Auditing a general ledger means working through a defined sequence: plan the engagement and set materiality, reconcile the subledgers to the trial balance, evaluate internal controls, sample and test transactions, scrutinize journal entries for signs of management override, substantively test the high-risk account balances, confirm key items with outside parties, evaluate what has happened since the balance sheet date, obtain written representations from management, and aggregate everything into an opinion. Each step exists because the numbers on the financial statements have to be defensible to the investors, lenders, and regulators who rely on them.1U.S. Securities and Exchange Commission. All About Auditors: What Investors Need to Know The rest of this article walks through those steps in the order an auditor performs them.
Plan the Engagement and Set Materiality
Planning is where the audit strategy is built. The audit team identifies the significant accounts and disclosures, assesses where the financial statements are most likely to contain a material misstatement, and decides how much work each area of the general ledger will require.2PCAOB. AS 2101: Audit Planning
The central number that comes out of planning is materiality. Materiality is the dollar threshold above which a misstatement could influence the decisions of someone relying on the financial statements. Auditors typically derive it from a percentage of a benchmark such as revenue, total assets, or pre-tax income.3PCAOB. AS 2105: Consideration of Materiality in Planning and Performing an Audit Misstatements below that threshold are tracked but not necessarily corrected. Misstatements above it must be fixed before a clean opinion can be issued.
Planning also includes analytical procedures. The auditor compares current-year balances to prior-year figures, budgets, and industry benchmarks. A revenue account that jumped 30 percent while the industry grew 5 percent draws scrutiny. An expense account that dropped without an obvious operational reason gets flagged. Those comparisons steer attention toward the accounts most likely to contain errors, and the resulting risk assessment drives sample sizes and the depth of testing everywhere downstream.
Gather Records and System Access
Before fieldwork begins, the auditor sends a Provided By Client (PBC) list that spells out every document and data file needed. A typical PBC package covers bank statements and reconciliations, the accounts receivable aging report, the accounts payable subledger, a fixed asset register with acquisition dates and depreciation calculations, accrued payroll schedules, copies of debt agreements with amortization tables, and all board minutes for the period under review. Companies holding investments or receiving grants will also see requests for annual statements and grant-level expenditure detail.
Beyond documents, auditors need electronic access to the accounting system or ERP: read-only login credentials, a user access matrix showing who can do what, and segregation-of-duties reports that flag conflicting permissions. They also want automated audit trails for financial transactions, showing what changed, when, and who approved it. Chasing down any of these items after fieldwork starts is the single most common cause of audit delays and fee overruns.
Reconcile Subledgers to the Trial Balance
The starting condition for any GL audit is a trial balance where total debits equal total credits. That is only the first check. The trial balance is only as reliable as the subsidiary ledgers feeding it, so the detailed accounts receivable aging must tie to the penny to the AR control account in the general ledger. Same for accounts payable, inventory, and every other subledger. A difference between a subledger and its control account is treated as a red flag and forces expanded testing.
High-risk and complex accounts need supporting schedules that walk from individual transactions up to the aggregated balance. A fixed asset schedule lists each asset, when it was acquired, its original cost, its useful life, the depreciation method, and the current-year depreciation expense. Accrued liability schedules show the methodology behind each estimate, whether that’s accrued payroll based on days worked after the last pay date or a warranty reserve calculated from historical claim rates. The auditor will challenge the assumptions, so they need to be documented before anyone asks.
Manual journal entries recorded near period-end deserve their own attention. Every one should carry a description that explains what the entry does and why it was necessary, along with supporting documents like contracts, invoices, or calculation worksheets. Entries with thin explanations are the first ones auditors pull.
Evaluate Internal Controls and Segregation of Duties
Auditors evaluate the control environment before deciding how much substantive testing to perform. Weak controls mean larger samples and more hours. Strong controls let the auditor reduce sample sizes and lean more on the system itself.
Segregation of duties is scrutinized most closely in the journal entry process. The person who enters a journal entry should not be the person who approves it. Someone who creates a vendor payment voucher should not have authority to approve journal entries, because that combination could allow fabricated expenses to flow through unchallenged. Smaller organizations where true segregation is impractical rely on compensating controls, such as mandatory management review of all entries above a dollar threshold. Compensating controls only help if the auditor can see them being applied, so the review has to be documented.
For a public company, the internal control environment carries additional weight under Section 404 of the Sarbanes-Oxley Act, and for large accelerated and accelerated filers the external auditor issues a separate opinion on internal controls over financial reporting integrated with the financial statement audit.4PCAOB. AS 2201: An Audit of Internal Control Over Financial Reporting5GovInfo. Sarbanes-Oxley Act of 2002 Private companies don’t get an ICFR opinion, but their auditors still document and test controls as part of the risk assessment.
Sample and Test Transactions
Auditors can’t examine every transaction in the ledger, so they sample. Statistical methods like Monetary Unit Sampling weight the selection toward higher-dollar items, so a $500,000 invoice is far more likely to be pulled than a $500 one. Non-statistical approaches, such as random selection or testing all transactions within a specific time block, are common for lower-risk accounts or control testing.
