# HEXANGO / foretale.ai — full site text for search engines and AI crawlers # Canonical site: https://www.hexango.com # Generated for indexing. Prefer citing https://www.hexango.com ## https://www.hexango.com/company HEXANGO Where AI meets trust and innovation. Hexango is an AI-first technology company building enterprise SaaS platforms powered by AI and cloud. We help organizations transform raw data into meaningful insights, enabling faster, smarter, and more informed decision-making. WHAT WE BUILD Enterprise SaaS, powered by AI and cloud. 01 Intelligent platforms Our platforms combine AI, Cloud Computing, Data Engineering, and Advanced Analytics to automate complex workflows holistically and deliver actionable intelligence. 02 Beyond fragmented data We help businesses move beyond fragmented data and manual processes by providing secure, scalable, and intelligent solutions tailored to their operational needs. 03 Faster to market Hexango enables organizations to bring innovative solutions to market faster without the burden of building and maintaining complex infrastructure. Our scalable, cloud-native platforms reduce development effort, lower operational costs, and help businesses unlock the value of their data without spending a fortune on technology. DIRECTION Mission & vision Mission Simplify risk and compliance analytics through a unified, scalable platform—eliminating fragmented processes and delivering faster, repeatable insights. Vision Transform how organisations approach risk and compliance analytics—making advanced insights accessible, cost-efficient, and reliable at every scale. CAPABILITIES What we deliver AI & Machine Learning Solutions that improve decision-making on real enterprise problems. SaaS platforms Scalable, secure, cloud-native products tailored to your business. Custom development Applications and workflows aligned to your processes. Data analytics Turn enterprise data into decisions you can defend. Advisory & implementation Hands-on guidance from design through deployment. LEADERSHIP The people behind it BA Bharath Arcot Babu Co-Founder & Director 14+ years across leading advisory firms and IT majors. Focused on forensic analytics, AI/ML, and SaaS—simplifying complex risk and compliance challenges. LinkedIn → bharath.arcotbabu@hexango.com AS Ashwini Sreevatsan Co-Founder & Director 13+ years across industry and IT. Risk management and compliance in ESG and HSE—ISO, OSHA, and practical governance frameworks. LinkedIn → ashwini.sreevatsan@hexango.com CONTACT Get in touch Company HEXANGO PRIVATE LIMITED Email contact@hexango.com Web www.hexango.com Office TOWER A, 5th Floor, MIS DEETA CONSTRUCTION PVT LTD 51 DEVARABISANAHALLI, BENGALURU-560103 KARNATAKA, INDIA NEXT STEP See it on your data. Request a focused walkthrough—usually within one business day. Only a valid email address is required; other fields are optional. Work email * Only a valid email address is accepted. Other fields below are optional. Name (optional) Company (optional) Role (optional) Industry (optional) Timezone (optional) Request a demo BROCHURE Download the foretale.ai brochure Enter your work email to receive the PDF. Work email * Download brochure --- ## https://www.hexango.com/fraud-analytics-framework Redirecting… — HEXANGO | foretale.ai This page has moved to Fraud, Risk & Compliance Analytics Framework . --- ## https://www.hexango.com/googleba85aa67cf10d8cc google-site-verification: googleba85aa67cf10d8cc.html --- ## https://www.hexango.com/index foretale.ai Autonomous AI for enterprise risk Detect financial leakage, uncover fraud, and identify compliance gaps—with explainable, audit-ready findings. Request a demo How it works → THE ENTERPRISE RISK CHALLENGE Hidden risks. Manual effort. Limited coverage. Financial leakage, fraud & compliance gaps buried in complex ERP data Manual analytics consume time — prep, custom tests, and reporting Limited coverage — due to time and budget constraints High cost to implement analytics — custom builds, tools, and specialist effort add up Issues escalate before teams can detect and respond MANUAL REACH · ~15% ASSESSED BLIND SPOT · 85% UNTOUCHED Financial Leakage Fraud Patterns Compliance Gaps Emerging Risks MEET FORETALE.AI An Autonomous AI Risk Analyst for Your Enterprise. foretale.ai autonomously understands your enterprise data, plans and executes specialized risk analytics, uncovers explainable findings with supporting evidence, and generates audit-ready reports. foretale.ai HOW IT WORKS Understand → Plan → Execute → Explain Designed to augment risk, audit, finance, and compliance teams—experts stay in control while AI executes the analysis. 01 Understand AI understands enterprise data, relationships, policies, manuals, feedback, and business context automatically—no manual data modeling required. 02 Plan AI plans the optimal analytics strategy based on your business context. 03 Execute Execute hundreds of risk analytics across millions of transactions—without manual scripting. 04 Explain Explainable findings, executive dashboards, and audit-ready reports. CAPABILITIES Enterprise Risk Coverage Purpose-built analytics across the risk domains that matter most. Financial Leakage Duplicate payments Overpayments Price variances Unclaimed discounts …and more Fraud Detection Vendor collusion Ghost vendors Conflict of interest Anomalous transactions …and more Controls & Compliance SoD Policy violations Control failures Compliance gaps …and more MARKET CONTEXT The challenge isn't analytics. It's the entire engagement. Available tools provide transactional risk analytics. Foretale brings the entire engagement together on one AI-powered platform . Capability Available Tools foretale.ai Why it matters Isolated Data Environment Varies Dedicated workspace per client AWS hyperscaler No cross-client leakage Autonomous Risk Analytics Limited Create customized risk analytics in minutes using AI Full engagement on one platform Limited Usually stitched Data → analytics → cases → report Manage multiple client engagements from a single login P2P, T&E, P-Cards, Inventory, O2C… ERP-Agnostic Limited Fixed schemas AI-assisted data modeling Conversational Data Preparation & Exploration Limited Prepare, transform & explore data using natural language Fuzzy & semantic matching at scale Limited Keyword / exact Ask: “gift-related spend?” Finds variants — no exact keywords Case Management Separate tool Built-in findings, actions, dashboards Knowledge Workspace Limited Clarifications, notes, docs & feedback together AI summarization & semantic search for better analytics WHY FORETALE.AI One platform. Complete risk intelligence. Connect your data. Assess risk. Deliver audit-ready findings—all on one autonomous AI platform . Talk to your data Find duplicate payments in AP Scanning full AP ledger… 12 duplicates found · $480K Explain the top case Same invoice, two vendors… Find duplicate payments in AP Scanning full AP ledger… 12 duplicates found · $480K Explain the top case Same invoice, two vendors… Unlimited Risk Analytics Execute hundreds of risk analytics—and instantly generate customized analytics as business needs evolve. No coding required. What You Gain Comprehensive Risk Coverage Analyze every transaction across hundreds of risk scenarios. Risk Assessments in Minutes AI-powered analytics executed in minutes. Lower Total Cost One platform replacing multiple tools and manual testing. Explainable AI Every finding explained with complete audit evidence. Flexible Deployment On-prem, your cloud, or managed SaaS PRODUCT See risk analytics unfold From enterprise data to evidence-backed findings—an autonomous path your experts can audit. FOUNDATION Built on Proven Expertise Methods forged in real advisory work—not theoretical AI demos. 28+ Years of combined experience across Big 4s and super majors — with battle-tested methods from complex forensic engagements. AWS AWS Native Fully AWS-native hyperscaler stack — built and run entirely on Amazon Web Services, with strong data safety, security controls, and AI governance in place. C Claude OpenAI 𝕏 Grok Models Foundation Models State-of-the-art foundational models powering analysis and reasoning. SAP SAP O Oracle Dynamics ERP Validated on real-world datasets through enterprise pilots. PRICING A little about your needs — we’ll do the rest. Every engagement is a little different. Share whatever you can below — only a work email is required — and we’ll thoughtfully prepare pricing with an ROI view for your scope. No obligation. Number of users Optional — how many people would use the platform? Data volume Select approximate volume (optional) < 1 GB 1–3 GB 3–10 GB 10 GB+ Business process to test Optional — select one or more if you already know the scope. P2P O2C GL FCPA ABAC T&E Other Work email * Only a valid work email is required. Other fields above are optional. Request pricing RESOURCES Guides by risk domain Articles and frameworks grouped by process area—Accounts Payable, Procurement, Travel & Expense, Order-to-Cash, General Ledger, and programme design. Accounts Payable Leakage and control risks in procure-to-pay and vendor payments. Article Duplicate Payment Detection Needs 15+ Analytics One duplicate-payment rule is not enough. Learn the scenarios that cause leakage, how to turn them into analytics, and how foretale.ai builds those tests. Article 8 Vendor Master Analytics Every Company Should Run How AI finds duplicate suppliers, shared bank accounts, and master-data gaps before they become payment leakage. Article What AP Actually Paid. PO ordered 100. Goods received 40. Invoice cleared 100—seven analytics that catch the gap. Article New Vendor. Big First Payment. Then Nothing. Vendor added Day 0. Paid Day 3. Next bill never—seven checks that catch rush vendors. Article Same Vendor. Too Many Invoices. Peer vendors send 4 invoices a month. This one sent 47—seven checks that catch unusual volume. Procurement Fake competition, collusion, and award risks that inflate cost before the invoice hits AP. Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. How shared vendor identities expose bid rigging—and seven analytics that catch fake competition. Article Vendor Relationship Networks. Two vendors never share a bank account, tax ID, or phone—yet they always bid together. Build a graph instead of rule-based analytics. Travel & Expense Behavioral risk in T&E—beyond policy gates and sampled audits. Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Why traditional expense audits miss the highest-risk transactions—and how AI changes the game. Article Personal Shopping. Business Expense Code. Seven analytics that catch shopping, lifestyle, and home-city spend submitted as business. Article Same Dinner. Three Claims. Meal total 9,600. Approval above 5,000. Submitted as 3,200 + 3,200 + 3,200—seven checks that catch split expenses. Payroll Post-termination pay, ghost employees, and payroll master gaps that drain salary spend. Article The Badge Was Deactivated. The Salary Kept Clearing. How payments after termination and payroll master gaps create silent leakage—and eight analytics that catch it. Article On Payroll. Nowhere in the Building. How ghost employees hide in payroll—and eight analytics that expose fictitious, duplicate, and no-show workers. Purchasing Cards Misuse and leakage risks in P-Card programs—beyond monthly statements and sampled receipts. Article 10 P-Card Analytics Every Organization Should Run How AI helps identify split purchases, personal spend, unauthorized merchants, and other purchasing-card risks before they become leakage or fraud. Order-to-Cash Billing, credits, pricing, and collection risks that quietly erode revenue. Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue How AI helps identify billing errors, revenue leakage, duplicate credits, and collection risks before they impact the bottom line. Article The List Price Was Fine. Policy capped the discount at 5%. The invoice took 18%—seven analytics that catch Order-to-Cash discount leakage. General Ledger High-priority journal and balance risks in the books of record—beyond trial-balance sampling. Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity How AI finds unusual journals, suspense build-up, period-end spikes, and control gaps that standard trial-balance reviews miss. Frameworks Reference guides for structuring enterprise risk and compliance analytics programmes. Framework Fraud, Risk & Compliance Analytics Framework A three-phase framework for enterprise fraud, risk, and compliance analytics: Pre-Analytics, Analytics, and Post-Analytics. Browse all resources → FAQ Questions teams ask before a demo Clear answers about foretale.ai—built by HEXANGO for enterprise risk, audit, finance, and compliance teams. What is foretale.ai? foretale.ai is an autonomous AI risk analyst from HEXANGO. It understands enterprise data, plans and executes specialized risk analytics, and produces explainable findings with audit-ready reports. What risk problems does foretale.ai solve? It helps teams detect financial leakage, uncover fraud, and identify compliance gaps across ERP and transaction data—without building custom scripts for every test. How does foretale.ai work? The platform follows Understand → Plan → Execute → Explain: it learns your business context, plans analytics, runs risk tests at scale, and returns evidence-backed findings your experts can review. Who is foretale.ai for? Risk, audit, finance, and compliance teams that need broader coverage, faster assessments, and lower cost than manual analytics or fragmented tool stacks. Does foretale.ai do autonomous data modelling? Yes. The Understand step maps enterprise data, relationships, policies, manuals, feedback, and business context automatically—so teams do not need to build or maintain manual data models before analysis can start. How does foretale.ai manage ERP datasets autonomously? It ingests and interprets ERP and related transaction datasets in a dedicated workspace, learns how entities and processes relate, and keeps analytics aligned to that context as you assess risk across large volumes of enterprise data. What does unlimited risk analytics mean? You can execute hundreds of risk analytics across millions of transactions and generate customized analytics as business needs evolve—without writing scripts or rebuilding a new pipeline for every test. Can we build custom dashboards? Yes. Results surface in executive dashboards and audit-ready reports. Custom visualizations are available as an option on Pilot and Professional plans, and are included on Enterprise. Does foretale.ai include case management? Yes. Findings move from detection into investigation workflows so teams can validate, escalate, track, and close cases with evidence—replacing fragmented BI, copilot, case management, and reporting tool stacks. Can we talk to our data in natural language? Yes. Teams can ask questions of their data in plain language—for example to find duplicate payments or explain a top case—and receive evidence-backed answers tied to the underlying transactions. Are findings explainable for audit? Yes. Every finding includes supporting evidence and lineage so experts can trace how a conclusion was reached and produce audit-ready reporting. How is customer data secured? foretale.ai runs on an AWS-native stack with encryption in transit and at rest, dedicated workspace isolation, least-privilege access, and security controls aligned to our Information Security and Access Control policies. Where can we deploy foretale.ai? Professional plans run as managed SaaS. Enterprise supports SaaS, private cloud, or on-prem