Boosting audit quality: a practical approach to journal entry testing

Is Journal Entry Testing required in every fi nancial statement audit, and why?

Journal entry testing is required in every fi nancial statement audit. Regardless of how strong an organisation’s internal controls appear, the risk of management override of controls persists and often manifests through journal entries—especially those recorded at period end, routed outside normal approvals, or posted to unusual accounts. Robust journal entry testing helps ensure transactions are properly recorded and that fi nancial statements are free from material misstatement. This article emphasises the need to assess the risk of management override of controls and provides a crafted practical approach to journal entry testing along with the good practices for the journal entry testing.

Meaning of Journal Entry

 A journal entry ( JE) records the fi nancial eff ects of a transaction in the accounting records / system. Every journal entry consists of major components like posting date and time, debit and credit accounts, amount of transaction, description / narration, voucher reference, and maker and checker identifi ers, etc. Journal entries may be either automated (systemgenerated) or manual (user-entered).

Types of Journal entries and their audit relevance

Journal entries are not all the same. Some are  posted by people, some are created automatically by the system, and some happen only occasionally depending on business events. Most of the entities take a hybrid approach; they use manual entries for adjustments and automated entries for routine transactions.

A manual journal entry is a journal entry made by hand either physically or through some accounting soft ware. Normally, manual journal entries include accruals, deferrals, adjustments entries, reclassifi cation entries, consolidation entries and audit adjustments. Since manual journal entries are entered by human, a major risk exists in these types of entries. Th e risk exists  because of the judgement, pressure to meet  the expectations, estimations, period-end adjustments etc.  Accordingly, the auditor is required to spend more time here, checking whether the entry was properly authorised and whether there are enough support and justifi cation behind it.

Manual journal entries can be standard journal entries and non-standard journal entries. Non-standard or oneoff journal entries are the unusual entries. Th ese entries do not happen frequently and are outside the normal process, for example- Journal entries relating to business combination, amalgamation or merger etc. Nonstandard entries involve a lot of judgement, complexity, sometime are of a signifi cant amount. These entries require deeper audit testing and robust documentation. Automated journal entries, use fixed rules and algorithms to record a transaction.

 For instance, monthly depreciation run can be done through an automatic journal entry. It  cannot be said that automated entries are risk free. These entries are to be evaluated through testing of IT General Controls (ITGC) and IT application controls (ITAC).

 As per the Standard on Auditing (SA) 240 - “The Auditor’s Responsibilities Relating to Fraud in an Audit or Financial Statements”, the management override of controls is a presumed risk in audit. Th e risk is presumed in audits without regard to the eff ectiveness of controls. Management override can involve a range of scenarios. For instance, the management may override controls by showing expenses as capital assets or asset under development, recording fictitious sales near the period closer,  reversal of provisions to manage profits etc.

Some of the common indicators that point towards management override can include posting on weekends or late nights, unusual debit and credit combinations which are not aligned with the process, entries posted by top management who normally do not post entries, entries with narrations like adjustment, reclass, rectification, rounded number adjustments’ and entries which are outside the normal workflow. 

Hence, it becomes pivotal for the auditor to design the nature, timing, and extent of the journal entry testing procedure and test the appropriateness of journal entries made in preparing the financial statements to detect the management override of controls. The auditor should come up with procedures that will be unpredictable and specifically target to detect high risk journal entries.

How to plan and perform Journal entry testing? 

The auditor should follow a systematic targeted approach consistent with the standards on auditing for performing journal entry testing.  First and foremost, the auditor should gain understanding of the financial reporting process and controls. 

