Skyline Nexus ERP Skyline Nexus ERP
Audit & assurance

Journal entry testing and fraud red flags

How auditors test journals under ISA 240: population completeness, risk-based selection criteria, a worked filtering funnel, Benford's law and fraud red flags.

Last reviewed 10 min

What journal entry testing is

Journal entry testing is the audit procedure in which the auditor analyses the whole population of journal entries, selects those with fraud-risk characteristics and tests whether each is appropriate, authorised and supported. ISA 240 requires it on every audit because management can override controls by posting entries directly to the ledger, and that risk cannot be assessed away.

Finance teams should understand the procedure as well as auditors do. The same criteria auditors use to find inappropriate entries are the ones a controller can use each month to review the ledger, and the controls that make journal testing uneventful are the controls that prevent fraud. This guide covers the requirement, the population, the selection criteria with a worked example, Benford's law, red flags and preventive controls.

Why management override is always a significant risk

Fraud usually needs three conditions, described in ISA 240 as fraud risk factors: an incentive or pressure (a bonus target, a covenant, market expectations), an opportunity (weak controls or the ability to override them) and an attitude or rationalisation that allows the act. Management is in a unique position to commit fraud because it can manipulate records and override controls that otherwise appear to work, which is why ISA 240 treats management override as a risk of material misstatement due to fraud in every audit, and therefore a significant risk.

Irrespective of the assessment of other risks, ISA 240 requires three responses: test the appropriateness of journal entries and other adjustments made in preparing the financial statements, review accounting estimates for bias (including a retrospective review of prior-year estimates), and evaluate the business rationale of significant transactions outside the normal course of business. For journals, the auditor must ask people involved in financial reporting about inappropriate or unusual activity, select entries made at the end of the period, and consider testing entries made throughout the period.

As of September 2026, ISA 240 (Revised) has been issued by the IAASB and applies to audits of periods beginning on or after 15 December 2026. It keeps the journal testing requirement and puts more emphasis on a fraud lens throughout risk assessment and response, and on communication about fraud in the auditor's report for publicly traded entities.

Start with the population, and prove it is complete

Journal testing is only as good as the data. The auditor first understands how entries reach the ledger: automated entries from sub-ledgers (sales, purchases, payroll, depreciation), standard recurring manual entries (accruals, allocations), non-standard manual entries, and top-side or consolidation adjustments made outside the ledger. Non-standard and top-side entries carry the highest risk because they bypass the controls built into transaction processing. Our guide on the general ledger explains how sub-ledgers feed control accounts.

Then the population is tested for completeness before anything is selected. The standard check is a roll-forward: for every account, opening trial balance plus the sum of journal lines for the period must equal the closing trial balance, and total debits must equal total credits across the population. Gaps in journal numbering, lines without a user or timestamp, and entries dated in the period but posted after it are all investigated. A population that does not roll forward is not a population; any selection from it proves nothing.

Selection criteria that target fraud risk

Auditors select by characteristics that fraudulent entries tend to share, not by size alone. Selecting only entries above a size threshold is a well-known weakness, because fraud is often split into amounts that stay below the thresholds people watch. The criteria below are combined and weighted to the entity's own risk assessment.

  • Timing: entries posted after the period end but dated within it, during the close window, or reversed early in the next period
  • Out of hours: postings at weekends, on public holidays or late at night, compared with normal working patterns
  • Round amounts: entries ending in 000 or 0,000, typical of estimates and plugs rather than invoices
  • Just below limits: amounts slightly under an approval threshold, such as 9,000 to 9,999 against a 10,000 limit
  • Unusual account pairs: manual debits to receivables with credits to revenue, or credits to expense accounts with debits to assets
  • Seldom-used accounts: accounts with very few postings in the year, suspense and clearing accounts
  • Unexpected users: entries by senior management, IT staff or users who do not normally post journals
  • Weak descriptions: blank, vague or repeated narrations such as adjustment or per CFO

Worked example: a filtering funnel

A company's ledger holds 9,600 journal entries for the year. The population rolls forward to the closing trial balance for every account. Of the 9,600 entries, 8,900 are automated postings from sub-ledgers whose controls the auditor has tested, leaving 700 manual entries as the main focus.

Running the criteria over the 700 manual entries flags 118 entries that meet at least one criterion: 182 criteria hits in total, because many entries meet several. Scoring each entry by the number of criteria it meets gives 14 entries with three or more hits, 31 with two and 73 with one (14 plus 31 plus 73 = 118). The auditor tests all 45 entries with two or more hits, selects 10 of the 73 single-hit entries by judgement (for example, every manual entry to revenue), and adds 5 entries chosen unpredictably from the 582 unflagged manual entries (700 minus 118). The test covers 60 entries.

Of the 14 entries with three or more hits, one is a EUR 250,000 credit to cost of sales and debit to inventory, posted by the finance director on a Sunday during the close, described as stock adjustment. That is the entry the whole procedure exists to find. It may be legitimate, supported by a count and a costing correction, or it may be profit manipulation; the test is to obtain the evidence and judge which.

Benford's law as an analytical pointer

Benford's law predicts that in many naturally occurring sets of numbers, the first significant digit is small more often than large. The expected frequency of first digit d is log10(1 + 1/d): about 30.1% of amounts start with 1, 17.6% with 2, 12.5% with 3, 9.7% with 4, 7.9% with 5, 6.7% with 6, 5.8% with 7, 5.1% with 8 and 4.6% with 9. Invented numbers rarely follow this pattern, which makes the test a useful pointer.

Suppose 5,000 expense claims are tested and 780 start with the digit 4, against about 485 expected (9.7% of 5,000). If the approval limit for claims is EUR 500, a first-two-digit test will likely show a cluster between 450 and 499, the signature of claims kept just under the limit. Deviation is measured with statistics such as the chi-square test or the mean absolute deviation, but the result is a reason to look at transactions, not evidence of fraud.