so data residency and architecture can match your security requirements. Do you use our data to train AI models? No. Customer content is not used to train third-party foundation models. AI features use only data authorized for the authenticated user and project, with session- and organization-scoped context. How do you govern AI responsibly? AI assists professional judgment—it does not replace it. We apply human oversight, Bedrock Guardrails, bias and safety reviews, and documented limitations. Details are in our Responsible AI Policy and AI Transparency Statement in the Trust Center. Can teams review and challenge AI findings? Yes. Findings are explainable with supporting evidence. Users can inspect reasoning and sources where available, and high-impact actions require human authorization before changing customer data. How is access controlled? Access uses authenticated accounts (Amazon Cognito), role-based authorization, and least privilege. Organizations control who can see which projects and data within their dedicated workspace. Where can security and compliance teams find documentation? Our Trust Center publishes policies on information security, access control, incident response, data retention, responsible AI, AI transparency, vulnerability disclosure, and architecture at hexango.com/trust-center. How do you handle privacy and data retention? Personal data is handled under our Privacy Policy. Retention and secure deletion follow project and contractual settings described in the Data Retention Policy—customers control how long operational data is kept. How is foretale.ai priced? Plans include a free assessment, Pilot ($14,900 one-time), Professional ($38,900/year), and custom Enterprise. Implementation starts at $8,900. NEXT STEP See it on your data. Request a focused walkthrough—usually within one business day. Only a valid email address is required; other fields are optional. Work email * Only a valid email address is accepted. Other fields below are optional. Name (optional) Company (optional) Role (optional) Industry (optional) Timezone (optional) Request a demo BROCHURE Download the foretale.ai brochure Enter your work email to receive the PDF. Work email * Download brochure --- ## https://www.hexango.com/privacy-policy ← Trust Center Privacy Policy How Hexango Private Limited collects, uses, and protects personal information Last updated October 01, 2025 This Privacy Notice for Hexango Private Limited describes how and why we may access, collect, store, use, and/or share your personal information when you use our services, including when you visit https://www.hexango.com, use foretale.ai, and engage with us through marketing or events. Summary of key points What personal information we process — We process personal information based on your interaction with our Services and product features. Sensitive personal information — We do not process sensitive personal information. Information from third parties — We do not collect personal information from third parties. How we process information — We process information to deliver, improve, and secure Services, communicate with users, prevent fraud, and comply with laws. 1. What information do we collect? Personal information you disclose to us may include names, email addresses, job titles, usernames, passwords, and contact preferences. All information you provide must be accurate and up to date. 2. How do we process your information? We process personal information to facilitate account creation and authentication, manage user accounts, protect individuals and systems, and meet legal obligations. 3. What legal bases do we rely on? Depending on jurisdiction, we rely on legal bases including consent, legal obligations, and vital interests. Additional legal basis disclosures are provided for the EU/UK, Switzerland, Canada, and US residents as applicable. 4. When and with whom do we share information? We may share personal information in limited circumstances, including business transfers such as mergers, financing, acquisition, or sale of company assets. 5. Do we offer AI-based products? Yes. We provide AI-powered capabilities in foretale.ai and may use AI service providers including Amazon Bedrock and AWS AI to deliver AI applications, AI insights, document generation, predictive analytics, machine learning, and natural language processing features. 6. How long do we keep your information? We keep personal information only as long as necessary for the purposes in this notice, or as required by law. When no longer needed, information is deleted or anonymized where feasible. 7. How do we keep your information safe? We use reasonable technical and organizational safeguards. However, no internet transmission or storage system can be guaranteed 100% secure. 8. Do we collect information from minors? No. We do not knowingly collect or market to children under 18 (or equivalent legal age). If such data is identified, we will take steps to remove it. 9. What are your privacy rights? Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing, withdraw consent, and request data portability. 10–11. DNT and US state privacy rights We currently do not respond to browser Do-Not-Track signals due to the absence of a uniform standard. US residents may have state-specific rights related to access, deletion, correction, portability, opt-out, and appeals. 12. Updates to this notice We may update this Privacy Notice from time to time. Material changes may be communicated by website notice or direct notification. 13. How to contact us Hexango Private Limited 51, Innov8, 5th Floor, Tower A, Mantri Square MIS Deeta Construction Pvt. Ltd., Devarabisanahalli Bengaluru, Karnataka 560103, India Email: contact@hexango.com 14. Request access, update, or delete data To submit a data subject request, use the official request form: Open data subject access request form --- ## https://www.hexango.com/resources/bid-rigging-analytics Three Suppliers. One Bank Account. The Bid Was Never Competitive. | foretale.ai ← Resources foretale.ai Learn More Home Resources Bid Rigging Analytics Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. How shared vendor identities expose bid rigging—and seven analytics that catch fake competition. Published 24 Jul 2026 · Updated 24 Jul 2026 Who should read this? Intended for: Procurement Leaders Finance Controllers Internal Auditors Compliance & Investigation Teams Risk Professionals Delivery can look real. The competition was not. What looked normal Three vendors bid. One won. Invoices matched the award. Goods or services arrived. On the surface, procurement worked. Then someone joined vendor master to bank details. All three suppliers paid into the same account . That is not three competitors. That is one economic party wearing three badges— classic cover for bid rigging . Why people should care If work is delivered, why does it matter? Because you did not get a market price—you got a managed one. Fake bidders rotate wins, submit cover bids, and keep prices high. The tender looks competitive. It never was. Shared bank accounts, addresses, tax IDs, or contacts are how that collusion shows up in data. Seven analytics that catch fake competition These tests use vendor master, bid/award history, and payment data— fields most ERPs and e-procurement systems already hold. Competing vendors sharing a bank account Vendors that bid against each other but remit to the same account or IBAN. Business impact: Strong signal that “competitors” are not independent. Shared tax ID, address, or phone across bidders Match master fields across vendors that appear on the same tender. Business impact: Exposes related parties posing as separate suppliers. Same contact email or phone on multiple bidders Flag identical buyer-facing contacts across supposedly independent vendors. Business impact: Operational proof of common control. Rotating wins among a closed vendor set The same small group of vendors repeatedly win against each other over time. Business impact: Classic bid-rotation pattern in award history. Persistent cover-bid / runner-up pattern One vendor always finishes a narrow second; prices cluster just above the winner. Business impact: Suggests bids designed to lose, not compete. Vendor created shortly before winning Short gap between vendor create date and first awarded tender. Business impact: Rushed entities used to shape a tender outcome. Unusually close bid amounts across “competitors” Bid prices land in a tight band with little real spread for the same scope. Business impact: Price collusion signal when paired with shared identity. Why tender reviews miss this Traditional Lowest compliant bid Check completeness, thresholds, and who won. Assumes bidders are independent. What risk needs Identity + award joins Bank accounts, tax IDs, contacts, and win patterns across tenders— not one award file in isolation. Key takeaway Bid rigging hides behind paperwork that looks complete. Join vendor identity to tender history—and fake competition stops looking competitive. How foretale.ai helps foretale.ai runs procurement risk analytics across vendor master, award, and payment data— shared bank accounts among bidders, related-party identity matches, rotating wins, cover-bid patterns, and price clustering—with explainable evidence for every finding. Procurement and audit teams review prioritized collusion risks across tenders—not only the winning bid. Was your last tender really competitive? Shared supplier identities and award patterns often sit in data you already have. Continuous AI analytics can surface fake competition before the next award locks in inflated cost. Request a demo Related reading Article Vendor Relationship Networks. Article 8 Vendor Master Analytics Every Company Should Run Tale Three Vendors. Shared Identity. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/discount-leakage The List Price Was Fine. | foretale.ai ← Resources foretale.ai Learn More Home Resources Discount Leakage Article The List Price Was Fine. Policy capped the discount at 5%. The invoice took 18%. Seven analytics that catch Order-to-Cash discount leakage. Published 31 Jul 2026 · Updated 31 Jul 2026 Who should read this? Intended for: Revenue / Commercial Controllers Order-to-Cash Leaders Finance Controllers Internal Auditors Pricing & Revenue Operations The sale looked booked. The margin was negotiated away. What looked normal Customer ordered. Goods shipped. Invoice posted. Cash came in. On the surface, Order-to-Cash worked. Then someone compared the invoice to the price list and discount policy: 01 List price — 100 02 Policy max discount — 5% 03 Invoice discount — 18% Revenue was recognized. Margin was not what pricing approved. That is discount leakage: the list price looked fine while the net price quietly broke policy . Why people should care Discounts are where commercial intent meets the invoice—and where margin most often dies unnoticed. Aging reports and DSO dashboards show collections. They rarely show whether the discount was authorized, stacked, timed correctly, or earned. A few points of unauthorized concession, repeated across customers and reps, becomes structural revenue leakage— without a single “fraud” alert firing. Seven analytics that catch discount leakage These tests join price lists, customer agreements, orders, invoices, credit notes, and payment timing— data most ERP and billing systems already hold. Invoice discount above approved max Compare line or header discount percent/amount to the customer class, contract, or price-list ceiling. Business impact: Stops unauthorized concessions that book as clean sales. Stacked discounts on the same line Trade, promo, cash, and rebate discounts applied together when policy allows only one path—or a capped total. Business impact: Finds “death by stacking” that single-field checks miss. Early-payment discount taken after due date Cash discount deducted or credited when payment arrived after the qualifying window. Business impact: Recovers giveaways that were never earned. Volume / tier discount without qualifying volume Tier pricing or rebate rates applied when cumulative volume never met the threshold. Business impact: Blocks unearned volume concessions. Chronic overrides by sales rep or customer Reps or accounts with repeated price overrides versus peer baselines and approval history. Business impact: Prioritizes where “exceptions” are the operating model. Credit note used as a backdoor discount Post-invoice credits that effectively rewrite the net price without a pricing approval trail. Business impact: Surfaces margin givebacks that never show as invoice discounts. Wrong discount matrix for channel or customer class Distributor, retail, or strategic rates applied to the wrong customer type or region. Business impact: Catches systematic mispricing across segments. Why O2C reviews miss this Traditional Price lists and approvals Was there a list price? Did someone approve the order? The invoice can still take more than policy allows. What risk needs List + policy + invoice + payment Discount depth, stacking, timing, volume, and credits— across every line, not a sample of exceptions. Key takeaway The list price can look fine. The discount is where margin leaks. How foretale.ai helps foretale.ai runs Order-to-Cash discount analytics across price lists, agreements, invoices, credit notes, and payment timing—above-policy discounts, stacking, unearned early-pay and volume concessions, chronic overrides, backdoor credits, and wrong customer-class rates—with explainable evidence for every finding. Controllers and revenue teams review prioritized discount breaks across 100% of billed lines—not a sample of “one-time” exceptions. How often does “booked revenue” still mean leaked margin? Most companies don’t know—until they join list price, policy, invoice discount, and payment terms at line level. Continuous AI analytics can surface discount leakage before the next billing cycle. Request a demo Related reading Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue Article What AP Actually Paid. Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/duplicate-payment-detection Duplicate Payment Detection: Why You Need 15+ Analytics | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources Duplicate Payment Detection Article Duplicate Payment Detection Needs 15+ Analytics Your ERP already paid that invoice. Somewhere in your ledger, a near-identical transaction is waiting to be paid again—and your duplicate check will probably miss it. Published 20 Jul 2026 · Updated 21 Jul 2026 Who should read this? Intended for: Internal Auditors Accounts Payable (AP) Managers Finance Controllers Procure-to-Pay (P2P) Process Owners Risk & Compliance Professionals One analytical test is not enough for a full duplicate payment assessment. Here’s why. One rule will never cover it Most teams start with a simple check: same vendor, same invoice number, same amount. That finds exact duplicates. It misses almost everything else. Easy to catch Exact duplicates Invoice INV-1042 for $12,500 paid twice under the same number. Your ERP often blocks this already. Where money leaks Near-duplicates Same bill as INV-1042 and INV1042 . Same amount two weeks later with a new number. Same bank account under two vendor codes. One rule won’t see these. Duplicate risk is not one problem. It is a set of business scenarios. Each needs its own test—or you leave gaps. Scenarios that cause duplicate payments Start here—not with SQL. These patterns show up again and again in AP data. 01 Same invoice number — two posts share one invoice ID. 02 Same vendor, different invoice format — 1042 , INV-1042 , and INV1042 are often the same bill. 03 Same amount within a time window — $47,850 to the same vendor twice in 14 days, with different invoice numbers. 