Web Project StudiosSilent failure audits

Silent Failure Audit · for UK and EU regulated businesses

I find the automated jobs that say they worked, and didn't.

VAT returns, e-invoices, GDPR deletion jobs, data pipelines. In five days I check that each one actually ran and produced what it should. Fixed fee. Written report.

“Most broken systems still report healthy.”

Monitoring catches errors. It can't catch a job that quietly did nothing.

Takes
5 working days
Costs
£1,500–£3,000 fixed
Access
Read-only
You get
A written report

The difference, in one picture

Your dashboard says everything ran. The audit checks whether it did.

Switch between the two views. The jobs are the same, and none of them ever raised an error.

Scheduled jobs, last quarter

Illustrative example

  • VAT return (MTD)QuarterlyDashboard saysCompletedActuallyNot checked
  • E-invoice batch (KSeF)NightlyDashboard saysCompletedActuallyNot checked
  • GDPR erasure jobNightlyDashboard saysCompletedActuallyNot checked
  • Payroll exportMonthlyDashboard saysCompletedActuallyNot checked
  • Audit log exportHourlyDashboard saysCompletedActuallyNot checked
5 of 5 jobs healthy

How it works

Three steps. No jargon.

  1. 1

    You tell me what runs on its own.

    A 15-minute call about the jobs nobody watches: filings, submissions, deletion jobs, reports, and the syncs between your systems.

  2. 2

    I check each one actually happened.

    Two questions for every process. Did it run when it should have? Did it produce what it should have? I only need read access, and nothing in production is changed.

  3. 3

    You get a written list.

    What ran, what didn't, what came out empty, and what each gap exposes you to. Ranked by risk, so a missed filing sits above a stopped log export.

What I check

If it runs without a person watching, it's in scope.

  • VAT returns (MTD)

    It says
    Completed
    I check
    Was a receipt returned for every quarter?
  • E-invoicing (KSeF, EU mandates)

    It says
    Batch sent
    I check
    Did every invoice get an ID back from the tax portal?
  • GDPR deletion and retention

    It says
    Success
    I check
    Were any records actually deleted?
  • Statutory filings (CT600, Companies House)

    It says
    Submitted
    I check
    Did the filing land and get accepted?
  • Data pipelines and reports

    It says
    Finished
    I check
    Is the output there, and is it a sensible size?
  • Integrations and syncs

    It says
    200 OK
    I check
    Did the other system actually receive it?

Why nobody notices

Monitoring watches for errors. A job that never starts doesn't make one.

Monitoring alerts you when something throws an error. A job that never starts throws nothing. A job that runs and processes zero records finishes "successfully". So the dashboard stays green, and the problem turns up months later as a penalty, a failed audit or a number nobody can explain.

  • 01Green means "no errors"

    It doesn't mean the work got done. Those are two different measurements, and almost nobody takes the second one.

  • 02Nothing checks the output

    A job can finish cleanly and produce an empty file. Unless something checks the file, that counts as a pass.

  • 03It compounds quietly

    A loud failure is fixed the same day. A silent one runs on for as long as it takes someone to notice.

What you get

One document. Every unattended process. A clear answer for each.

Findings, ranked by exposure

Illustrative example

  1. HighVAT return: no run recorded for Q3 or Q4Two statutory filings missed
  2. HighRetention job: 0 records erased since FebruaryPersonal data held past policy
  3. MediumAudit log export: empty file for 41 daysGap in the audit trail
  4. OKPayroll export: running, output as expectedNo action needed
Duration
5 working days
Fee
£1,500 for one area, £3,000 for a full sweep. Fixed.
Access
Read-only, removed at the end
Changes to your systems
None
Deliverable
Written findings and a one-hour walkthrough call
If nothing is wrong
The report says so, in writing. Same fee.

Who it's for

For the person whose name is on the filing.

Finance directors

You sign the VAT return, and you're trusting a job you can't see.

Compliance and data protection leads

Your retention policy says personal data is deleted on time. Is it?

CTOs and heads of engineering

You inherited years of scheduled jobs. Which ones still do anything?

  • Financial services and insurance
  • Businesses under e-invoicing mandates
  • UK statutory filers
  • PE-backed businesses before a sale

Who you'll work with

One person. 25 years of building these systems.

Web Project Studios is me, not an agency. I've spent 25 years building and fixing .NET and Azure systems, around 10 of them leading the teams that build them, much of it in regulated domains where the audit trail matters as much as the feature. I found this problem in my own unattended pipelines: a job that had reported success for weeks without running once.

More about me

Where this comes from

  • doFaktur.pl

    E-invoicing under Poland's KSeF mandate

    An invoicing product built against a national e-invoicing regime, where a submission that reports success and never lands is a compliance problem, not a bug.

    dofaktur.pl
  • Government filing integrations

    HMRC and Companies House APIs

    Integration work against Making Tax Digital, corporation tax returns and Companies House. The same failure mode, with a deadline attached to every one.

  • Unattended pipelines

    Scheduled multi-stage automation

    Pipelines that run on a schedule with nobody watching, built with approval gates, CI and monitoring. Running these is how I found the failure this practice is built around.

Common questions

The questions I hear most.

What does the first engagement look like?

The Silent Failure Audit. Five working days, read-only, and a fixed fee: £1,500 for one process area, £3,000 for a full sweep. You get a written findings document listing what should have run, what actually did, what produced output, and the exposure attached to anything that didn't.

We already have monitoring and alerting.

Almost everyone does, and it's usually good at what it's built for. But alerting is triggered by something going wrong. A process that never starts doesn't go wrong, it just doesn't happen, so it raises nothing and appears nowhere. That's the specific gap this looks at, and it's a design characteristic of the tooling rather than a failure to configure it properly.

What if you don't find anything?

Then the report says so and you have that in writing, which is worth something on its own if you're heading into an audit or a sale. I'd rather tell you it's fine than manufacture a finding. The fee is the same either way, which is deliberate.

How much access do you need?

Read access to scheduler and execution history, logs, and enough of the output side to check that things landed. No write access, and no production changes during an audit. If access takes time to arrange I'll scope around what's available.

Is this only for regulated businesses?

No, but that's where it pays for itself fastest, because the cost of a process that silently stopped is a penalty or a failed audit rather than an internal annoyance. If nothing you run unattended carries that weight, this is probably not urgent for you and I'll say so.

Start with the audit

How would you know if it stopped?

Pick the process you'd least like to have quietly failed. If you can't say how you'd find out, that's the one to check first.

Check my systems

Five days, fixed fee. You get a written findings document.

Currently working with a small number of clients.