The Financial Plan Nobody Asked For, Because Everyone Assumed It Existed.
Five months into a $14.2M program, three views of the same budget, and the offshore question that only surfaced when the numbers did.
"Send Me Your Financial Plan"
Thomas Richter’s Slack message arrived at 09:14 on a Monday. It was four words long: send me your financial plan. The context was routine. Atlas Bank Finance was preparing a quarterly review of major capital programs for the board. Richter needed each program’s Financial Plan to feed his consolidated view. Three other program managers had sent theirs by Friday. Falcon’s was overdue.
The program manager did not have one.
Falcon had a board-approved budget ($14.2M, broken into four categories, documented in the business case from October 2024). It had a commitment log (kept in Confluence by Ahmed Hassan, tracking every vendor contract, purchase order, and internal charge). It had spend tracking in Atlas Bank’s corporate finance system (Oracle-based, producing monthly spend reports by cost center). Five months in, the program was on budget, on track, and had drawn $180K from its contingency reserve in a fully authorised way. None of those things were a Financial Plan.
A budget is an approval. A commitment log is an inventory. A spend report is an accounting output. A Financial Plan is the bridge between all three and the governance framework the program operates under. It explains what the money is buying, in which workstream, on what schedule, with what reserve position, and how changes to any of those get authorised. The charter had not required it as a named artifact. The business case had assumed it would emerge from delivery. In practice, it had not emerged at all.
The PM called Richter at 09:45 to acknowledge the gap. Richter was not angry, but he was clear. The board review could proceed with his internal numbers; he had what he needed from the corporate finance system. The problem was the next internal audit cycle. An audit that asked for a program Financial Plan and received a commitment log and a spend report would find the gap within an hour.
The PM had fifteen working days to produce a Financial Plan for a program that had been running for five months. The structure could not be improvised. Whatever shape it took, it would become the audit reference for the remaining thirteen months of the program.
Three Orthogonal Views. One Plan.
The PM walked the design through Hassan on 17 June. The core insight came from a conversation with Richter’s deputy earlier that morning: audit challenges arrive from three different angles, and a Financial Plan that supports only one view fails the other two. Spend by vendor is how procurement audits money. Spend by phase is how the board and the finance committee audit money. Spend by workstream is how the program audits itself against delivery. The same dollars have to reconcile across all three.
The first two views existed already in raw form: the commitment log supported the vendor view, the business case supported the phase view. The third view did not. The program had been reporting spend by vendor and by phase but not by workstream (mobile app, microservices platform, core banking integration, regulatory reporting module, infrastructure). Producing it required a tagging change: every commitment in Jira and every cost line in MS Project would need a workstream identifier, feeding a monthly rollup report the PMO would author.
Raman costed the workstream-tagging work stream at $22,000 of PMO effort to stand up and $4,000 per month ongoing. Drawn from the unallocated reserve, which had been at $350,000 after the Post 08 instrumentation drawdown. Approved by the PM under discretionary authority; logged for the next steering.
On 19 June, Nadia Benali (CRO) saw the draft Financial Plan in pre-read for the monthly steering. The vendor breakdown made the onshore/offshore split visible for the first time in program reporting. The integrator contract ($5.68M over the program) was roughly 60 percent onshore and 40 percent offshore, with the offshore component running through the vendor’s delivery center in a third country with lower build-hour rates.
This was not new. It had been in the procurement contract from October 2024. It had never been visible in program reporting because the program had never reported vendor spend at that resolution. Benali’s concern was not commercial; it was data residency. Atlas Bank’s data residency posture (R11 in the Risk Register from Post 06) required that build-time access to production PII stay in-market. She wanted confirmation that the offshore team was not touching production data.
It was not. The offshore team worked on anonymized test fixtures maintained by the onshore integrator, and the contractual attestation had always been in the vendor contract. But the Financial Plan, once it surfaced the onshore/offshore split, now had to make the attestation explicit for Benali’s auditors to trace. The Financial Plan added a dedicated row linking the offshore spend line to the R11 attestation, including a reference to the specific clause in the vendor contract.