04 Different vendor, same bank account — two vendor masters, one bank account, cash leaves twice. 05 Credit notes and reversals — a credit is raised, then the original invoice is paid again anyway. 06 Partial payments — splits and short-pays make “same amount” checks look clean when they are not. 07 Partial invoices against a PO — 60% then 40% is normal, until the full amount (or a partial) is billed again. How is this possible in ERPs? Translate scenarios into analytics Each scenario becomes one or more tests. Together, they give you coverage. Alone, none of them is enough. Matching rules Clear yes/no checks for high-confidence cases—exact invoice + vendor + amount, or the same bank account across two vendor IDs. Few hits. High confidence. Similarity scoring Score how close two invoice numbers or vendor names are. Example: INV-1042 and INV1O42 should score high, not fail a string match. Thresholds Define “close enough”: amount within $1, dates within 30 days, similarity above 85%. Set these from your data—not from a generic template. Exceptions to exclude Rent, utilities, and approved installments repeat on purpose. Exclude them, or your queue fills with noise. Risk scoring Rank findings so analysts review the strongest cases first: exact matches, then strong near-matches, then weaker signals. Common mistakes Looking only for exact matches You catch what the ERP already blocks—and miss the leakage. Ignoring master data quality Duplicate vendors and messy invoice numbers break every test you write. Using one rule for every business A company with 40 vendors is not the same as one with 4,000. Thresholds must fit the process. Producing too many false positives If the queue is full of noise, people stop trusting the analytics. Key takeaway Good duplicate payment analytics combine business understanding, clean data, and several detection techniques—not a single SQL query. How foretale.ai helps Building this by hand takes time: map scenarios, write tests, tune thresholds, and cut false positives. foretale.ai turns those scenarios into analytics in minutes. It understands your data, creates many tests at once—matching rules, similarity checks, windows, exclusions, and risk ranking—and runs them with clear evidence for every finding. You test across the full range of duplicate payment scenarios—not only the exact-match check most teams start with. See it in action See how Foretale designs and executes these analytics automatically. Request a demo Related reading Article Same Vendor. Too Many Invoices. Article 8 Vendor Master Analytics Every Company Should Run Article What AP Actually Paid. How it’s possible Why ERPs still let duplicates through These are common ways the same real-world invoice can still be paid more than once. Non-PO Invoice Processing Invoices processed without purchase order matching controls. Invoice Number Variations The same invoice submitted with different numbering or formatting conventions. OCR and Data Entry Errors Character recognition or manual entry errors create different invoice identifiers. Vendor Master Duplication The same supplier maintained under multiple vendor records. Cross-Company Processing The same supplier invoice processed across different legal entities or ERP instances. Tolerance Overrides and Workflow Exceptions Authorized users approve invoices that exceed configured matching controls. Credit Notes and Reissued Invoices Legitimate document corrections complicate duplicate payment detection. Got it © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/expense-behavior Expense Behavior Analytics: Why Audits Miss High-Risk Spend | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources Expense Behavior Article Stop Looking at Expense Reports. Start Looking at Expense Behavior . Why traditional expense audits miss the highest-risk transactions—and how AI changes the game. Published 21 Jul 2026 · Updated 21 Jul 2026 Who should read this? Intended for: Internal Auditors Finance Controllers Travel & Expense (T&E) Managers Expense Process Owners Risk & Compliance Professionals This topic is about risk , not reporting. Policies catch rule violations. Behavior reveals fraud. The problem Companies process millions in employee expenses every year. Most audits still sample only 1–5% of claims. Policy engines catch what they are built to catch: over-limit meals, missing receipts, weekend travel flags. Those are rule violations. The highest-risk transactions often look fine in isolation— until you look at how someone spends over time, against peers, and across systems. What audits review Expense reports Sampled claims. Policy checks. Receipts attached. Approvals complete. The report looks clean. What risk requires Expense behavior Patterns across claims, cards, peers, vendors, and timing. The story only appears when you watch the person—not the single form. Where money actually leaks These patterns rarely trip a single policy gate. Together, they drive real leakage and fraud exposure. 01 Duplicate reimbursements — the same spend claimed more than once, or reimbursed after a card payment. 02 Split claims — one purchase broken into smaller reports to stay under approval limits. 03 Weekend spending — travel and entertainment that doesn’t align with business calendars. 04 Personal expenses — retail, family travel, or lifestyle spend coded as business. 05 Excessive mileage — distances and trips that don’t match itineraries or peer norms. 06 Hotel rate anomalies — rates far above market, role, or booking channel for the same city. 07 Meals exceeding peer averages — consistent outliers vs role, grade, and cost centre. 08 Claims after employee termination — spend or reimbursements that continue past exit dates. 09 Round-dollar patterns — repeated even amounts that suggest fabricated or padded claims. 10 Frequent small claims below approval limits — high volume under the radar of managers and policy caps. Why rules fail Misuse adapts Once a limit or keyword is known, spend is reshaped to stay just inside the rule. Rules generate false positives Legitimate travel trips the same flags as misuse—so reviewers stop trusting the queue. Auditors cannot review every receipt Sampling and annual cycles leave most behavior unobserved between reviews. How AI changes the approach Instead of asking only “Does this violate policy?”, AI asks whether the behavior is unusual. Traditional Does this violate policy? Binary checks against limits, categories, and mandatory fields. Useful—but incomplete. Behavior-led Is this risky? Peer comparison, change detection, vendor and timing signals, and resemblance to known abuse patterns. Is this employee different from peers? Role, grade, and cost-centre baselines expose outliers. Is spending behavior changing? Sudden jumps vs the person’s own history matter more than one receipt. Is this vendor unusual? New or rare merchants for that role raise the priority of review. Is timing suspicious? Weekends, post-termination windows, and clustered submissions are signals. Does the pattern resemble previous fraud? Split claims, double-dips, and round-dollar runs look familiar once you’ve seen them. Real examples Illustrative cases based on common T&E risk patterns. Savings estimates reflect avoided leakage when behavior monitoring replaces sample-only review. Duplicate reimbursement after card payment An employee’s corporate card cleared a hotel stay; the same invoice was later reimbursed as out-of-pocket. Policy saw two “clean” transactions. Behavior matched card feed to claim. Estimated impact: $8K–$25K / year in a mid-size sales org Split meals under the approval limit Client dinners were filed as three claims under $75 on consecutive days. No single claim breached policy. Pattern analytics flagged the cluster under one merchant and approver. Estimated impact: $15K–$40K / year across high-travel teams Mileage far above peer norms A field role claimed 35% more monthly miles than peers with the same territory. Individual trips looked plausible. Peer baselines made the outlier obvious. Estimated impact: $12K–$30K / year for a regional field force Claims after termination Card and reimbursement activity continued for two weeks after exit. HR and T&E systems weren’t joined in the audit sample. Continuous monitoring caught the window. Estimated impact: $5K–$50K per incident, depending on access and role Frequent sub-limit claims Dozens of round-dollar “office supplies” claims stayed under manager review thresholds. Volume and vendor mix looked nothing like peers in the same cost centre. Estimated impact: $20K–$60K / year in a large shared-services population Key takeaway Continuous monitoring of expense behavior beats annual audits of expense reports. Policy still matters—but risk lives in the pattern. How foretale.ai helps foretale.ai turns expense and related data into behavior-led risk analytics— peer baselines, change detection, vendor and timing signals, and known abuse patterns— with explainable evidence for every finding. Your experts review the highest-risk behavior first, instead of sampling reports and hoping the sample is lucky. See it in action See how Foretale monitors expense behavior—not just expense reports. Request a demo Related reading Article Personal Shopping. Business Expense Code. Article 10 P-Card Analytics Every Organization Should Run Article Duplicate Payment Detection Needs 15+ Analytics © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/expense-split Same Dinner. Three Claims. | foretale.ai ← Resources foretale.ai Learn More Home Resources Expense Split Article Same Dinner. Three Claims. Meal total 9,600. Approval needed above 5,000. Submitted as 3,200 + 3,200 + 3,200. Seven checks that catch split expenses. Published 6 Aug 2026 · Updated 6 Aug 2026 Who should read this? Intended for: Finance Controllers T&E / Expense Leaders Internal Auditors AP Operations Risk & Compliance Professionals Each claim looked fine. The split did not. What looked normal Three expense claims. Each under the limit. Each approved. On paper, policy worked. Then someone added them up: 01 Meal total — 9,600 02 Approval needed above — 5,000 03 Submitted as — 3,200 + 3,200 + 3,200 One dinner. Three claims. The split kept each line under the limit. Why people should care Limits only work if one spend stays as one claim. When people break a large spend into many small ones, each claim looks fine. Approvers never see the full amount. That is how policy gets skipped without a hard “reject.” Seven checks that catch split expenses These tests join merchant, employee, date, amount, and payment type— data most expense systems already hold. Same merchant, same day, multiple claims under the limit Several claims to one merchant on one day, each under the approval cap. Business impact: Finds the classic dinner split in one glance. Same employee, several claims that add up to one large spend Claims close in time that together cross the limit the single lines avoided. Business impact: Rebuilds the full spend approvers never saw. Claims just under the approval or receipt threshold Amounts clustered just below the line that needs a receipt or extra approval. Business impact: Spots gaming of the threshold. Split across card and out-of-pocket for the same event Part on the corporate card, part claimed as cash for the same meal or trip. Business impact: Catches double paths for one spend. Same attendees / same restaurant, billed more than once Matching people, place, or time across more than one claim. Business impact: Flags repeat billing of the same event. Peer spike: far more sub-limit claims than others in the same role One employee files many just-under-limit claims vs peers. Business impact: Prioritizes people who live under the cap. Pattern over time: always just under the limit A long run of claims that sit just below policy thresholds. Business impact: Shows habit, not a one-off mistake. Why reviews miss this Traditional One claim at a time Is this amount under the limit? Is there a receipt? Each line can pass while the full spend is hidden. What risk needs Claims added together Same person, same day, same merchant— do several small claims hide one large spend? Key takeaway Policy looks at each claim. Risk looks at the total. How foretale.ai helps foretale.ai checks expense claims across merchant, employee, date, and amount— same-day splits, under-limit clusters, card plus out-of-pocket doubles, repeat events, peer spikes, and long-run threshold patterns—with clear evidence for every finding. Controllers and auditors review the full spend—not one small claim at a time. How often do “small” expenses add up to a big one? Most companies do not know—until they join claims by person, merchant, and day. Continuous AI checks can surface splits before the next reimbursement run. Request a demo Related reading Article Personal Shopping. Business Expense Code. Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Article 10 P-Card Analytics Every Organization Should Run © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/fraud-analytics-framework Fraud, Risk & Compliance Analytics Framework | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources Fraud Analytics Framework Framework Fraud, Risk & Compliance Analytics Framework Three phases—Pre-Analytics, Analytics, and Post-Analytics—so programmes deliver clarity, precision, and action—not just more alerts. Published 20 Jul 2026 · Updated 21 Jul 2026 Who should read this? Intended for: Internal Auditors Risk & Compliance Professionals Finance Controllers Fraud / Forensic Analytics Teams Procure-to-Pay (P2P) Process Owners Most programmes equate analytics with detection. Real value comes from sequencing all three phases. Why sequencing matters Real value comes from clarity before models, precision in what you prioritize, and action after findings. Miss any one of these, and the system underdelivers. Phase 1 Pre-Analytics — foundation first Solve the right problem with reliable inputs. 1. Data readiness Availability of core datasets (PO, invoices, payments, vendors, users) Data completeness (IDs, timestamps, amounts) Historical depth (12–24 months minimum) Data quality (duplicates, inconsistencies, missing values) Outcome: You trust your data enough to analyze it. 2. Process clarity Defined Procure-to-Pay (P2P) workflows Known exceptions and manual overrides Approval hierarchies and enforcement 3-way match consistency Outcome: You understand how transactions should behave. 3. Stakeholder alignment Clear ownership (Audit / Finance / Compliance) Defined investigation responsibility Alignment on goals (fraud detection vs savings vs compliance) Outcome: Someone is accountable for acting on insights. 4. Success metrics Defined KPIs (duplicate payment %, recovery value, leakage reduction) Baseline metrics established Clear definition of success Outcome: You know how to measure impact. Phase 2 Analytics — focused & scalable Detect meaningful risks—not just generate alerts. 5. Risk prioritization Top high-impact scenarios: duplicate payments, split POs, vendor collusion, price anomalies Focus on financially measurable risks Outcome: You are solving high-value problems first. 6. Technology fit Approach selection (rules vs ML vs hybrid) Scalability with data volume Integration with ERP / data sources Explainability of results Outcome: The solution fits your environment and use case. Phase 3 Post-Analytics — insight to impact Convert findings into measurable business outcomes. 