The Weakest Line in Every Ledger

2026-07-10 · 3,580 words · Singular Grit Substack · View on Substack

Double-entry bookkeeping is 600 years old and still brilliant — inside one company.

At the seam where two companies meet, the evidence behind the numbers is softer than almost anyone admits. Here is what a third record fixes, what it doesn’t, and why it matters now.

Keywords: triple-entry accounting, audit evidence, invoice–payment reconciliation, selective disclosure, cryptographic receipts, assurance, internal controls, e-invoicing, reconciliation, trust


Every set of accounts is a story about things that happened. A sale was made. A bill was raised. Money moved. The numbers on the page are a compressed summary of thousands of these small events, and the whole edifice of modern finance — audits, loans, valuations, tax, investor confidence — rests on the assumption that the summary is faithful to the events.

Most of the time, it is. Bookkeeping is one of the great inventions of the commercial world, and the version we still use was already mature when Luca Pacioli wrote it down in 1494. Double-entry is elegant precisely because it is self-checking: every entry has two sides, debits equal credits, and a mistake shows up as an imbalance. For five centuries it has let a single organisation keep an internally consistent account of itself.

But look closely at where the errors, the disputes, and the frauds actually cluster, and you find they are rarely inside a company’s books. They are at the seam — the join between one company’s records and another’s. The invoice you sent and the invoice they received. The payment they say they made and the payment you say you got. The thing your ledger insists happened and the thing their ledger insists happened. Double-entry keeps each side internally consistent. It says nothing about whether the two sides agree, and even less about whether either side is telling the truth.

This is the weakest line in every ledger. And once you see it, you cannot unsee it.

The evidence problem nobody names

Ask an auditor what they actually do, stripped of the jargon, and a large part of the answer is: they try to find out whether the events behind the numbers really happened, in the amounts and at the times claimed. To do that, they gather evidence. And not all evidence is equal.

There is a quiet hierarchy of reliability that every auditor carries in their head. Evidence is stronger when it comes from outside the company being audited, when it was generated under good controls, when the auditor obtains it directly rather than through the client, and when it is documentary rather than verbal. A signed contract from an independent third party sits near the top. A number typed into a spreadsheet by the person whose bonus depends on it sits near the bottom.

Here is the uncomfortable part. The evidence behind a huge share of ordinary business activity — the invoices, the remittance advices, the confirmations that substantiate transactions between two companies — sits closer to the bottom of that hierarchy than most people outside the profession realise.

Consider what an invoice actually is. It is a document one party creates, about itself, and sends to the other. It is trivially editable. The “copy” in your accounts payable folder and the “copy” in their accounts receivable folder are two separate files that can drift apart, be altered after the fact, be lost, or be fabricated. When an auditor wants to be sure, the traditional tool is the external confirmation: a letter to the customer or supplier asking them to confirm the balance. Confirmations are slow, they come back incomplete, they are sometimes ignored entirely — and, notoriously, they can be forged. Some of the largest accounting frauds in living memory turned on confirmations that looked perfectly genuine and were completely fake.

So the profession does something rational in the face of soft evidence and limited time: it samples. It cannot test every transaction, so it tests a carefully chosen subset and extrapolates. Sampling is a sensible response to cost. But it is, unavoidably, a response to a weakness. If the evidence for each individual transaction were strong, cheap, and instantly verifiable, you would not need to sample it. You would just check all of it.

That is the possibility worth taking seriously. Not a better sample. No sample at all, for the questions this approach can answer.

What “a third record” means

The idea has a slightly awkward name — triple-entry accounting — and a long, on-and-off history among accountants and technologists. Strip away the branding and the concept is simple.

Each party keeps its own double-entry books, exactly as before. Nothing about that changes. But in addition, for each transaction, each party publishes a small, sealed note to a shared record that both sides — and only the people they permit — can inspect. The seller publishes a note that says, in effect, an invoice with these properties existed at this moment. The buyer publishes a note that says a payment with these properties existed at this moment. And the two notes are privately linked, so that the obligation and its settlement are tied together in a way an authorised outsider can later confirm.

