Red Flag Report
Executive Summary
Key Takeaways
- ✓ A red flag report is a rapid, scope-limited assessment of a financial model that identifies critical and significant issues without conducting a full audit.
- ✓ It is appropriate for time-sensitive decision-making, internal screening, and preliminary due diligence.
- ✓ It is not appropriate as a substitute for a full audit where formal independent assurance is required.
- ✓ Scope limitations must be clearly disclosed to all readers.
- ✓ A red flag report does not produce a model audit certificate.
- ✓ Findings should be specific and actionable, not vague.
Definition¶
A red flag report is a rapid, high-level assessment of a financial model designed to identify critical or significant issues without conducting a full, exhaustive independent audit. It provides a targeted view of whether a model contains material errors, structural weaknesses, or significant limitations that would affect its fitness for a specific purpose — typically a pending investment decision, a financing transaction, or a commercial negotiation.
A red flag report is sometimes called a preliminary model review, a model health check, or a model screening assessment. The defining characteristic is scope limitation: it is a rapid review that identifies significant issues, not a comprehensive verification of every formula and reference.
Why It Matters¶
Full independent model audits take time — days to weeks depending on model complexity. In time-sensitive transactions (M&A negotiations, lender deadline-driven processes, bid submissions), there is not always time to complete a full audit before a decision must be made or a document must be submitted.
A red flag report addresses this gap. By focusing the reviewer's attention on the most likely locations of material error — structural consistency, key outputs, critical formulas, and obvious anomalies — a red flag review can provide meaningful assurance within a fraction of the time required for a full audit.
However, a red flag report has important limitations that both the commissioner and the users of the report must understand:
- It does not constitute a full independent verification
- It may not identify all material errors
- It should not be presented to third parties as equivalent to a full model audit
- It does not provide a basis for a model audit certificate as a condition precedent to financial close
A red flag report is an appropriate tool for internal decision-making, rapid due diligence screening, and bid-stage model assessment. It is not appropriate as a substitute for a full audit in a transaction requiring formal independent assurance.
Technical Background¶
Typical Scope of a Red Flag Report¶
A red flag review typically focuses on the following areas:
| Review Area | What Is Checked |
|---|---|
| Balance sheet integrity | Do the three financial statements integrate and balance? |
| Formula errors | Are there visible formula errors (#REF!, #VALUE!, #DIV/0!, #NAME?) in any cells? |
| Circular references | Does the model contain unresolved or undisclosed circular references? |
| Key outputs spot-check | Can the key outputs (DSCR, IRR, NPV) be manually verified at one or two points? |
| Hardcoded numbers | Are there visible hardcoded numbers in formula-dense calculation sections? |
| Assumption disclosures | Are key assumptions clearly disclosed and internally consistent? |
| Model structure | Is the model structure logical and does it appear to follow the intended economic structure of the transaction? |
| Sensitivity analysis | Is sensitivity analysis present for key assumptions? |
| Broken links | Are there references to external files that are not available? |
What is typically not included in a red flag review:
- Verification of every formula across the full model
- Complete output recalculation
- Detailed cross-referencing of assumptions against source documents
- Comprehensive audit trail review
- Assessment of the commercial reasonableness of assumptions
Red Flag Report vs Full Audit¶
| Characteristic | Red Flag Report | Full Model Audit |
|---|---|---|
| Scope | Targeted; key areas only | Comprehensive; all formula rows |
| Duration | Hours to 1–2 days | Days to weeks |
| Output | Summary of issues identified | Complete findings report; certificate where applicable |
| Coverage | Material issues likely identified; minor issues may be missed | All material and minor findings identified |
| Third-party reliance | Not appropriate as sole basis | Appropriate for lender CP; investment committee |
| Cost | Lower | Higher |
When to Use a Red Flag Report¶
Red flag reports are appropriate when:
- Time does not permit a full audit before a decision must be made
- The purpose is internal screening rather than third-party assurance
- A preliminary view is needed to decide whether a full audit should be commissioned
- A model has been received from a counterparty and a rapid assessment of its reliability is needed before relying on it in negotiations
- A model has been updated since a prior full audit and a quick check of the changes is required
Findings in a Red Flag Report¶
Because a red flag report does not verify every formula, the findings framework is typically simpler than for a full audit:
| Classification | Description |
|---|---|
| Critical | Issue that materially affects key outputs or indicates a structural model failure |
| Significant | Issue that is notable and should be investigated, but whose materiality cannot be confirmed without further analysis |
| Observation | Note on model quality, structure, or best practice that does not indicate a material error |
The absence of a finding in a red flag report does not confirm that no issue exists in that area — only that no issue was identified within the scope of the review.
Communicating Scope Limitations¶
The most important governance aspect of a red flag report is clearly communicating its scope limitations to all readers. The report should state:
- What was reviewed and what was not
- That the review is not equivalent to a full independent audit
- That material errors may exist that were not identified within the review scope
- How the report should and should not be used
Failure to communicate these limitations creates a risk that recipients will over-rely on the report — treating it as equivalent to full assurance when it is not.
Audit Considerations¶
1. Define Scope Before Starting¶
Agree the scope of the red flag review with the client before beginning. The scope should specify which areas will be reviewed and which will not. This prevents misunderstanding about what the review does and does not cover.
2. Focus on Highest-Risk Areas First¶
A well-executed red flag review prioritises the areas most likely to contain material errors in this type of model. For a project finance model, this means: three statement balance, DSCR calculation, debt schedule mechanics, and key revenue assumptions. For a corporate DCF, this means: revenue growth assumptions, terminal value calculation, WACC inputs, and discount rate application.