Sample size follows the risk assessment. Higher assessed risk of material misstatement leads to larger samples. The auditor also weighs the tolerable misstatement rate, meaning the maximum error in the population that would still be acceptable. If an account balance sits close to the materiality threshold, expect a bigger sample.
Modern audit teams supplement manual sampling with computer-assisted audit techniques, or CAATs, which analyze the full population of general ledger entries rather than a subset. These tools scan for entries posted on weekends or holidays, entries made by users whose access level should not allow posting, round-dollar entries without supporting invoices, and duplicate amounts across different accounts. The exceptions CAATs identify become the starting point for targeted substantive testing.
Test Journal Entries for Management Override
Auditing standards require the auditor to presume that management override of controls is a fraud risk in every engagement.6PCAOB. AS 2401: Consideration of Fraud in a Financial Statement Audit That presumption drives a specific procedure: understand the company’s financial reporting process, identify and select journal entries for testing, and inquire of the people involved about unusual activity.
Period-end entries get the most attention because they carry the highest fraud risk. A company trying to inflate revenue or hide expenses is most likely to do it through adjusting entries recorded just before the books close. The auditor traces selected entries back to source documents (shipping records, vendor invoices, contracts) to verify the date, amount, and economic substance of the transaction. Entries that lack support, bypass the normal approval workflow, or hit unusual account combinations get escalated.7PCAOB. Audit Focus: Journal Entries
The fraud risk work also includes a retrospective review of prior-year accounting estimates against actual outcomes. If management’s estimates consistently lean in the direction that flatters earnings, the pattern itself is evidence of bias, even when each individual estimate looked reasonable at the time.
Substantively Test the High-Risk Accounts
Once planning and risk assessment are complete, substantive testing focuses on the balances and transaction classes where misstatement risk is highest.
Revenue Recognition
Revenue is the account most prone to manipulation, which is why the standards create a presumption that improper revenue recognition is a fraud risk. Auditors test whether the company correctly applies the five-step model under ASC 606: identify the contract, identify performance obligations, determine the transaction price, allocate that price, and recognize revenue as obligations are satisfied. For service contracts, that often means verifying that revenue is spread over the service period rather than recognized entirely upfront.
Cut-off testing selects sales transactions near the end of the period to confirm that revenue and the related cost of goods sold land in the same fiscal period. Non-operating items like surplus equipment sales get checked to make sure they are not mixed into operating revenue. For contracts with return rights, the auditor confirms the company recorded a reasonable return liability based on historical experience.
Expense Classification and Capitalization
The line between a capital expenditure and an operating expense is a consequential judgment call. Capitalizing puts a cost on the balance sheet and spreads its impact over years through depreciation. Expensing hits the income statement immediately. Misclassification in either direction distorts current earnings and asset values.
Auditors pull a sample of fixed asset additions and trace each one to the original vendor invoice and work order, verifying that the cost genuinely provides a future economic benefit. They also work the other way, reviewing large repair and maintenance charges to confirm that capital-eligible costs are not being buried in operating expenses, which would understate assets and current income.
Estimates, Accruals, and Reserves
Accounting estimates are inherently subjective, which makes them difficult to audit and attractive targets for manipulation.8PCAOB. AS 2501: Auditing Accounting Estimates The allowance for doubtful accounts is the classic example. The auditor analyzes the receivables aging, evaluates the historical write-off rate, and tests whether changes to the allowance are supported by actual changes in economic conditions. A sudden reduction in the allowance without a corresponding improvement in customer payment behavior is a red flag.
Warranty reserves follow the same logic. The auditor recalculates the liability using the company’s historical claims data and contractual obligations, then checks whether the methodology is consistent with prior years. Accrued income taxes require reconciling book income to taxable income and verifying the calculation of deferred tax assets and liabilities. Across all of these, the auditor tests both mathematical accuracy and the reasonableness of the underlying assumptions.
Inventory
Inventory testing combines physical verification with valuation work. The auditor attends and observes the company’s physical inventory count, independently counting a sample of items and comparing them to recorded quantities. Discrepancies trigger investigation. On the valuation side, the auditor reviews purchase invoices to verify unit costs, confirms the company is applying its cost method consistently (FIFO, LIFO, or weighted average), and tests that inventory is recorded at the lower of cost or net realizable value. Obsolete or slow-moving items that should be written down are a frequent finding.
Lease Accounting
Under ASC 842, most leases appear on the balance sheet as a right-of-use asset and a corresponding lease liability. The auditor verifies that the lease liability was initially measured at the present value of remaining lease payments using the appropriate discount rate, typically the rate implicit in the lease or the company’s incremental borrowing rate. The right-of-use asset should equal the initial lease liability plus any prepayments and direct costs, minus incentives received. For operating leases, a single lease cost should be recognized on a straight-line basis over the lease term. For finance leases, amortization of the asset and interest on the liability are tested separately.
