Why journal entries get special attention
Of all the things an auditor examines, journal entries get a specific, required look. AICPA auditing standards (AU-C section 240) require auditors to test journal entries and other adjustments. That is where management override of controls often shows up. A senior person who wants to move the numbers rarely steals cash. They post an entry. That makes the general ledger both an audit focus and one of the richest fraud screens you have.
The good news: these are checks you can run yourself, continuously, so nothing an auditor finds is ever a surprise.
What “high-risk” journal entries look like
Auditors, and good monitoring, focus on entries that look unusual in ways tied to error or manipulation:
- Manual entries to accounts that normally only receive automated postings.
- Entries posted at odd times — weekends, holidays, late at night, or right at period-end.
- Round-dollar amounts or amounts just below an approval threshold.
- Entries with no independent approval, or where the preparer and approver are the same person.
- Rare account combinations — a pairing of accounts that almost never occurs.
- Backdated or post-close entries that quietly change a period you thought was done.
None of these proves anything on its own. Together, when screened the same way each time, they surface the few entries worth a human look.
A statistical screen worth knowing: Benford’s Law
For larger data sets, Benford’s Law is a useful screen. In many natural sets of numbers, the first digit follows a pattern. The digit 1 appears first about 30% of the time. Larger digits appear less often. Made-up numbers often do not follow that curve, so a Benford review of journal entry amounts can flag groups worth checking. It is a screen, not a verdict, but auditors and fraud examiners do use it.
How to run it yourself
The mechanics are simple if you have the data. Pull the full journal entry population, not a sample. Add who posted each entry, who approved it, when it posted, and which accounts it touched. Then apply the risk filters above. The hard part is doing that for every entry, every period, without a data project each time. That is why it usually happens only once a year, in the audit.
The payoff
When you test your own entries all year, three things happen. You catch errors before they grow. You close off the most common management-override fraud. You also walk into the audit with the same analysis the auditor must perform already done.
Ressura’s General Ledger module runs continuous journal entry testing — timing, approval, thresholds, rare combinations, and Benford screening — on your whole ledger.