14.3 Diagnostic, Prescriptive, Predictive, Anomaly, and Text Analysis

Key Takeaways

  • B4e: determine when to use diagnostic, prescriptive, predictive, anomaly detection, and text analysis — match the method to the question, not to the fanciest tool.
  • Diagnostic explains why a known pattern happened (why duplicates posted). Prescriptive says what to change. Predictive estimates who or what will fail next. Anomaly detection flags items unlike their peers. Text analysis mines non-structured language (contract clauses, tickets).
  • A descending sort, a filter, or the biggest invoices is not predictive. Predictive needs a forward-looking score grounded in past outcomes, not this week's ranking.
  • Anomaly flags are leads, not fraud conclusions. Reading two PDFs is inspection, not text analysis of the population.
  • Do not answer a B4e method-choice item with Chapter 15 ratios/variances/trends/benchmarks or Chapter 13 AI/RPA/dashboard tools.
Last updated: August 2026

B4e: pick the method that answers the question you wrote

Quick Answer: B4e asks you to determine when to use diagnostic analysis, prescriptive analysis, predictive analysis, anomaly detection, and text analysis. Match the method to the question: why did this happen; what should change; who or what will fail next; which items are unlike the rest; what does the unstructured language say. A descending sort is not predictive. Ratios, variances, trends, and benchmarks are Chapter 15. AI, RPA, and dashboards as tools are Chapter 13.

Section 14.2 defined the analytics process. This section is the method inside the analyze step. GIAS Standard 14.2 (analyses and potential engagement findings) is why the method must be able to support a condition you might later evaluate. You still do not write Chapter 15's cause-effect-significance package here; you choose an analysis that can feed it.

The 2025 syllabus does not list descriptive as a B4e method. Arranging what already happened — counts, totals, sorts — still happens in survey scans (Chapter 11.2) and as input to the five methods. The fail is calling that arrangement predictive (or diagnostic, or prescriptive) when it has not earned the name.

The five methods, with internal-audit uses

MethodQuestion it answersUse whenInternal-audit exampleNot this
DiagnosticWhy did this happen?A condition is already visible; you need driversWhy 18 duplicate invoices posted: same clerk after a bank-detail change; re-post after a failed ACH; the system reused invoice numbersListing the 18 rows and stopping
PrescriptiveWhat should we do (or stop doing)?You have cause and you are advising actionBlock same-ID vendor-change and payment-release; retire shared IDs; require a second release above a thresholdA wish list with no link to the cause
PredictiveWhat is likely next?A scoring rule or model uses past outcomes to rank future riskWhich vendors are most likely to fail the duplicate-pay control next month, based on past confirmed issuesSorting this month's invoices from large to small
Anomaly detectionWhich items do not look like the rest?You need outliers without yet knowing whyInvoices whose amount, timing, or vendor profile is far from the peer groupCalling every large invoice an anomaly
Text analysisWhat does the language contain?Evidence is non-structured or free textMining contracts for termination, audit-rights, or price-escalation clauses; scanning tickets for overrideReading two contracts and claiming the population was mined

Diagnostic — why the duplicates happened. Start from a known pattern (the 18 exact duplicates from a scan). Diagnostic work disaggregates: by vendor, by user, by day, by whether a reversing document exists, by whether the second payment followed a bank-detail change. The output is a why you can take to a walk-through: 14 of 18 are vendor 4412, same user ID, within 48 hours of a bank-account edit. That is still analysis, not yet the Chapter 15 finding paragraph. Choose diagnostic when the stem already puts the condition on the table and asks what to do next to explain it.

Prescriptive — what to fix. Prescriptive analysis recommends an action given the objective and constraints: change the SOD rule in the ERP, recertify user IDs, stop the weekend upload job until a review exists. On CIA Part 2 this is engagement-level advice grounded in the analysis, not the CAE's residual-risk protocol (Part 3) and not a full operations-research solver. If the stem asks which analysis tells management what to change, the answer is prescriptive — after diagnostic work has a cause. Prescribing tone at the top from a sort of invoice amounts is theater.

Predictive — who will fail next month. Predictive methods use past labeled outcomes (confirmed duplicate payments, confirmed access violations, confirmed claim issues) to score future items or people. Vendors with a new bank account, no PO history, and a round-dollar first invoice that scored like last year's confirmed duplicates is predictive if you built and checked that scoring rule. Ranking this week's invoices by dollar amount is not. A hunch is not. A regression, a simple weighted score with a back-test, or a documented risk score can all be predictive in kind. The exam cares that you know future likelihood. It does not ask you to code a neural net; that tool conversation is Chapter 13.

