Skills / Audit and assurance

Journal entry anomaly scan

What it does

Journal entry testing is a required procedure, not a discretionary one — and it is the procedure most often performed as theater: a sample of twenty entries pulled from a population of four hundred thousand, with no stated basis for selection. Full-population scanning is available and cheap, which changes what a reasonable procedure looks like.

26 tests run across the whole population: duplicates, round-dollar, weekend and holiday, after-hours, manually posted, self-approved, approval-threshold circumvention, same-day splitting, unreversed accruals, and Benford leading-digit distribution.

A single flag is weak; converging flags are strong. The value is not in the round-dollar list or the weekend list — it is in the entry that appears on four lists at once. Results are ranked by accumulated risk so you read the top of that ranking instead of working through each test in sequence.

What it proves

Testing an incomplete extract produces false comfort, so a population integrity gate runs first: every entry must balance, document-number continuity is checked, field population rates are measured, and activity by account is tied out to the trial balance. Not one anomaly test runs until the population is proven.

What you get

Seven tabs:

  1. Workpaper Summary — objective, population and how it was obtained, completeness tests and results, criteria and thresholds, tests performed, exceptions by test, selections and their basis, conclusion, and signature block. This tab has to stand on its own if someone re-reads the file in three years.
  2. Population Integrity — balancing by entry, entry-number continuity, field population rates, and activity by account for tie-out.
  3. Ranked Exceptions — every flagged entry with its accumulated score, every flag it hit, amount, date, posting lag, user, approver, and columns for selection, support obtained, and disposition.
  4. One tab per test — so a reviewer can re-perform any single test.
  5. User Activity Profile — entries and dollars by user and month, with manual percentage and self-approval count. Reveals the mid-year behavior change that no single-entry test catches.
  6. Benford — leading-digit distribution against expected, clearly labelled as directional only.
  7. Not Selected — the population that was flagged but not selected, with reasons. The absence of this tab is what makes a selection look arbitrary.

Where it stops

The output is an attribute listing, never a conclusion about intent. An entry posted at 2:14 a.m. on a Sunday for exactly $250,000 by the person who also approved it is a characteristic, and characteristics require investigation, not accusation. It writes "posted outside business hours by the approving user" and leaves the follow-up to determine what that means.

Every exception gets a disposition after inquiry — most turn out to be a batch process, a time-zone artifact, or an overseas shared-service team. A cleared exception is evidence too, and gets documented.

Where a control weakness is evident it is reported as a control observation to management. Where a matter suggests possible fraud, that routes through the engagement's communication protocol — a firm decision, not a scan output.