a. Sampling leaves blind spots
Forty judgmental selections out of fifty thousand entries. The unusual item is, by definition, the one the sample is least likely to catch.
Continuous assurance platform
Plumbline tests every transaction against your controls the day it posts — not the sample you pull in March. Anomalies surface early, evidence assembles itself, and the working file is ready before the close.
Live sandbox — Northwind Traders, Q3 FY26 engagement
The kind of teams Plumbline is built for
Illustrative organizations — Plumbline is a concept product, not a live vendor
The controls are annual. The risk is continuous. Between those two facts is where restatements live.
Forty judgmental selections out of fifty thousand entries. The unusual item is, by definition, the one the sample is least likely to catch.
Support is scattered across email threads, shared drives and screenshots. Tie-out is manual and the trail breaks the moment someone leaves.
Last year's workpapers are a PDF. The tests get rebuilt, the rationale gets re-explained, and institutional memory walks out the door.
Each one runs continuously against connected ledgers. Findings flow into the same working file, and the working file is the audit trail.
Test 100% of transactions against every control, on every run. Coverage is a fact you can point to, not a sampling argument you have to defend.
A model scores every entry for weekend posting, round-dollar amounts, post-close timing, dormant accounts and unusual debit–credit pairings. High scores rise to the top of the queue.
Prebuilt JE analytics with the rationale attached — who posted, when, against which assertion, and why it cleared or didn't. Export a defensible package in one click.
Every "prepared by client" item in one register — owner, due date, status, and the file itself. Reminders go out automatically; nothing sits in a forwarded email.
Each test result links to the assertion it supports and the evidence behind it. Open a number, walk the whole chain — sign-off, review note, source document.
From exception to disposition to signed report in one thread. Severity, root cause, management response and status — tracked, timestamped, exportable.
Read-only connections to the systems you already run. No agents on your servers, no exports to babysit.
General ledger, sub-ledgers, bank feeds and HRIS — linked read-only in an afternoon. Plumbline maps your chart of accounts and control framework on the way in.
Every posting is scored and tested as it lands. Coverage, exceptions and control status update continuously — no batch window, no month-end scramble.
Work the exception queue, attach dispositions, and hand off a complete working file with the trail already inside it.
// the auditor workspace — engagement overview
Open the interactive demoBy the numbers
Every action in Plumbline is logged, attributed and immutable. The tool holds itself to the standard it holds you to.
Audited annually against security, availability and confidentiality. Report available under NDA.
TLS 1.3 in transit, AES-256 at rest, per-tenant keys. Nothing leaves the region you choose.
SAML and OIDC single sign-on, SCIM provisioning, and role-based access down to the engagement.
Plumbline can read your ledgers. It can never post to them. The connection is one-way and scoped.
Who looked, who signed, who changed a disposition — hash-chained and exportable for your own inspectors.
US, EU or UK regions. Pick one at provisioning and your tenant is pinned to it for good.
We used to find the weird journal entry in the following year's audit. Now we find it the Monday after it posts.
Dana Whitlock — Corporate Controller, Meridian Freight (illustrative)
A representative scenario, not an actual customer quote
Bring the whole team into the working file. You're billed on the ledgers you connect, not the people who review them — priced against what a sampling-based review already costs in analyst hours, not against headcount.
For a single internal audit or controllership function.
For practices running many client engagements side by side.
For groups with many entities, regions and frameworks.
No. It replaces the spreadsheet-and-email machinery around the audit. External auditors use the same working file — many firms run Plumbline on the engagement themselves, which is why the Firm plan exists.
Never. Connections are read-only and scoped at provisioning. Plumbline observes and tests; posting stays entirely in your accounting system.
NetSuite, Sage Intacct, QuickBooks, Microsoft Dynamics, Workday and Oracle out of the box, plus SFTP and a flat-file loader for anything else. Bank feeds through standard aggregators.
A single entity is usually testing within a week. Multi-entity firm rollouts run two to four weeks with a named implementation lead.
In the region you pick — US, EU or UK — pinned for the life of the tenant. Per-tenant encryption keys, and an export path if you ever leave.
Set the line
A 30-minute walkthrough on a sandbox engagement — full-population testing, the risk radar and the working file, end to end.
Client portal
Continuous assurance for your engagements. This is a portfolio demo — any email and password will take you in.
Fictional company · no real authentication · nothing is stored