The word “sealed” is doing real work here, so let me be precise about it. The published note does not reveal the contents of the invoice. It is more like a tamper-evident wax seal than an open letter. Anyone can see that the note exists and when it was made. Nobody can read what is inside it, or alter it afterwards without the alteration being obvious, unless they are given a specific key to a specific part of it.

That is the whole architecture, and Figure 1 shows it in one view. Two parties, two ordinary sets of books, and above them a thin shared layer of sealed notes joined by a private link. Underneath sits the auditor, who can verify some things on sight and other things only with permission.

What has actually changed? Four properties of the evidence, and it is worth naming each one because the value lives in the specifics, not in the buzzwords.

Source. The note is not the reporter’s word for it. Once published, it is a fixed, independent record that neither party can quietly revise. The evidence stops being “what the client’s system says today” and becomes “what was committed at the time, visible to an outsider.”

Integrity. Because the note is tamper-evident, an auditor is no longer asking is this the real invoice or an edited one? Any post-hoc change to a committed value breaks the seal. The document either matches what was sealed, or it doesn’t, and you can tell instantly.

Timing. The note carries an objective, independent timestamp. One of the oldest games in accounting is moving a transaction across a period-end to flatter a set of results. A seal made at a knowable time puts a hard, external bound on when a record can have existed — you cannot backdate what was already sealed.

Linkage. The private connection between the invoice note and the payment note means the obligation and its settlement are provably related. Reconciliation — the grinding, error-prone process of matching what was owed to what was paid — stops being an act of detective work across two mismatched systems and becomes an act of verification.

None of this touches the inside of either company’s books. It works on the seam, which is exactly where the weakness always was.

The clever part: showing one thing without showing everything

If that were the whole story, there would be an obvious objection, and it is the objection that has sunk most “put your accounts on a shared ledger” proposals for a decade. Businesses will not publish their commercial information. They will not tell the world — or even their auditor’s whole team, or a rival who happens to be watching — what they charged, on what terms, to whom. Price is a secret. Terms are a secret. Customer relationships are a secret. A system that requires transparency to deliver trust is dead on arrival, because transparency is the one thing companies cannot give.

This is where the interesting cryptography earns its keep, and it is worth understanding in plain terms because it dissolves the objection completely.

The trick is that a sealed field can be proven to exist and to be unchanged without being revealed. The public seal on the “gross amount” field is a commitment: it fixes the value beyond later alteration, and anyone can check that the seal is well-formed, but the seal itself discloses nothing about the number underneath. It is a promise you can verify without reading.

Then, separately, the value can be opened to exactly one person, for exactly one field, under a specific signed authorisation. An auditor who needs to test the gross amounts on a set of invoices receives a key that opens the gross-amount field — and only that field. The due date stays sealed. The invoice ID stays sealed. The tax detail, the payment terms, the counterparty’s identity: all stay sealed, unless a separate, separately authorised key is granted for each.

Figure 2 makes the point concrete. Six fields, six public seals, one of them opened to one auditor. Opening a field does not open its neighbours. A different question requires a different authorisation. The auditor gets precisely the evidence the audit needs, and nothing more leaks — not to a competitor, not to the public, not even to parts of the audit team that have no business seeing it.

This is a genuinely different bargain from the one usually on offer. The old choice was binary and unappealing: either keep your data private and give the auditor weak evidence, or hand over strong evidence and lose your privacy. Selective disclosure breaks the binary. You get reporter-independent, tamper-evident, timestamped evidence and you keep your commercial terms confidential. The auditor’s questions get sharper answers; your secrets stay secret.

What actually changes for the people who do the work

Concepts are cheap. What matters is whether the day-to-day work of the people who live inside this problem gets better. Look at it from three chairs.

The audit partner

The partner sells assurance and carries the liability, and both of those improve for the same reason: the evidence gets harder.

Start with the shift from sampling to full testing. When the evidence for each transaction is strong and cheap to check, the economics of sampling collapse — in the good way. Instead of testing a random subset and extrapolating, the auditor can recompute the seals across the entire covered population and match every invoice note to every payment note. The output is not “we tested sixty items and found two exceptions, so we estimate the error rate.” The output is “we tested all of them, and here are the precise items that do not reconcile.” Substantive effort concentrates on a short, bounded list of genuine exceptions rather than being spread thin across a sample chosen to manage cost.