Anomaly detection — outlier invoices. Anomaly methods flag items that are statistically or logically unlike peers: a z-score on amount versus the vendor's history, a first-time vendor with a round-dollar invoice, postings at 02:14 when the process runs at 14:00, quantities that dwarf the PO. The flag is not a conclusion. Many anomalies are legitimate rush orders. Use anomaly detection when you do not yet have a why and you need a lead list from the full population. Then diagnose. Sampling one large invoice you happened to see and calling it anomaly detection misses the method: the point is unlike the rest, not large.

Text analysis — contract clause mining. Text methods extract meaning from non-structured language: search, classification, clause extraction. Internal-audit uses: Does this population of vendor MSAs contain audit-rights and clawback language we think we have? Do incident write-ups mention the same failed lockout step? Do invoice memo lines say consulting on a hardware PO? You still inspect hits; text analysis aims the reading. Two PDFs opened in a hotel room are inspection, not text analysis of the population.

Loading diagram...
Match the B4e method to the question — then chain only if the objective needs a chain

Sequence, mix, and the sort-is-not-predictive trap

Real engagements chain methods when the objective needs a chain. Anomaly detection or a structured match surfaces outliers. Diagnostic analysis explains a cluster. Prescriptive analysis says what to change. A predictive score, if you have labeled history, aims next period's testing. Text analysis often joins the structured file (clause present = yes/no) so you can diagnose the no population.

Do not chain them as a ritual. If the objective is whether termination clauses exist in 200 vendor contracts, start with text analysis, not a predictive employee-turnover model. If the objective is why vendor 4412 duplicated, start diagnostic, not a new anomaly screen of the whole GL.

A sort is not predictive. Sorting AP by amount, newest vendor, or weekend flag is arrangement of what already happened. It can support a survey scan (Chapter 11.2). It can feed anomaly thinking if you have a peer-group rule (this amount versus this vendor's history), which is then anomaly detection, still not prediction. It does not estimate who will fail next month. CIA stems love: the auditor sorted invoices descending by amount and called the top 20 a predictive model of fraud. The error is the label, not the sort. Use the sort if you need the largest items; name the method what it is.

Benford's law, if it appears, is a conformity / anomaly screen unless you have turned the result into a validated forward score — which almost nobody has on a two-week AP job. Do not call it predictive to sound current.

Anomaly is not fraud. Eighteen outliers are a lead list. Diagnostic work, walk-throughs, and evidence Chapter 12 would respect still sit between the flag and a finding. Prescriptive is not a slogan. Fix SOD in the system is prescriptive when it follows a cause; enhance culture is not a B4e method output. Text analysis is not two PDFs. Population plus a rule for what you extracted plus inspection of hits is the method. Opening the two contracts in the kickoff packet is reading.

Worked example: five questions, five methods

Same procure-to-pay file, five different objectives:

  1. Which invoices are unlike their vendor's last 12 months? → anomaly detection.
  2. Why did vendor 4412 duplicate? → diagnostic (user, bank-change, re-post).
  3. What control change would stop same-ID bank-change plus release? → prescriptive.
  4. Which current vendors look like last year's confirmed duplicate-pay cases heading into next month? → predictive, and only if you have that labeled history and a score you can explain.
  5. Do MSAs for these vendors include audit rights and a right to claw back overpayments? → text analysis of the contracts.

If the team answers all five by sorting the register, they have not determined when to use the methods. If they answer (4) with a model they cannot explain and never back-tested, they confused Chapter 13 tools with B4e method choice. If they answer (3) with a current-ratio analysis, they wandered into Chapter 15. If they answer (1) by picking the single largest invoice in the sample, they never ran anomaly detection on the population.

Keep Chapter 15's analytical review (ratios, variances, trends, benchmarks, technique selection) in Chapter 15. Keep Chapter 13's technology options in Chapter 13. B4e is only: given this question, which of the five methods belongs.

Exam traps

  • Calling a sort, a filter, or the big ones predictive.
  • Using diagnostic as a synonym for any spreadsheet.
  • Using prescriptive without a cause.
  • Treating anomaly flags as fraud.
  • Treating text analysis as having read two documents.
  • Importing ratios, variances, trends, benchmarks (B5) or AI / RPA / dashboards (B3) into a B4e method-choice item.

B4e is done when you can name the question, name the method, and refuse the label that was only there to sound advanced.

Illustrative method outputs on one P2P file (different questions, not interchangeable totals)
Test Your Knowledge

Eighteen exact-duplicate invoices are already listed. The engagement objective is to explain why they posted. Which B4e method is appropriate next?

A
B
C
D
Test Your Knowledge

Which task is predictive analysis rather than a simple arrangement of current data?

A
B
C
D
Test Your Knowledge

An auditor sorts the AP register descending by amount and labels the top 20 a predictive fraud model. What is the error?

A
B
C
D