Journal Entry Testing: The Audit Test Every Finance Team Should Run Themselves
Why journal entries get special attention
Of all the things an auditor examines, journal entries get a specific, mandatory look. AICPA auditing standards (AU-C section 240) require auditors to test journal entries and other adjustments because that’s where management override of controls shows up. A senior person who wants to move the numbers rarely steals cash — they post an entry. That makes the general ledger both an audit focus and one of the richest fraud-detection surfaces you have.
The good news: these are checks you can run yourself, continuously, so nothing an auditor finds is ever a surprise.
What “high-risk” journal entries look like
Auditors — and good monitoring — focus on entries that are unusual in ways that correlate with error or manipulation:
- Manual entries to accounts that normally only receive automated postings.
- Entries posted at odd times — weekends, holidays, late at night, or right at period-end.
- Round-dollar amounts or amounts just below an approval threshold.
- Entries with no independent approval, or where the preparer and approver are the same person.
- Rare account combinations — a pairing of accounts that almost never occurs.
- Backdated or post-close entries that quietly change a period you thought was done.
None of these is proof of anything on its own. Together, and screened consistently, they surface the handful of entries worth a human look.
A statistical screen worth knowing: Benford’s Law
For larger populations, Benford’s Law is a useful screen. In many natural sets of numbers, the leading digit follows a predictable distribution — 1 appears as the first digit about 30% of the time, and larger digits progressively less. Fabricated numbers often don’t follow that curve, so a Benford analysis of journal entry amounts can highlight populations worth investigating. It’s a screen, not a verdict — but it’s one auditors and fraud examiners genuinely use.
How to run it yourself
The mechanics are straightforward if you have the data: pull the full journal entry population (not a sample), enrich each entry with who posted it, who approved it, when, and to which accounts, and then apply the risk filters above. The hard part is doing it across every entry, every period, without a data project each time — which is exactly why it usually only happens once a year, in the audit.
The payoff
When you test your own entries continuously, three things happen: you catch errors before they compound, you close off the most common management-override fraud, and you walk into the audit with the exact analysis the auditor is required to perform already done.