7. Control maturity Evaluation of existing preventive controls Identification of control gaps Strengthening controls based on findings Outcome: Reduced future risk—not just detection. 8. Data access & security Secure and scalable data pipelines Role-based access controls Compliance with data security standards Outcome: Sustainable and compliant analytics operations. 9. Investigation capability Defined case management workflow Clear validation and escalation process Tracking and closure of findings Outcome: Insights are acted upon—not ignored. The real differentiator Pre-phase → Clarity. Analytics → Precision. Post-phase → Action. Real value comes from all three working together. Pre-phase Clarity before you model Analytics Precision in what you prioritize Post-phase Action after findings How foretale.ai helps foretale.ai supports the full sequence: it understands enterprise data and process context, plans and executes focused risk analytics at scale, and returns explainable findings with evidence so teams can investigate, strengthen controls, and close cases. You spend less time assembling tools and scripts—and more time acting on risks that matter. See it in action See how Foretale runs risk analytics across Pre-Analytics clarity through Post-Analytics action. Request a demo Related reading Article 10 P-Card Analytics Every Organization Should Run Article Duplicate Payment Detection Needs 15+ Analytics Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/from-prompt-to-closed-case Redirecting… — HEXANGO | foretale.ai This page has moved. Return home . --- ## https://www.hexango.com/resources/general-ledger-analytics 8 General Ledger Analytics to Catch High-Risk Activity | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources General Ledger Analytics Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity How AI finds unusual journals, suspense build-up, period-end spikes, and control gaps that standard trial-balance reviews miss. Published 22 Jul 2026 · Updated 22 Jul 2026 Who should read this? Intended for: Finance Controllers Financial Reporting Teams Internal Auditors SOX / Controls Owners Risk & Compliance Professionals The General Ledger is the financial control backbone. Period-end reviews of totals still miss the risk in the journals. Why the General Ledger is the financial control backbone Every process eventually posts to the GL. If something is wrong in AP, revenue, expenses, intercompany, or closing adjustments, it shows up here—as a journal, a balance, or a pattern over time. Most period-end reviews still sample trial balances and a handful of journals. High-risk activity often looks fine in isolation until you compare every posting to history, peers, and process norms. Eight General Ledger analytics to run These tests prioritize the risks controllers, auditors, and SOX teams care about most— without treating every outlier as wrongdoing by default. Unusual manual journal entries High-value or period-end manuals outside normal behavior— unusual preparer, approver, amount, account combination, or off-hours posting. Business impact: Higher risk of error, override, or concealment in the books of record. Suspense / clearing account build-up Aging balances, long-outstanding items, rising trends, and unreconciled clearing accounts. Business impact: Classic control weakness—risk sits unresolved and reporting quality declines. Round-dollar and recurring exact amounts Repeated even amounts and identical recurring postings— may indicate estimates, manual adjustments, or attempts to conceal irregular activity. Business impact: Faster identification of adjustments that need explanation. Weekend, holiday, and after-hours postings Compare timing to historical patterns and process expectations. Separate manual journals from overnight system batches before escalating. Business impact: Surfaces unusual human activity without flooding queues with batch jobs. Reversal and reclassification spikes Unusual volumes of reversals and reclasses—especially near month-end, quarter-end, and year-end. Business impact: Stronger close assurance; a common SOX testing focus. Dormant accounts suddenly active Quiet accounts that suddenly move— incorrect postings, new business, or unauthorized journals. Investigate before assuming intent. Business impact: Catches unexpected activity where reviewers rarely look. Potential segregation-of-duties conflicts Journals that appear to circumvent approval or SoD controls. GL data alone rarely proves SoD failure—confirm with user master, workflow logs, and ERP authorizations. Business impact: Prioritizes journals that need control evidence—not just balance review. Intercompany and related-party anomalies One-sided eliminations, mismatched balances, timing differences, and missing counterpart entries. Business impact: Protects group reporting and reduces late consolidation surprises. How AI changes General Ledger monitoring Traditional GL checks ask whether a journal breaks a rule. AI asks whether the posting is unusual in context. Traditional asks Rules and reconciliations Is this journal over the approval limit? Is this account reconciled? AI asks Behavior and patterns Is this unusual vs history? Does this preparer normally use this account? Does timing differ from peers? Is a dormant account suddenly active? Does the pattern resemble prior high-risk journals? Key takeaway Continuous GL monitoring beats period-end sampling of totals. The highest-priority risks live in journal behavior—not only in the trial balance. Compare every journal to history, preparer norms, and process expectations— instead of hoping the sample caught what mattered. How foretale.ai helps foretale.ai runs General Ledger risk analytics across your enterprise data— unusual manuals, suspense aging, timing outliers, reversal spikes, dormant-account activity, potential control conflicts, and intercompany anomalies—with explainable evidence for every finding. Controllers and auditors review prioritized risks across 100% of postings, not a period-end sample. See GL risk before close What high-priority journal and balance risks are sitting in your General Ledger today? Continuous AI analytics can surface unusual postings, suspense build-up, and period-end spikes across your full GL—before they affect reporting quality. Request a demo Related reading Framework Fraud, Risk & Compliance Analytics Framework Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue Article Duplicate Payment Detection Needs 15+ Analytics © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/ghost-employees On Payroll. Nowhere in the Building. | foretale.ai ← Resources foretale.ai Learn More Home Resources Ghost Employees Article On Payroll. Nowhere in the Building. How ghost employees hide in payroll—and eight analytics that expose fictitious, duplicate, and no-show workers. Published 27 Jul 2026 · Updated 27 Jul 2026 Who should read this? Intended for: Payroll Managers HR Controllers Finance Controllers Internal Auditors Risk & Compliance Professionals The employee number is real. The person may not be. What looked normal An employee ID sits in the master. Salary clears every cycle. Cost center looks fine. Ask who last saw them at a desk, on a badge reader, or in a system login—and the trail goes quiet. That is the ghost-employee problem: pay without presence . Sometimes the person never existed. Sometimes they are a duplicate persona. Sometimes they are shelved headcount still marked active while someone else collects the deposit. Why people should care Ghost payroll is not a rounding error. It is recurring cash leaving the company every pay cycle. Headcount reports and sample audits rarely catch it. Ghosts look complete in HR forms and payroll output—until you join identity, bank details, activity, and pay results across the full population. Eight analytics that expose ghost employees These tests use employee master, bank details, pay results, and—where available—access or time data. In SAP-style landscapes that often means Employee Master ( PA0000 / PA0001 ), Bank Details ( PA0009 ), Basic Pay ( PA0008 ), and Payroll Results ( PCL2 / RT ). Paid with no recent activity signal Join payroll to badge, VPN, SSO, or timesheet activity. Surface active employees paid with zero recent presence. Business impact: Strong no-show / shelved-headcount signal across locations. Duplicate national ID, tax ID, or contact Match employees on national ID, tax ID, phone, or email—exact and near-duplicate—under different employee numbers. Business impact: One person (or one fabricated identity) occupying multiple payroll seats. Shared bank accounts across “employees” Detect two or more active employees remitting to the same IBAN / account ( PA0009 ). Business impact: Classic collection point for ghost or proxy payroll. Employee bank matches a vendor bank Compare employee bank details to vendor bank master ( LFBK ) for exact account / IBAN matches. Business impact: Diversion path between payroll ghosts and AP payees. Incomplete or placeholder master data Flag active paid employees with missing tax ID, blank address, generic email, or placeholder names. Business impact: Fictitious records often skip the fields real onboarding requires. Impossible supervisor / org span Detect managers with implausible direct-report counts, circular reporting, or reports with no org home. Business impact: Ghosts need a reporting line—weak org design hides them. Created and paid with almost no tenure signal Short gap from employee create date to first large payment, with weak onboarding or access evidence. Business impact: Rushes used to insert fictitious workers into a pay run. Off-cycle pay without corresponding presence Cluster manual / off-cycle payments to employees who also fail activity and identity tests. Business impact: Override paths that fund ghosts outside the standard cycle. Why headcount reviews miss this Traditional Headcount and sample payslips Reconcile FTEs to budget and spot-check a few employees. Assumes every active ID is a real, present person. What risk needs Identity + presence + pay joins Duplicate IDs, shared banks, missing master fields, and zero-activity pay— across the full payroll population, not a sample of names. Related—but different—from post-termination pay Ghost employees are about people who should not be on payroll at all . Post-termination leakage is about real leavers whose pay did not stop . Both drain cash. The detection joins overlap—and the investigation paths differ. Read the companion piece: The Badge Was Deactivated. The Salary Kept Clearing. Key takeaway An employee number is not proof of a person. Join identity, bank details, presence, and pay results—and ghost payroll stops looking like headcount. How foretale.ai helps foretale.ai runs payroll risk analytics across employee master, bank details, and pay results— no-activity paid employees, duplicate identities, shared banks, employee–vendor bank matches, incomplete masters, and off-cycle anomalies—with explainable evidence for every finding. Payroll, HR, and audit teams review prioritized ghost-employee risks across the full population—not only a sample of names. Who on your payroll has never shown up? Identity, bank, and activity signals often sit in data you already have. Continuous AI analytics can surface ghost employees before the next cycle clears again. Request a demo Related reading Article The Badge Was Deactivated. The Salary Kept Clearing. Article 8 Vendor Master Analytics Every Company Should Run Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources ← Home Resources Articles and frameworks for risk, audit, finance, and operations teams—grouped by domain. Accounts Payable Leakage and control risks in procure-to-pay and vendor payments. Article Duplicate Payment Detection Needs 15+ Analytics One duplicate-payment rule is not enough. Learn the scenarios that cause leakage, how to turn them into analytics, and how foretale.ai builds those tests. Article 8 Vendor Master Analytics Every Company Should Run How AI finds duplicate suppliers, shared bank accounts, and master-data gaps before they become payment leakage. Article What AP Actually Paid. PO ordered 100. Goods received 40. Invoice cleared 100—seven analytics that catch the gap. Article New Vendor. Big First Payment. Then Nothing. Vendor added Day 0. Paid Day 3. Next bill never—seven checks that catch rush vendors. Article Same Vendor. Too Many Invoices. Peer vendors send 4 invoices a month. This one sent 47—seven checks that catch unusual volume. Procurement Fake competition, collusion, and award risks that inflate cost before the invoice hits AP. Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. How shared vendor identities expose bid rigging—and seven analytics that catch fake competition. Article Vendor Relationship Networks. Two vendors never share a bank account, tax ID, or phone—yet they always bid together. Build a graph instead of rule-based analytics. Travel & Expense Behavioral risk in T&E—beyond policy gates and sampled audits. Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Why traditional expense audits miss the highest-risk transactions—and how AI changes the game. Article Personal Shopping. Business Expense Code. Seven analytics that catch shopping, lifestyle, and home-city spend submitted as business. Article Same Dinner. Three Claims. Meal total 9,600. Approval above 5,000. Submitted as 3,200 + 3,200 + 3,200—seven checks that catch split expenses. Payroll Post-termination pay, ghost employees, and payroll master gaps that drain salary spend. Article The Badge Was Deactivated. The Salary Kept Clearing. How payments after termination and payroll master gaps create silent leakage—and eight analytics that catch it. Article On Payroll. Nowhere in the Building. How ghost employees hide in payroll—and eight analytics that expose fictitious, duplicate, and no-show workers. Purchasing Cards Misuse and leakage risks in P-Card programs—beyond monthly statements and sampled receipts. Article 10 P-Card Analytics Every Organization Should Run How AI helps identify split purchases, personal spend, unauthorized merchants, and other purchasing-card risks before they become leakage or fraud. Order-to-Cash Billing, credits, pricing, and collection risks that quietly erode revenue. Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue How AI helps identify billing errors, revenue leakage, duplicate credits, and collection risks before they impact the bottom line. Article The List Price Was Fine. Policy capped the discount at 5%. The invoice took 18%—seven analytics that catch Order-to-Cash discount leakage. General Ledger High-priority journal and balance risks in the books of record—beyond trial-balance sampling. Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity How AI finds unusual journals, suspense build-up, period-end spikes, and control gaps that standard trial-balance reviews miss. Frameworks Reference guides for structuring enterprise risk and compliance analytics programmes. Framework Fraud, Risk & Compliance Analytics Framework A three-phase framework for enterprise fraud, risk, and compliance analytics: Pre-Analytics, Analytics, and Post-Analytics. --- ## https://www.hexango.com/resources/new-vendor-first-payment New Vendor. Big First Payment. Then Nothing. | foretale.ai ← Resources foretale.ai Learn More Home Resources New Vendor First Payment Article New Vendor. Big First Payment. Then Nothing. Vendor added on Day 0. Paid on Day 3. No next bill. Seven checks that catch rush vendors and one-time big payments. Published 5 Aug 2026 · Updated 5 Aug 2026 Who should read this? Intended for: AP / Procure-to-Pay Leaders Finance Controllers Vendor Master Owners Internal Auditors Risk & Compliance Professionals The vendor looked new and urgent. The payment looked final. What looked normal A new supplier was set up. An invoice came in. Payment cleared. On paper, AP worked. Then someone looked at the dates: 01 Vendor added — Day 0 02 First payment — Day 3 03 Next bill — never That pattern is simple and risky: create fast, pay big, then disappear . Why people should care Real suppliers usually come back. Fake or weak ones often do not. A rush setup plus a large first payment plus no follow-up spend is how shell vendors and one-time setups get cash out. Aging reports will not show this. You need create date, pay date, and later activity side by side. Seven checks that catch this These tests use vendor master, invoices, and payments— data most ERP systems already have. Paid within days of vendor create Flag vendors where the first payment is very soon after the vendor was added. Business impact: Surfaces rush setups before they look “normal.” First payment much larger than peers Compare the first payment to typical first payments in the same category or company code. Business impact: Finds big cash-outs on day one. One payment, then silence Vendors with a single paid invoice and no later bills or POs for a long period. Business impact: Highlights one-and-done suppliers. Bank details changed just before first pay Bank account added or changed shortly before the first payment cleared. Business impact: Catches last-minute payee switches. Paid with thin master data Payment cleared while tax ID, address, or bank fields were still blank or incomplete. Business impact: Stops pay-first, fix-later leakage. Blocked, then paid Vendor was blocked or held, then reopened, then paid soon after. Business impact: Flags status games around payment. Same person creates and pays The user who created the vendor also posted or released the first payment. Business impact: Shows weak split of duties on new suppliers. Why reviews miss this Traditional Invoice and approval Was the invoice approved? Was the amount in budget? That still misses create-to-pay speed. What risk needs Create + pay + later activity How fast was the vendor paid, how big was the first pay, and did anyone come back? Key takeaway New is not the problem. New, paid fast, then gone is the problem. How foretale.ai helps foretale.ai checks new vendors across create date, first payment, later activity, bank changes, thin master data, block-and-reopen paths, and user roles— with clear evidence for every finding. AP and audit teams review the riskiest new vendors first—not a random sample of invoices. How many new vendors were paid once and never seen again? Most companies do not know—until they join vendor create date with payment history. Continuous AI checks can surface these patterns before the next rush payment. Request a demo Related reading Article 8 Vendor Master Analytics Every Company Should Run Article Duplicate Payment Detection Needs 15+ Analytics Article Vendor Relationship Networks. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/order-to-cash-analytics 7 Order-to-Cash Analytics to Protect Revenue | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources Order-to-Cash Analytics Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue How AI helps identify billing errors, revenue leakage, duplicate credits, and collection risks before they impact the bottom line. Published 21 Jul 2026 · Updated 21 Jul 2026 Who should read this? Intended for: Finance Controllers Order-to-Cash Process Owners Accounts Receivable Managers Internal Auditors Revenue Operations Leaders Every sale doesn’t automatically become revenue. Order-to-Cash analytics finds where it quietly leaks. Every sale doesn’t automatically become revenue Between order creation, shipping, invoicing, collections, and cash application, organizations lose millions through billing mistakes, pricing inconsistencies, duplicate credits, delayed invoicing, and collection failures. Most companies monitor KPIs like DSO and overdue receivables. Few continuously analyze every transaction to identify where revenue is quietly leaking. This is where Order-to-Cash analytics makes a measurable difference. Seven Order-to-Cash analytics to run These tests connect orders, deliveries, invoices, credit notes, customer behavior, and payment history— the joins traditional aging reports rarely make. Orders not invoiced Identify sales orders that have been fulfilled but never invoiced. Business impact: Lost revenue and delayed cash flow. Duplicate customer invoices Detect invoices generated multiple times for the same shipment or order. Business impact: Customer disputes and reputational damage. Credit notes exceeding expected levels Analyze customers, products, or business units with unusually high credit-note activity. Business impact: Revenue erosion and potential abuse. Unauthorized pricing or discount overrides Compare invoice prices against approved price lists and discount policies. Business impact: Margin leakage and unauthorized concessions. Long invoice delays Measure the elapsed time between delivery and invoice creation. Business impact: Higher DSO and slower cash conversion. High-risk overdue receivables Identify customers with rapidly increasing overdue balances or deteriorating payment behavior. Business impact: Increased bad debt risk. Cash application exceptions Find payments that remain unapplied or are matched manually more often than expected. Business impact: Inefficient collections and inaccurate receivable balances. Why traditional reports miss these issues Standard ERP reports show totals and aging buckets. They rarely connect data across orders, deliveries, invoices, credit notes, customer behavior, and payment history. Traditional KPIs and aging DSO, overdue buckets, and period totals. Useful summaries—incomplete for leakage. What risk needs Transaction-level joins Order → delivery → invoice → credit → payment, with behavior and exception patterns over time. AI can continuously analyze every transaction, detect anomalies, prioritize risks, and explain why a transaction deserves attention—reducing manual effort while expanding coverage. Final thoughts Revenue leakage often isn’t one major incident. It’s hundreds of small process failures, pricing inconsistencies, billing delays, and collection exceptions. Organizations that continuously monitor their Order-to-Cash process gain faster collections, stronger controls, and greater confidence that every legitimate sale becomes cash. How foretale.ai helps foretale.ai runs Order-to-Cash risk analytics across your enterprise data— unbilled orders, duplicate invoices, credit-note outliers, pricing overrides, invoice delays, high-risk receivables, and cash application exceptions—with explainable evidence for every finding. Your teams review prioritized risks across 100% of transactions, instead of hoping sample reports catch the leaks. Find the hidden revenue risks What hidden revenue risks exist in your Order-to-Cash process? Continuous AI-driven analytics can uncover billing anomalies, pricing exceptions, and collection risks across 100% of your transactions—before they impact your financial results. Request a demo Related reading Article The List Price Was Fine. Article 10 P-Card Analytics Every Organization Should Run Article 8 General Ledger Analytics Every Company Should Run to Catch High-Risk Activity © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/p-card-analytics 10 P-Card Analytics Every Organization Should Run | HEXANGO · foretale.ai ← Resources foretale.ai Learn More Home Resources P-Card Analytics Article 10 P-Card Analytics Every Organization Should Run How AI helps identify split purchases, personal spend, unauthorized merchants, and other purchasing-card risks before they become leakage or fraud. Published 21 Jul 2026 · Updated 21 Jul 2026 Who should read this? Intended for: Finance Controllers Procurement & P-Card Program Owners Accounts Payable Managers Internal Auditors Risk & Compliance Professionals Policy limits don’t stop creative spenders. Transaction-level P-Card analytics do. Convenience without continuous control is risk Purchasing cards speed up buying—and open a fast path for split transactions, personal purchases, blocked merchant categories, missing receipts, and charges that never get reconciled. Most programs review monthly statements, sampled receipts, and hard policy blocks. Few continuously analyze every charge against cardholder behavior, peers, merchants, timing, and other payment channels. That gap is where P-Card leakage and misuse quietly accumulate. Ten P-Card analytics to run These tests connect card transactions, merchant categories, cardholder profiles, receipt status, and AP/expense activity—the joins statement reviews rarely make. Split purchases below approval thresholds Find sequences of related charges that stay just under single-transaction or daily limits. Business impact: Bypass of approval controls and inflated discretionary spend. Unauthorized merchant category (MCC) spend Detect charges in blocked or restricted MCCs—even when merchant names look benign. Business impact: Policy breaches and unapproved category exposure. Personal or non-business purchases Flag merchant patterns inconsistent with role, cost center, or travel/project context. Business impact: Misuse of company funds and weak culture of control. Duplicate and near-duplicate charges Identify repeated amounts at the same merchant within short windows—or slight variants that look like retries. Business impact: Overpayment and unresolved dispute leakage. Unusual timing patterns Surface weekend, holiday, late-night, or out-of-cycle spend that breaks a cardholder’s normal pattern. Business impact: Higher likelihood of personal use or compromised credentials. Peer and historical spend outliers Compare cardholders to role/peer baselines and their own history for sudden volume or merchant shifts. Business impact: Early detection of escalating misuse before month-end review. Missing or late receipt reconciliation Track charges without supporting receipts, delayed submissions, or chronic unmatched items. Business impact: Incomplete audit trail and unchallenged non-compliant spend. Cash-equivalent and high-risk merchant activity Monitor cash advances, money services, gift cards, and other cash-like MCCs with elevated abuse risk. Business impact: Hard-to-trace diversion and rapid cash extraction. Dormant, orphaned, or post-termination card use Find inactive cards that suddenly revive, cards without owners, or spend after offboarding. Business impact: Unauthorized access and control failure at the lifecycle edge. Cross-channel duplicate payments Match P-Card charges against expense claims and AP invoices for the same merchant, amount, or invoice reference. Business impact: Paying twice—once on card and again through AP or reimbursement. Why statement reviews miss these issues Monthly card reports show totals, top merchants, and policy exceptions. They rarely connect behavior across time, peers, MCC risk, receipt gaps, and parallel payment channels. Traditional Statements and samples Monthly totals, receipt spot-checks, and hard MCC blocks. Useful controls—incomplete for creative misuse. What risk needs Transaction-level joins Charge → merchant → cardholder → peers → receipts → AP/expense, with timing and exception patterns over time. AI can continuously analyze every P-Card transaction, detect anomalies, prioritize risks, and explain why a charge deserves attention—reducing manual review while expanding coverage. Final thoughts P-Card risk is rarely one dramatic fraud case. It’s repeated small splits, personal merchants, missing receipts, and charges paid twice through another channel. Organizations that continuously monitor purchasing-card activity strengthen program controls, reduce leakage, and give auditors evidence across 100% of transactions—not a sample of statements. How foretale.ai helps foretale.ai runs P-Card risk analytics across your enterprise data— split purchases, unauthorized MCCs, personal spend patterns, duplicate charges, timing anomalies, peer outliers, receipt gaps, cash-like merchants, dormant-card activity, and cross-channel duplicates— with explainable evidence for every finding. Your teams review prioritized risks across 100% of card transactions, instead of hoping monthly samples catch the exceptions. Find the hidden P-Card risks What risks sit in your purchasing-card program today? Continuous AI-driven analytics can uncover split purchases, personal spend, and cross-channel duplicates across 100% of transactions—before they impact your financial results. Request a demo Related reading Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Article Duplicate Payment Detection Needs 15+ Analytics Article 7 Order-to-Cash Analytics Every Company Should Run to Protect Revenue © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/payroll-analytics The Badge Was Deactivated. The Salary Kept Clearing. | foretale.ai ← Resources foretale.ai Learn More Home Resources Payroll Analytics Article The Badge Was Deactivated. The Salary Kept Clearing. How payments after termination and payroll master gaps create silent leakage—and eight analytics that catch it. Published 27 Jul 2026 · Updated 27 Jul 2026 Who should read this? Intended for: Payroll Managers HR Controllers Finance Controllers Internal Auditors Risk & Compliance Professionals Access ended on Friday. The direct deposit ran on Tuesday. What looked normal The employee left. HR closed the file. IT revoked systems access. On the next payday, salary still cleared to the same bank account. No one stole a check in the mail. The payroll run simply never learned what the badge system already knew. That gap—between HR status and payroll payment —is where ghost pay and post-termination leakage live. Why people should care Payroll is often the largest operating expense line. A small rate of “still paid after exit” compounds quietly across months and locations. Classic reviews sample a few terminations and check the final payslip. They rarely join termination date, last physical/system activity, bank details, and every subsequent payment across the full population. Eight payroll analytics that catch silent leakage These tests use employee master, bank details, pay results, and—where available—access or time data. In SAP-style landscapes that often means Employee Master ( PA0000 / PA0001 ), Bank Details ( PA0009 ), Basic Pay ( PA0008 ), and Payroll Results ( PCL2 / RT ). Payments after termination date Flag pay results posted after the employment end date—excluding documented final settlements. Business impact: Direct cash leakage from delayed or missed offboarding in payroll. Paid with no recent activity signal Join payroll to badge, VPN, SSO, or timesheet activity. Surface employees paid with zero recent presence. Business impact: Ghost-employee and shelved-headcount patterns that master status alone misses. Shared bank accounts across employees Detect two or more active employees remitting to the same IBAN / account ( PA0009 ). Business impact: Possible family proxy, identity sharing, or diversion setup. Employee bank matches a vendor bank Compare employee bank details to vendor bank master ( LFBK ) for exact IBAN / account matches. Business impact: Classic payroll–AP diversion and related-party payment risk. Bank detail change just before payday Flag bank account changes