the line-item mapping, which no library gets right unattended.
- Digit-distribution and Benford testing scripts — Flag unnatural numeric patterns in transaction or line-item populations. Limitation: only valid on naturally occurring unbounded data, and generates noise on rounded or capped values.
- Beneish and Altman scoring implementations — Composite screens for earnings manipulation likelihood and bankruptcy risk. Limitation: derived from specific historical samples, so they misfire badly outside their calibration sectors.
- Document diff and text-comparison tools — Show year-on-year changes in accounting policy notes and auditor language. Limitation: formatting churn in filed PDFs generates false differences requiring manual review.
- Corporate graph and link analysis platforms — Visualise ownership, directorship and related-party networks around the reporting entity. Limitation: registry coverage is uneven, so absence of an edge means nothing.
- Full-text filing search engines — Locate specific disclosure language across an issuer population or a sector. Limitation: coverage stops at jurisdictions that publish machine-readable filings.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Recalculate every headline figure from the filed statements rather than transcribing it. Preparers and data vendors both introduce error, and the act of rebuilding surfaces the perimeter problems and policy changes that a copied number conceals entirely.
- Read the auditor report before the numbers. A key audit matter, an emphasis of matter or a change of firm tells you where management judgement is doing the heavy lifting, which is where manipulation, if present, will be found.
- Treat restatements as the highest-value document in the set. A restatement is a formal admission of where the prior reporting was wrong, and the pattern of what gets restated is often more diagnostic than any ratio.
- Composite scores such as Beneish are screening instruments, not findings. Analysts who report a score as a conclusion get caught by sector effects; analysts who use it to select which notes to read at length do not.
- Cash conversion is harder to fabricate than revenue. When accrual earnings and operating cash flow diverge persistently over several periods without a working capital explanation in the notes, that divergence outranks every other signal.
- Compare the same note across years side by side rather than reading each year fresh. Deletions, softened qualifiers and newly vague language in policy and contingency notes are the cheapest early warning available.
- Fix the consolidation perimeter before any comparison. Most wrong accounting findings are not manipulation but the analyst comparing a group against a standalone entity, or across a changed year end, and mistaking the artefact for a signal.
- Build the benign explanation with real effort. An anomaly with a plausible innocent cause that you did not test is not evidence, and an entity accountant will demolish it in the first meeting.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Accounting Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of reported findings that survive challenge by the subject entity or its auditors without material revision, measured over a rolling twelve months.
- Median time from a new filing or restatement appearing on the registry to a completed re-assessment of any entity on the standing watch list.
- Share of anomalies raised that were later explained by a perimeter, framework or currency artefact rather than by underlying economics, which should fall over time.
- Number of distress or manipulation events in the covered population that the capability flagged in advance, against the number that were missed entirely.
- Percentage of conclusions in issued products that trace to an exhibited filed document with page reference, rather than to a vendor summary or secondary reporting.
- Calibration score of stated confidence levels against subsequent outcomes, recorded per analyst and reviewed at least annually.
- Reduction in downstream decisions reversed because the financial assessment turned out to be based on the wrong reporting entity.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Comparing entities on different accounting standards or fiscal calendars without normalising, producing differences that are purely technical
- Treating a single ratio anomaly as fraud when sector economics, seasonality or one non-recurring transaction explains it entirely
- Skipping the notes, where related-party dealings and contingent liabilities are disclosed because they must be but need not be prominent
- Over-relying on aggregator data that silently omits restatements, amendments and separately filed subsidiary accounts
- Analysing small private companies with abridged filing exemptions as though the disclosure were comparable to a listed issuer
- Publishing an unproven fraud allegation, which carries defamation and market-manipulation exposure regardless of analytical quality
Legal and ethical considerations
Filed accounts are public record and free to analyse, but conclusions about misconduct are consequential. Allegations of fraud made publicly without adequate evidence attract defamation liability, and in listed securities may constitute market manipulation. Non-public financial information obtained from insiders raises insider dealing and confidentiality issues. Aggregator data may carry reuse restrictions. Where findings support litigation or regulatory referral, preserve the original filings with retrieval dates, document methodology fully, and distinguish clearly between an observed anomaly and an asserted intent.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Accounting Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 data points, 4 mission domains, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can accounting intelligence prove fraud on its own?
No. Filed accounts can establish that a reported figure is implausible, that disclosure changed without explanation, or that cash and earnings diverge without a stated cause. Proving fraud requires intent, and intent is established from internal records, communications and testimony that no public filing contains. Treat statement analysis as the instrument that tells you where to direct compulsory process and interviews. In an evidential setting the accounting reconstruction is normally presented as expert opinion supporting inferences drawn from primary documents, not as the proof itself. Presenting a ratio anomaly as proof of dishonesty is the fastest way to lose a case.
How many reporting periods do I actually need?
