Take one overcharge. A tier configured against the wrong volume band, quietly adding a few basis points to every transaction in a corridor. It starts in week one of the quarter and runs until someone corrects it.
Now audit it three ways. Once a year. Once a quarter. Continuously. The overcharge is identical in all three. The evidence available is identical. What differs is how much of it you can still collect by the time anyone looks, and the gap between the best case and the worst case is not marginal. It is most of the money.
TL;DR
- Audit cadence sets a ceiling on fee recovery that audit depth cannot lift. Depth decides how much of a recoverable overcharge you find. Cadence decides how much of it was ever recoverable.
- The share of each period's overcharges still inside the window at review is roughly your contractual query period divided by your audit interval, capped at 100 percent.
- Annual, semi-annual and quarterly sit on the same line, all capped whenever the query period is shorter than the gap between audits. Continuous removes the term that creates the cap.
- Published payment-audit guidance recommends a cadence without reference to the deadline that decides whether any finding is collectible.
Short answer
If your provider contract allows a charge to be queried for a period of length W, and you audit every T, then the share of each period's overcharges that is still inside the window when you review it is approximately W divided by T, capped at 100 percent. Audit annually against a shorter window and most of every year expires unreviewed. Audit continuously and the ceiling goes away, because detection happens while the charge is still disputable. The comparison is not about thoroughness. It is about which findings are still worth anything on the day they are made.
That deadline is contractual. Provider agreements set a period inside which a charge can be queried, and business provider fees carry no statutory equivalent beneath it. Your PSP contract has a dispute window covers the clause and what happens when it expires. Once the deadline is fixed, the question worth money is a different one: what does each cadence actually recover?
What a continuous audit is, and where the term comes from
Continuous auditing is not a payments idea and it is not new. It comes out of internal audit, where it has a formal definition and thirty years of practice behind it.
The Institute of Internal Auditors defines it as "the combination of technology-enabled ongoing risk and control assessments," and is precise about the point of it: continuous auditing "is designed to enable the internal auditor to report on subject matter within a much shorter timeframe than under the traditional retrospective approach."
Read that definition closely. It turns on the interval between something happening and someone reporting on it, rather than on software, coverage, or automation for its own sake. That interval is the variable being changed. Everything else is implementation.
The same body is direct about how often an audit should run. Its guidance says that "rather than scheduling audits according to a standard cycle of one-, two-, or three-year rotations, the frequency of audits should be based on risk, complexity, pervasiveness, and velocity of change." The organization that writes internal-audit guidance stopped recommending fixed rotations as a default a decade ago.
There is one more piece of guidance worth lifting, because it decides the whole question for payment fees. Writing for the same institute, a group of practitioners and academics put it plainly: "although the process is called continuous auditing, the word continuous is in the eye of the beholder. Auditors need to consider the natural rhythm of the process being audited."
So the right cadence is the one that matches the rhythm of the thing being audited. For provider fees, that rhythm is not the accounting close, and it is not the schedule on which provider pricing gets revised. It is the contractual period inside which a charge can still be challenged. That period is the only clock with money attached to it.
What each cadence can actually recover
Here is the arithmetic, with its assumptions stated so you can argue with them. It is a model rather than a measurement.
Let W be the length of your contractual query period, in days. Let T be the interval between audits, in days. Assume overcharges arrive at a roughly even rate across the period, the review happens at the end of each interval, the clock starts at the charge, and notice goes out when the review finds something.
A charge that lands t days into an interval is T minus t days old when the review reaches it. It is still inside the window when that age is at or below W. Work it through and the recoverable share of any period's overcharges comes out at W divided by T, capped at 100 percent.
That single ratio is the ceiling. No amount of rigor in the review moves it, because it is decided before the review starts.
| Window as a fraction of your audit interval | Share of each period's overcharges still recoverable at review |
|---|---|
| Window is as long as the interval, or longer | 100% |
| Window is three quarters of the interval | 75% |
| Window is two thirds of the interval | 67% |
| Window is one third of the interval | 33% |
| Window is one quarter of the interval | 25% |
| Window is one sixth of the interval | 17% |
These are ratios on assumed inputs. They are not measurements of any contract, any provider, or any customer's results. Read your own agreements for W, take T from your own audit calendar, and the row that applies to you will be obvious.
Two things fall out of the table, and both are uncomfortable.