The auditor should ask questions such as:

  • Who can post journal entries? 
  •  How are journal entries posted? 
  • Who approves Journal entries? 
  • Can one person be both the maker and checker of a journal entry
  • Have there been any unusual journal entries during the year
  • Has the management asked anyone to override controls over journal entries during the year?
  • Who has super user rights?
“As per the Standard on Auditing (SA) 240 - “The Auditor’s Responsibilities Relating to Fraud in an Audit or Financial Statements”, the management override of controls is a presumed risk in audit”
The auditor should perform a walkthrough of a key transaction to identify areas susceptible to misstatement. The auditor should understand authorisation hierarchy and segregation of duties. The auditor should understand the processes around initiating, processing, authorising, and recording journal entries. The auditor should understand who perform the control activities, what the control frequency is and what supporting documentation is available with respect to manual journal entries, non- recurring / nonstandard journal entries and post-closing journal entries.
The auditor should assess the design and implementation of controls over journal entry initiation, review and posting. Then perform the test of operating effectiveness of controls over journal entries.  This will ensure that the auditor understands how journal entries flow from source document to financial statements.
In the second step, the auditor should inquire from the management and key personnel about awareness of unusual journal entries, cases of override or manipulation, authorisation rights for manual posting, and incentive, pressure or rationalisation that might result in fraud. Such inquiries should be corroborated through audit procedures. 
In the third step, the auditor determines the testing approach. The Auditor determines the high-risk criteria based on fraud risk assessment, IT control environment, and engagement specific factors.

How to Determine the High Risk Criteria? 

Generic risk filters do not work and a tailored approach to criteria needs to be developed for the control environment and business risk in each engagement.  The Auditor is required to take consideration of six risk factors while identifying high risk journal entries that required granular audit. These include: 

1. Risk of material misstatement due to fraud: Transactions linked to areas with high fraud susceptibility for instance, revenue recognition, estimates;

2. Control effectiveness: Where control over journal entry initiation, approval or posting are weak or ineffective;

3. Nature and complexity of accounts affected: Entries involving provisions, reserves related party balances, or adjustments without underlying transactions;

4. System complexity, the entity’s financial reporting process, and nature of evidence that can be tested;

 
 
AccountDebitCredit
Capital work-in-progress50,00,0003 
Repairs and maintenance 50,00,000
Narration: "Reclass – project cost"4
  • 1Weekend, late-night, period-end posting
  • 2Same person as maker and checker
  • 3Round-number amount
  • 4Vague narration; expense moved to balance sheet

An illustrative entry combining several warning signs discussed below

Why test journal entries in every audit

Journal entry testing belongs in every financial statement audit. However strong an entity's controls look, management can still override them, and that override usually shows up in journal entries: those booked at period end, those that bypass normal approval, or those hitting unusual accounts.

Well-designed testing gives the auditor comfort that transactions are recorded properly and that the financial statements are free of material misstatement. The article sets out why the risk of override must be assessed, a step-by-step testing approach, and practices that improve quality.

What a journal entry is

A journal entry records the financial effect of a transaction in the books or accounting system. Its main components typically include:

  • posting date and time
  • accounts debited and credited, and the amount
  • description or narration
  • voucher reference
  • maker and checker identifiers

Entries are either automated (generated by the system) or manual (keyed in by a user).

Types of journal entries and their audit relevance

Most entities use a hybrid model: automated entries for routine transactions and manual entries for adjustments. Each type carries a different risk profile.

TypeTypical examplesWhy it matters to the auditor
Manual, standardAccruals, deferrals, adjustments, reclassifications, consolidation and audit adjustmentsHuman input brings judgement, estimates and pressure to hit targets. Check authorisation and supporting justification.
Manual, non-standard (one-off)Entries for business combinations, amalgamations or mergersInfrequent, outside normal process, judgemental, complex and often large. Needs deeper testing and strong documentation.
AutomatedMonthly depreciation runNot risk-free. Evaluate through IT general controls (ITGC) and IT application controls (ITAC).

Management override of controls

Under SA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements, management override of controls is a presumed risk in every audit, regardless of how effective controls appear.

Override can take many forms, such as presenting expenses as capital assets or assets under development, booking fictitious sales close to period end, or reversing provisions to smooth profits.

Common indicators

  • entries posted on weekends or late at night
  • debit and credit combinations that don't fit the normal process
  • entries posted by senior management who don't usually post
  • narrations such as "adjustment", "reclass" or "rectification"
  • round-number adjustments
  • entries processed outside the normal workflow

The auditor therefore needs to design the nature, timing and extent of journal entry procedures carefully, make them unpredictable, and aim them squarely at high-risk entries.