Five is the working minimum for trend work and eight is better where the sector is cyclical. Two periods cannot distinguish a trend from a one-off, and three will not survive an acquisition or a disposal in the middle of the series. If only two periods exist, because the entity is newly incorporated or newly consolidated, say so explicitly and downgrade confidence rather than proceeding as if the series were adequate. Where periods are missing, check whether the gap is a late filing, a change of year end or a re-registration, because each of those is itself a signal worth reporting.
What do I do when the entity files nothing useful?
Small private entities in permissive jurisdictions often file abridged accounts with no cash flow statement and minimal notes. Pivot to indirect evidence: charges and security registered against assets, employment and pension filings, court and enforcement records, customs and trade data, procurement awards, property and vehicle registrations, and the filings of consolidated parents or trading counterparties in stricter jurisdictions. Also check whether any group member files fuller accounts elsewhere. Record the limitation prominently: an assessment built on abridged filings carries materially lower confidence and the product must say so rather than implying full-statement rigour.
Is Benford analysis worth running?
It is worth running on transaction-level populations and is largely useless on filed statement line items, where the sample is far too small and the values are rounded, capped or derived. Where it is applicable, treat a deviation as a direction for sampling rather than as a result: you follow it by pulling the actual records in the deviating band and examining them. Document the population, the test variant and the significance threshold before running it, because retrofitting thresholds to a result is indefensible. In litigation, expect the method itself to be attacked, so a specialist should own the analysis.
How should confidence be expressed to a non-financial decision maker?
In terms of the decision, not the technique. State what you assess, at what confidence, what it would cost if you are wrong, and what evidence would change the judgement. Avoid quoting scores that the reader cannot interpret, and avoid the false precision of a percentage attached to a subjective judgement. A usable formulation names the specific claim, for example that the entity is unlikely to meet obligations maturing within twelve months without new financing, gives the two or three facts driving it, and identifies the filing or event that would settle the question.
What may a private-sector analyst not do to obtain accounting data?
Do not obtain bank statements, tax filings or internal ledgers through pretext calls, impersonation, paid insiders or any form of unauthorised access, and do not commission a third party to do so on your behalf. Do not conduct covert surveillance on finance staff. Do not use data you know or suspect to have been obtained unlawfully. Legitimate routes are public registries and filings, licensed commercial data, information supplied under a contractual audit right or a transaction data room, court records, and material obtained through formal legal process. Where the evidence you need requires compulsion, the correct step is to refer to counsel or to law enforcement.
How do I handle filings amended after I retrieved them?
Registries frequently replace documents in place without version history, so retrieval date and file hash are part of the evidence. Store the original artefact, not a re-query. Set a monitoring trigger on the entity so an amendment is detected rather than discovered late, and when one appears, diff it against your stored copy and re-run any affected analysis. In evidential work, the amendment itself may be significant, and having the superseded version with a documented retrieval time is often the strongest point in the exhibit. Never cite a filing without stating when you obtained it.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- IFRS and IAS as issued by the IFRS Foundation, which govern recognition, measurement and disclosure and define whether an apparent policy change is permitted.
- ISA 240, the international auditing standard on the auditor responsibilities relating to fraud, which frames what an audit does and does not test for.
- PCAOB auditing standards and inspection regime, which govern audits of United States listed issuers and publish quality findings on individual firms.
- US GAAP as codified by the Financial Accounting Standards Board, which governs recognition and disclosure for domestic United States filers.
- ISO/IEC 27037 on identification, collection and preservation of digital evidence, which governs how retrieved filings and extracts are handled for evidential use.
- ICD 203 analytic standards, which govern the expression of confidence, sourcing and alternative explanation in assessed intelligence products.
- Beneish M-score and Altman Z-score as published academic methodologies, which govern how manipulation and distress screens are constructed and reported.
- Data protection law including the UK Data Protection Act 2018 and the EU General Data Protection Regulation, which govern processing of personal data about directors and officers.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- EDGAR full-text search and filing archive — US Securities and Exchange Commission. Authoritative archive of filings by issuers registered in the United States
- Companies House register — UK Companies House. Statutory register of United Kingdom company filings, officers and control declarations
- IFRS Accounting Standards — IFRS Foundation. The authoritative international financial reporting standards and their amendment history
- Auditing standards and inspection reports — Public Company Accounting Oversight Board. Standards and audit quality findings for firms auditing listed issuers
- Global LEI index — Global Legal Entity Identifier Foundation. Open register of legal entity identifiers and parent relationship records
- Report to the Nations on occupational fraud — Association of Certified Fraud Examiners. Recurring empirical study of occupational fraud schemes, losses and detection methods
- Corporate reporting review and enforcement findings — UK Financial Reporting Council. Regulator findings on defective financial reporting and audit quality
- Enforcement decisions on financial reporting — European Securities and Markets Authority. Published European supervisory decisions on issuer financial statements
- UN Comtrade database — United Nations Statistics Division. Official bilateral merchandise trade statistics used to corroborate declared trading activity
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: screens filings for ratio and accrual anomalies with peer benchmarking and disclosure-note extraction. Explore the platform, or browse the rest of the library by following any tag above.