3. Document What Was Not Reviewed¶
The report must be clear about what was not reviewed, not only what was. A recipient reading only the findings section may not appreciate the scope limitations unless they are prominently stated.
4. Escalation Protocol¶
If the red flag review identifies a critical finding early in the process, the reviewer should consider whether this indicates that a full audit is required before any reliance can be placed on the model — and communicate this recommendation clearly.
5. No Certificate¶
A red flag report does not produce a model audit certificate. If the subsequent process requires a certificate (for example, as a condition precedent to financial close), a full audit must be conducted.
Common Errors¶
| Error | Description | Risk |
|---|---|---|
| Scope not defined | Review begins without agreed scope | Reviewer and client have different expectations about what was covered |
| Limitations not disclosed | Report does not state what was not reviewed | Recipient over-relies on the report |
| Presented as equivalent to full audit | Red flag report submitted to lenders as a condition precedent document | Lenders granted assurance that was not provided |
| No escalation when critical finding identified | Critical finding noted without recommendation for full review | Client proceeds with a model that is materially unreliable |
| Findings too vague | Report lists "concerns" without specific cell references or quantification | Client cannot action the findings |
Best Practices¶
State the scope of the red flag review on the cover page of the report, before the findings. Readers should understand what they are reading before they read the findings, not after.
Quantify critical findings where possible. A finding that says "the DSCR calculation appears to exclude commitment fees from debt service" is actionable. A finding that says "there may be issues with the DSCR calculation" is not.
Include a clear statement of recommended next steps. If the red flag review identifies issues that warrant a full audit, recommend it explicitly and explain why.
Continue Reading¶
Prerequisites¶
- What Is a Financial Model Audit? — the parent pillar
Related Pillars¶
Related Technical Guides¶
Related Glossary¶
How OXXON tests thisRun a free structural check with FMAE
Frequently Asked Questions
How long does a red flag review take?
A basic red flag review of a moderately complex financial model can be completed in 4 to 8 hours. A more comprehensive red flag review of a complex project finance model may take 1 to 2 days. The scope definition determines the time requirement.
Can a red flag report be used in court or regulatory proceedings?
This depends on the nature of the proceedings and the scope of the report. A red flag report that clearly states it is not a comprehensive audit cannot be relied upon as evidence of full model verification. Legal and regulatory reliance on model review reports should be assessed by qualified legal advisers.
Who commissions a red flag report?
Red flag reports are typically commissioned by: the party receiving a model from a counterparty (to assess reliability before relying on it); a buy-side due diligence team (to screen a target's financial model); a project company before committing to a full lender-required audit (to identify issues that need to be fixed); or an investment committee seeking rapid assurance before a conditional approval.
Is a red flag report always cheaper than a full audit?
Yes, because its scope is narrower. However, the appropriate choice between a red flag report and a full audit should be driven by the purpose and the reliance being placed on the review, not solely by cost. Using a red flag report where a full audit is required to save cost, and then relying on it as if it were a full audit, creates more risk than the cost saving justifies.
Related Articles
Audit Methodologies for Financial Models
Financial model audit methodologies fall into three primary categories: manual line-by-line review, automated structural analysis, and deterministic rule-based checking. Each methodology differs in scope, speed, consistency, and the types of errors it is designed to detect. The appropriate methodology depends on transaction complexity, time constraints, and institutional risk appetite.
Model Materiality
Model materiality is the threshold at which an error, deviation, limitation, or uncertainty in a financial model is considered significant enough to affect a decision, require remediation, or warrant disclosure. A finding is material if, had it been known, it would or could have changed a decision made using the model's outputs. Model materiality is a judgement — it depends on the purpose of the model, the magnitude of the finding, and the sensitivity of the key outputs to the finding. The same error may be material in one context and immaterial in another.
Model Audit Certificate
A model audit certificate (also referred to as a model audit report or model assurance certificate) is a formal written document issued by an independent auditor or model review firm confirming that a financial model has been independently reviewed, describing the scope of the review, identifying findings, and providing a level of assurance about the model's arithmetical accuracy and internal consistency. In project finance, a model audit certificate is typically a condition precedent (CP) to financial close, meaning that lenders will not fund the first drawdown until the certificate has been delivered by an approved independent reviewer.
What Is Model Risk?
Model risk is the risk that a decision is wrong not because the underlying business or investment case was flawed, but because the model used to evaluate it was. It is a distinct category of risk from market risk, credit risk, or operational risk, and it applies to any organisation that relies on a financial model, spreadsheet or otherwise, to support a material decision. Most published model risk content addresses statistical and regulatory capital models used inside banks. This page defines model risk specifically as it applies to Excel based financial models, the kind used every day for investment decisions, lending, and transaction evaluation, which is a related but distinct problem from the quantitative model risk literature most search results return.
What Is a Financial Model Audit?
A financial model audit is an independent, structured examination of an Excel based financial model to confirm that its mechanics, logic, and outputs are reliable enough to support a decision. It is not a check of whether the assumptions are optimistic or conservative. It is a check of whether the model actually calculates what its author believes it calculates. Every year, lenders extend debt, investment committees approve capital, and boards sign off on transactions using numbers that came out of a spreadsheet nobody outside the immediate deal team has independently verified. A financial model audit exists to close that gap before it becomes expensive.
Dependency Analysis in Financial Models
Dependency analysis in financial models is the process of mapping the relationships between input cells and output cells to determine which inputs drive which outputs and by how much. A dependency map shows, for any given cell, which cells it depends upon (its precedents) and which cells depend upon it (its dependents). In a model audit or risk assessment context, dependency analysis is used to identify the inputs that have the greatest influence on key outputs, to verify that the dependency structure matches the model's intended design, and to detect structural anomalies such as outputs that are unexpectedly disconnected from their intended inputs.