Flominzo

Free resource

AI agent payment audit checklist. The evidence to prepare before an agent pays.

A free checklist of the evidence risk and compliance teams ask for before an AI agent can pay: agent register, mandates, controls, decisions and reconciliation.

Last updated:

Download the CSV checklist
On this page 5 sections

What this checklist is

A working list of the evidence a risk, compliance or audit team will ask for before an AI agent is allowed to move money, and after it has. Each row names an item, what to provide, the evidence that proves it, an owner and a status, so you can work through it together and hand over the result.

It is vendor-neutral. Use it with your own systems, a payment provider’s controls or Flominzo AgentPay. It opens in Excel, Google Sheets or Numbers.

Download the CSV checklist

What it covers

SectionWhat it asks for
Agent registerEach agent’s identity, owner, version history and the tools it can call.
MandatesScope, caps, payees, approvers, expiry and revocation, with every version kept.
EnforcementWhere the rules are checked, and proof the agent cannot change them.
Failure behaviourWhat happens when a check errors, times out or the mandate has expired.
DecisionsA sample of attempts with the rule that decided and the approver.
IdempotencyOne key per intent, and a status lookup before any retry.
ReconciliationHow each payment is matched to provider, settlement and bank evidence, and who owns a difference.
Liability and recoveryWho bears the loss in each flow, and how disputes and recoveries work.

A few rows from the checklist

ItemWhat to provideEvidence
Fail closed on errorsNo payment when a check errors or times outTest: make the limit service unavailable; no payment is sent
New or changed bank detailsA waiting period and approval before paying new or changed detailsTest: change a payee’s details; the next payment waits
Status before retryA timeout is resolved by a status lookup, never by resendingTest: time out the provider; one payment results
Intent and mandate matchedEach payment tied to its intent and the mandate version in forceReport linking payments to intents and versions

How to use it

  1. Assign an owner to every row before the review, not during it.
  2. Attach the evidence, not a description of it: the mandate file, an event export, a reconciliation report.
  3. Run the tests in the evidence column: break a control, change a payee, replay a timeout.
  4. Keep the completed checklist with the mandate version it was prepared for, and repeat it when the agent or the mandate changes.

Go further

Read an audit trail for AI agent payments for the reasoning behind each item, and use the AI agent payment policy template to write the mandate itself.

See how Flominzo AgentPay records each decision

Let’s make it specific to you.

Bring your systems, payment flows, and questions. We’ll help define the next step.

Talk to the team