Exception Review

An exception review is the procedure that pulls together every finding raised across an engagement — from reconciliations, journal-entry testing, AP/AR review, and other substantive work — and decides what to do with it. It classifies each finding by materiality and severity, aggregates uncorrected misstatements against overall materiality, evaluates whether management's response is adequate, and reaches a documented conclusion on whether the financial statements are fairly stated. This page walks through the full process step by step, a worked aggregation-of-misstatements example, the red flags a careful reviewer watches for, and how firms run exception review faster with OCTA Flow while a human signs off on every conclusion.

Why exception review matters, and where it goes wrong

Every substantive procedure on an engagement throws off findings — a reconciling difference that won't clear, a journal entry posted by someone outside their authority, a receivable that looks uncollectible, a payment that shows up twice. Individually, most of these look small. The exception review is the control that stops "small" from becoming an unnoticed pattern. It's the point in the engagement where every finding gets weighed against a threshold instead of a gut feeling, where recurring issues from last year get flagged as a systemic weakness rather than a one-off, and where the firm makes — and documents — an actual decision on each item: fix it, waive it, refer it, or escalate it.

The place this goes wrong is aggregation. A reviewer can clear twenty individually immaterial findings and still miss that, added together, they approach or exceed materiality — which is exactly the scenario auditing standards require firms to evaluate. It also goes wrong when a finding with a qualitative red flag (a related-party transaction, a management override, a possible fraud indicator) gets sized only by its dollar amount and waived because the number looks small. And it goes wrong when management's response is accepted at face value — "we'll fix it next quarter" — without the reviewer confirming a correcting entry was actually proposed and is adequate. The output that avoids all of this is a single, consolidated exception log with a materiality-tested conclusion behind it, not a folder of loose findings from different procedures.

The exception review process, step by step

A rigorous exception review follows a consistent sequence, regardless of which procedures generated the underlying findings. The steps below are the full procedure OCTA Flow executes; they also stand alone as a best-practice process any firm can follow.

1. Load the materiality thresholds. Pull the engagement's overall materiality, performance materiality, and tolerable misstatement for individual accounts. Performance materiality is typically set at 50–75% of overall materiality — a buffer that accounts for the risk that undetected or immaterial misstatements could aggregate to something material. Every finding gets measured against these three numbers.

2. Classify each finding. Every finding gets two independent classifications:

  • Quantitative classification, based on amount: Significant if the finding is at or above performance materiality; Moderate if it's at or above tolerable misstatement but below performance materiality; Minor if it's below tolerable misstatement.
  • Qualitative classification, based on nature: regardless of dollar amount, any finding involving a fraud risk indicator, a related-party transaction, management override of controls, or an internal control deficiency gets flagged as elevated severity. A small dollar amount never neutralizes a qualitative red flag.

3. Map each finding to a financial statement line item. Identify the caption each finding affects — Revenue, Accounts Receivable, Inventory, and so on — using the account reference from the chart of accounts where one is available. This is what lets the aggregation step in the next stage roll findings up by account and by statement line, not just as a flat list.

4. Aggregate the findings and compare to overall materiality. Total the projected misstatement across all findings and compare it to overall materiality. This is the step that catches the pattern individual review misses: a set of findings that are each immaterial on their own but material in aggregate. The aggregate of uncorrected misstatements is the number that drives the engagement conclusion — see the worked example below.

5. Cross-reference prior-period findings. Where a prior-period findings set exists, identify three groups: findings that recur from the prior year (a signal of a systemic control weakness, not an isolated error), findings that were corrected since last period, and findings that are new this period. A recurring finding is treated more seriously than a first-time occurrence of the same size.

6. Evaluate management's response. For each finding with a management response on file, assess four things: did management agree with the finding; did they propose a correcting entry; is the proposed correction adequate to fully resolve the misstatement; and is the remediation timeline reasonable. A response that disagrees with a well-supported finding, without adequate support of its own, is itself a flag.

7. Determine a disposition for every finding. Each finding closes out as one of four dispositions: Corrected (management has posted, or will post, an adjustment); Waived (below materiality on its own, and the aggregate remains acceptable); Referred for further procedures (the evidence on hand isn't sufficient to conclude); or Escalated (material, or carrying a fraud or related-party indicator, regardless of amount). No finding should be left without one of these four.

