kyslan

Kyslan / Library

Checklist

The MSP billing audit checklist

Updated 27 August 2026 · 9 min read · By Kyslan, a Northbeams product

The short answer

A billing audit reconciles three sources that normally never meet: the agreements in your PSA, the reality in your RMM and directory, and the invoices you actually raised. Fourteen checks cover the ground: seats, devices, zero-time tickets, non-billable flags, block balances, out of hours rates, onboarding fees, licence counts, completed projects, annual uplifts and contract dates. Run them over 90 days, price every finding annually, then decide for each one whether to recover backwards or correct forwards.

Kyslan finds the unbilled work in your own PSA, then writes the change order that bills it. First report free, read-only. Claim it back →

Before you start

An audit that produces a spreadsheet nobody acts on has cost you a day and returned nothing. Three decisions before the first query:

  1. Fix the period. Ninety days is the right window: long enough that patterns show, recent enough that clients remember the work.
  2. Name the owner. One person who will price the findings and decide what happens to each one. Not a team.
  3. Agree the recovery policy up front. Deciding case by case, after you have seen the amounts, turns every finding into a debate. Decide now: inside the current quarter, recover with evidence. Older than that, correct forward.

The fourteen checks

In this order. The early ones are the largest and the cleanest to act on.

1. Pull the three sources

Export agreements from the PSA, endpoint and user counts from the RMM or directory, and every invoice raised in the period from the accounting system. All three must cover the same date range or nothing that follows is comparable.

2. Reconcile contracted seats against real users

Compare active user accounts in the client directory against the seats on their agreement. Any difference above one is a finding. Record the count difference and multiply by the seat price for the annual value.

3. Reconcile contracted devices against deployed agents

Compare RMM agent counts by device class against contracted devices. Exclude decommissioned assets, then list every managed device that is not on an agreement.

4. Find closed tickets with no time entry

List closed tickets in the period with zero logged time, grouped by engineer and ticket type. These are delivered work with no record, and no record can be billed.

5. Find billable work closed as non-billable

List non-billable hours by ticket type and by engineer. Look for a ticket type or a board whose default flag is wrong, which is more often the cause than individual discipline.

6. Check every prepaid block balance

List every block of hours with its remaining balance. Flag anything at or below zero, anything below 20% remaining, and any expired block still receiving time entries.

7. Check out of hours work against the premium rate

Filter time entries with a start time outside contracted hours and check the rate applied. Any at the standard rate is under-billed by the difference.

8. Check onboarding and offboarding fees

Count new user and leaver tickets per client, then check the matching setup and removal fees were invoiced.

9. Reconcile licence counts against the vendor portal

Compare licence seats billed by your vendor against licence seats invoiced to the client, per client, per month. Drift here is monthly and almost always in the client's favour.

10. Find completed projects with no final invoice

List projects marked complete with no invoice raised in the following 30 days, and check fixed-price milestones against the billing schedule.

11. Check annual uplifts

List every agreement with an uplift clause and the date it was last applied. Anything over 13 months is overdue and the arrears compound because the base never caught up.

12. Check contract dates

List agreements that expired in the last 90 days or expire in the next 90. Expired and still delivering is a revenue risk, expired and still billing is a legal one.

13. Price every finding

Convert each finding into an annual figure. A monthly seat gap is the gap times the seat price times twelve, not a one-off. Sort the list by annual value, largest first.

14. Decide recover back or correct forward

For each finding, decide whether to invoice retrospectively with evidence attached, or to correct the agreement from next month. Anything inside the current quarter is usually worth recovering. Older items are usually worth correcting forward.

The two checks people skip

Numbers 11 and 12, uplifts and contract dates, get skipped because they are contractual rather than operational and feel like somebody else's job. They are also the two with the longest tail: a missed uplift compounds every year afterwards, and an expired agreement still being served is an exposure that grows quietly until something goes wrong and someone asks what the contract says.

What a finding needs to contain

A finding that cannot be handed to a client is not finished. Each one needs:

How often to run it

CadenceWhat it catchesWhat it misses
WeeklyBlock balances, zero-time tickets, non-billable flagsNothing, if the queries are automated
Monthly, before invoicingSeats, devices, licence counts, out of hours ratesLittle. This is the minimum that holds
QuarterlyProjects, uplifts, contract datesTwo months of seat drift, every quarter
AnnuallyRoughly half of it, badlyMost of it, and too late to invoice what it finds

The practical answer is monthly before the invoice run for checks 2, 3, 6, 7 and 9, weekly for 4, 5 and 6, and quarterly for the contractual ones. Annual audits find money that is by then too old to ask for, which is the worst possible outcome: all of the discomfort of discovering the loss, none of the recovery.

Automating it

Every check here is a query, and every one of them needs a join across agreements, tickets, time entries, invoices and projects. That is why they do not get run by hand for long: the first pass is interesting, the fourth is a chore, and by the second quarter it is on someone's list and not in their week.

Platform-specific notes: ConnectWise Manage, HaloPSA, Autotask PSA.

Kyslan runs all fourteen against your PSA with a read-only key, prices each finding annually, and re-scans every week so new gaps are caught while they are still easy to invoice. The first audit is free and there is a sample report if you would rather see the output before connecting anything.

Common questions

What is an MSP billing audit?

A billing audit reconciles three records that normally never meet: the agreements held in the PSA, the actual users and devices being served according to the RMM or directory, and the invoices actually raised. The output is a list of work delivered and never billed, priced and evidenced, so each item can either be invoiced retrospectively or corrected on the agreement going forward.

How long does an MSP billing audit take?

Run by hand across a 90 day window, expect roughly half a day to a full day for a book of twenty to thirty clients, most of it spent joining data across agreements, tickets, time entries and invoices rather than reading results. The first run is the slow one. Automated, the same fourteen checks run in minutes and can be scheduled weekly.

How far back should an MSP billing audit look?

Ninety days is the practical window. It is long enough for patterns to be visible and recent enough that clients still recognise the work when you show them the tickets. Going back a full year finds more money but most of it is too old to invoice without an argument, so older findings are usually better used to correct the agreement going forward.

Should I bill a client for work found in an audit?

For anything in the current quarter, yes, with the ticket numbers and time entries attached and framed as a correction rather than a dispute. For older work, correcting the agreement from next month is usually worth more than the retrospective invoice, because a recurring gap corrected today pays every month afterwards and costs no goodwill.

How often should an MSP audit its billing?

Monthly, immediately before the invoice run, is the minimum that holds. Block balances, zero-time tickets and non-billable flags are worth checking weekly. Contractual checks such as annual uplifts and expiry dates can run quarterly. Annual audits find money that has aged past the point where it can comfortably be invoiced.

Keep reading

See your own number, then send the invoice for it

Kyslan reads 90 days of your tickets, time entries and contracts, finds the work you delivered and never billed, then writes the change order that puts it back on the invoice. Read only, nothing installed, first report free.

Claim it back

Free · read-only key · no card · HaloPSA, ConnectWise Manage, Autotask PSA or a CSV export