FohBoh.ai / For the Vendor

You have received a CAAR.
Here is what it is.

Certified Analysis & Audit Report Guide for vendors FohBoh.ai, Inc.

One of your restaurant customers has sent you a Certified Analysis & Audit Report — a CAAR — identifying discrepancies in what they were billed. This page explains what that document is, how it was produced, how to check it yourself, and what a useful response looks like.

It is written for the person who has to evaluate the claim: a billing analyst, an account manager, a controller, or counsel. It is not a sales page.

01What a CAAR is, and who produced it

A CAAR is a reconciliation report. It compares what you billed a customer against two other things: the customer's own transaction records, and the rate schedule in the agreement the two of you signed. Where those three sources disagree, the report says so, states the amount, and cites the specific records the finding rests on.

It was produced by FohBoh | Sentry, an independent certification service the operator uses to audit vendor billing. Nobody at the operator's business calculated the figures, and nobody at FohBoh negotiated them. The report is the output of a fixed rule set applied to sealed data.

That distinction is the reason this document exists rather than a spreadsheet. A spreadsheet from a customer invites a conversation about methodology. A CAAR is designed to make the methodology the least interesting part of the conversation, so the two of you can talk about the money.

02What FohBoh is, and is not

Worth being direct about this, because it changes how you should read the claim.

FohBoh isFohBoh is not
A certification service. It normalizes, reconciles and certifies operational data, and issues a sealed report. Not a debt collector. It does not pursue payment, contact you on the operator's behalf, or take a share of anything you credit.
Paid a fixed fee by the operator for producing the certified report, whether or not you ever pay a cent. Not on contingency. There is no bounty. FohBoh has no financial interest in the size of the finding or the outcome of your discussion.
Independent of both parties, sitting between the operator's systems and their books. Not the operator's agent. The claim is the operator's to make. FohBoh certified the record; it did not file the claim and will not argue it.
Why this should matter to you

An auditor paid a percentage of what it finds has a reason to find more. This one does not — its fee is the same whether the report shows $400 or $40,000, and the same whether you credit the amount or refuse it. If you were preparing to discount the findings as motivated, that argument does not apply here.

03How the numbers were produced

Eight steps, in the same order, every time. The order is the point, because it determines what could and could not have influenced the result.

StepWhat happens
1 · IngestSource data arrives from the operator's systems and from your own statement and settlement files, as issued.
2 · SealEvery file is hashed with SHA-256 the moment it is received — before any analysis runs. This is what establishes that the evidence was not shaped to fit a conclusion.
3 · NormalizeRecords are mapped into a common structure so unlike formats can be compared without altering values.
4 · ReconcileCross-system comparison — point-of-sale against your settlements, settlements against bank deposits, billed rates against the executed schedule.
5 · Apply rulesA governed, versioned rule set executes. The report names the rule behind each finding by its identifier.
6 · ScoreEvidence coverage is measured and a Trust Score is calculated. See section 05.
7 · Narrative sealThe written findings are generated from the results and sealed with their own hash.
8 · IssueThe report is released with its hash, its rule versions, and its evidence manifest attached.

No artificial intelligence is involved in the calculations.

The engine is deterministic. It has no model, no inference, no sampling, no extrapolation and no estimation in the variance calculations. Given the same inputs and the same rule version, it returns the same result — the same figures, and the same hash. That property is what makes the report reproducible rather than merely plausible, and it means "the model got it wrong" is not an available explanation for a discrepancy.

Findings are stated at the level the underlying data supports: individual transactions, individual batches, individual orders. Where a report states a count — thirty-four batches, four hundred and seventeen pickup orders — every one of them is identified in the evidence manifest.

04Reading the report

Every CAAR carries the same structure. If you review more than one, the second takes a fraction of the time.

SectionWhat you will find, and what to do with it
CoverThe CAAR identifier, the entity, the period, the module, the total certified recoverable amount, and the Trust Score. Quote the CAAR identifier in every reply — it is how both sides stay on the same document.
Chain of custodyEach source file, when it was received, and its hash at receipt. Check the files listed are the ones you issued.
FindingsOne entry per discrepancy: what was billed, what the agreement provides for, the difference, the rule that fired, and the records involved. This is where a disagreement should be aimed.
Contract basisThe specific provisions each finding is measured against, as loaded from the executed agreement. If you believe an amendment supersedes one, this is the section to address.
Evidence manifestEvery source record, by identifier. This is how a stated count becomes checkable.
SealThe SHA-256 hash of the final document, the rule-set version, and the timestamp of issue.

