AutoMaat
Knowledge base· Detection and control

How do you detect revenue leakage automatically?

The building blocks of automatic leak detection: pulling data, matching, rules, thresholds and alerts with an owner. Plus how to keep false alerts down.

Ricardo Mastenbroek9 min read
Lees dit artikel in het Nederlands

You detect revenue leakage automatically by having software run, at fixed intervals, the comparisons you would otherwise do by hand. Won deals against invoices, contract prices against invoice lines, job sheets against billing, usage against subscriptions. For that you need five building blocks: read access to the source systems, a shared key to link records, written-down rules, thresholds that filter out noise and an alert that lands with an owner. Anomaly detection and AI add to that for leaks that break no fixed rule.

How do you check revenue without going through everything by hand?

A manual check has four steps: exporting data, linking data, comparing and investigating the differences. The first three take the most time and are the same every time. Only the fourth needs human judgement.

Automatic detection takes over exactly those first three steps. The result is not a report with thousands of rows, but a short list of deviations for a person to assess. The time you save goes into investigating instead of collecting. And because the check can run every night at no extra effort, you find a leak within days rather than at the end of the year.

That last point may matter even more than the time saved. A job sheet flagged as uninvoiced after three days is easy to put right. After ten months nobody remembers what was done, and the customer is surprised by an invoice for work from last spring. How to find leakage in general, manually or otherwise, is covered in how to find revenue leakage in a business.

The five building blocks

1. Read access to the sources. The detection has to be able to pull data from the CRM, the billing or accounting system, time tracking, the planning system and, where needed, the contract register. For detection, read access is enough. Nothing has to be written. Most systems, such as HubSpot, Salesforce, Exact, Xero and NetSuite, offer an API for this. Where there is no API, a scheduled export works too.

2. A shared key. To link a deal to an invoice, you have to know they belong together. Ideally the deal number or contract number appears on the invoice, or the customer has the same ID in every system. Without that key every automatic comparison fails, or produces so many false alerts that nobody reads them any more. This is often the first thing to fix. See also revenue leakage from data problems.

3. Written-down rules. A rule describes what has to be right. Examples:

  • Every deal that is marked as won has an invoice within 30 days.
  • The price on an invoice line equals the contract price, including any indexation applied.
  • Every completed job sheet has an invoice line within 14 days.
  • The number of licences invoiced is equal to or higher than the number of active users.
  • A discount with an end date no longer appears on an invoice after that date.

4. Thresholds. Not every difference is a leak. A rounding difference of a few cents, an invoice that arrives a day later than the rule requires, a deal that is deliberately invoiced in instalments. Thresholds determine when a difference is large enough to report: in euros, in days or in percentages.

5. An alert with an owner. A deviation that sits in a dashboard is rarely picked up. A deviation that lands as a task with a person, with the amount and the evidence attached, is. Every rule therefore has an owner: who investigates this when it fires?

Rules and anomaly detection

Rules work well for leaks with a clear right and wrong. But some leaks break no rule at all. A customer who orders 8 percent less every quarter. An account manager who consistently gives more discount than colleagues. A product whose average selling price is slowly falling. There is no fixed limit that says when this becomes a problem.

That is what anomaly detection is for: a method that works out what is normal from the data itself and reports what deviates from it. Normal can be a customer's own history, or the behaviour of comparable customers. How that works is explained in what anomaly detection is.

The difference in practice:

Rules Anomaly detection
Finds Breaches of an agreement Deviations from a pattern
Example Invoice price lower than contract price Customer keeps ordering less than last year
Explainable Fully: rule X was broken Partly: this deviates from what is normal
False alerts Few, provided the data is right More, needs tuning
When to start Always Once the rules are in place

Start with rules. They produce reliable findings fastest, and they force you to get your data in order. Anomaly detection comes afterwards, as a layer on top. What AI specifically adds, such as reading contracts and linking records that do not match exactly, is covered in can AI detect revenue leakage.

The biggest problem: false alerts

An automatic check that reports too much dies a quiet death. After a few weeks of a hundred alerts a day, five of them real, nobody reads them any more. Then you are in the same position as without a check, only with more noise.

False alerts almost always have one of these causes:

  • Missing link key. The deal and the invoice belong together, but the software does not know it.
  • Legitimate exceptions. A deal is deliberately invoiced in instalments, a customer has an agreed discount that is not in the contract register.
  • Timing. An invoice that the process only issues after delivery is flagged as missing while it is on its way.
  • Wrong thresholds. Set too tight, so every small deviation becomes an alert.

The solution is a feedback loop. Every alert closed as unjustified gets a reason. You collect those reasons, and every month you adjust the rules, thresholds or data. After a few months the share of false alerts has usually fallen sharply. A check without that feedback loop stays stuck at the level of its first week.

Worked example

Worked example: suppose a business services firm closes 900 deals a year and checks once a year, by hand, whether all won deals have been invoiced. That check takes a controller four working days and finds on average 12 deals without an invoice, with an average value of EUR 7,500. Of those 12, the controller can still invoice 7. For the other 5 it is too long ago: the customer disputes it or the contact has gone.

With a nightly automatic check, the same 12 deals are found, but on average within two weeks of the moment the invoice should have gone out. Suppose 11 of the 12 are then invoiced.

  • Manual: 7 × EUR 7,500 = EUR 52,500 recovered, 5 × EUR 7,500 = EUR 37,500 permanently lost.
  • Automatic: 11 × EUR 7,500 = EUR 82,500 recovered, 1 × EUR 7,500 = EUR 7,500 lost.

The difference of EUR 30,000 is not in what is found, but in when. The numbers are an example. The principle applies broadly: the sooner a leak is reported, the greater the chance you can still put it right.

Step-by-step plan: your first automatic check

  1. Choose one check with a clear rule and a high volume. Won deals against invoices is a good first choice. How to design that check is covered in how to check CRM against billing.
  2. Do it once by hand first. You learn where the data does not line up, what exceptions there are and which thresholds make sense.
  3. Fix the link key. Make sure the deal or contract number appears on the invoice, or that customers have the same ID in both systems.
  4. Write the rule and the threshold out in plain language. "Every won deal above EUR 1,000 has an invoice with the same deal number within 30 days."
  5. Automate the pulling and comparing. That can be done with a script, a SQL query in a data warehouse such as Snowflake, a report with alerts in Power BI or a platform built for the purpose.
  6. Route the alert to an owner. As a task, not as a dashboard.
  7. For two months, keep track of which alerts were unjustified and why. Only then adjust rules and thresholds.
  8. Only then add the second check.

Which tools you can use

There is no single right way. The choice depends on what you already have and who maintains it.

  • Scripts and queries. Flexible and cheap if you have a developer or data analyst. Fragile if that person leaves.
  • BI tools with alerts. If you already use Power BI or a similar tool, you can build checks in it. The drawback is that BI tools are mainly built to display, not to assign and follow up tasks.
  • A revenue intelligence platform. Software built specifically to connect revenue systems, run comparisons and report deviations in euros. RiOS is such a platform, currently in beta. What it does, module by module, is shown on the system page.

Whichever tool you choose, the building blocks stay the same. Without a link key, a rule, a threshold and an owner, no tool works.

Frequently asked questions

Do I need write access to my systems for automatic detection?

No. Read access is enough to find leaks. Write access is only needed if you also want corrections to be applied automatically, and that is a separate decision with its own controls.

How often should an automatic check run?

For most revenue checks, daily or weekly is enough. More important than the frequency is that the alert reaches an owner quickly and that they act on it.

What if my data is not good enough?

Then that is the first thing the check tells you. Start with the fields the first check needs and clean those up. An automatic check is also a measuring instrument for data quality.

Can AI replace the rules?

No, AI complements them. For comparisons with a clear right and wrong, rules are better: faster, cheaper and fully explainable. AI adds value for unstructured sources, uncertain matches and patterns without a fixed limit.

Share this article
Knowledge base · Detection and control

More in this cluster

All 18 topics in this cluster

More from AutoMaat

Rather know what this costs you specifically?

The Revenue Audit puts a euro amount on where your revenue leaks.

Plan the Revenue Audit