Aggregating misstatements against materiality (worked example)

The step that separates a real exception review from a checklist is the aggregation schedule — sometimes called a summary of audit differences or a "SUD" — which totals corrected and uncorrected misstatements and tests the uncorrected total against overall materiality. Here's a worked example.

Engagement thresholds:

  • Overall materiality: $500,000
  • Performance materiality (70% of overall): $350,000
  • Tolerable misstatement: $50,000

Findings identified during the engagement (5 of 15 total reviewed):

Finding Description Amount Classification Disposition
F001 Revenue recorded in the wrong period (October sale booked in September) $180,000 unfavorable Moderate Corrected — management posted a reversing entry
F002 Duplicate payment to a vendor identified during AP testing $95,000 unfavorable Moderate Uncorrected — referred for recovery
F003 Bad debt write-off with no supporting collectibility analysis $80,000 unfavorable Moderate Uncorrected — referred, management disagrees
F004 Warranty reserve accrued above the supportable estimate $35,000 favorable Minor Uncorrected — waived individually, tracked in aggregate
F005 Undisclosed related-party loan to an officer Not sized in dollars Qualitative — elevated Escalated regardless of amount

Aggregation of misstatements:

Favorable Unfavorable
Corrected misstatements $0 $180,000
Uncorrected misstatements $35,000 $175,000
Total $35,000 $355,000
Overall materiality $500,000
Net uncorrected misstatement (% of overall materiality) $140,000 (28%)

The net uncorrected misstatement — $175,000 unfavorable less $35,000 favorable, or $140,000 — sits at 28% of overall materiality. On its own, that's below the threshold that would force an adjustment, so the engagement conclusion can state the uncorrected misstatements are not material, individually or in aggregate. But two things keep this from being a rubber stamp: F002 and F003 together ($175,000) are approaching tolerable misstatement territory fast, so they get tracked into next period rather than quietly waived, and F005 is escalated outright because a related-party indicator overrides the fact that it wasn't sized in dollars at all. That's the aggregation discipline — the total drives the conclusion, but qualitative findings never get diluted into it.

Key controls and red flags

The difference between logging findings and running a genuine exception review is what you watch for as findings come in. A careful reviewer flags:

  • Aggregate uncorrected misstatements approaching or exceeding overall materiality — the single most important test in the whole procedure
  • Recurring findings from the prior period — a signal of a systemic control weakness, not a one-time error
  • Findings involving revenue recognition or management estimates — these carry a higher inherent risk of bias
  • Management responses that disagree with a finding without adequate support — a disagreement isn't a resolution
  • Findings classified as minor individually but material in aggregate — the pattern aggregation exists to catch
  • Any finding with a fraud indicator — escalate immediately, regardless of dollar amount

Applying these consistently across every finding, from every source procedure, is what turns exception review from a filing exercise into the engagement's actual control over materiality.

What a completed exception review produces

A finished exception review isn't a pile of flagged line items — it's a consolidated workpaper a partner can sign off on and that stands on its own for the file. A complete exception review package includes:

Deliverable For whom What it shows
Manager summary CFO / audit partner Total exceptions by severity, total value at risk, exceptions resolved vs. open, and an overall risk rating (Low / Medium / High / Critical)
Exception log Reviewer / controller Every finding for the period — ID, category, severity, title, description, amount, date, financial statement account, status, and disposition — the complete record
By category Controller Findings grouped by category, with count, total value, and resolution rate per category
Resolved items Auditor Closed findings — the resolution action taken, who resolved it, the date, and the correcting journal entry reference
Open items Controller Unresolved findings — escalation status, owner, and target resolution date

How OCTA Flow automates exception review

OCTA Flow does the consolidation, classification, and aggregation math for you and leaves the judgment calls — and the sign-off — with your team. The workflow mirrors the process above:

  1. Pick the Exception Review Skill. Flow already knows the full procedure: classify each finding by materiality and severity, map it to a financial statement line, aggregate uncorrected misstatements, cross-reference prior-period findings, and evaluate management's response.
  2. Connect your data. Point Flow at the findings generated by your other procedures for the period, the engagement's materiality thresholds, and — where available — prior-period findings, management responses, and the chart of accounts.
  3. Run. Flow classifies every finding quantitatively and qualitatively, maps each to a financial statement caption, builds the aggregation-of-misstatements schedule, and flags recurring issues against the prior period.
  4. Review findings by severity. Instead of a flat list, Flow surfaces every finding ranked by severity, with a plain-English explanation, its materiality classification, and a recommended action: request an approval, recover a payment, ask for a written explanation, or escalate. Your team works the judgment calls, not the sorting.
  5. Sign off. Once every finding has a disposition and the aggregation total is tested against materiality, Flow assembles the exception log with the full audit trail intact.
Illustrative view of how Flow surfaces findings by severity, each with a recommended action. Not a product screenshot.

