Use case

Loops for Finance and Planning

A standing-order loop for finance is the unattended Monday pack when numbers move — not the collaborative forecast sign-off room. SOX reconstruction still applies to what the loop produced.

Finance and planning already have a Monday ritual. Actuals arrive. Someone rebuilds variance against a plan version. Someone lists exceptions. Someone drafts a commentary the line will treat as a target. The failure mode is a pack nobody can reconstruct when audit asks which extract it cited — and a journal that posted because someone clicked confirm. Sarbanes-Oxley (US Congress, 2002) does not mention standing orders; it still asks issuers for a trail showing how a number became the number.

This page is unattended standing-order work, not the shared collaborative room where controller, FP&A, and the business partner sign a forecast or variance. The standing order runs when the Monday pack is due or the numbers moved in the ledger, and it skips when the extract hash matches last run. It compiles the same scoped reads into the same outputs. It does not post journals. For the room that signs what people act on, read collaborative AI for finance and planning.

Three nouns, as vocabulary:

Sarbanes-Oxley (US Congress, 2002) does not mention standing orders. It asks issuers for internal control over financial reporting — a trail showing how a number became the number. Section 404, as implemented in the SEC’s ICFR guidance, still wants evidential matter a third party can consider. You do not need to be an issuer for the reconstruction test to bite. If the Monday pack becomes what the line manages against, SOX reconstruction still matters for what the loop produced: which extract, which period, which recipe version, who was notified, what was skipped.

What a finance standing-order loop is

Three common starts, from six things that start a loop:

  1. When the calendar says Monday — the recurring pack: actuals vs plan, exception list, driver tab refresh.
  2. When the numbers moved — ledger extract updated, cube refreshed, material variance against threshold.
  3. When the file lands — business partner uploads the operational file that explains the line.

The job is narrow: detect the start, pull the same scoped reads every time, produce the pack or exception list, and skip when the extract hash matches last run. It does not post journals. Posting belongs on the collaborative job with a named controller sign. A loop is not an agent: the standing order does not sign the pack.

Pin the plan version and the definitions — currency, BU map, bookings versus pipeline — on the job before the recipe runs. “Latest workbook in email” is how last August’s commentary cannot be replayed. The standing order should rebuild variance against the locked plan version, not against whichever file arrived last.

Why FP&A or the controller should care

Because speed is the usual failure mode, and unattended drafting is safer than unattended posting.

FP&A’s personal assistant can already draft a fluent variance note. The failure is custody: which actuals file, which tab was live, whether the partner saw the commitment implied. A standing order that compiles the same reads into the same run record every week reduces version-chasing. It does not replace the signer.

The common belief is that controls live at the ERP write. The plan and the commentary often become management truth weeks before they become entries. Protect only the post, and the loop’s most consequential output — the pack leaders act on — travels with no signature. Hence the split: the standing order produces the draft pack; the collaborative job signs what people act on.

McKinsey’s State of AI (2025) keeps showing high adoption and low redesign. Most organisations use AI somewhere in finance. Few can replay last Monday’s pack without the author. What auditors are asking for overlaps: identity, content, time, custody. Reconstruction is the test even when you are not mapping every SOX article.

You should care if:

  • the “Monday pack” is already a chain of exports nobody can replay
  • a commentary cited August actuals and nobody can find that extract
  • journals still post from a confirm box the analyst clicks through
  • the line received a “new target” from an automation that nobody signed

Write-back governance stays on the journal path. Collaborative AI for revenue operations is the sibling when the moving number is pipeline, not books.

Words you will hear

  • Extract hash. A fingerprint of the actuals file or ERP pull. Unchanged hash → skip.
  • Locked plan version. The plan the recipe rebuilds against. Not “latest.”
  • Exception list. Rows that crossed a threshold, with sources cited.
  • Commentary skeleton. Draft language that points at attached sources — not a private rewrite.
  • SOX reconstruction. An independent reader can chain extract → inputs → signed pack.
  • Eval loop. After a signed journal, read-back matches payload.
  • Agentic workflow. “Explain variance” with no saved recipe — expensive, uneven.

The ICO’s AI guidance is a reminder that purpose and minimisation apply when the “user” is automation touching personal data in payroll or headcount extracts. Scope the read.

How to compile one finance standing order

Start from a close ritual someone already runs.

Example: Weekly variance when actuals refresh

Trigger: file lands in the controlled folder or ERP actuals extract event.

Preconditions: read-only ERP or warehouse connection; pinned definitions; last extract hash stored.

Steps:

  1. Pull actuals for the agreed period and scope.
  2. Compare hash to last run. If unchanged, skip and log.
  3. Rebuild variance against the locked plan version — not “latest workbook in email.”
  4. Draft exception list and commentary skeleton that cites attached sources.
  5. Land outputs on the run record; notify FP&A and controller roster.

