The interface register: the document auditors ask for first
Published [date]
Ask how figures reach your ledger from other systems and, in most organisations, the answer is a list of names and a promise to find out. An interface register replaces that with a document: every connection you own, what it carries, who answers for it, and whether the records on both sides matched the last time it ran.
Why auditors start here
When external auditors test controls over financial reporting, they want to know which figures in the ledger arrived from another system, and how you know they arrived complete and accurate. Access and change controls tell them who can alter a system. The interfaces are where those controls meet the numbers.
Without a register, the audit team works it out by sampling and asking. Each question lands on someone in finance or IT who is also trying to close the month, and each answer is a fresh piece of detective work. With a register, the conversation starts from a document you prepared, and the questions get narrower.
The same question is now being asked in the boardroom. For financial years starting on or after 1 January 2026, companies that report against the UK Corporate Governance Code are expected to include a board declaration on the effectiveness of their material internal controls, or explain why not. Where a material figure passes between systems, the interface carrying it is part of that control, whether or not anyone has written it down.
What a register contains
One row per interface. An interface is any route by which data leaves one system and arrives in another, whether that is an API call, a scheduled file, or a spreadsheet someone uploads on the third working day.
| Column | What it records |
|---|---|
| Reference | A permanent ID, such as INT-012, never reused when an interface is retired. |
| Process | Order to cash, procure to pay, record to report or hire to retire. |
| Source and target | The two systems, and the objects that move between them: customers, invoices, journals, starters. |
| Trigger and timing | Scheduled, event-driven or manual, and the time it must finish by for the next step to start. |
| Platform | Where it runs: your integration platform, a database job, a script on a server, or a person. |
| Owners | A business owner and a technical owner, by name. A team mailbox is not an owner. |
| Control | How completeness and accuracy are proved: record counts, control totals, key matching. |
| Last run | When it last ran, and whether the records on both sides matched. |
| Held records | Where rejected records go, who is told, and how they are released. |
Two of those columns do most of the work. The owner column turns a list into accountability. The last-run column separates a register from an inventory: an inventory tells you what exists, a register tells you whether it worked.
The rows people leave out
The rows most often missing are the manual ones. A bank statement downloaded and uploaded by hand. A payroll journal rekeyed from a PDF. A price list emailed to someone who pastes it into the ERP. None of them appears in a middleware catalogue, and all of them move figures that end up in the accounts. They belong in the register for the same reason as the automated ones, and they are usually the ones with the weakest control.
How to start one
- Start from the ledger, not the middleware. List every source that posts to the general ledger, then work outwards through the systems that feed those sources. A catalogue exported from your integration platform will miss scripts, file drops and uploads.
- Ask the people who close the month. Which files do they wait for? Which spreadsheets do they upload? Which totals do they check by eye? Each answer is a row.
- Name an owner before you record a status. An interface without an owner is your first finding, and the easiest one to act on.
- Record the control you have, not the one you want. If the only check is someone comparing two totals on a Monday morning, write that down. The gap between what exists and what should exist is the useful part.
- Keep it where people will maintain it. A spreadsheet that is kept current beats a tool nobody opens. Make it part of change control: no interface changes without a register change.
From document to live register
Once an interface reconciles automatically, its last-run and status columns can fill themselves from the run logs, and the register becomes a live view rather than a quarterly exercise. The example on our homepage shows what that view looks like, and Reconcile in the pipe, not in the report explains where the control column gets its evidence.
But start with the document. A live register built on an incomplete list only automates the gaps. The rows you find by asking the people who close the month are worth more than the dashboard that eventually displays them.
A test for this quarter
Ask for the list. If it takes more than a day to produce, arrives without owners, or leaves out the spreadsheets, you know where to start. Our systems review produces a register as part of the map of your estate, and both are yours to keep, whoever builds what comes next.