Live demo
19,800 transactions. Which 149 would you open?
One quarter of invoices and expenses, $215,593,342 across 16 vendors and cost centres. Splitting under the $5,000 approval limit was injected into two of them. Every test below runs in your browser on the actual amounts, and nothing here is a claim about anybody’s intent.
Step one, the part that has to be true first
The book as a whole follows Benford
Real spend spans orders of magnitude, and when it does its leading digits land on log10(1 + 1/d). About 30% of amounts start with a 1 and under 5% start with a 9. If this did not hold on the clean data, flagging anything for violating it would prove nothing.
30.5% of amounts start with a 1 against an expected 30.1%. Nigrini’s MAD bands put anything under 0.006 in the close-conformity range, and this sits at 0.0012.
Step two
Two units do not, and the worse-looking one is innocent
Same test, one unit at a time. The largest digit deviation in the whole book belongs to a vendor that has done nothing at all, and the vendor that was actually splitting purchases barely registers. That is the honest shape of this signal and it is why the digit test cannot be the whole product.
Fixed per-seat pricing across a narrow band of quantities. Amounts land in a bounded range instead of spanning orders of magnitude, so the leading digits cannot follow Benford and were never going to. The test is working correctly and the answer is still not evidence of anything.
This is the vendor with splitting injected into it, and the digit test can barely see it. The MAD sits inside Nigrini's acceptable band and the chi-square only just clears 0.05. Anyone reporting this as a finding on its own would be overselling it.
Step three, and the stronger signal
A pile below the limit and a hole above it
Nothing to do with digits. Someone splitting a $7,000 purchase to stay under a $5,000 approval limit leaves two invoices in the four thousands and none in the five thousands. Do it enough times and the shape of the spend around the boundary stops being smooth.
Run the same test on Meridian Facilities Group at every limit in the approval policy. Only one of them shows anything. A pattern that fires at every arbitrary boundary would be a property of the distribution, not of anyone’s behaviour.
Step four
Sixteen units, thirty-two tests, three survivors
Two tests on each of 16 units is 32 simultaneous tests. At an uncorrected 5% you expect false hits every single run, and a nightly product that hands back false hits every night gets switched off inside a month. Benjamini-Hochberg at 5.0% is what keeps the list worth reading.
| Unit | Lines | Digit p | Limit p | q after BH | Under limit | Outcome |
|---|---|---|---|---|---|---|
| Atlas Freight SystemsVendor | 1,400 | 0.5193 | 0.0330 | 0.2112 | $23,982 | Clear |
| Corvus Print & MailVendor | 900 | 0.9319 | 0.0896 | 0.4776 | — | Clear |
| Helio FacilitiesVendor | 1,100 | 0.4082 | 0.2008 | 0.7140 | — | Clear |
| Northgate LegalVendor | 700 | 0.1555 | 0.5637 | 0.6621 | $4,743 | Clear |
| Pinewood CateringVendor | 1,600 | 0.5486 | 0.7055 | 1.0000 | $4,770 | Clear |
| Quarry Road HardwareVendor | 1,200 | 0.0117 | 0.0495 | 0.0936 | — | Clear |
| Sable AnalyticsVendor | 800 | 0.8728 | 0.1655 | 0.6621 | — | Clear |
| Field OperationsCost centre | 2,100 | 0.5945 | 0.6219 | 1.0000 | $7,191 | Clear |
| MarketingCost centre | 1,500 | 0.5262 | 0.8527 | 1.0000 | — | Clear |
| R&D PrototypingCost centre | 1,300 | 0.4278 | 0.8348 | 1.0000 | $2,411 | Clear |
| FacilitiesCost centre | 1,000 | 0.2672 | 0.4669 | 0.8551 | $7,200 | Clear |
| TravelCost centre | 1,800 | 0.2973 | 0.7237 | 0.8648 | $4,819 | Clear |
| IT SupportCost centre | 950 | 0.4280 | 0.8185 | 1.0000 | $2,380 | Clear |
| Meridian Facilities GroupVendor | 1,250 | 0.0263 | 1.6e-11 | 2.5e-10 | $139,733 | Review |
| Regional BuildoutCost centre | 1,600 | 0.3186 | 4.8e-6 | 5.2e-5 | $86,085 | Review |
| Northwind LicensingVendor | 600 | 6.4e-13 | 0.1451 | 2.1e-11 | $26,388 | Review |
2 clean units in this run cleared an uncorrected 0.05 on one of the two tests: Atlas Freight Systems, Quarry Road Hardware. Nothing is wrong with any of them. That is what 5% means when you run 32 tests. Correction removed them and cost nothing real: the two units with splitting injected clear the corrected bar by three orders of magnitude and more.
Step five, the actual product
Review these, in this order
Ordered by dollars sitting under the limit, not by p-value. A unit flagged on digits alone carries no money and belongs at the bottom, whatever its p-value says. This is the whole output: 149 lines out of 19,800, ranked.
| INV-1113-0031 | 2026-06-03 | Emergency callout | $4,974.58 |
| INV-1113-0443 | 2026-06-13 | Fit-out labour | $4,972.11 |
| INV-1113-0162 | 2026-07-16 | Fit-out labour | $4,970.55 |
| INV-1113-0171 | 2026-07-10 | Building services | $4,967.66 |
| INV-1113-0073 | 2026-06-12 | Emergency callout | $4,966.64 |
| EXP-1114-0318 | 2026-07-15 | Temporary power | $4,968.81 |
| EXP-1114-1215 | 2026-07-03 | Contract labour | $4,967.46 |
| EXP-1114-0528 | 2026-06-02 | Site prep | $4,966.80 |
| EXP-1114-0253 | 2026-06-30 | Site prep | $4,960.53 |
| EXP-1114-0069 | 2026-07-23 | Temporary power | $4,955.13 |
Whether the price list explains the digit distribution. Fixed per-unit pricing across a narrow band of quantities produces exactly this shape and is entirely legitimate. If the contract matches, clear it and suppress the unit.
A Benford deviation is evidence of an anomaly and never evidence of fraud. Item 3 above is a real vendor with a fixed per-seat price list, which is why its digits look nothing like Benford and why its spend is perfectly smooth across the approval limit. It is on the list because the digit test cannot tell the difference, and it comes off the list in about thirty seconds once a human opens the contract. That is the division of labour this product is built around. Ledger ranks and prioritises. It does not decide that anything is wrong, and it does not accuse anyone.