close to a pay run, especially for high earners or recent joiners. Business impact: Account-takeover and insider diversion window. Duplicate national ID, tax ID, or contact Match employees on national ID, tax ID, phone, or email—exact and near-duplicate. Business impact: Duplicate personas on payroll under different employee numbers. Off-cycle / manual payment concentration Cluster manual, off-cycle, or adjustment payments by initiator, cost center, and employee. Business impact: Override paths that bypass standard payroll controls. HR status vs payroll status mismatch Compare HR employment status to payroll payability. Catch “inactive in HR, active in pay.” Business impact: Process break between HRIS and payroll that keeps ghost pay alive. Why offboarding reviews miss this Traditional Final payslip check Confirm last day, unused leave, and one final payment. Assumes the next cycle will stop automatically. What risk needs Status + pay + bank joins Every payment after exit, every shared bank, every HR–payroll mismatch— across the full population, not a sample of leavers. Key takeaway Deactivating a badge is not the same as stopping a salary. Join HR status to payroll results and bank details—and post-termination pay stops looking invisible. How foretale.ai helps foretale.ai runs payroll risk analytics across employee master, bank details, and pay results— payments after termination, shared employee banks, employee–vendor bank matches, off-cycle concentration, and HR–payroll status mismatches—with explainable evidence for every finding. Payroll, HR, and audit teams review prioritized leakage across the full population—not only a sample of leavers. Who was still paid after they left? Termination dates and pay results often sit in data you already have. Continuous AI analytics can surface post-termination pay before the next cycle clears again. Request a demo Related reading Article On Payroll. Nowhere in the Building. Article 8 Vendor Master Analytics Every Company Should Run Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/personal-expenses Personal Shopping. Business Expense Code. | foretale.ai ← Resources foretale.ai Learn More Home Resources Personal Expenses Article Personal Shopping. Business Expense Code. Seven analytics that catch shopping, lifestyle, and home-city spend submitted as business. Published 28 Jul 2026 · Updated 28 Jul 2026 Who should read this? Intended for: Finance Controllers T&E / Card Program Owners People Managers Internal Auditors Risk & Compliance Professionals The form said client dinner. The merchant said retail. What looked normal Receipt attached. Category selected. Manager approved. On the report, it was a business meal—or travel, or “misc.” On the card feed, it was a home-city store, a weekend lifestyle merchant, or a recurring personal brand. That is the personal-expense problem: company money, private spend —hidden behind a clean code. Why people should care Personal spend is one of the most common T&E leaks—and one of the easiest to normalize. Policy engines catch missing receipts and over-limit meals. They rarely ask whether the merchant, timing, or city matches a real business trip. Sampling misses the pattern. Peers and history do not. Seven analytics that catch personal spend These tests use expense claims, card feeds, merchant categories, travel calendars, and peer baselines— data most T&E and card programs already hold. Lifestyle and retail merchants coded as business Flag grocery, apparel, electronics, streaming, and similar merchants on T&E or card. Business impact: Surfaces the most common “personal as business” pattern. Home-city spend while claimed as travel Compare merchant city to employee home location and approved trip destinations. Business impact: Catches local lifestyle spend dressed as out-of-town travel. Weekend or holiday spend without a trip Entertainment and dining on non-work days when no travel itinerary exists. Business impact: Prioritizes timing that rarely matches real client work. Recurring same-merchant personal patterns Same gym, grocery, or lifestyle merchant repeating across months on company spend. Business impact: Exposes subscriptions and habits, not one-off mistakes. Peer outliers for the same role Spend far above role, grade, and cost-centre peers at the same merchants or categories. Business impact: Finds lifestyle outliers without reviewing every receipt. Card paid—then reimbursed as out-of-pocket Match corporate-card cleared spend to later expense claims for the same merchant or amount. Business impact: Stops personal (and business) spend from being paid twice. Description vs merchant mismatch Claim text says client / travel; merchant category says retail or personal services. Business impact: Flags the “story on the form” against the store on the feed. Why expense reviews miss this Traditional Receipts and limits Is a receipt attached? Under the meal cap? Approved? The form can look perfect. What risk needs Merchant + behavior joins Merchant type, home city, trip calendar, peers, and card vs claim— across every transaction, not a sample. Key takeaway Personal expenses rarely fail the form. They fail the join between what was claimed and where the money actually went. How foretale.ai helps foretale.ai runs personal-expense risk analytics across T&E and card data— lifestyle merchants, home-city mismatches, weekend outliers, recurring personal patterns, peer comparisons, and card-vs-claim double dips—with explainable evidence for every finding. Controllers and auditors review prioritized personal-spend risks across 100% of claims—not a receipt sample. How much “business” spend is personal? Most companies don’t know—until they join merchant, timing, and peer behavior to every claim. Continuous AI analytics can surface personal expenses before they become accepted practice. Request a demo Related reading Article Stop Looking at Expense Reports. Start Looking at Expense Behavior. Article 10 P-Card Analytics Every Organization Should Run Article Duplicate Payment Detection Needs 15+ Analytics © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/three-way-match What AP Actually Paid. | foretale.ai ← Resources foretale.ai Learn More Home Resources Three-Way Match Article What AP Actually Paid. You ordered 100 units. Warehouse received 40. AP paid for 100. Seven analytics that catch the gap. Published 29 Jul 2026 · Updated 29 Jul 2026 Who should read this? Intended for: AP / Procure-to-Pay Leaders Finance Controllers Procurement Operations Internal Auditors Risk & Compliance Professionals The invoice matched the PO. You paid for 60 that never arrived. What looked normal Purchase order approved. Invoice in tolerance. Payment run cleared. On paper, three-way match worked—or close enough. In the warehouse, quantity was short, timing was wrong, or the goods receipt never existed. That is the three-way match problem: AP pays on two documents while the third is missing, inflated, or delayed . Why people should care Three-way match is the control most companies say they run—and the one leakage most often slips through. ERP tolerances, two-way shortcuts, and “pay first, resolve later” exceptions quietly turn match into a rubber stamp. Sampling a few invoices finds the obvious. Population analytics find the pattern: chronic short receipts, price creep, and invoices that never meet a goods movement. Seven analytics that catch three-way match gaps These tests join purchase orders, goods receipts (or service entries), and vendor invoices— data most ERP and AP systems already hold. Invoice with no goods receipt Flag invoices posted or paid against a PO with no GR / service entry for the line. Business impact: Stops payment when nothing was received. Invoice quantity above received quantity Compare billed quantity to cumulative GR quantity by PO line—beyond tolerance. Business impact: Catches overbilling on short or partial deliveries. Invoice price above PO price Unit price or extended amount exceeds PO (and tolerance) without an approved change order. Business impact: Surfaces price creep that two-document reviews miss. Full invoice paid on partial receipt Payment cleared at 100% while GR remains open or partial on the same PO lines. Business impact: Finds “pay in full, receive later” leakage. Goods receipt after invoice payment GR posted after the invoice was paid—or backdated to look like a match. Business impact: Flags match repaired after cash left the company. Duplicate invoice against the same PO / GR Same vendor, amount, or reference billed more than once to one PO or receipt. Business impact: Blocks double pay dressed as a clean match. Chronic match exceptions by vendor Vendors with repeated quantity, price, or missing-GR exceptions versus peer baselines. Business impact: Prioritizes suppliers where “exceptions” are the operating model. Why AP reviews miss this Traditional Tolerance and workflow Is the invoice in tolerance? Was someone approved? Two documents can look fine while the receipt is thin. What risk needs PO + GR + invoice joins Quantity, price, timing, and open receipts— across every line, not a sample of exceptions. Key takeaway The paperwork can look easy. The arithmetic is the risk: ordered vs received vs paid. How foretale.ai helps foretale.ai runs three-way match analytics across PO, goods receipt, and invoice data— missing receipts, quantity and price overbills, full pay on partial GR, post-payment receipts, duplicate invoice-to-PO links, and chronic vendor exceptions—with explainable evidence for every finding. Controllers and auditors review prioritized match breaks across 100% of AP lines—not a tolerance sample. How often does “matched” still mean overpaid? Most companies don’t know—until they join PO, GR, and invoice at line level. Continuous AI analytics can surface three-way match gaps before the next payment run. Request a demo Related reading Article Duplicate Payment Detection Needs 15+ Analytics Article 8 Vendor Master Analytics Every Company Should Run Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/unusual-invoice-volume Same Vendor. Too Many Invoices. | foretale.ai ← Resources foretale.ai Learn More Home Resources Unusual Invoice Volume Article Same Vendor. Too Many Invoices. Peer vendors send about 4 invoices a month. This one sent 47. Seven checks that catch unusual invoice volume. Published 6 Aug 2026 · Updated 6 Aug 2026 Who should read this? Intended for: AP / Procure-to-Pay Leaders Finance Controllers Internal Auditors Procurement Operations Risk & Compliance Professionals Each invoice looked fine. The count did not. What looked normal Invoices were approved. Amounts looked small. Payment runs cleared. On paper, AP worked. Then someone counted the bills: 01 Peer vendors — 4 invoices / month 02 This vendor — 47 invoices / month 03 Many amounts — just under the approval limit One bill can look clean. Too many bills from one vendor is the risk. Why people should care High invoice count is often how limits get avoided—or how noise hides bad bills. Teams review amount and approval. They rarely ask: is this vendor sending far more invoices than before, or far more than peers? That gap is where invoice splitting, duplicate-style billing, and rush submissions hide. Seven checks that catch unusual invoice volume These tests count invoices by vendor over time and compare to history and peers— data most AP systems already hold. Spike vs the vendor’s own history Invoice count this month much higher than the same vendor’s past months. Business impact: Finds sudden volume jumps on known suppliers. Much higher count than peer vendors Compare invoice count to vendors in the same category, plant, or spend type. Business impact: Spots outliers that “normal” vendors do not show. Many invoices just under the approval limit Lots of bills clustered just below the amount that needs extra approval. Business impact: Surfaces possible invoice splitting. Many invoices on the same day A burst of invoices from one vendor on one day or in a short window. Business impact: Flags dump-and-clear submission patterns. High count, low average amount Very many small invoices that add up to large spend. Business impact: Finds volume used to stay under controls. Same PO, many invoices One purchase order billed with an unusual number of invoices. Business impact: Catches over-billing dressed as many small bills. Quiet period, then a spike Little or no billing for a while, then a sudden flood of invoices. Business impact: Prioritizes dormant vendors that suddenly get busy. Why reviews miss this Traditional One invoice at a time Is the amount right? Was it approved? Each bill can pass while the count is wrong. What risk needs Count across time How many invoices, vs history, vs peers, and how often they sit under the limit. Key takeaway A single invoice can look clean. The count is what bites. How foretale.ai helps foretale.ai checks invoice volume by vendor against history and peers— spikes, under-limit clusters, same-day bursts, high-count low-amount patterns, many invoices on one PO, and quiet-then-spike behavior—with clear evidence for every finding. AP and audit teams review the noisiest vendors first—not one invoice at a time. Which vendors send far more invoices than they should? Most companies do not know—until they count bills by vendor over time. Continuous AI checks can surface unusual volume before the next payment run. Request a demo Related reading Article Duplicate Payment Detection Needs 15+ Analytics Article What AP Actually Paid. Article New Vendor. Big First Payment. Then Nothing. © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/vendor-master-analytics 8 Vendor Master Analytics Every Company Should Run | foretale.ai ← Resources foretale.ai Learn More Home Resources Vendor Master Analytics Article 8 Vendor Master Analytics Every Company Should Run How AI finds duplicate suppliers, shared bank accounts, and master-data gaps before they become payment leakage. Published 23 Jul 2026 · Updated 23 Jul 2026 Who should read this? Intended for: Accounts Payable Managers Finance Controllers Procurement Leaders Internal Auditors Risk & Compliance Professionals Payment risk often starts in the vendor master. Clean payments cannot fix dirty supplier data. Payment controls start with the vendor master Duplicate payments get attention. The setup that enables them—duplicate vendors, shared bank accounts, incomplete records—often does not. Most teams review new-vendor forms and periodic master cleanses. Few continuously test vendor data against payment activity. Eight vendor master analytics to run These tests use vendor master fields plus payment history— data most ERPs already hold. Duplicate and near-duplicate vendors Match vendors on name, tax ID, address, or phone—exact and fuzzy. Business impact: Same supplier paid twice under different IDs. Shared bank accounts across vendors Find the same bank account or IBAN linked to multiple vendor IDs. Business impact: Classic shell-vendor and diversion indicator. Incomplete vendor master records Flag active vendors missing tax ID, bank details, or a complete address. Business impact: Weak onboarding and higher payment error risk. Vendors paid shortly after creation Compare vendor create date to first payment date; short gaps deserve review. Business impact: Surfaces rushed onboarding before controls catch up. Dormant vendors suddenly paid Identify vendors with long inactivity that restart with new payments. Business impact: Catches unexpected reactivation in the supplier base. One-time vendors with high spend Find vendors with a single invoice or payment at a