Explicit non-goals: no journal post; no planning-cube write that behaves like books; no email to the line with “your new target.”

When commentary must commit the business, open the collaborative planning job. Partner rejects there. Controller signs there. The standing order may attach the run record as input.

A second common compile: Monday calendar. Same recipe, time-based trigger, same skip if the extract has not moved. Prefer the file-lands trigger when actuals already arrive in a folder — you avoid running theatre on a bank holiday when nothing refreshed.

Eval loops still matter on the write path: after a signed journal, read-back accounts and amounts. That sensor is not the Monday pack. Do not collapse them because both contain the word “loop.” How to evaluate loop engineering asks whether you can replay triggers and skips — the finance equivalent of audit reconstruction.

What “done” looks like

A good finance standing-order week:

  • The run record shows extract period, hash, recipe version, skip or delta.
  • The exception list points at sources on the job, not at a private chat rewrite.
  • No ERP post from the standing order.
  • An independent reader can open the collaborative signed pack and trace inputs to the loop run without the authors’ memory.

Retention on run logs should match how long you must explain the number — not how long chat keeps threads. RBAC for enterprise AI applies: the standing order uses read grants. Posting tokens stay on human signers.

When audit or SOX asks how a commentary was produced, the answer should chain: extract on the run record → inputs on the collaborative job → signed pack. If the chain breaks at “someone ran a prompt,” the standing order did not fail — custody did.

How to start with one trigger

Pick when the file lands if actuals already arrive in a folder — or Monday calendar if timing is fixed.

This cycle:

  1. Name the artefact the standing order may produce: exception list, variance tab — not the signed board number.
  2. Pin definitions and plan version on the job.
  3. Add controller or deputy and FP&A to the roster for notifications.
  4. Require skip logs when hash unchanged.
  5. After four runs, ask an independent reader to reconstruct the pack from the run record alone.

Partner-facing numbers still belong in the collaborative room, not in an email the standing order generates. If the loop notifies the line, restrict it to “pack ready” — not “your new target.” That distinction is what keeps unattended compile separate from management commitment.

Loops for revenue operations and loops for legal and compliance cover pipeline and policy triggers. If the pack is still a chat ritual, read what is loop engineering and six things that start a loop before you pick a trigger. A loop is not an agent is why the Monday compile should not invent a journal.

Automate the pack compile. Leave the signature on the artefact people act on — and keep journals off the unattended path entirely.

How this shows up in Nimbus

Nimbus workstreams and governance can host the standing-order pack and the sign-off room together: extract hash, locked plan version, run page, roster notification — and a separate job where the controller signs. Journals stay fail-closed.

What is a Nimbus Loop is the product noun for the standing order. Score skip logs and recipe version with how to evaluate loop engineering before you let a Monday compile look like a close.

Common questions

Monday packs vs the sign-off room

Is a standing-order loop the same as the planning sign-off meeting?

No. Sign-off is collaborative AI — controller, FP&A, partner, named signer. A standing-order loop compiles the Monday pack or reacts when actuals move, and skips when nothing material changed. It produces the draft pack and the exception list. It does not post journals and it does not sign the number people will manage against. If you collapse the two, you either get an unattended post or a meeting that still starts from a chat ritual. Automate the compile. Leave the signature on the artefact people act on.

Does SOX apply to a loop that only reads the ERP?

The loops outputs can become management truth before anything posts. If leaders act on the pack, you need the same reconstruction test: what ran, on which extract, with what skip log. Sarbanes-Oxley does not mention standing orders. It asks issuers for internal control over financial reporting — a trail showing how a number became the number. You do not need to be an issuer for that test to bite. A fluent variance commentary is not that trail. Retention on run logs should match how long you must explain the number.

What is the difference between a standing-order loop and an eval loop?

A standing-order loop is an operator recipe that admits a run when a trigger fires. An eval loop is a harness sensor — schema check, read-back, human gate — that grades whether the job finished correctly. After a signed journal, the eval loop asks whether accounts and amounts match the ERP. That sensor is not the Monday pack. An agentic workflow is the third noun: open-ended replan, such as close the books with no saved recipe. Do not collapse the three because a slide said loops.

Can the loop email the line their new target?

No. Partner-facing numbers belong in the collaborative room, not in an email the standing order generates. If the loop notifies the line, restrict it to pack ready — not your new target. That distinction keeps unattended compile separate from management commitment. A forecast can become a hiring freeze weeks before it is a ledger entry. Put a name on the artefact people act on, not only on the post.

See what governed AI looks like on your stack.

Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.