Journal entry testing is the set of audit procedures required by PCAOB AS 2401 and AICPA AU-C Section 240 to address the risk that management overrides controls by recording improper entries or adjustments. The work follows a predictable arc: understand how entries flow through the system, build risk-based criteria to select the entries most likely to be manipulated, and vouch each selected entry back to source documentation with skeptical inquiry. Done well, it targets the small subset of entries where fraud actually hides. Done poorly, it becomes a recurring PCAOB inspection finding.
Why the Standards Require It
Executives sit in a position no other employee occupies. They can directly manipulate accounting records and prepare misleading financial statements by sidestepping controls that otherwise work as designed. AS 2401 treats this as a given rather than something the auditor evaluates case by case, and it requires every audit to include procedures aimed specifically at management override, regardless of how strong the control environment looks.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
The standard identifies two primary ways fraud enters the financial statements through entries. The first is unauthorized entries recorded during the year or at period end. The second is adjustments that never appear as formal journal entries at all: consolidating adjustments, report combinations, and reclassifications folded directly into financial statement drafts.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit That second category is the one audit teams most often underweight. Entries posted directly to statement drafts bypass the general ledger, and if you only test the ledger, you miss them.
For non-issuer audits under GAAS, AU-C Section 240 imposes parallel requirements. The auditor must test journal entries and other adjustments even when no specific fraud risk has been identified, because the possibility of override always exists.
AS 2401 requires four specific steps:
- Obtain an understanding of the entity’s financial reporting process and the controls over journal entries and other adjustments.
- Identify and select journal entries and other adjustments for testing.
- Determine the timing of the testing.
- Inquire of individuals involved in the financial reporting process about inappropriate or unusual activity relating to journal entries.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
AS 2301 adds a related requirement: incorporate unpredictability into procedures year to year. Vary which entries you select, adjust when you test, and occasionally look at items outside your usual filters. If you test the same accounts the same way every December, you are advertising which entries will never be scrutinized.
Understand the Process Before You Select Anything
Before pulling a single entry, you need to know how entries move through the system. AS 2401 is explicit that you understand the financial reporting process and controls over journal entries before selecting items to test.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit Skipping this step is one of the most common deficiencies the PCAOB flags on inspection.2Public Company Accounting Oversight Board. Audit Focus – Journal Entries
AS 2110 sets out what to understand about the period-end process, including how transaction totals reach the general ledger, how entries are initiated, authorized, recorded, and processed, and how recurring and nonrecurring adjustments flow into the annual and quarterly statements.3Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
In practice, that means mapping who can initiate entries into the general ledger or transaction processing systems, what approvals are required before posting, whether entries are created online with no physical trail or prepared on paper and uploaded in batches, and whether any preformatted templates or automated exception reports exist for entries that fail control checks.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit You also have to identify every source of adjustments that reaches the financial statements outside the general ledger. Consolidating entries, intercompany eliminations, and top-side adjustments made in spreadsheets or reporting tools all belong on that list.
The general ledger holds entry types with very different risk profiles. Routine transactions like payroll runs or sales postings are typically system-generated and flow through standardized automated controls. Manual entries recorded outside those automated sub-ledgers carry more risk because they depend on human judgment and are easier to manipulate without detection.
High-Risk Characteristics That Drive Selection
Selection criteria are where the testing lives or dies. PCAOB staff guidance identifies the characteristics that distinguish entries most likely to involve fraud, and those characteristics form the backbone of a defensible sample.
- Entries posted to unrelated, seldom-used, or unexpected accounts, such as a large expense coded to a miscellaneous revenue line.
- Entries recorded by individuals who do not typically make journal entries, particularly senior managers or executives who would normally have no reason to touch the ledger directly.
- Entries recorded at period end or as post-closing adjustments, especially those with little or no explanation.
- Entries made before or during financial statement preparation that lack account numbers.
- Entries containing round dollar amounts or amounts with a consistent ending number, which suggest an estimate or arbitrary figure rather than a calculation tied to source documentation.2Public Company Accounting Oversight Board. Audit Focus – Journal Entries
Timing
Entries recorded in the final days before the books close deserve extra attention, because that window is when accruals, estimates, and last-minute adjustments concentrate. Those entry types lean heavily on management judgment, which makes them more susceptible to manipulation. Entries posted outside standard business hours raise questions about oversight and segregation of duties. An entry posted at 11 p.m. on a Saturday may have a clean explanation, but it warrants a closer look than one posted during working hours.
Amounts Just Below Approval Thresholds
Entries recorded just below a defined approval threshold are a classic indicator. If the company requires VP approval for any adjustment over $100,000, a string of $99,500 entries from the same preparer is not a coincidence. The same logic applies to entries falling just under your materiality threshold. When several of these characteristics stack on one entry, a round-dollar amount posted by an executive to an unusual account on the last day of the quarter, the combination demands immediate investigation.
Using Data Analytics To Build the Sample
Modern ERP systems generate millions of entries per year, so manual scanning of the full population is not realistic. Computer-assisted audit techniques and audit analytics software are essential for processing the complete general ledger file and isolating entries that match your risk criteria.
Start by extracting the entire population of entries from the client’s system into a standardized format. Population completeness matters enormously. If entries are missing from the extract, no filter you build can catch them, and failing to test completeness of the journal entry population is a recurring PCAOB inspection deficiency.2Public Company Accounting Oversight Board. Audit Focus – Journal Entries Reconcile the extract totals to the trial balance before you filter anything.