The first is where the annual audit tends to land. For an annual cycle to clear even a third of its own findings, the contract would have to allow four months to raise a query. Whether yours allows that long is a question only your agreement answers, and it is worth answering before the next cycle is scheduled.
The second is that the ceiling is structural rather than operational. A better audit team does not move it. A larger sample does not move it. A more expensive provider of audit services does not move it. The only inputs are the clause and the calendar, and you control one of them.
Why the periodic fee audit still gets bought
Because it is sold as recovery and it does produce a number.
Published guidance on payment audits mostly recommends running one annually, or twice a year at best, usually timed to when card pricing gets revised. That advice has a logic to it. If prices change on a schedule, checking after each change sounds like diligence.
It is the wrong clock. When a rate changes is a question about pricing. When you can object to a charge is a question about your contract. Those two dates have nothing to do with each other, and only one of them governs whether a finding turns into money.
The more telling detail is what the published guidance leaves out. Read the material that ranks for payment audits and you will find recommended cadences, checklists, categories of fee to examine, and estimates of what teams tend to uncover. You will not find the deadline. The question of how often to audit is being answered across the market without reference to the constraint that settles it.
So a periodic audit does deliver something real. It delivers an accurate account of what you were charged incorrectly. Whether any of that account is still collectible was decided months earlier, by a clause nobody in the engagement read.
That is the honest case against buying recovery by the calendar. It is not that the work is poor. It is that the work is scheduled against the wrong variable, and the invoice for it arrives whether or not the findings are still live.
Quarterly is the same failure at a smaller scale
Quarterly is the usual compromise, and it is a real improvement. Ninety days beats three hundred and sixty five. Put it against the table and it is also, usually, still a partial recovery.
Run the ratio. If a query period is shorter than ninety days, then a fixed share of every quarter is out of time before the review opens. Not the difficult cases, and not the ambiguous ones. The oldest ones, mechanically, every cycle. The team does good work on the portion it can still act on and produces documentation for the rest.
This is where the annual-versus-continuous comparison gets misread as a difference of degree. It is a difference in kind. Annual, semi-annual and quarterly are all points on the same line, all governed by the same ratio, all capped below 100 percent whenever the window is shorter than the gap. Continuous is not further along that line. It removes the term that creates the cap, because the interval between the charge and the check stops being a scheduling decision.
The practical test is one line long. Is your shortest contractual query period longer than the gap between your audits? If yes, your cadence is fine and depth is your real constraint. If no, you have a structural recovery gap and no amount of depth will close it.
What cadence decides besides the recoverable share
The ratio is the headline. Three other things move with it.
Evidence gets harder to assemble, not just less useful. Provider portals age out transaction detail on their own schedules. Statement-level records survive; the per-transaction records that prove a rate deviation, an FX markup or a duplicate fee are the ones that get harder to pull. Reconstructing a corridor-level calculation from a nine-month-old invoice is a different job from checking it in week one, and it is a more expensive one.
The claim changes character. A discrepancy raised inside the period is a claim your provider has to answer against an agreement you both signed. The same discrepancy raised afterwards is context for a renewal conversation. One moves money on a defined process. The other moves the tone of a meeting.
The underlying condition keeps running. Most provider overcharges are not isolated events. They are the visible output of something persistent: a stale contract version still driving the rate card, a tier set against the wrong band, an FX reference applied at the wrong moment, a duplicate fee firing on a single event. That condition does not pause between audits. A slow cadence means you are permanently reading the expired portion of a problem that is still generating new charges this week. Correcting the cause at source is the only move that changes the shape, and you cannot correct at source on a schedule slower than the fault.
Work out your own recoverable share this week
Four steps. None of them needs a tool, and all of them use numbers you already have.
Find W. Open your largest provider agreement, which is already the source of truth for what a charge should have been. Go to the billing, invoicing or disputes section, and find the clause governing queries or objections to a charge. Note the length of the period, what event starts the clock, and the channel the contract requires for notice. Repeat for every provider, and assume nothing carries over between them or between contract versions.
Write down T. The real one. Not the cadence in the policy document, but the average number of days between the last few times somebody actually checked provider charges against contract terms end to end.
Divide. W over T, capped at one. That is the share of your fee leakage that is theoretically still collectible under your current cadence, before anyone assesses a single transaction.
