Journal Entry Testing
Journal entry testing is the audit and controls procedure that examines an entity's journal entries for indicators of fraud, in line with AS 2401 (PCAOB) and ISA 240 — the standards addressing the risk that management or staff override controls to make fraudulent entries. It works by confirming the population of entries is complete, running risk-based filters across every entry, scoring each one, and pulling a targeted sample for detailed testing. This page walks through the full process step by step, the red flags a rigorous reviewer watches for, and how firms run journal entry testing faster with OCTA Flow while a person makes every judgment call.
Why journal entry testing matters, and where it goes wrong
Both AS 2401 and ISA 240 single out journal entries as a distinct fraud risk, separate from the ordinary risk of error. The reasoning is specific: management override of controls is one of the few fraud schemes that can bypass every other control in the system, because the person making the fraudulent entry often has the authority to approve it too. A misstatement caused by an honest mistake and one caused by a deliberately falsified entry can look identical in the ledger — the difference is intent, and intent doesn't show up in a trial balance. Testing journal entries is how an auditor or controller goes looking for the pattern, not just the number.
The difficulty is scale and subtlety. A mid-sized entity can post hundreds or thousands of journal entries a period, and the fraudulent ones are, by design, made to look ordinary. A single round-dollar entry or a Saturday posting means nothing on its own — plenty of legitimate entries are round numbers, and plenty of controllers work weekends before a close deadline. The signal is in the combination: an entry that is self-approved, round-dollar, and posted after hours is a very different risk than one that is merely round-dollar. Manually screening every entry against eight or nine risk indicators, tracking which ones stack on the same entry, and then defending a sample selection to a reviewing partner is exactly the kind of high-volume, high-judgment work that's easy to under-scope when time is short — which is precisely when the risk is highest.
The journal entry testing process, step by step
A proper fraud-risk journal entry test follows a consistent sequence, built around AS 2401 / ISA 240. The steps below are the full procedure OCTA Flow executes; they also stand alone as a best-practice process any firm or internal audit function can follow.
1. Verify population completeness. Reconcile total debits and credits in the journal entry population to the general ledger totals for the period. If they don't agree, the population may be incomplete, and testing a partial population understates the risk — document the difference and investigate before moving forward.
2. Load materiality thresholds. Note overall and performance materiality for the engagement. These thresholds drive both the flagging logic and the sample selection later in the process — they're not a formality, they're the yardstick every entry gets measured against.
3. Apply risk-based filters. Screen every entry in the population against a standard set of fraud risk indicators:
- Unauthorized preparer or approver — an entry posted or approved by someone without the authority for the accounts or amounts involved.
- Weekend or holiday posting — entries dated on a Saturday, Sunday, or a recognized holiday, which warrant an explanation.
- After-hours posting — entries with timestamps outside normal business hours (commonly 7 AM–7 PM local time).
- Round-dollar amounts — entries in exact round numbers (e.g., $10,000, $50,000), which can indicate an estimate rather than a transaction, or manipulation dressed up as one.
- Unusual account combinations — entries that debit and credit accounts that wouldn't normally interact, such as a debit to Cash paired with a credit straight to Revenue, or a debit to Expense with a credit to Liability and no corresponding asset movement.
- Minimal or generic descriptions — entries labeled only "adjustment" or "reclassification," or left with no description at all.
- Large entries near period end — entries posted in the last three business days of the period that exceed performance materiality.
- Entries that reverse in the following period — particularly where the reversal is a materially different amount than the original entry, which can indicate period-end manipulation.
- Self-approved entries — entries where the same person is both preparer and approver, removing the second set of eyes a control is supposed to provide.
4. Score and rank entries. Assign a risk score based on how many indicators each entry triggers. As a standard benchmark: High risk = 3 or more indicators, Medium risk = 1–2 indicators, Low risk = 0 indicators. An entry that stacks multiple indicators is a materially different risk than one that trips a single filter, and the score should reflect that.
5. Select the sample. Build the test sample from four tiers:
- All entries above overall materiality — 100% selection, no sampling judgment involved.
- All High-risk entries — every entry scoring 3+ indicators.
- A random sample of Medium-risk entries.
- A random sample of Low-risk entries — for baseline testing, to confirm the "normal" population really is normal.
6. Document the testing plan. For each selected entry, list the specific supporting documentation to obtain — approvals, source invoices, reconciliations, board authorizations — so the sample can actually be tested, not just listed.