Risk-Based Filters
Once the data is loaded, build queries around the high-risk characteristics from planning. Typical filters isolate entries by posting date (last week of the quarter, weekends, holidays), by preparer (user IDs belonging to executives or people outside accounting), by account (suspense, infrequently used, intercompany), and by amount (round numbers, amounts near approval thresholds). Layering filters produces a manageable subset from what started as millions of records.
Analytical Techniques
Statistical techniques can surface patterns that filtering alone misses. Benford’s Law is useful here. In naturally occurring data, the digit 1 appears as the leading digit roughly 30% of the time and 9 appears less than 5% of the time. Fabricated numbers rarely conform. Running a Benford’s analysis on entry amounts and comparing actual to expected distribution highlights accounts or entry types worth digging into. Deviation is not proof of fraud; it tells you where to look.
Gap analysis examines sequential numbering for breaks that may indicate deleted or voided transactions. It is straightforward and easy to overlook, especially where year-end entries use a separate numbering sequence from routine postings.
Trend analysis adds a time dimension, flagging unusual spikes in activity for a specific account, preparer, or entry type during periods that historically show low volume. A surge in accrual entries during the final week of the quarter, when the prior three quarters showed a steady daily pace, is worth investigating.
The output is a prioritized list ranked by concentration of risk indicators. That list becomes your testing sample. The goal is targeted selection, not random sampling.
Testing Each Selected Entry
With a prioritized sample, the work shifts to detailed examination. For each entry, pull the complete supporting documentation: invoices, contracts, internal memos, board resolutions, or whatever should exist given the transaction.
Authorization and Classification
Check preparer and approver against the delegation of authority. Someone approving an entry above their authorization limit is a control deficiency regardless of whether the underlying transaction is legitimate. Verify that the accounts debited and credited make sense for the transaction described. A capital expenditure booked as an operating expense distorts both the income statement and the balance sheet, and it may be an innocent error or a deliberate attempt to smooth earnings.
Vouching to Source
Trace each entry back to its source transaction to confirm the recorded amount reflects a real economic event. This is where many fraudulent entries fall apart. A legitimate entry has a trail: a purchase order, a vendor invoice with matching quantities and prices, a receiving report. An entry created only to move numbers around rarely has documentation that survives scrutiny.
Examining Documents With Skepticism
Look for signs of alteration: inconsistent fonts, mismatched dates, correction fluid, digital editing artifacts. When documents are copies of copies, request originals. For electronic documentation, check metadata such as timestamps, user logs, and modification history to confirm the document was created when and by whom it claims to be.
If supporting documentation is missing or inadequate for a high-risk entry, treat it as a serious finding. That typically requires immediate discussion with management and, depending on circumstances, escalation to the audit committee. Absence of evidence is not evidence of absence, but for a high-risk entry, the burden shifts to management to explain.
Inquiry
When documentation is ambiguous or incomplete, inquire of the people involved in the transaction. These conversations often reveal whether an unusual entry had a legitimate business purpose or was an attempt to manipulate the statements. The inquiry requirement in AS 2401 is not optional: the auditor must ask individuals involved in financial reporting about inappropriate or unusual activity related to journal entries.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit Confirm that each tested entry was properly posted to the general ledger and is accurately reflected in the trial balance.
Failure to find sufficient evidence supporting a high-risk entry affects the audit directly. It may require expanding the sample, performing compensating procedures, or, if the effect is material and uncorrected, modifying the audit opinion.
Documenting Results and Reporting Findings
Work papers need to tell a complete story. Document the methodology used to select entries, linking the final sample back to the risk filters and analytics performed. For every entry tested, record what you found: whether it was properly supported, authorized at the appropriate level, and classified to the correct accounts. Reach a conclusion for each individual entry, not just a blanket statement covering the sample.
The work papers should also carry an overall conclusion about the effectiveness of controls over journal entries and the resulting risk of material misstatement. Control deficiencies must be communicated formally to management and, when significant or material, to the audit committee.
Findings that suggest potential fraud or intentional misstatement trigger a separate reporting obligation. AS 2401 requires the auditor to communicate possible fraud to the appropriate level of management and, when senior management’s integrity is in question, directly to the audit committee.1Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit The communication must be prompt and confidential. The number and nature of unsupported or unauthorized entries feed directly into the overall risk assessment. A pattern of unexplained entries concentrated at year-end, even if individually immaterial, may collectively indicate a systemic problem that affects the opinion.
Common PCAOB Inspection Deficiencies
The PCAOB publishes the deficiencies it finds most often, and journal entry testing appears repeatedly. The recurring failures include:
- Not obtaining an understanding of the financial reporting process and controls over journal entries before beginning selection and testing.
- Failing to identify and select entries that address the risk of material misstatement from fraud.
- Not testing whether the extracted population is complete, meaning entries could be missing from the data set entirely.
- Testing only some of the entries that met the fraud criteria without documenting an appropriate reason for excluding the rest.
- Failing to document how the risk factors in AS 2401 led to the specific fraud criteria used for selection, including whether manual versus automated entries were considered.2Public Company Accounting Oversight Board. Audit Focus – Journal Entries
The pattern is consistent. Audit teams either rush past the foundational steps or narrow their scope without justification. The best defense on inspection is documented reasoning at every decision point: why you chose the criteria you did, why certain entries were excluded, and what you concluded about each entry you tested.