Benford's law applies only to data that spans several orders of magnitude and is not assigned or capped. Invoice numbers, prices set by a list, amounts with a fixed maximum, or small populations will not conform even when nothing is wrong.

Testing the entries selected

For each selected entry the auditor obtains the supporting documentation, confirms the entry was prepared and approved by authorised people in line with the entity's controls, checks that the accounts, amount and period are appropriate, and asks whether the business rationale makes sense. Entries that reverse soon after the period end deserve particular attention, because they may have existed only to change the reported balance at the reporting date.

Findings are evaluated for what they say about controls and management's intent, not just their amount. An inappropriate entry below materiality can still indicate fraud and trigger the requirements of ISA 240 and ISA 450 on the nature of misstatements. The selection criteria, the population reconciliation and the results are documented so that a reviewer can re-perform the logic.

Fraud red flags in and around the ledger

Journal testing finds entries; red flags tell you where to look. The following patterns recur in published fraud cases, and each can be monitored with simple ledger analytics.

  • Revenue spikes in the last days of the period followed by credit notes or returns early in the next
  • Manual adjustments to inventory, provisions or accruals that move profit towards a target
  • Supplier bank details changed shortly before a payment, or payments to new suppliers with no purchase order
  • Duplicate or split payments just below authorisation limits
  • Suspense, clearing or intercompany balances that age without explanation
  • Closed periods reopened, or entries dated in a closed period
  • Unusual reluctance to provide data, or one person who never takes leave and handles everything
  • Related party transactions that are not disclosed or lack commercial rationale

Preventive controls that make journal testing uneventful

The strongest defence is to make inappropriate entries hard to post and easy to see. Restrict manual posting to accounts that need it and block it on control accounts such as receivables, payables, inventory and VAT, which should only move through their sub-ledgers. Require approval of manual journals above a threshold by someone other than the preparer, and have journals posted by senior management reviewed by the audit committee or an independent director.

Lock periods once they are reported, restrict who can reopen them, and review the access list and the activity log regularly: who posted what, when and from where. Our guide on financial controls a small business actually needs explains how to achieve segregation of duties with a small team, and the guide on how to cancel or correct a transaction explains why reversal leaves a better trail than deletion.

Journal controls and evidence in Skyline Nexus ERP

Skyline Nexus ERP supports several of these controls at account level. Each account can be set to Allow Manual Posting or not, and flagged as a control account (Accounts Receivable, Accounts Payable, Payroll, VAT, Inventory, Fixed Assets), so manual journals to sub-ledger accounts can be blocked. Only draft journals can be deleted; posted journals are reversed, leaving both entries visible. Posting into a soft-closed or locked period is refused, and period status changes are audit-logged.

Manual journals can require approval: with Require Approval for Journals on, entries at or above the Approval Threshold are submitted for approval, and amounts at or above twice the threshold need a second level. In practice approval sits with the Admin role, so segregation of duties is set by role design: keep that role with reviewers, separate from those who prepare journals, and use the Audit Trail, which records who created and who approved each entry, to confirm that no one approved their own work.

For the testing itself, the Audit Trail records created, updated, approved, posted, reversed and deleted events with the user, old and new values, IP address and browser, and the system Activity Log adds logins, deletions and a risk column. The Audit Pack (Excel) includes Journal Entries and Journal Lines sheets together with the Trial Balance, which gives the auditor the population and the roll-forward check in one workbook.

Common questions

What is journal entry testing?

Journal entry testing is an audit procedure required by ISA 240 in which the auditor obtains the full population of journal entries, checks it is complete, selects entries with fraud-risk characteristics and tests whether each is appropriate, authorised and supported. Journal entry testing responds to the risk that management overrides controls by posting entries directly to the ledger.

Why is management override of controls always a significant risk?

Management override of controls is always a significant risk because management can manipulate records and bypass controls that otherwise operate effectively, and the risk is unpredictable in how it might occur. ISA 240 therefore requires specific responses on every audit, including journal entry testing, a review of estimates for bias and evaluation of significant unusual transactions.

What criteria do auditors use to select journal entries for testing?

Auditors select journal entries using fraud-risk criteria such as posting after period end or during the close, weekend or out-of-hours posting, round amounts, amounts just below approval limits, unusual account combinations, seldom-used accounts, entries by senior management or unexpected users, and weak descriptions. Combining several criteria for journal entries is more effective than using size alone.

What is Benford's law in auditing?

Benford's law in auditing is an analytical test comparing the distribution of first digits in a data set with the expected pattern, in which about 30.1% of amounts start with 1 and only 4.6% with 9. Large deviations, such as a spike just under an approval limit, point to transactions worth examining. Benford's law is a pointer, not proof of fraud.

How do you test the completeness of a journal entry population?

The completeness of a journal entry population is tested with a roll-forward: for each account, the opening trial balance plus the period's journal lines must equal the closing trial balance, and total debits must equal total credits. Auditors also check for gaps in journal numbering and for entries posted after the period end but dated within it.

What are common red flags of fraud in journal entries?

Common red flags of fraud in journal entries include manual entries to revenue near period end, entries reversed shortly after period end, round or just-below-limit amounts, postings at weekends or by senior management, entries to seldom-used or suspense accounts, vague descriptions, and entries dated in closed periods. Each red flag justifies examining the supporting evidence.

This guide is general information, not tax, accounting or legal advice. Rules differ from country to country and change over time; confirm the current position with your tax authority or a qualified adviser before acting on anything here.

Ready to run your operation on a single workspace?

Talk to us about your business

Tell us what you run and we will come back with a straight answer about fit, timeline and price.

No card, no obligation. We reply within one business day.