This is the governance compounding effect the series has described in several earlier posts. The Financial Plan did not create the offshore question; the offshore question was always there. But the Financial Plan was the first artifact where the question could be seen and therefore the first artifact where it could be answered in writing. A program that never produces a Financial Plan never surfaces that question, which means the question sits unanswered until an auditor asks it under less favourable conditions.
Drafting the Financial Plan
The prompt below uses GRADE: Goal, Roles, Actions, Deliverable, Evaluation. GRADE earns its slot here because of the Evaluation dimension. For a Financial Plan, the evaluation criterion is not clarity, completeness, or narrative flow. It is audit defensibility: every number must reconcile across three views, every drawdown must trace to an authorising decision, every attestation must link to a primary contract document. Forcing the model to plan against that evaluation criterion produces a different output than asking for a “good financial plan.” GRADE is less widely cited than CRAFT or RISEN, but for artifacts that live or die at audit, the Evaluation dimension is the one that actually matters.
Financial Plan Draft, Extract
The AI produced a plan structured around the three views. The commitment structure extract is shown below, along with the three flagged items that required human resolution.
Commitment Structure — By Vendor (extract)
| Vendor | Contract Value | Committed | Paid | Remaining |
|---|---|---|---|---|
| Platform Integrator (Volkov) | $5,680,000 | $5,680,000 | $1,620,000 | $4,060,000 |
| Infrastructure provider | $2,840,000 | $1,980,000 | $620,000 | $2,220,000 |
| Security audit firm | $480,000 | $240,000 | $120,000 | $360,000 |
| Other vendors (7 total) | $720,000 | $520,000 | $280,000 | $440,000 |
1. Vendor view shows gross contract value; does not distinguish onshore from offshore delivery. For the Platform Integrator contract (Volkov), the contract references a delivery mix but does not surface it in the financial view. If Atlas Bank’s data residency posture (R11) requires build-time access to production PII to remain in-market, the Financial Plan should make the onshore/offshore split visible and attach a data residency attestation to any offshore line.
2. “Committed” and “Paid” are conflated across milestones in progress. The $180K instrumentation work stream from Post 08 is committed but only partially paid at this point. Treating committed-not-yet-paid and committed-and-paid as the same category distorts burn rate and obscures cash-flow position. Recommend separating them.
3. Reserve drawdown log requires authorising references. The plan shows reserve position but does not link each drawdown to its authorising decision. For audit defensibility, every drawdown must reference the steering minutes, PM discretionary authority memo, or charter change record that authorised it. Current drawdown log shows dates and amounts only.
Financial Plan v1.0, Extract
Published 30 June 2025. Extract showing the Commitment Structure (by vendor, including onshore/offshore split) and the Reserve Position with drawdown log. Full plan carries all five sections with the same audit-trail discipline.
Commitments tracked at contract level with committed-not-yet-paid and committed-and-paid separated. Offshore delivery lines carry an explicit data residency attestation referencing R11 and the vendor contract clause.
| Vendor / Line | Contract | Committed | Paid | Unpaid | Audit Reference |
|---|---|---|---|---|---|
| Platform Integrator (Volkov) — onshore | $3,408,000 | $3,408,000 | $972,000 | $2,436,000 | Contract PI-2024-11; 60% of total. In-market delivery. |
| Platform Integrator (Volkov) — offshore | $2,272,000 | $2,272,000 | $648,000 | $1,624,000 | Contract PI-2024-11 cl. 7.3. Attestation: No production PII access; test fixtures only. Links to R11. |
| Infrastructure provider | $2,840,000 | $1,980,000 | $620,000 | $1,360,000 | Contract IP-2024-14. In-country data centres; no data residency exception. |
| Security audit firm | $480,000 | $240,000 | $120,000 | $120,000 | Contract SA-2025-03. On-site engagement; no data residency exception. |
| Other vendors (7) | $720,000 | $520,000 | $280,000 | $240,000 | Individual contracts in commitment log Conf/PF-CL. |
| Vendor spend total | $9,720,000 | $8,420,000 | $2,640,000 | $5,780,000 |
| Date | Purpose | Amount | Running | Authorising Decision |
|---|---|---|---|---|
| 23 May 2025 | Benefits Plan instrumentation work stream (cost baseline, branch data feed, agent-network reach) | $180,000 | $350,000 | PM discretionary auth; steering 5 Jun 2025, item 4.2. Framed as preventive investment against benefits audit failure; links to R01. |
| 20 Jun 2025 | Workstream cost tagging stand-up ($22K) + 12 months of ongoing cost ($4K × 12 = $48K) | $22,000* | $328,000 | PM discretionary auth; to be ratified at steering 3 Jul 2025. *Stand-up only drawn; ongoing cost runs from workstream budget once stood up. |
The three orthogonal views reconcile to the program budget baseline. Auditors can verify at a glance.