Worked example: a journal entry flagged by three indicators
The value of scoring is that it turns a list of individually minor flags into a single, defensible risk signal. Here's how one entry moves from "unremarkable at a glance" to High risk:
JE-1187 — $50,000 — Saturday, March 28
- Dr Miscellaneous Expense $50,000 / Cr Cash $50,000
- Preparer: A. Reyes — Approver: A. Reyes
- Description: "adjustment"
Run against the risk filters, this single entry triggers three separate indicators:
| Indicator | Why it's flagged |
|---|---|
| Self-approved | Preparer and approver are the same person — no independent review occurred |
| Round-dollar amount | $50,000 exactly, with no supporting calculation implied by the amount itself |
| Weekend posting | Dated Saturday, outside the normal posting cadence |
Three indicators triggered places JE-1187 at a risk score of 3 — High risk under the standard benchmark, which means it is automatically pulled into the test sample regardless of whether it exceeds materiality on amount alone. (A fourth indicator is arguably present too — "adjustment" is a generic description — which would push the score higher still.) The entry now needs the supporting documentation a High-risk item requires: the approval trail showing why no second approver was involved, the source support for the $50,000 figure, and an explanation for the weekend timing. On its own, a round-dollar Saturday entry might be nothing. Self-approved, round-dollar, and posted on a Saturday, with a one-word description, is the exact profile fraud-risk testing exists to catch.
Key controls and red flags
The difference between a checklist run through the filters and a reliable fraud-risk test is what a reviewer does with the results. A careful reviewer watches for:
- A population completeness gap — journal entry total does not tie to the GL total, which undermines every test that follows
- Any self-approved entry — the single strongest individual red flag, regardless of amount
- Entries by terminated employees or generic system accounts — postings from access that shouldn't be active
- Entries reversing a prior-period accrual at a different amount than the original — a mismatch that can indicate the reversal itself was manipulated
- A large debit to retained earnings without board authorization — a top-side entry bypassing normal transaction-level controls
- A credit to revenue accounts by non-revenue personnel — someone outside the revenue process posting directly to a revenue-recognition-sensitive account
- Any entry stacking three or more indicators — the combination is the signal, not any single filter in isolation
Applying these consistently — across the full population, every period, not just a spot-check — is what turns journal entry testing from a documentation exercise into an actual fraud-risk control.
What a completed journal entry test produces
A finished test isn't just a filtered spreadsheet — it's a documented workpaper an audit partner or controller can sign off on and an external auditor can follow. A complete journal entry testing package includes:
| Deliverable | For whom | What it shows |
|---|---|---|
| Manager summary | Audit partner / CFO | Population size, risk-flagged count and percentage, critical findings, round-dollar entry count, manual-vs-system entry ratio, and an overall risk assessment (Low / Medium / High) |
| Full JE population | Auditor / controller | Every journal entry for the period — JE number, date, preparer, approver, debit/credit accounts, amount, description, manual-or-system flag, and risk score — the complete tested population |
| Risk-flagged entries | Reviewer | High-risk entries — self-approved, round-dollar, after-hours, unusual accounts, missing description — with severity noted and a follow-up action assigned |
| Self-approved entries | Auditor | Every entry where preparer and approver match — names, amounts, accounts, dates, and the percentage of the total population this represents |
| Statistical sample | Auditor | The random and risk-based sample selected for detailed testing, the sampling basis, and the test results for each item |
| Sample selection detail | Auditor | Each selected entry with the supporting documentation obtained |
| Exceptions and findings | Auditor | Documented exceptions, the auditor's conclusions, and any entries requiring escalation |
How OCTA Flow automates journal entry testing
OCTA Flow runs the mechanical screening for you and leaves the judgment — and the sign-off — with your team. The workflow mirrors the process above:
- Pick the Journal Entry Testing Skill. Flow already knows the full procedure: verify population completeness, load materiality, run every risk-based filter, score and rank each entry, and select the sample.
- Connect your data. Point Flow at the accounting system, or upload the period's files — the journal entry population, GL totals, and materiality thresholds. User access data and a holiday calendar sharpen the unauthorized-preparer and weekend/holiday tests when available.
- Run. Flow reconciles the population to the GL, runs every entry through the fraud risk filters, and scores each one by how many indicators it triggers.