Management override of controls is a presumed risk in every audit, regardless of how effective controls appear.

Planning and performing journal entry testing

The article describes a systematic, targeted approach aligned with the Standards on Auditing, carried out in five steps.

Understand the financial reporting process and controls

Ask who can post entries, how they are posted and approved, whether one person can act as both maker and checker, whether there were unusual entries during the year, whether anyone was asked to override controls, and who holds super-user rights.

Perform a walkthrough of a key transaction, understand the authorisation hierarchy and segregation of duties, and learn who performs each control, how often, and what support exists for manual, non-recurring and post-closing entries. Assess design and implementation of controls over initiation, review and posting, then test operating effectiveness so the flow from source document to financial statements is clear.

Inquire of management and key personnel

Ask about awareness of unusual entries, instances of override or manipulation, rights to post manually, and any incentives, pressures or rationalisations that could lead to fraud. Corroborate the answers with audit procedures.

Decide the testing approach

Set high-risk criteria based on the fraud risk assessment, the IT control environment and engagement-specific factors. See high-risk criteria.

Determine the period subject to testing

Decide which sub-populations of entries to test. See period subject to testing.

Confirm the population is complete and accurate

Before any analysis, address data reliability risks: input, integration, extraction and manipulation risk. See completeness and accuracy testing.

Determining high-risk criteria

Generic filters don't work. Criteria must be tailored to each engagement's control environment and business risks. The auditor should weigh six factors when identifying entries that need detailed work:

  1. Risk of material misstatement due to fraud: areas highly susceptible to fraud, such as revenue recognition and estimates.
  2. Control effectiveness: weak or ineffective controls over initiation, approval or posting.
  3. Nature and complexity of accounts: provisions, reserves, related-party balances, or adjustments with no underlying transaction.
  4. System complexity: the entity's reporting process and the kind of evidence available for testing.
  5. Entries outside the normal course of business.
  6. Characteristics of fraud and journal entries.

Determining the period subject to testing

The Standards on Auditing recognise three sub-populations of journal entries:

  • entries made at the end of the period
  • entries made throughout the period
  • entries made while preparing the financial statements (post-closing entries)

Material post-closing entries and other financial statement adjustments should be tested whether or not a specific fraud risk has been identified. The auditor should also consider testing entries across the whole period, because fraud can occur at any time and may be deliberately concealed. Testing throughout the year also adds unpredictability.

The population to request is a general ledger extract of all journal entries for the period plus a listing of post-closing entries. The auditor should then screen and layer that population to narrow and refine it.

Completeness testing

Completeness can be tested in several ways:

  1. Full roll-forward: roll forward all account balances to confirm every transaction between opening and closing balances is included.
  2. Selective roll-forward: roll forward selected balances where risk is confined to particular ledgers.
  3. System query extraction: run a query that produces the full journal entry dataset.

The extracted totals are then agreed to the general ledger, trial balance and financial statements.

Accuracy of relevant data elements

Before testing, decide whether the relevant data elements (RDEs) can be relied on. These include preparer ID, date, GL amount, debit/credit indicator, description, GL name and GL code. Reliability can be established in two ways:

ApproachWhat the auditor does
Control approachTests management's controls over the accuracy and completeness of the internal information.
Direct approachTests the accuracy and completeness of the information directly.

This reliability work should be completed and documented before high-risk entries are identified.

Selecting entries and resolving exceptions

Once the population is shown to be reliable and complete, apply the high-risk criteria to select entries. Where ITGCs and ITACs are effective, automated entries can be excluded from the population before the criteria are applied.

After testing, evaluate whether any anomaly points to a control deficiency or an intentional misstatement. Not every unusual entry is fraud, but every unusual entry needs an explanation.