| View | Total | Components |
|---|---|---|
| By Vendor | $14,200,000 | Vendor spend $9.72M + internal headcount $3.55M + other $0.93M (see Section 2.2) |
| By Phase | $14,200,000 | P1 $2.3M + P2 $7.4M + P3 $2.1M + P4 $0.27M + Contingency $2.13M (see Section 2.3) |
| By Workstream | $14,200,000 | Mobile app $2.1M + Microservices $4.2M + Core banking $2.8M + Reg reporting $1.2M + Infra $1.76M + PMO $0.01M + Contingency $2.13M (see Section 2.4) |
| ✓ Reconciliation status | PASS | All three views equal $14.2M. Reconciled as of 30 Jun 2025. |
Procurement contracts: Held in Atlas Bank Procurement Vault; accession numbers referenced in Section 2.1.
Commitment log: Confluence page Conf/PF-CL, maintained by PMO Lead; updated within 48 hours of any new commitment.
Reserve drawdown authorizations: PM discretionary authorisations logged in PMO memos PMO-FM-YYYY-NN; steering ratifications in minutes of the relevant meeting.
Data residency attestation: Vendor contract PI-2024-11 clause 7.3; linked to Risk Register R11. Quarterly attestation refresh required.
- Restructured into three orthogonal views. AI produced a single budget table. PM built three views (by vendor, by phase, by workstream) with explicit reconciliation between them. Audit challenges come from all three angles; a plan supporting one view fails the other two.
- Split the Platform Integrator line into onshore and offshore components. AI flagged this correctly. PM separated the contract value into two lines ($3.41M onshore, $2.27M offshore), attached the data residency attestation to the offshore line, and linked to R11 and vendor contract clause 7.3. Benali’s auditors could now trace it without further questions.
- Separated committed-not-yet-paid from committed-and-paid. AI conflated these. PM added two columns. The $2.64M paid vs $5.78M unpaid split on the vendor view exposed cash-flow position that the conflated view had hidden.
- Added authorising-decision references to every drawdown. AI produced a bare drawdown log with dates and amounts. PM added the authorising-decision column, linking the $180K instrumentation drawdown to steering minutes 5 Jun 2025 item 4.2 and the $22K workstream-tagging stand-up to the upcoming 3 Jul ratification. Every drawdown now traces to an auditable decision.
- Distinguished stand-up cost from ongoing cost in the workstream tagging line. AI treated the $22K as the full drawdown. PM clarified that stand-up was drawn from reserve; ongoing $4K/month runs from the workstream’s own budget from month 6 onward. This closed a forward-looking ambiguity that would have created a finding.
Atlas Bank Internal Audit conducted the annual review of Falcon in the second week of March 2026. The audit team requested the Financial Plan, the commitment log, the reserve drawdown log, and the procurement contracts. The team traced every dollar across the three views: by vendor, by phase, by workstream. Each drawdown was matched against its authorising minutes reference. The offshore attestation was cross-checked against the vendor contract clause and the R11 entry in the Risk Register. The audit closed in eleven days, with zero “insufficient documentation” findings. The program’s internal audit score was 4.7 of 5, which contributed directly to benefit B09 (directive-aligned reporting quality, target 4.5) from the Benefits Plan in Post 08. A Financial Plan written from commitment-log data in June 2025 determined an audit outcome nine months later.
A fictional case study for teaching purposes. Atlas Bank, Project Falcon and all named individuals are invented. Technologies are industry-standard and publicly available.