Free resource
AI agent payment audit checklist. The evidence to prepare before an agent pays.
A free checklist of the evidence risk and compliance teams ask for before an AI agent can pay: agent register, mandates, controls, decisions and reconciliation.
Last updated:
Download the CSV checklistOn this page 5 sections
What this checklist is
A working list of the evidence a risk, compliance or audit team will ask for before an AI agent is allowed to move money, and after it has. Each row names an item, what to provide, the evidence that proves it, an owner and a status, so you can work through it together and hand over the result.
It is vendor-neutral. Use it with your own systems, a payment provider’s controls or Flominzo AgentPay. It opens in Excel, Google Sheets or Numbers.
What it covers
| Section | What it asks for |
|---|---|
| Agent register | Each agent’s identity, owner, version history and the tools it can call. |
| Mandates | Scope, caps, payees, approvers, expiry and revocation, with every version kept. |
| Enforcement | Where the rules are checked, and proof the agent cannot change them. |
| Failure behaviour | What happens when a check errors, times out or the mandate has expired. |
| Decisions | A sample of attempts with the rule that decided and the approver. |
| Idempotency | One key per intent, and a status lookup before any retry. |
| Reconciliation | How each payment is matched to provider, settlement and bank evidence, and who owns a difference. |
| Liability and recovery | Who bears the loss in each flow, and how disputes and recoveries work. |
A few rows from the checklist
| Item | What to provide | Evidence |
|---|---|---|
| Fail closed on errors | No payment when a check errors or times out | Test: make the limit service unavailable; no payment is sent |
| New or changed bank details | A waiting period and approval before paying new or changed details | Test: change a payee’s details; the next payment waits |
| Status before retry | A timeout is resolved by a status lookup, never by resending | Test: time out the provider; one payment results |
| Intent and mandate matched | Each payment tied to its intent and the mandate version in force | Report linking payments to intents and versions |
How to use it
- Assign an owner to every row before the review, not during it.
- Attach the evidence, not a description of it: the mandate file, an event export, a reconciliation report.
- Run the tests in the evidence column: break a control, change a payee, replay a timeout.
- Keep the completed checklist with the mandate version it was prepared for, and repeat it when the agent or the mandate changes.
Go further
Read an audit trail for AI agent payments for the reasoning behind each item, and use the AI agent payment policy template to write the mandate itself.
See how Flominzo AgentPay records each decisionLet’s make it specific to you.
Bring your systems, payment flows, and questions. We’ll help define the next step.
Talk to the team