When an exception is found

  • obtain supporting documentation
  • establish who initiated the entry and why
  • test authorisation
  • evaluate the accounting rationale
  • assess whether it signals control failure or intent
  • document what was tested, why, what was found, and why the conclusion is acceptable or not

Common pitfalls

Reviews and peer inspections have repeatedly raised these concerns:

  • No documented rationale for the high-risk criteria chosen, or for deciding not to test criteria identified at risk assessment.
  • Generic criteria reused across audits without tailoring to the entity.
  • Using the journal entry population without testing its completeness and accuracy.
  • Sampling from high-risk entries, when every entry meeting the high-risk criteria should be tested.
  • Flagging large populations as high risk without refined filters.
  • Insufficient depth on non-standard and post-closing entries.
  • Not reconciling the journal entry population to the audited financial statements.

Each of these weakens audit quality and falls short of the Standards on Auditing.

Case studies on journal entry fraud

1. WorldCom

WorldCom inflated profits by capitalising operating "line costs" as assets through manual journal entries, and these top-level entries were not adequately examined by the external auditors.

Lesson: scrutinise large manual capitalisation entries.

2. Enron

Enron used complex structures such as special purpose entities and mark-to-market accounting to mislead stakeholders. Journal entries moved liabilities off the balance sheet and boosted revenue.

Lesson: independently test consolidation and related-party adjustments for economic substance and documentary support.

3. Capitalisation of revenue expenditure

Under pressure to protect EBITDA margins, a company posted manual entries in the last week of the quarter with narrations like "reclass", "capitalisation" and "project cost". Many were round amounts posted by senior finance staff. Routine costs such as repairs, subcontracting and administration were shifted from profit and loss to CWIP, intangibles and prepaid expenses, improving EBITDA.

4. Deferment of revenue

Senior management bonuses depended on at least 5% quarterly revenue growth. After roughly 10% growth in Q1, management had finance defer part of Q1 revenue to Q2 through manual entries booked at the Q1 close and reposted in Q2. Revenue moved between quarters with no commercial reason, an incentive-driven override.

5. Reversal of audit adjustments

In a multinational group, reporting deadlines fell before the Indian statutory audit closed. Prior-year statutory audit adjustments were booked in the Indian accounts but never reflected in the group reporting pack. Rather than update group figures or maintain a statutory-to-group reconciliation, the finance team reversed those audit adjustments in the statutory books near period end so they matched group reporting.

Good practices

  1. Tailor engagement-specific high-risk criteria to the entity's environment and risk profile.
  2. Document the rationale for each high-risk criterion.
  3. Screen and layer the population, then re-evaluate and document the risk-assessment criteria after screening.
  4. Ensure engagement partner oversight of journal entry testing.
  5. If a criteria run returns too many entries, refine the criterion and run it again.
  6. Test non-standard entries and post-closing adjustments in detail.
  7. Use IT tools to find unusual patterns in the population.

Using technology in journal entry testing

New sectors such as crypto-currency, gaming, digital assets and e-commerce create challenges that traditional methods may struggle with, making data analytics and AI increasingly important.

  • AI anomaly detection can review 100% of entries to flag risky or potentially fraudulent ones.
  • Machine learning models trained on past frauds and irregularities can estimate the likelihood of management override.
  • Pattern recognition can spot behaviour such as splitting entries just below authorisation limits, or posting on weekends and holidays.

Technology improves efficiency, but the auditor remains responsible for obtaining sufficient appropriate evidence. It doesn't replace professional scepticism.

Conclusion

Journal entries are the building blocks of financial statements, and testing them is a core defence against management override. That testing is only as strong as the approach behind it. Because its quality shapes the reliability of the financial statements, auditors should keep strengthening their journal entry procedures to give stakeholders greater assurance.

References

  • ICAI, SA 230: Audit Documentation
  • ICAI, SA 240: The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements
  • ICAI, SA 315: Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment
  • ICAI, SA 330: The Auditor's Responses to Assessed Risks
  • ICAI, SA 500: Audit Evidence
  • ICAI, SA 530: Audit Sampling

Summary of "Boosting Audit Quality: A Crafted Practical Approach to Journal Entry Testing" by CA. Lalit Agarwal, The Chartered Accountant, October 2026, pp. 91–95 (ICAI). Author contact: fcalalitagarwal@gmail.com, eboard@icai.in