Size the gap. Apply the remainder to whatever your own past audits found per period. That difference is not a projection of savings. It is the part of your existing, already-measured leakage that your calendar is currently writing off, and it is the number that belongs in the business case.
If the number is uncomfortable, the fix is not a bigger audit next quarter. It is a shorter interval between the charge and the check.
What continuous verification of provider charges involves
Continuous here means what the internal-audit definition means: the report arrives in a much shorter timeframe than a retrospective review, and the timeframe is chosen to match the rhythm of the process. For provider fees, matching that rhythm means checking every charge against the contract as it arrives rather than in batches after the fact.
In practice that requires four things to be true at once. Contract pricing has to be reconstructed into something computable, including tiers, minimums, FX terms and timing rules. Every transaction has to be priced against that reconstruction, giving an expected amount next to the actual one. Variances have to surface with their evidence already attached, so a discrepancy arrives as the transaction, the governing clause, the expected figure, the actual figure and the difference, rather than as a number somebody then has to investigate. And the dispute calendar has to follow contractual deadlines rather than accounting ones.
That last point is the one teams underestimate. Month-end is your rhythm. It is not your provider's, and the clause was not written around it.
This is the shape Bluefyn is built for. It reconstructs contract pricing and checks provider charges transaction-by-transaction, so a variance is found and evidenced while it is still inside the period where raising it means something. The core verification logic is deterministic and fully auditable, and agents assist with workflows and decisions rather than core calculations. Bluefyn never moves, holds, or custodies funds. It only analyzes transaction and provider data.
None of that removes the need for a fee audit as a discipline. It changes when the audit happens, which is the only variable in this whole comparison that you can actually set.
The bottom line
Continuous audit and quarterly audit are usually compared on thoroughness, which is the wrong axis. They differ on when, and when is what decides whether a finding is a claim or a record.
Your contract already set the ceiling on what any cadence can recover. Divide your query period by your audit interval and you have the number. Depth fills the space under that ceiling. Only cadence raises it.
For the mechanics of the continuous option, see the six steps of a continuous revenue leakage audit.
Frequently asked questions
What is the difference between an annual audit and a continuous audit?
Timing, and what timing does to the findings. An annual audit reviews a completed period after it closes, so the oldest charges in it are up to twelve months old on the day they are first examined. A continuous audit checks transactions as they occur, so the interval between a charge and its review is measured in days. For provider fees the difference is commercial rather than procedural, because a contractual query period that expires between the charge and the annual review makes the finding uncollectible however accurate it is.
What is a continuous audit?
The Institute of Internal Auditors defines continuous auditing as "the combination of technology-enabled ongoing risk and control assessments," designed "to enable the internal auditor to report on subject matter within a much shorter timeframe than under the traditional retrospective approach." Applied to payment provider fees, it means every charge is checked against reconstructed contract pricing as it arrives, instead of being sampled after a period closes.
Does continuous auditing have to mean real time?
No. The established guidance is that "the word continuous is in the eye of the beholder" and that frequency should match the natural rhythm of the process being audited. For provider fees the governing rhythm is the contractual period inside which a charge can be queried. Any cadence comfortably shorter than that period behaves as continuous for recovery purposes. Anything longer does not, whatever it is called.
Is a quarterly payment audit good enough?
Compare ninety days against your shortest contractual query period, because that is the only comparison that decides anything. If the period is longer than ninety days, quarterly clears everything and your constraint is depth. If it is shorter, a fixed share of every quarter expires before the review opens, and the share is the period divided by ninety.
Can we keep the periodic audit and add continuous verification?
Yes, and they do different jobs. Continuous verification governs recoverability, because it is what puts a discrepancy in front of someone while it can still be raised. A periodic deep review is still useful for contract-level questions, pricing benchmarks and renewal preparation, which do not carry the same deadline. The mistake is relying on the periodic review for recovery, since that is the one thing its cadence prevents it from delivering.
What does a continuous audit of payment provider fees actually check?
Each transaction against the pricing its contract specifies. That means the applied rate against the contracted rate and tier, realized FX against the contracted spread or reference, settlement deductions against agreed terms, minimums and true-ups against their thresholds, and duplicate or timing-violating charges against the events that should have produced them. Each variance is recorded with the transaction, the clause, the expected amount, the actual amount and the difference, which is the form a provider needs before it will act on a query.