Then there is the file. Audit work has to be defensible not just on the day it is signed but years later, if a matter is ever litigated or reviewed. A folder of confirmation letters and photocopied invoices ages badly. A base of tamper-evident, timestamped, independently re-verifiable evidence ages well: the partner, or a court, or a regulator, can re-check it long after the fieldwork is done and get the same answer. In a profession where liability has a long tail, that is not a small thing.

There is a labour dividend too, though it should be described carefully. As routine verification becomes cheap and automatable, the low-value grind — vouching documents, chasing confirmations — shrinks, and the auditor’s attention moves to the things that genuinely require judgement. That is a better use of expensive human expertise, and over time it changes what an audit costs to produce.

The accountant and controller

For the person who actually closes the books, the recurring pains are reconciliation and defensibility, and both ease.

Reconciliation is the obvious win. Matching what was invoiced to what was paid, across two companies’ systems, is one of the most tedious and error-prone parts of the monthly and annual close. When the invoice and the payment are cryptographically linked at the moment they happen, the match is not something you reconstruct after the fact — it is something you verify. Unexplained differences, the bane of the close, largely become explained exceptions with a precise cause.

Disputes ease too. A great deal of commercial friction between trading partners is, at bottom, an argument about whose record is right — we invoiced you on the third, you say you never received it; you say you paid, we have no record. When each party’s claim is a signed, timestamped, tamper-evident note, that class of argument mostly evaporates. There is a shared, neutral fact to point at. He-said-she-said becomes verify-and-move-on.

And crucially, the accountant keeps their confidentiality. Selective disclosure means you can hand your auditor exactly the evidence they need without exposing your pricing to anyone, and without putting a single commercial figure on a public ledger.

The CFO

For the CFO the value operates on three levers, and they are the levers CFOs actually care about.

The first is control and governance. This evidence layer sits outside management’s unilateral reach. A record, once sealed and mutually attested, cannot be quietly altered or a period quietly restated without the change being detectable. That is a control with a property most internal controls lack: it cannot be repurposed by the very people it is meant to constrain, because it does not live entirely inside the organisation’s own systems. For anyone who has to sign off on the integrity of financial reporting and answer to an audit committee, a control that management cannot silently override is worth a great deal.

The second is cost of capital and financing. More reliable evidence on the covered facts reduces friction on exactly the assertions the evidence speaks to, which over time shows up in the cost and smoothness of the audit. And a verifiable, tamper-evident link between an obligation and its settlement is precisely the kind of evidence that underwrites working-capital finance — receivables discounting, supply-chain finance — where a lender’s whole risk is did this invoice really arise, and will it really be paid? Better evidence on that question is, quite directly, cheaper money.

The third is risk and signal. A large share of cross-border and value-added-tax exposure comes down to factual opacity: did a transaction occur, between which parties, for what amount, and does the invoice reconcile to the payment? Removing that opacity lowers the temperature of exactly the disputes that generate tax adjustments and penalties. And adopting a reporter-independent evidence layer is a credible signal — to investors, to lenders, to tax authorities — that a company is not relying on “trust us” for the integrity of its numbers. Pre-commitment of that kind tends to be rewarded.

The honesty that makes it credible

Here is the part that separates a serious idea from a sales pitch, and it is the part I want to insist on, because the temptation to overclaim in this territory is enormous and has discredited a decade of louder proposals.

A sealed, linked, selectively disclosed record does several specific things extremely well. It also does not do a number of things, and pretending otherwise would be worse than useless. Knowing the boundary precisely is what lets a professional actually rely on the tool instead of dismissing it.

It does not detect collusion. If a buyer and a seller agree to invent a transaction — both publishing perfectly well-formed notes for a sale that never happened — the cryptography will happily confirm that two matching, tamper-evident, timestamped records exist. It confirms the records; it cannot confirm the reality behind them when both parties are lying in concert. Fabrication by agreement passes every check.