high amount. Business impact: Prioritizes one-off suppliers that bypass normal scrutiny. Inactive or blocked vendors still paid Match payment activity to vendors marked inactive, blocked, or deleted. Business impact: Control bypass in status and payment processing. Conflicting tax IDs across vendor records Same tax ID on multiple vendor names—or one vendor with conflicting IDs. Business impact: Master-data conflict that enables duplicate or diverted pay. Why traditional reviews miss these issues Master cleanses and approval checklists look at records in isolation. Risk appears when vendor data is joined to payment history over time. Traditional Forms and periodic cleanses New-vendor approval and occasional duplicate name searches. Useful—incomplete. What risk needs Master + payment joins Bank accounts, tax IDs, create dates, status, and payment timing— tested continuously across the full supplier base. Key takeaway Duplicate payment detection starts upstream. Continuous vendor master analytics stop leakage before the remittance runs. How foretale.ai helps foretale.ai runs vendor master risk analytics across your enterprise data— duplicate suppliers, shared bank accounts, incomplete records, create-to-pay gaps, dormant reactivation, and conflicting identifiers—with explainable evidence for every finding. AP and audit teams review prioritized master risks across 100% of vendors, not a periodic cleanse sample. Clean the master before the payment What vendor master risks are sitting in your supplier file today? Continuous AI analytics can surface duplicate vendors, shared bank accounts, and control gaps before they become payment leakage. Request a demo Related reading Article New Vendor. Big First Payment. Then Nothing. Article What AP Actually Paid. Article Duplicate Payment Detection Needs 15+ Analytics © HEXANGO · Resources · Home --- ## https://www.hexango.com/resources/vendor-relationship-networks Vendor Relationship Networks. | foretale.ai ← Resources foretale.ai Learn More Home Resources Vendor Relationship Networks Article Vendor Relationship Networks. Two vendors never share a bank account, tax ID, or phone—yet they always bid together. Build a graph instead of rule-based analytics. Published 29 Jul 2026 · Updated 29 Jul 2026 Who should read this? Intended for: Procurement Leaders Finance Controllers Internal Auditors Compliance & Investigation Teams Risk Professionals Exact-match rules see clean vendors. The network is what connects them. What looked clean Two suppliers. Separate legal entities. Different bank accounts, tax IDs, and phone numbers. Every exact-match duplicate rule passes. Then you look at how they behave together: they always bid on the same tenders, rotate who wins, share directors and postal addresses, and submit quotations minutes apart. That is not two competitors. That is one economic circle with two badges— and rule-based analytics never draw the edge between them. Never share. Yet they… Never share What rules check Bank account Tax ID Phone Yet they What the network shows Always bid together Alternate winning tenders Share directors Share postal addresses Submit quotations within minutes Why people should care Sophisticated collusion avoids the fields your duplicate rules scan. Shared bank accounts and identical tax IDs are still high-value signals— but many rings deliberately keep those clean. What they cannot hide as easily is relationship structure : co-bidding, win rotation, people, addresses, and bid timing. If your analytics only fire on exact equals, those rings stay invisible. Five relationship edges a graph catches Treat vendors (and related people or addresses) as nodes. Treat shared behaviour and attributes as edges. Dense clusters—especially with bid-rotation patterns—are the investigation queue. Always bid together Vendors that co-appear on the same tenders far more often than chance or category peers. Business impact: Surfaces pairs that move as a pack, not as independent competitors. Alternate winning tenders Win/loss sequences that rotate between the same small set of suppliers over time. Business impact: Flags managed competition that keeps prices high while looking fair. Share directors / beneficial owners Link vendor master and registry data where people sit on more than one “independent” bidder. Business impact: Proves common control even when bank and tax IDs differ. Share postal addresses Same building, suite, or normalized address across supposedly unrelated suppliers. Business impact: Connects entities that never share payment identifiers. Quotations within minutes Near-simultaneous bid submissions—or near-identical file metadata—across “separate” vendors. Business impact: Exposes coordinated cover bidding that timing rules alone rarely catch. Why rule-based analytics miss this Traditional Exact-match rules Same bank? Same tax ID? Same phone? If not, the vendors look independent. What risk needs Relationship graphs Co-bidding, rotation, people, places, and timing— edges across tenders and master data, not one field at a time. Key takeaway Clean identifiers do not mean independent suppliers. Build a graph instead of rule-based analytics. How foretale.ai helps foretale.ai builds vendor relationship networks across tender history, awards, vendor master, and related attributes—co-bidding, win rotation, shared people and addresses, and bid-timing clusters—with explainable evidence for every edge and community. Procurement and audit teams investigate dense clusters—not a spreadsheet of exact-match duplicates. How many “independent” bidders are actually one network? Most companies don’t know—until they stop checking fields in isolation and start mapping relationships. Continuous AI analytics can surface vendor networks before the next award. Request a demo Related reading Article Three Suppliers. One Bank Account. The Bid Was Never Competitive. Article 8 Vendor Master Analytics Every Company Should Run Tale Three Vendors. Shared Identity. © HEXANGO · Resources · Home --- ## https://www.hexango.com/tales/four-steps Four Steps. From Data to Dollars. — A foretale.ai Story ← Home foretale.ai Demo foretale.ai Four steps. From data to dollars. How easy it is to get started. The promise Risk analytics without the project. 1 Connect 2 Objective 3 Analyze 4 Review Experts stay in control. The heavy lifting is autonomous. Step 1 1 Connect your data. ERP Finance HR Procurement Payments More Point foretale.ai at the systems you already run. Step 2 2 Set the risk objective. Find duplicate payments, shared vendor identity, and ghost employees in the last 24 months. Say what you care about—in plain language. Step 3 3 foretale.ai runs the analytics. Understand Plan Execute Autonomous. Continuous. Across the full dataset. Step 4 A case for human review. CASE-0912 · High Duplicate payment cluster — Vendor VX-2201 Same invoice pattern across two payment runs. Evidence and lineage attached. Assigned · AP Controls People judge. The platform prepares the case. The result Money back. Leakage stopped. Recover what already leaked Stop what would leak next Savings you can explain to finance and audit. foretale.ai Connect. Ask. Recover. Request a demo Play again Click or → to continue --- ## https://www.hexango.com/tales Redirecting… — HEXANGO | foretale.ai This section has been removed. Return home . --- ## https://www.hexango.com/tales/shared-identity Three Vendors. Shared Identity. — A foretale.ai Story ← Home foretale.ai Demo foretale.ai Three vendors. Shared identity. A procurement collusion walkthrough. Tender outcome Three suppliers bid. VX-8841 Awarded VX-1192 Runner-up VX-4408 Third On the surface, competition looks intact. Risk question Do these three vendors share identity details in our ERP? One question. Full table coverage. Understand ERP tables linked. ERP Vendor LFA1 PO / Bid EKKO Bank LFBK Invoice RBKP Payment REGUH Vendor master → bank → bids → invoices → payments. Shared identity checks More than the bank. Bank / IBAN LFBK Tax ID / VAT LFA1 Address LFA1 Phone / email LFA1 Contact person LFA1 Win rotation EKKO Any shared field can expose related parties. High-risk entity VX-8841 Priority VX-8841 surfaces. Shared bank, tax ID, and contact across bidders. Network graph One economic party. VX-8841 VX-1192 VX-4408 Bank LFBK · Tax ID Buyer Same bank details, tax ID, and buyer affinity. Case management Assigned for investigation. CASE-0481 · High Suspected vendor collusion — VX-8841 Shared bank / IBAN, tax ID & address with VX-1192 and VX-4408 (LFBK, LFA1) . Priya Mehta · Investigations Close Assessment closed. $550K in recovery Evidence retained with full ERP lineage. foretale.ai From question to closed case. Request a demo Play again Click or → to continue --- ## https://www.hexango.com/trust-center/access-control ← Trust Center Access Control Policy Identity, authentication, and authorization Last updated June 20, 2026 This policy defines how access to foretale.ai systems and customer data is granted, managed, and revoked. Identity management Customer users authenticate through Amazon Cognito with email-based accounts. Password policies enforce minimum complexity requirements. Organization administrators manage user provisioning within their tenant. Authentication API and WebSocket endpoints require valid JWT tokens issued by Cognito. Tokens are verified against Cognito JWKS with audience and expiry checks on sensitive services. Session tokens are short-lived; refresh follows Cognito defaults. Internal service-to-service calls use separate authenticated channels. Failed authentication attempts are logged and monitored. Authorization Access to project data is enforced at the application layer through stored procedures and project-scoped authorization checks. Users may only access projects explicitly assigned to their account within their organization. Least privilege Internal engineering access to production is granted on a need-to-know basis, time-limited where possible, and requires approval. Production database access is restricted and audited. Access reviews and offboarding Customer administrators are responsible for timely deprovisioning of users. Internal access is reviewed periodically and revoked upon role change or employment termination. --- ## https://www.hexango.com/trust-center/ai-transparency ← Trust Center AI Transparency Statement How AI is used in foretale.ai Last updated June 20, 2026 We believe customers should understand when and how AI is used. This statement describes our AI capabilities, data handling, and limitations. Where AI is used foretale.ai uses AI to assist with document analysis, risk and compliance workflows, natural language queries over authorized data, summarization, and test recommendations. Model providers Primary inference runs on Amazon Bedrock with organization-configurable models. We do not use customer content to train third-party foundation models. Optional observability tooling (e.g., LangSmith) may process prompts and outputs when explicitly enabled. Data used by AI features AI features access only data authorized for the authenticated user and project. Context is scoped per session and organization. Attachments and query results are processed transiently and stored according to project retention settings. Safety and guardrails Amazon Bedrock Guardrails and application controls filter harmful content and constrain off-topic responses. Rate limits protect against abuse. Known limitations AI outputs may be incomplete, outdated, or incorrect. They should not be treated as legal, audit, or regulatory advice. Users must verify outputs against source records and apply professional judgment. Models may hallucinate facts not present in source data. Complex regulatory interpretations require expert human review. AI does not replace formal audit procedures or sign-off requirements. Contact Questions about AI use in foretale.ai: contact@hexango.com. --- ## https://www.hexango.com/trust-center/architecture ← Trust Center AWS Architecture How foretale.ai is built on Amazon Web Services Last updated June 20, 2026 foretale.ai runs on AWS in us-east-1. Customer data is isolated per organization with dedicated configuration, storage prefixes, and database authorization. The diagram below shows major components and trust boundaries — not every internal service. Amazon Cognito API / WebSocket Amazon Bedrock AWS Lambda / ECS RDS · DynamoDB · S3 AWS Secrets Manager TRUST BOUNDARIES Identity — Amazon Cognito authenticates users; JWT tokens authorize API and WebSocket access. Control plane — PostgreSQL central database and DynamoDB hold organization configuration — not customer analytics datasets. Data plane — SQL Server stores project analytics data; S3 stores files; access is project-scoped. Secrets — AWS Secrets Manager holds database and service credentials — never embedded in application code. --- ## https://www.hexango.com/trust-center/cookie-policy ← Trust Center Cookie Policy How we use cookies and similar technologies Last updated June 20, 2026 This Cookie Policy explains how HEXANGO PRIVATE LIMITED uses cookies, local storage, and similar browser technologies when you visit https://www.hexango.com, access foretale.ai at https://www.foretale.ai or https://www.foretale.net, or use related services. What are cookies and similar technologies Cookies are small text files stored on your device when you visit a website. We also use similar technologies such as local storage, session storage, and IndexedDB to keep the application working, maintain your sign-in session, and remember preferences. Where this policy applies This policy covers: foretale.ai web application (https://www.foretale.ai and https://www.foretale.net). https://www.hexango.com marketing website and Trust Center. Embedded content such as Amazon QuickSight dashboards when enabled for your organization. Essential cookies and storage These are required for the service to function. Without them, you cannot sign in or use core features. Authentication tokens and session identifiers managed through Amazon Cognito. Security and CSRF-related storage needed to protect your account. Load balancing and routing cookies from our hosting infrastructure. Session continuity for AI assistant and workflow features within foretale.ai. Functional cookies and storage These remember choices you make to provide a smoother experience. They are not strictly required but improve usability. UI preferences and layout settings within the application. Language or display preferences where supported. Draft form state to prevent loss of work during a session. Analytics and performance We use limited analytics to understand how the marketing website and platform perform and to improve reliability. Analytics data is aggregated and does not include customer project content. We do not use cookies for cross-site advertising. Google Analytics 4 on https://www.hexango.com — page views, traffic source/medium, and campaign parameters (UTMs). IP anonymization is enabled for Analytics on the marketing site. Third-party cookies Some features rely on subprocessors that may set their own cookies or use browser storage when you use those features: Amazon Web Services / Amazon Cognito — authentication and identity. Google Analytics 4 — marketing website usage measurement on https://www.hexango.com. Google Firebase — demo request, pricing quote, and brochure forms on https://www.hexango.com (if submitted). Amazon QuickSight — embedded analytics dashboards (when enabled). What we do not use We do not currently use cookies for: Targeted advertising or ad retargeting. Social media tracking pixels. Selling