- Review findings by severity. Instead of a spreadsheet of every entry, Flow surfaces the ones that matter — ranked by severity, each with a plain-English explanation of which indicators fired and a recommended action: request an explanation from the preparer, request supporting documentation, or escalate to the controller or audit committee. Your team works the exceptions and the sample, not the full population line by line.
- Sign off. Once the sample is selected, documented, and the findings are dispositioned, Flow assembles the workpaper with the full audit trail intact.
The result: the population-wide screening that used to take hours of filtering and cross-checking is done in minutes, and your team's time goes to the entries — and the judgment calls — that actually carry fraud risk.
Control and trust: Flow proposes, you approve
This is what matters most to a firm putting its name on a fraud-risk conclusion: OCTA Flow never writes to your books or your workpapers on its own. Every flag, every risk score, and every recommended action is a proposal that a person reviews and confirms. Flow does the screening and shows its reasoning; the auditor or controller makes the call on what it means.
That control model runs through the whole test:
- Findings, not silent changes. Flow raises what it found and why — a self-approved entry, a round-dollar amount, a weekend posting — and your team decides what it means and what happens next.
- Severity and escalation built in. A self-approved entry is flagged as critical from the start and can be escalated to a controller, CFO, or audit committee rather than sitting unresolved in a spreadsheet.
- A complete audit trail. Every filter applied, every score assigned, every sample selection, and every disposition is logged — so the test is fully traceable end to end, exactly what a fraud-risk procedure needs to withstand review.
You get the speed of automated screening with the accountability of human judgment on every finding — which is the only way a fraud-risk conclusion should be reached.
What journal entry testing draws on
To run a journal entry test, Flow uses the same sources a preparer already works from:
- Journal entry population — the full set of journal entries for the period, with preparer, approver, date, accounts, amounts, and descriptions (required)
- GL totals — general ledger account totals for the period, used to verify the population is complete (required)
- Entity materiality — overall and performance materiality thresholds (required)
- User information — user roles, access levels, and approval authority, used to identify unauthorized preparers or approvers (optional)
- Holiday calendar — the recognized holidays for the period, used to identify weekend and holiday postings (optional)
Flow works from whatever your client has connected — it matches each input by its purpose, so it doesn't matter what the files are named or which accounting system they came from.
Related skills and terms
Glossary terms
- Journal entry
- General ledger
- MaterialityComing soon
How-to guides
- How to build a journal entry testing sampleComing soon
Checklist
- Journal entry fraud indicator checklist (free template)Coming soon
Frequently Asked Questions
What is journal entry testing? Journal entry testing is the audit procedure that examines an entity's journal entries for indicators of fraud rather than ordinary error. It's required under AS 2401 (PCAOB) and ISA 240, both of which specifically address the risk that management or staff can override controls to post fraudulent entries. The procedure verifies the population is complete, screens every entry against risk indicators, scores each one, and pulls a targeted sample for detailed testing.
What are the main journal entry fraud indicators? The standard set includes: self-approved entries, unauthorized preparers or approvers, weekend or holiday postings, after-hours postings, round-dollar amounts, unusual account combinations, minimal or generic descriptions, large entries near period end, and entries that reverse in the subsequent period at a different amount. No single indicator proves fraud — the risk signal comes from how many stack on the same entry.
How do you score journal entry risk? Count the number of fraud indicators each entry triggers. A common benchmark is High risk at 3 or more indicators, Medium risk at 1–2, and Low risk at 0. High-risk entries go into the test sample automatically; Medium- and Low-risk entries are sampled randomly for broader coverage.
Why does AS 2401 / ISA 240 single out journal entries? Because management override of controls — the fraud scheme these standards specifically target — often involves the same person who has both the authority to make an entry and the authority to approve it. That combination can bypass every other control in the system, which is why journal entry testing exists as a distinct procedure rather than being folded into general substantive testing.
Can journal entry testing be automated? The population reconciliation, the risk filtering, and the scoring can be automated and reviewed, while the conclusion on each finding — and the audit sign-off — stays with your team. That's the model OCTA Flow uses: screen everything, surface what matters, let a person decide.
Does OCTA Flow post entries or make audit conclusions directly? No. Flow flags entries and proposes actions; a person on your team or engagement reviews every finding and decides what it means before anything is documented as a conclusion. Nothing is written or concluded automatically.
See how firms run faster, fully-documented journal entry testing with human sign-off on every finding → start a 30-day OCTA Flow trial.