It does not establish economic substance or value. That a sale was recorded says nothing about whether the goods were delivered, whether the revenue was earned in this period under the applicable standards, whether the receivable is collectable, whether the counterparty is a genuinely independent party or a related shell, or whether management’s intent matches the paperwork. These are judgement calls, and they remain exactly where they belong: with the human who is accountable for them.

It does not confer legal admissibility. Whether a court in a given jurisdiction will accept a given record as proof of anything is a question of law, not of cryptography, and it is not something a seal can settle.

And it does not, by itself, prove completeness. It can flag a missing counterpart — an invoice with no matching payment, a payment with no matching invoice — which is genuinely useful and often catches things a sample would miss. But it cannot prove that an obligation which both parties simply chose never to record does not exist.

Notice what this list has in common. Everything the approach does is about the existence, integrity, timing, and linkage of records — the factual, mechanical layer. Everything it declines to do is about substance, intent, value, and law — the interpretive, human layer. It narrows the factual-occurrence gap. It does not narrow, and does not pretend to narrow, the judgement gap.

That division is not a limitation grudgingly admitted. It is the whole point. A tool that claimed to replace professional judgement would be both dangerous and false. A tool that upgrades the evidence so that judgement can be spent where judgement actually matters — that is genuinely useful, and it is honest about being useful only there.

Why this is arriving now

Ideas like this have circulated for years without much happening. Three things have changed, and together they move this from a whiteboard concept toward something practical.

The first is the maturing of the underlying cryptography. The building blocks — commitments that hide a value while fixing it, deterministic signatures, key structures that let you derive a separate key for every field, authorisation envelopes that grant access to one thing for one purpose — are no longer research curiosities. They are well-understood, efficient, and boring in the way that reliable infrastructure should be boring. The interesting engineering is no longer in the primitives; it is in assembling them into something an accountant would recognise as an evidence workflow.

The second is the global wave of e-invoicing mandates. Tax authorities across Europe, Latin America, and Asia are, one after another, requiring invoices to be issued, cleared, or reported through structured digital channels in real time or near-real time. Italy, India, Mexico, and a lengthening list of others already run schemes in this spirit; the European Union is moving in the same direction. The practical effect is that structured, machine-readable transaction data is increasingly being produced at the moment of the transaction anyway. The marginal step from “structured e-invoice” to “sealed, linked, selectively disclosable evidence” is far smaller than the step from paper.

The third is simply digitalisation catching up with the seam. For decades, enterprise software has automated the inside of the company — the general ledger, the ERP, the close. The relationship between companies has lagged, still riding on emailed PDFs and portal logins and reconciliation spreadsheets. As the tooling for inter-organisational processes matures, the seam is finally getting the attention the inside of the company got a generation ago. Strengthening the evidence at that seam is a natural next move.

What this is really about

It would be easy to file all this under “blockchain for accounting” and move on, and that would be a mistake, because the interesting part is not the technology. The interesting part is a shift in what we treat as evidence.

For five hundred years, the record of a transaction between two companies has been, at bottom, a matter of assertion. You assert your version, they assert theirs, and everyone downstream — auditors, lenders, tax authorities, investors — spends enormous effort testing, sampling, confirming, and reconciling those assertions against each other, precisely because assertions are cheap and mutable and occasionally false. The entire apparatus of assurance is, in large part, a very expensive machine for coping with soft evidence.

Harden the evidence at the source — make the record reporter-independent, tamper-evident, timestamped, and privately linkable, without forcing anyone to give up their commercial confidentiality — and you change the economics of that whole machine. You do not eliminate the need for judgement; you sharpen it, by clearing away the noise of did this even happen the way they say so that human attention can go to the questions that genuinely need a human: is this real, is it valued correctly, does the substance match the form, should I trust the people involved.

The weakest line in every ledger has always been the one where two stories are supposed to meet and don’t quite. We have spent centuries building institutions to manage the gap. It is worth asking, now that the tools exist, whether we can narrow the gap itself — carefully, honestly, and without pretending it closes entirely.

Because the goal was never to remove judgement from finance. The goal was to stop wasting it on questions a good receipt should have answered all along.


If this was useful, consider subscribing — I write about the plumbing of trust in finance: audit, assurance, reconciliation, and the surprisingly deep problem of proving that a thing happened.


← Back to Substack Archive