A practical note: the certified recoverable amount on the cover is a calculation under the stated rules and evidence. It is not an invoice, and it is not an assertion that a court has decided anything. It is the number the record supports.

05The Trust Score, and why you only see certified reports

Every run produces a Trust Score from 0 to 100. It measures evidence coverage — how much of the data needed to check a finding was actually present — rather than confidence in the conclusion. A run with gaps scores lower, and the report names each gap.

85–100Certified. A CAAR is issued. Evidence coverage was complete enough to stand behind the figures. This is the only tier you will ever receive.
75–84Validated. A sealed report is issued to the operator listing every evidence gap and how to close it — but no CAAR, and no certified amount.
0–74Reviewed. A sealed report is issued to the operator with the gaps itemised. Again no CAAR, and no certified amount.

The consequence is worth stating plainly: if the evidence had been thin, you would not be holding this document. A run that cannot be certified never becomes a CAAR. The operator receives it, sees exactly what was missing, and either closes the gap and runs again or lets it go. Nothing reaches you until the coverage threshold is met.

So the Trust Score on your cover page is not a hedge. It is the residue of a gate the run had to pass before the report existed.

06The record is fixed at issue

A CAAR is sealed at the moment it is generated. Its hash is computed over the final rendered document, and the document is written to an append-only vault under storage-level retention controls. From that point forward it cannot be edited — not by the operator, not by their accountant, not by FohBoh, and not by anyone who later wishes the number were different.

The same applies to the source evidence. Each file was hashed at receipt, before any rule ran, so the inputs are as fixed as the output.

Two things follow, and they cut in both directions.

  • The version in your inbox is the version that persists. If this discussion is still running in eighteen months, in front of an auditor or in a proceeding, the document produced will be byte-for-byte the one you are reading now. There is no later, softer revision to wait for.
  • The same permanence protects you. The operator cannot quietly enlarge a finding after you have responded, add a discrepancy that was not in the original run, or produce a differently-worded version of the report that suits them better. If they want to change the figures, they have to run a new certification — which gets a new identifier, a new hash, and a visible relationship to this one.
Practical consequence

If you re-save, re-export, or print the attached PDF to a new file, the hash will no longer match — not because anything was falsified, but because the bytes changed. Keep the original file as received. If you need to circulate it internally, forward it rather than re-generating it.

07Verifying it yourself

You do not have to take the seal on faith, and you do not need anything from FohBoh to check it. The hash is printed on the report. Compute it on the file you received and compare.

Confirming the seal

macOS or Linux:

shasum -a 256 CAAR-M02-2026-07-000418.pdf

Windows PowerShell:

Get-FileHash -Algorithm SHA256 .\CAAR-M02-2026-07-000418.pdf

The value returned should match the SHA-256 printed in the report's seal section, character for character. If it matches, the document is exactly as issued. If it does not, the file has been altered or re-saved somewhere between issue and your inbox — ask the operator for the original.

Verifying the seal confirms integrity: that this is the document that was issued, unchanged. It does not, on its own, mean you agree with the findings — that is what section 10 is for. But it does remove one whole category of argument from the table, which is usually in everyone's interest.

08Why the rules of evidence matter here

Not because anyone wants a courtroom. Because the way this document is built determines how much of a conversation there is left to have — and it is worth knowing what your counsel will see when you forward it to them.

RuleWhat it does here
FRE 803(6)
Business records
The underlying records — your settlement or statement files, the operator's point-of-sale export — are records of a regularly conducted activity. They are the foundation everything else rests on.
FRE 902(13)
Self-authentication
The report is a record generated by an electronic process that produces an accurate result, accompanied by a written certification. Authenticity does not require a live witness. Nobody has to be produced to say the document is what it says it is.
FRE 902(14)
Hashed copies
Every source file in the pack is a copy authenticated by digital identification — the SHA-256 taken at receipt. This is the rule the hashing in section 07 is built for.
FRE 1006
Summaries
A calculation proving the content of voluminous records that cannot conveniently be examined. Since the rule was amended on December 1, 2024, such a summary is admitted as substantive evidence — not as a demonstrative aid — whether or not the underlying records are separately introduced.
The part that concerns you directly

Rule 1006(b) requires the party offering a summary to make the underlying records available to the other side. That obligation is the most common reason summaries get excluded — people produce the chart and not the data.