Intercompany Transactions
For consolidated entities, the auditor confirms that intercompany transactions (loans, sales, management fees between a parent and its subsidiaries) are properly eliminated in consolidation. Intercompany balances must offset exactly; if they don’t, someone recorded something the other party didn’t, and the difference has to be tracked down. Those transactions should also be documented at arm’s-length values, reflecting what unrelated parties would agree to under the same circumstances.
Send External Confirmations
Some audit evidence only becomes reliable when it comes from outside the company. External confirmations involve the auditor contacting third parties directly to verify balances or terms.9PCAOB. AS 2310: The Confirmation Process The common targets are banks (cash balances, loan amounts, credit lines), customers (outstanding receivable balances), and attorneys (pending or threatened litigation that could affect the statements).
The auditor controls the confirmation process from start to finish. The company prepares the letters, but the audit team mails them and receives the responses directly. That sequence prevents anyone at the company from intercepting or altering a response. When a bank confirms a loan balance that doesn’t match the general ledger, or a customer disputes a receivable amount, the auditor investigates the difference before clearing the account.
Evaluate Subsequent Events and Going Concern
The audit does not end at the balance sheet date. Auditors are required to evaluate events that occur between the balance sheet date and the date they sign the audit report.10PCAOB. AS 2801: Subsequent Events Some events, like the resolution of a lawsuit that was pending at year-end, require adjusting the financial statements. Others, like a major acquisition that closed in January, do not change the numbers but must be disclosed in the notes.
To catch these events, auditors read the latest available interim financial statements, inquire of management about significant changes in debt, capital, or working capital since year-end, and ask whether any unusual adjustments have been made. They also check for changes in related-party relationships and the current status of items that were based on preliminary data at year-end.
Separately, the auditor evaluates whether the company can continue operating as a going concern, meaning it has the financial capacity to meet its obligations for a reasonable period after the financial statements are issued.11PCAOB. AS 2415: Consideration of an Entity’s Ability to Continue as a Going Concern Indicators of going concern doubt include recurring losses, negative cash flows, loan defaults, and loss of a major customer. If substantial doubt exists, the auditor assesses management’s plans to address the situation and decides whether the financial statement disclosures are adequate. A going concern modification in the audit report is one of the most consequential findings an auditor can issue.
Obtain Written Management Representations
Before issuing the opinion, the auditor obtains a written representation letter signed by management.12PCAOB. AS 2805: Management Representations This is not a formality. In it, management formally confirms that the financial statements are fairly presented, that all material transactions have been recorded, that all known fraud or suspected fraud has been disclosed, and that all subsequent events requiring disclosure have been identified. If management refuses to sign, the auditor cannot issue an opinion.
The letter also covers specific items the auditor flagged during the engagement, such as the completeness of related-party disclosures or the reasonableness of significant estimates. Every assertion in the letter needs to be accurate, because signing it creates a documented commitment that can have legal consequences if the statements later prove materially misleading.
Aggregate Results and Issue the Opinion
After substantive testing is complete, the auditor aggregates all identified misstatements, both corrected and uncorrected, and evaluates whether the financial statements as a whole are materially misstated.13PCAOB. AS 2810: Evaluating Audit Results The evaluation considers both dollar amount and nature. An error that turns a profit into a loss might be material even if it falls below the quantitative threshold.
The audit team communicates findings to management through a schedule of proposed adjustments and a management letter that outlines control deficiencies and recommendations. Material misstatements have to be corrected through adjusting journal entries before a clean opinion can be issued. The management letter might raise items like inadequate segregation of duties, missing documentation for revenue contracts, or inconsistent application of the capitalization policy.
The auditor then issues one of four opinions, and the type matters. An unqualified opinion means the financial statements are free from material misstatement, and it’s the outcome every company wants. A qualified opinion means the statements are fairly presented except for a specific identified issue; investors and lenders will want to know what that exception is. An adverse opinion means the statements are materially misstated and should not be relied upon, which can crater investor confidence and trigger loan covenant violations. A disclaimer means the auditor could not obtain enough evidence to form an opinion, and in practice that lands about as hard as an adverse.
Remediate Findings Before the Next Cycle
The audit report is not the finish line. The management letter contains specific recommendations, and implementing them is what separates companies whose audits get cleaner and cheaper each year from those that keep repeating the same findings. Typical remediation includes revising the chart of accounts to reduce misclassification risk, updating accounting policy manuals to reflect current standards, tightening access controls in the ERP, and building automated reconciliation workflows that catch subledger discrepancies during the year rather than at year-end.
When the auditor identifies a control gap around journal entry approval, the useful fix is not just updating a policy document. It’s configuring the system to enforce the approval workflow, training the team on why the control matters, and running a test cycle before the next audit to confirm the new process holds up under scrutiny. That’s what turns audit findings from a recurring cost into a one-time correction.