The result: the classification and aggregation math that used to take a reviewer hours across a spreadsheet is done instantly, and your people spend their time on the handful of findings that actually require a judgment call.

Control and trust: Flow proposes, you approve

This is what matters most to a firm putting its name on the engagement conclusion: OCTA Flow never writes to your books, and it never signs off on your behalf. Every classification, every aggregation total, and every recommended action is a proposal your reviewer confirms before the exception review is considered closed. Flow does the sorting and shows its reasoning; a person makes the call on materiality and disposition.

That control model runs through the whole review:

  • Findings, not silent resolutions. Flow raises what it found, how it's classified, and what it recommends — your team decides the disposition.
  • Severity and escalation built in. A qualitative red flag — fraud risk, related party, management override — is flagged as elevated regardless of dollar amount, and can be escalated to a manager or partner rather than quietly waived.
  • A complete audit trail. Every classification, aggregation calculation, management-response evaluation, and disposition is logged, so the conclusion is fully traceable back to the underlying findings.

You get the speed of automated classification and aggregation with the accountability of a human-signed conclusion — exactly what a materiality judgment requires.

What the exception review draws on

To run an exception review, Flow uses the same inputs a reviewer already works from:

  • Upstream findings — the findings generated by other procedures during the engagement, with description, amount, and source (required)
  • Engagement materiality — overall materiality, performance materiality, and tolerable misstatement (required)
  • Prior-period findings — last period's findings, for recurring-pattern analysis (optional)
  • Management responses — management's response to each finding, where one has been provided (optional)
  • Chart of accounts — for mapping findings to the correct financial statement line item (optional)

Flow works from whatever your engagement has connected — it matches each input by its purpose, so it doesn't matter what the files are named or which system or procedure they came from.

Glossary terms

  • MaterialityComing soon
  • Audit trail
  • Financial statementsComing soon

How-to guides

  • How to aggregate misstatements in an auditComing soon

Checklist

  • Exception review checklist (free template)Coming soon

Frequently Asked Questions

What is an audit exception review? It's the procedure that consolidates findings raised by other audit or review procedures, classifies each one by materiality and severity, aggregates uncorrected misstatements against overall materiality, and concludes on whether the financial statements are fairly stated after considering both corrected and uncorrected items.

What is the aggregation of misstatements? It's a schedule that totals corrected and uncorrected misstatements, split into favorable and unfavorable amounts, and compares the net uncorrected total to overall materiality. It's the step that catches misstatements that are immaterial individually but material when added together — sometimes called a summary of audit differences.

How do you determine if uncorrected misstatements are material? Compare the net uncorrected misstatement — unfavorable amounts less favorable amounts — to overall materiality, both on its own and combined with other uncorrected items from the period. A ratio well under materiality generally supports a "not material" conclusion, but qualitative factors like fraud risk or related-party involvement can outweigh the dollar amount entirely.

What's the difference between corrected and uncorrected misstatements? A corrected misstatement is one management has adjusted or agreed to adjust in the books. An uncorrected misstatement remains in the financial statements as presented. Both get evaluated — corrected items to confirm the fix was adequate, uncorrected items to test them against materiality.

What happens to a finding that's below materiality? It can be waived individually, but it still gets tracked in the aggregation schedule. If enough small findings accumulate toward materiality, or if a finding carries a qualitative red flag regardless of size, it gets escalated rather than dismissed.

Can exception review be automated? The classification, financial-statement mapping, and aggregation math can be automated and reviewed, while the materiality judgment and disposition decisions stay with your team. That's the model OCTA Flow uses.


See how firms run faster, fully-documented exception reviews with human sign-off → start a 30-day OCTA Flow trial.