personal data collected through cookies. Managing cookies Most browsers let you block or delete cookies through settings. Blocking essential cookies may prevent you from signing in or using foretale.ai. To clear application data, use your browser's site data or storage controls for foretale.ai or foretale.net. Updates and contact We may update this Cookie Policy from time to time. Material changes will be posted on this page with an updated date. For questions, contact contact@hexango.com. See also our Privacy Policy at https://www.hexango.com/privacy-policy. --- ## https://www.hexango.com/trust-center/data-retention ← Trust Center Data Retention Policy How long we retain data and how it is deleted Last updated June 20, 2026 This policy describes retention periods and deletion practices for data processed through foretale.ai. General principles We retain data only as long as necessary to provide the service, meet legal obligations, resolve disputes, and enforce agreements. When data is no longer needed, it is deleted or anonymized where feasible. Customer content Project data, uploaded files, and analytics artifacts remain available for the duration of the customer subscription and are deleted or returned upon contract termination per the data processing agreement, subject to legal hold. Account and identity data User profile and authentication records are retained while the account is active. Upon account deletion request, personal identifiers are removed within 30 days unless retention is required by law. Logs and telemetry Security and application logs are typically retained for 90–365 days depending on log type and regulatory requirements. Aggregated, anonymized analytics may be retained longer for service improvement. AI conversation history AI assistant conversations may be stored to support continuity, audit, and quality review within the customer organization. Retention aligns with project settings and organizational policies. Deletion requests Customers may request deletion through their organization administrator or via our data subject request process linked from the Privacy Policy. --- ## https://www.hexango.com/trust-center/incident-response ← Trust Center Incident Response Plan Detecting, containing, and recovering from security incidents Last updated June 20, 2026 This plan outlines how HEXANGO PRIVATE LIMITED responds to security incidents affecting foretale.ai or customer data. Objectives Minimize impact to customers, preserve evidence, restore services promptly, and meet applicable legal and contractual notification obligations. Incident classification Incidents are classified by severity to determine response urgency. Critical: Confirmed unauthorized access to customer data or production systems. High: Active exploitation attempt, service-wide outage with security impact. Medium: Suspected vulnerability with plausible exploit path. Low: Policy violations, phishing attempts, or non-exploitable findings. Response phases Our response follows industry-standard phases: Detection & analysis — Triage alerts, logs, and reports; assign incident lead. Containment — Isolate affected systems; revoke compromised credentials. Eradication — Remove threat; patch vulnerabilities; rotate secrets. Recovery — Restore services; validate integrity; resume normal operations. Post-incident — Root cause analysis, customer notification if required, lessons learned. Communication Affected customers are notified without undue delay when their data is reasonably believed to be compromised, in accordance with applicable law and contractual commitments. Status updates are provided through designated customer contacts. Reporting security issues External researchers and customers may report vulnerabilities or incidents to contact@hexango.com. See our Vulnerability Disclosure page for coordinated disclosure guidelines. --- ## https://www.hexango.com/trust-center ← Home Trust Center foretale.ai by HEXANGO PRIVATE LIMITED Last updated June 20, 2026 Security, privacy, and responsible AI at Hexango This Trust Center provides transparency into how we build, secure, and operate foretale.ai. These documents are maintained for customers, partners, and security researchers. Share this page in your vendor assessments and compliance reviews. Security contact Report vulnerabilities or incidents to contact@hexango.com . Policies & documentation Responsible AI Policy Governance, oversight, and safety for AI features. Information Security Policy How we protect confidentiality, integrity, and availability. Access Control Policy Authentication, authorization, and least privilege. Incident Response Plan Detection, containment, recovery, and notification. Data Retention Policy Retention periods and secure deletion practices. Privacy Policy How we collect, use, and protect personal information. Terms of Use Terms governing access to foretale.ai and acceptable use. Cookie Policy How we use cookies and similar browser technologies. AI Transparency Statement Where AI is used, data handling, and known limitations. Vulnerability Disclosure Coordinated disclosure and security research guidelines. AWS Architecture Infrastructure overview and trust boundaries. Public document URLs https://www.hexango.com/trust-center/responsible-ai https://www.hexango.com/trust-center/information-security https://www.hexango.com/trust-center/access-control https://www.hexango.com/trust-center/incident-response https://www.hexango.com/trust-center/data-retention https://www.hexango.com/trust-center/terms-of-use https://www.hexango.com/trust-center/cookie-policy https://www.hexango.com/trust-center/ai-transparency https://www.hexango.com/trust-center/vulnerability-disclosure https://www.hexango.com/trust-center/architecture https://www.hexango.com/privacy-policy --- ## https://www.hexango.com/trust-center/information-security ← Trust Center Information Security Policy Protecting customer and company information Last updated June 20, 2026 HEXANGO PRIVATE LIMITED maintains an information security program aligned with industry best practices to protect the confidentiality, integrity, and availability of data processed through foretale.ai. Security governance Executive leadership assigns ownership for information security. Policies are reviewed annually. Risk assessments inform control selection and prioritization. Infrastructure security foretale.ai is hosted on Amazon Web Services (AWS) in us-east-1. Production workloads run in isolated tenant configurations with organization-scoped storage, database access, and configuration. Compute: AWS Lambda and Amazon ECS on Fargate for serverless and container workloads. Data stores: Amazon RDS (PostgreSQL, SQL Server), Amazon DynamoDB, Amazon S3, and Redis. Identity: Amazon Cognito for user authentication and JWT-based API authorization. Secrets: AWS Secrets Manager for credentials; no secrets in source code or images. Encryption Data is encrypted in transit using TLS 1.2+. Database connections use encrypted channels. Customer files are stored in private S3 buckets with presigned URL access and short-lived credentials. Monitoring and logging We maintain audit logs for authentication events, administrative actions, and critical application operations. Logs are retained per our Data Retention Policy and reviewed for security anomalies. Vendor and subprocessors Third-party providers with access to customer data are evaluated for security posture and bound by contractual obligations. Primary infrastructure subprocessors include Amazon Web Services. AI inference may use Amazon Bedrock; optional tracing may use LangSmith when enabled. Employee access Access to production systems follows least-privilege principles and is limited to personnel with a documented business need. See our Access Control Policy. --- ## https://www.hexango.com/trust-center/responsible-ai ← Trust Center Responsible AI Policy Governance for AI-powered features in foretale.ai Last updated June 20, 2026 Hexango is committed to developing and deploying artificial intelligence responsibly. This policy describes how we design, evaluate, and operate AI capabilities within foretale.ai to support risk and compliance professionals. Purpose and scope This policy applies to all AI-powered features in foretale.ai, including conversational agents, document summarization, analytics assistance, and automated workflow recommendations. It covers internal development practices and customer-facing AI behavior. Human oversight AI outputs are designed to assist professional judgment, not replace it. Users retain responsibility for decisions made using platform outputs. High-impact recommendations require human review before action in production workflows. Users can inspect AI reasoning steps and source references where available. Automated actions that modify customer data require explicit user authorization. Escalation paths to human support are available for disputed or uncertain outputs. Fairness and bias mitigation We evaluate models and prompts for disparate impact across common use cases. Training and inference data is scoped to customer-authorized content and platform metadata — we do not use customer data to train foundation models. Prompt and guardrail reviews before production deployment. Monitoring for anomalous or harmful output patterns. Regular evaluation against representative compliance and risk scenarios. Safety controls We use Amazon Bedrock Guardrails and application-level controls to reduce harmful, off-topic, or non-compliant outputs. Rate limiting and context budgets protect system stability and data exposure. Transparency and accountability We document model providers, primary use cases, and known limitations. See our AI Transparency Statement for customer-facing disclosures. Questions about this policy: contact@hexango.com. Continuous improvement We review this policy at least annually and after material changes to AI capabilities. Feedback from customers and internal audits informs updates. --- ## https://www.hexango.com/trust-center/terms-of-use ← Trust Center Terms of Use Terms governing access to foretale.ai Last updated June 20, 2026 These Terms of Use govern your organization's access to and use of foretale.ai, provided by HEXANGO PRIVATE LIMITED. By creating an account or using the service, you agree to these terms on behalf of your organization. Acceptance By accessing foretale.ai at https://www.foretale.ai or https://www.foretale.net, you represent that you have authority to bind your organization and accept these Terms of Use, our Privacy Policy, and applicable order forms or subscription agreements. Service description foretale.ai is a software-as-a-service platform for risk and compliance analytics, including AI-assisted workflows, document analysis, and reporting. The application is available at https://www.foretale.ai and https://www.foretale.net. Features may change over time as we improve the product. Accounts and eligibility You must provide accurate registration information and maintain the security of account credentials. You are responsible for activity under your organization's accounts. The service is intended for business use by authorized professionals. Organization administrators control user provisioning within their tenant. You must promptly notify us of unauthorized access at contact@hexango.com. You may not share credentials or circumvent access controls. Acceptable use You agree not to: Use the service in violation of applicable law or regulation. Upload unlawful content or data you are not authorized to process. Attempt to probe, scan, or test the vulnerability of systems without authorization. Reverse engineer, decompile, or extract source code except where permitted by law. Interfere with service availability or other customers' use of the platform. Use AI outputs as a substitute for required professional judgment or regulatory sign-off. Customer data and license You retain ownership of data you submit to foretale.ai. You grant HEXANGO PRIVATE LIMITED a limited license to host, process, and display customer data solely to provide and improve the service, as described in the Privacy Policy and any data processing agreement. Intellectual property HEXANGO PRIVATE LIMITED owns the platform, software, documentation, and branding. No rights are granted except as expressly stated in these terms and your subscription agreement. Confidentiality and security We implement safeguards described in our Trust Center, including our Information Security Policy and Access Control Policy. You are responsible for configuring access within your organization and classifying data appropriately before upload. Disclaimers The service is provided "as is" to the extent permitted by law. foretale.ai assists professional workflows but does not provide legal, audit, or regulatory advice. AI-generated outputs may be incomplete or incorrect and require human verification. Limitation of liability To the maximum extent permitted by law, HEXANGO PRIVATE LIMITED is not liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, data, or business opportunity. Direct liability is limited to fees paid for the service in the twelve months preceding the claim, unless otherwise required by applicable law or agreed in writing. Suspension and termination We may suspend or terminate access for material breach, security risk, or non-payment under applicable agreements. Upon termination, you may request export of customer data subject to our Data Retention Policy and contractual terms. Changes We may update these Terms of Use from time to time. Material changes will be posted on this page with an updated date. Continued use after changes take effect constitutes acceptance where permitted by law. Governing law and contact These terms are governed by the laws of India, without regard to conflict-of-law principles, unless otherwise specified in your subscription agreement. Questions: contact@hexango.com. --- ## https://www.hexango.com/trust-center/vulnerability-disclosure ← Trust Center Vulnerability Disclosure Coordinated disclosure and security research Last updated June 20, 2026 We welcome good-faith security research and responsible disclosure. This page describes how to report vulnerabilities in foretale.ai and what you can expect from us. Scope In scope for reporting: foretale.ai web application (app and authenticated areas). Public API endpoints at gateway.foretale.net and api.foretale.net. Authentication flows managed by Amazon Cognito for foretale.ai. Out of scope The following are generally out of scope: Social engineering, phishing, or physical attacks. Denial-of-service or load testing without prior written approval. Issues in third-party services outside our control. Findings from automated scanners without demonstrated impact. Missing security headers or cookies without exploitable impact. How to report Email contact@hexango.com with a detailed description, steps to reproduce, potential impact, and any proof-of-concept. Encrypt sensitive details if needed — request our PGP key in your initial message. Safe harbor We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access data belonging to others, and give us reasonable time to remediate before public disclosure. Our commitment Upon receiving a valid report, we aim to: Acknowledge receipt within 3 business days. Provide an initial assessment within 10 business days. Keep you informed of remediation progress. Credit researchers upon request after fix deployment (unless you prefer anonymity). Security contact For vulnerabilities, incidents, or security questions: contact@hexango.com ---