The evidence pack described in the next section is that tender, prepared in advance. Whatever else happens, the underlying set is already assembled and available to you. If your figures differ from the report's, you have everything needed to demonstrate it.

None of this means a finding is correct, and none of it decides whether anything is owed. It means the argument, if there is one, will be about the numbers and the contract rather than about whether the document can be trusted to say what it says.

09The evidence pack

Alongside the CAAR, the operator can provide the complete evidence pack: every source record the reconciliation relied on, sealed, with the manifest that ties each one to the findings it supports. That includes your own settlement and statement files exactly as you issued them. This is the set contemplated by Rule 1006(b) — assembled before anyone asked for it.

The pack exists so your team can reproduce the calculation independently. If your figure differs from the report's, working through the pack will show where the two diverge — a different denominator, a different effective date, a rate table that was never loaded, an amendment that was not provided. In practice that is where most disagreements actually live, and finding it is faster than exchanging positions.

If you have received the CAAR but not the pack, ask the operator for it. If you are being escalated to, you have probably received both.

10Responding well

What makes a response useful, from the perspective of getting this closed:

  • Reference the finding, not the report. Findings are numbered. A response that addresses finding 4 specifically moves things forward; one that addresses "the claim" does not.
  • If a document supersedes the contract basis, send it. An amended addendum or a countersigned tier change resolves a finding immediately if it exists — and if it was never provided to the operator, it could not have been loaded.
  • If your own records differ, say where. Give the transaction, batch or order identifiers. The manifest makes them directly comparable.
  • If a finding is correct, credit it and set it aside. Partial resolution is normal. Most CAARs contain a mix, and separating the agreed items from the disputed ones shrinks the conversation quickly.

What does not work

A general denial, a restatement of policy, or a referral to a self-service portal will not close a certified claim. The record is specific, so a non-specific response leaves the operator with nothing to evaluate — and it is itself preserved in the claim file, which is not a pattern that reads well later. Operators track rejections; a third one typically moves the matter to outside counsel with the sealed pack attached, which is a worse outcome for both sides than a substantive reply now.

11If you disagree

Disagreeing with a CAAR is entirely reasonable, and the document is built to make a real disagreement legible. There are only a few places one can live:

Where the dispute sitsHow to resolve it
The contract basis is wrongAn amendment, addendum or schedule change was in force and was not loaded. Provide the executed document with its effective date.
The source data is incompleteA file you issued was missing or partial. Identify it; the chain-of-custody section lists exactly what was received.
The interpretation is contestedYou read a provision differently — which base commission applies to, what counts as a qualifying transaction. State your reading and cite the clause. This is a genuine dispute and the record does not pretend to settle it.
The arithmetic is wrongRare, and checkable. Reproduce it from the pack and show the divergence. If a rule is defective, that matters well beyond this one claim and FohBoh will want to know.

Notice what is not on that list: whether the numbers were assembled honestly, whether the evidence was selected to suit the conclusion, and whether the document has been altered since issue. Those are the arguments the seal and the pre-analysis hashing are designed to retire, so that the remaining conversation is about substance.

12What a CAAR does not claim

Being precise about the limits is part of the document being trustworthy.

  • It is not a legal opinion, and it is not an independent audit under any auditing standard.
  • It does not adjudicate liability. A certified recoverable amount is a calculation under stated rules and evidence, not a determination that you owe it.
  • It does not guarantee admissibility. The report is structured so that authenticity does not require a live witness, which is a narrower thing. Admissibility and evidentiary weight are decided by a court on the facts, the forum and the applicable rules — not by FohBoh. Foundation for a summary under Rule 1006 is a separate question from authentication, and a custodian declaration describing how the report was produced is available on request.
  • It does not certify your systems, your compliance, or your conduct. It certifies a reconciliation of defined data against defined terms, for one period.
  • It cannot certify what it was not given. Certification attaches to the data in scope. Records that were never provided are outside it, and the report says which.

13Questions

Questions about the claim — the amount, the credit, the timing — go to the operator. It is their claim, and FohBoh will not discuss it on their behalf or intervene in it.

Questions about the methodology — how a rule works, what a Trust Score band means, how to verify a seal, how to reproduce a figure from the pack — can come to FohBoh directly at certification@fohboh.com. We will answer them for either party, because a methodology that only one side understands is not much of a standard.

If you would like to see the structure of a CAAR before yours arrives, there is an example report published in full.