- Source provenance and completeness
- Retain original evidence, source identity, receipt and version, detect duplicates and gaps, preserve corrections separately, link each accepted field to its source, and reconcile expected source populations to received records.
- Deterministic money and ledger logic
- Use typed decimal amounts, explicit currency and unit rules, approved calendars, versioned chart and policy mappings, exact totals, balanced entries, documented tolerances, and reproducible calculations outside model output.
- Segregation and least privilege
- Separate authority, custody, preparation, recording, review, release, administration, and audit where required; restrict access to current duties; detect incompatible roles; and use documented alternative controls where qualified owners approve them.
- Approval and change control
- Bind approval to the exact payload, policy version, reviewer identity, role, threshold, time, evidence, and exception. Material source, amount, account, payee, bank, rule, model, or configuration changes invalidate stale approval and require controlled review.
- Commit, reversal, and reconciliation
- Use typed idempotent commands, authoritative receipts, bounded retry, explicit reversal or correction, source-to-subledger-to-ledger or bank reconciliation, suspense ownership, ageing, and period-close treatment for every unresolved difference.
- Security, privacy, retention, and audit
- Protect financial and personal data, isolate untrusted documents from instructions, validate output, restrict exports, monitor privileged actions, review service providers, retain required evidence, dispose of data under policy, and test that audit records cannot be altered by the actor they monitor.