1. Learn
  2. Align
  3. Perform
  4. Review

Review5 min read

Post Coverage Is a Protective Audit, Not a Finance Task

By J Damien Scott, Trusted Advisor

An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.

An unfilled post is an unprotected site

A contract security operation sells hours of presence at defined posts. The client's risk assessment justified the post, the post order defines what the officer does there, and the schedule commits a named, licensed, trained person to it. Every one of those links is a protective control. When a post goes unfilled, or is filled by someone unlicensed, or is filled for six hours and billed for eight, the site is less protected than the contract says and the client does not know.

Finance sees the same event as leakage: hours worked that were never billed, or hours billed that were never worked, or overtime paid that the contract will not recover. The two views are of one record. That is the argument of this article: the controls that stop money leaking are the controls that prove protection was delivered, and a security leader who leaves them to finance has given away the audit of their own program.

Every hour that leaked from the invoice was an hour a client paid for protection that nobody could prove was delivered.

What the numbers found

As Chief Operations Officer, with full-charge P&L ownership across 127 accounts, I reduced revenue leakage by 95%. The mechanism was five controls redesigned together: timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and a formal exception review, all under customer account governance. In the same period, overtime expense fell by 90% through restructured staffing models, schedule discipline, supervisor accountability, review of schedule exceptions, and a qualified relief bench.

The leakage was not fraud in the main. It was the accumulated effect of a schedule that lived in one system, a timekeeping record that lived in another, and an invoice built from a third, with nobody reconciling the three at the level of a single post on a single night. Reconciliation exposed the pattern immediately: posts filled from the relief bench and never re-entered against the right contract, call-offs covered by overtime that the contract capped, and a handful of posts where the schedule said covered and the timekeeping said nothing.

That last category is the one that matters for protection. A post where the schedule says covered and the timekeeping record says nothing is either a timekeeping failure or an absence. Until reconciliation forces the question, the program cannot tell which, and a program that cannot tell whether its posts were staffed cannot claim it protected the site.

Preventive controls and detective controls

The 2025 edition of the GAO's Standards for Internal Control, the Green Book, includes an appendix of examples of preventive and detective control activities and the sources of data that support them. The distinction is the right lens for a protective operation. A preventive control stops the unfilled post from happening: a staffing model with a relief bench, a licensing check at onboarding, a scheduling rule that will not assign an unlicensed officer to a regulated state. A detective control finds the unfilled post after the fact: the reconciliation of schedule against timekeeping against invoice.

Programs invest in preventive controls because they are visible and feel like management. They underinvest in detective controls because a detective control's product is bad news. The 95% figure came almost entirely from the detective side. The staffing model and the relief bench prevented recurrence, but the reconciliation is what revealed the scale of the problem, and without the revelation the prevention would have been sized wrong.

COSO's Internal Control Integrated Framework names monitoring as one of the five components of effective internal control, and issued separate guidance in 2009 on monitoring because organizations were treating it as an afterthought. Reconciliation is monitoring. It is the component that tells the other four whether they worked.

Exception review is the review loop

A reconciliation that only produces a corrected invoice has done half its job. The other half is the formal exception review: every mismatch between schedule, timekeeping, and contract is logged as an exception, classified by cause, and reviewed on a fixed cycle by the operations lead and the account owner together. The classification is what converts a billing correction into a protective finding. A run of exceptions at one site means the staffing model is wrong for that site. A run of exceptions from one supervisor means a training or accountability problem. A run of exceptions on one contract means the contract's post structure no longer matches the client's risk.

ISO 31000:2018 sets out monitoring, reviewing, and continually improving risk management as criteria for a functioning framework. Exception review is that criterion applied to the most granular unit a security operation has, one post on one shift. The Three Lines Model adds the question of who reviews the reviewer: the account owner who checks the operations lead's exception log is the second line, and the internal audit that samples the log is the third.

Licensing belongs in the same loop. Full licensing compliance across five regulated states came from onboarding controls, renewal tracking, supervisor verification, compliance reporting, and exception escalation, which is the same five-part structure as the leakage controls. An unlicensed officer on a post is both a regulatory exposure and an unprotected site, and the exception review catches it for the same reason it catches an unbilled hour.

The cycle matters as much as the content. A weekly exception review is short enough that the supervisor who worked the shift is still available to explain it, and long enough that a pattern across a week is visible. Monthly is too slow: by the time a run of exceptions at one site is noticed, the client has had four weeks of thinner coverage than the contract states, and the relief bench that would have fixed it has been assigned elsewhere. The review also needs a written disposition for every exception, even a one-word one, because an exception log with gaps is itself an exception, and an auditor will read it that way.

What the CFO and the CSO share

The chief financial officer wants the invoice to be right and the overtime to be recoverable. The chief security officer wants the post to be filled by the right person. They are looking at the same record, and in most organizations they have never compared notes on it. The security leader who claims the reconciliation as a protective audit gains two things: the evidence that the program delivered what the contract promised, and a seat in the conversation about margin that security is normally excluded from.

Review feeds Learn. The exception log is a map of where the operation's protective posture is weakest, drawn from its own records rather than from an assessment. The posts that keep appearing in it are the posts an adversary would find first. A protective program that reads its own billing exceptions as intelligence has understood what the Review phase is for.

GRC & OperationsPost coverage validationException reviewPreventive and detective controlsRevenue leakage

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles