All posts
8 min read

What is journal entry testing?

By MacrosLM Team · Reviewed by Aisana Aisina, ex-PwC Audit Expert

Journal entry testing is an audit procedure that examines a company's general-ledger entries and other adjustments to catch the ones used to manipulate the financial statements. Auditors pull the population of journal entries and adjustments, single out the ones that look risky or unusual, and trace them back to the supporting documentation to confirm each is legitimate. The goal is narrow and specific: detect fraud hidden in the books, especially the kind that comes from management overriding its own controls.

It isn't optional. Testing journal entries and other adjustments is required in every financial statement audit, under AICPA standards (AU-C 240), PCAOB standards (AS 2401), and internationally (ISA 240). The reason is blunt: the use of journal entries to cook the books is always possible, even in companies with strong internal controls, so the standards mandate the test regardless of how clean the control environment looks.

Below is why it's required, what auditors look for, how the testing works, the red flags that draw scrutiny, and how AI is reshaping the procedure in 2026.

Why it's required: management override

Internal controls are designed to stop most errors and fraud, but they share one structural weakness: the people who run the controls can override them. A CFO can instruct staff to post an entry that bypasses the normal approval path, or make a top-side adjustment directly to the financial-statement draft that never touches the operating systems at all.

That's why the standards treat management override of controls as a fraud risk present in every audit. Auditors can't assume it away, even when controls test effectively, because override sits above the controls. Journal entry testing is the primary procedure for addressing it. A fraud risk is also a "significant risk" under audit standards, which means it demands a stronger response and more persuasive evidence, and journal entry testing, done properly, is exactly that response.

The kinds of manipulation this is meant to catch are well documented: recording out-of-period revenue to inflate the top line, improperly capitalizing repair costs as fixed assets to boost earnings, understating payables with post-closing entries to income, or reclassifying expenses into reserves and intercompany accounts to lift profit.

How the testing works

The procedure follows a logical sequence rather than a random sample.

  1. Understand the journal entry process. Before testing anything, the auditor maps how entries get made: who can post them (the logical-access rights in the accounting software), whether a second person approves them, whether estimates are booked through journal entries and by whom, and whether financial statements are consolidated in a spreadsheet outside the system where adjustments escape review. Weak spots here point to where the risk lives.
  2. Inquire about inappropriate or unusual activity. The standards specifically require the auditor to ask the people involved in the financial reporting process — not just accounting staff, but others who initiate, record, process, or review journal entries — whether they're aware of any inappropriate or unusual activity relating to the processing of journal entries and other adjustments. This inquiry is a mandated step in its own right, not an optional courtesy.
  3. Set the fraud-risk criteria and select entries. The auditor defines the characteristics that flag an entry or adjustment as higher-risk, then identifies and selects the ones that meet those criteria. The population in scope is journal entries and other adjustments — consolidating entries, reclassifications, and adjustments made to combine or consolidate financial statements, not just entries posted in the general ledger. Selection is driven by the auditor's fraud-risk assessment, the presence of risk factors, and how effective the controls over journal entries actually are. Importantly, auditors are expected to test entries meeting their criteria, and to document a rationale if they limit the scope, including a deliberate look at manual versus automated entries.
  4. Examine the support and timing. Selected entries and adjustments are traced to their underlying documentation to test whether they're appropriate. The standards specifically direct auditors to focus on entries made at period-end (where manipulation clusters) and to consider whether testing is also needed for entries made throughout the period.

Because the entire population of entries can be enormous, the standards point auditors toward computer-assisted audit techniques (CAATs). Software can evaluate the whole dataset rather than a manual sample, which both reduces the chance of missing something and frees the auditor to spend time investigating the entries that matter. This is especially true when entries exist only electronically and the data has to be extracted before it can even be reviewed.

The red flags

Certain characteristics make an entry stand out as worth testing. Common fraud-risk indicators include:

  • Nonstandard or manual entries, particularly at period-end, and especially for round-dollar amounts.
  • Entries posted to unrelated, unusual, or seldom-used accounts that don't fit the normal flow.
  • Entries with little or no description, or with a description that doesn't match the amount.
  • Entries made by someone who doesn't normally post them, or posted outside business hours.
  • Top-side adjustments made directly to the financial-statement draft, bypassing the subledgers.
  • Entries lacking second-person approval, especially where one individual can both record and post without review.
  • Significant entries in sensitive accounts like revenue, made late in the period.

None of these proves fraud on its own. They identify where to look. The auditor still has to examine the support and apply professional skepticism, maintaining a questioning mind rather than accepting management's explanation at face value.

Where it fits in the audit

Journal entry testing is part of the broader response to fraud risk and management override, alongside reviewing accounting estimates for bias and evaluating the business rationale of significant unusual transactions. It also connects to SOX control testing: the controls over who can post and approve journal entries are themselves key controls an auditor evaluates, and weak journal-entry controls drive more substantive testing. Manipulative entries are also exactly the kind of thing a quality-of-earnings review hunts for when it questions whether reported earnings are real.

How journal entry testing is changing in 2026

Journal entry testing is one of the audit procedures AI is reshaping fastest, and 2026 is the transition year. The reason is a natural fit: the procedure is fundamentally a search for unusual items in a huge dataset, which is exactly what pattern-recognition technology does well.

The headline shift is from sampling to full-population testing. Traditionally an auditor might pull 25 or 50 entries from a population of thousands. Machine-learning tools now let every entry flow through an algorithm, get a risk score, and be flagged if it matches learned fraud patterns. The PCAOB has highlighted AI-based journal entry testing as a transformative use case, and the appeal is obvious: instead of investigating randomly selected entries that often reveal nothing, auditors spend their time on the genuinely suspicious ones.

The regulatory picture, though, is unsettled, and that matters:

  • No binding AI standard exists yet. The PCAOB adopted amendments to AS 1105 and AS 2301 (effective for audits of fiscal years beginning on or after December 15, 2025) covering technology-assisted analysis of electronic data, but the Board was explicit that those amendments were not written to cover AI specifically. As of 2026 there's no binding PCAOB standard or formal safe harbor confirming that AI-based testing satisfies the rules.
  • Full-population testing may not be the free win it sounds like. PCAOB Board Member Christina Ho has openly raised the scenario where a firm uses AI to test 100% of journal entries, only for inspectors — absent any standard defining what an acceptable AI-based audit looks like — to demand an unreasonable level of detail, pushing the firm to "return to manual sampling because manual sampling is less risky from a PCAOB compliance standpoint." Firms doing it are operating without a defined benchmark, which is a real and slightly absurd tension: do more than the standard requires, and you may still get a finding.
  • Documentation is the live question. Under AS 1215, auditors document the procedures, evidence, and conclusions. When an AI tool assists, it's unresolved how much you must document about the tool itself: its inputs, its validation, its known limitations. Current PCAOB and FRC guidance converges on the same expectation, that working papers let a reviewer understand what the tool did, how its outputs were evaluated, and that a human reviewed and signed off.

Two things are not in doubt. First, data completeness still has to be proven: testing the entire population only helps if you've validated that the population is actually complete and accurate, a long-standing requirement (AS 1105) that AI doesn't remove. Second, the auditor remains accountable for the opinion no matter how sophisticated the tooling. As the UK FRC put it in its June 2025 guidance on AI in audit — reinforced by follow-on guidance in March 2026 — regulatory accountability for AI deployment and audit quality is unchanged: the human auditor is always accountable. Worth noting against all this momentum: PCAOB staff continue to flag journal-entry testing as a frequent source of inspection deficiencies, so the fundamentals still trip firms up even before AI enters the picture.

The practical takeaway for 2026: AI can do the searching across the full population, but the criteria, the skepticism, the data-completeness check, and the documented human sign-off are not things it takes off your plate. They're the parts the standards still pin on you.

The practical problem: volume

The conceptual procedure is clear. The practical obstacle is scale. A mid-sized company can post hundreds of thousands of journal entries in a year, and the risky ones are a needle in that haystack. Testing them means extracting the full general-ledger population, applying the fraud-risk criteria across every entry, isolating the exceptions, and tracing each one back to its support, often across systems and formats that don't line up cleanly. This is precisely the work the standards expect technology to absorb, and increasingly do across the whole population rather than a sample.

Here's what that looks like end to end: a full-population sweep of 14,328 manual journal entries against 11 fraud-risk criteria, on a fictional mid-market real-estate operator.

The self-approval and suspense-posting criteria hit the fewest entries but get tested at 100% — many firm methodologies treat a segregation-of-duties breach as automatic scope regardless of dollar amount, even though no standard mandates that specific threshold. The escalated entry didn't fail on any single indicator; it failed because the same accrual-and-reversal pattern repeated across five of the last eight quarters, which is exactly the kind of pattern-over-single-instance signal AU-C 240 expects an auditor to catch.

MacrosLM's Testing of Journal Entries agent can take the full general-ledger population, apply the fraud-risk criteria across every entry, flag the ones that meet them (round-dollar period-end entries, unusual account combinations, missing approvals, odd posting times, top-side adjustments), and tie each flagged entry back to its supporting documentation through an evidence layer, so the auditor reviews an exception list instead of building the extract by hand. Because every conclusion traces to a source, it speaks directly to the 2026 documentation question of showing what the tool did and how its output was evaluated. What it doesn't do is replace the skepticism: deciding which criteria fit the engagement, confirming the population is complete, judging whether a flagged entry is a genuine concern or has a legitimate explanation, and signing off, all stay with the auditor, who owns the conclusion.

Bottom line

Journal entry testing is the required audit procedure for catching financial-statement manipulation hidden in the general ledger, aimed squarely at the management-override risk that exists in every audit. Auditors understand the entry process, set fraud-risk criteria, select the entries that meet them (with extra focus on nonstandard, round-number, period-end items), and trace them to support. The criteria and the judgment are the auditor's; the volume is what makes it heavy, which is why the standards lean on technology to do the searching.


Sources

  • AICPA — AU-C Section 240, Consideration of Fraud in a Financial Statement Audit.
  • PCAOB — AS 2401 Consideration of Fraud in a Financial Statement Audit.
  • IAASB — ISA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements.

This article is for general information and is not audit, accounting, or legal advice. Journal entry testing requirements and procedures depend on the engagement and applicable standards, and should be designed and performed by qualified professionals.

Frequently asked questions

What is journal entry testing?
Journal entry testing is an audit procedure that examines a company's general-ledger entries to catch the ones used to manipulate the financial statements. Auditors select entries that look risky or unusual and trace them to supporting documentation to confirm each is legitimate.
Why is journal entry testing required?
Because management can override its own controls — a CFO can direct staff to post an entry that bypasses the normal approval path. Standards (AU-C 240, AS 2401, ISA 240) treat that override risk as present in every audit, so testing journal entries is mandatory regardless of how strong the control environment looks.
What are common red flags in journal entry testing?
Nonstandard or round-dollar entries at period-end, postings to unusual or seldom-used accounts, missing or generic descriptions, entries from someone who doesn't normally post them, top-side adjustments that bypass the subledgers, and missing second-person approval.
How is AI changing journal entry testing in 2026?
AI lets auditors score every entry in the population instead of pulling a sample of 25 to 50, shifting the norm toward full-population testing. No binding PCAOB or AICPA standard yet defines what an acceptable AI-based audit looks like, so documenting the tool's inputs, validation, and human sign-off remains the auditor's responsibility.
AA

Reviewed by Aisana Aisina

ex-PwC Audit Expert. Written by the MacrosLM editorial team.

View profile →