Skip to content
New: ask the Rexfin Analyst Agent about your model. Every figure comes back cited.
· 6 min read

Five Rule-Based Checks That Watch Your Numbers, Not an AI's Guess

Rexfin's integrity scan runs five deterministic checks over your actuals (Benford deviation, duplicates, round-number bias) and flags irregularities for a human to judge. No AI, no ML.

By The Rexfin team

The word “fraud” doesn’t appear anywhere in Rexfin’s integrity scan: not in the findings, not in the copy, not in the underlying checks. That’s a deliberate, tested rule. What the scan does is flag statistical patterns that are worth a second look: an irregularity, not an accusation. Deciding what an irregularity means is a human job. Finding it in a trial balance with hundreds of rows is where the scan earns its keep.

Five checks, all arithmetic, none of it AI

The scan runs five deterministic checks over a workspace’s internal actuals, and the design constraint stated plainly in the spec is rule-based only: no AI, no ML, no model making a judgment call that can’t be reproduced.

Benford deviation compares the distribution of first digits in company-level figures against what Benford’s law predicts, using a chi-square test with an honest sample-size gate (no verdict on too little data) and an explicit caveat that this is an indicative, account-level signal, not a definitive finding. Duplicate amount looks for the same value, on the same predicate and department, showing up in two different months within a rolling window, but only for income-statement-type lines, since balance-sheet carry-forwards are supposed to repeat, and it excludes anything that’s clearly a recurring schedule like rent or salaries. Round-number bias measures how much of a dataset sits on exact multiples of 1,000; too much can indicate estimates standing in for real figures, though the check also recognizes when a workspace is simply reporting in thousands and skips itself accordingly. Period-end concentration checks whether a disproportionate share of a month’s activity lands in its last two days (a classic manipulation signature) though today it honestly reports itself as skipped in most workspaces, since it needs day-level posting dates and internal actuals are contractually monthly. Duplicate row catches cross-upload exact duplicates, aware that a newer upload correcting an earlier one is a legitimate restatement, not a duplicate to flag.

Guardrails that keep it useful instead of noisy

A naive version of these checks floods a real workspace with false alarms: recurring rent looks like a duplicate, a static balance sheet line looks unchanged for a reason, quarterly onboarding uploads look like duplication. The scan’s guards exist specifically because that failure mode was tested for directly: minimum-history requirements before a check will render a verdict at all, exclusion of recurring schedules, and (in one specific edge case) a single hedged flag rather than silence when a company’s revenue is suspiciously identical across periods, since flat revenue is itself a textbook smoothing pattern worth naming, just not worth shouting about the way a genuine duplicate is.

Where the findings land

A scan doesn’t create a separate dashboard. Every finding rides the same insights feed that already carries other flagged items in a workspace: same new-to-acknowledged-to-resolved lifecycle, same UI, and the exact triggering trial balance rows attached as citation chips so a finding isn’t a bare assertion. Clicking through takes you to the underlying KPI and variance view the flagged rows came from, not a canned explanation.

The scan runs automatically when a trial balance upload is confirmed, and on demand through a run-now action gated to editor-level access, consistent with the role-based access that governs the rest of a workspace. An integrity card on the company statements page shows how many checks ran, how many findings came back, when the scan last ran, and (for any check that didn’t render a verdict) the honest reason why, rather than a blank space that looks like nothing was checked.

What it doesn’t do, on purpose

If the underlying actuals feed is unavailable, checks skip individually rather than failing the whole scan or throwing an error page: a workspace with a temporary data gap sees “skipped, source unavailable” on the affected checks, not a crash. And there’s a known, named gap in what the scan can catch today: a full-replacement re-upload that quietly changes a previously reported month’s value is, under the current data model, a legitimate correction: the scan doesn’t yet surface “this number was different last time you looked” as its own disclosure. That’s flagged internally as a real limitation worth its own design, not something papered over.

Who this is for

A controller who wants a second, independent pass over a trial balance before it becomes the basis for a board pack, not instead of judgment, but before it. Anyone who has been burned by a duplicate posting or a suspiciously round estimate making it into a set of actuals unnoticed. See how integrity findings sit alongside the rest of the workspace at the product tour hub, or book a demo to see a live scan run against a real trial balance.

Part of Rexfin Product Tour: Every Number Traceable

Keep reading

Book a demo

See your numbers tie out.

Book a 30-minute demo. Bring a question you can never answer fast enough, and we will model it live against real financial data.