Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161


Journal entry testing PCAOB inspectors evaluate ranks among the most persistently deficient areas across every category of registered firm. The PCAOB published a dedicated Audit Focus publication on journal entries in January 2025 — specifically because staff continued identifying a large number of deficiencies in this area across inspection cycles.

A PCAOB auditing standard — AS 2401, Consideration of Fraud in a Financial Statement — recognizes that when financial statements are materially misstated due to fraud, manipulation of the financial reporting process using inappropriate or unauthorized journal entries is often involved. PCAOB staff continues to identify a large number of deficiencies related to the auditor’s examination of journal entries.

Furthermore, journal entry testing directly addresses the risk every auditor must treat as a significant risk on every engagement — management override of controls. No other area of the audit creates a more direct path for management to commit financial statement fraud while circumventing controls that otherwise appear to operate effectively.

At Shah Teelani & Associates, we treat journal entry testing as a mandatory fraud-risk procedure on every PCAOB engagement. This blog explains why PCAOB inspectors focus here, what AS 2401 requires, and what the most common deficiencies reveal about where engagement teams consistently fall short.


Why Journal Entries Create Unique Fraud Risk

Journal entries are the mechanism through which every transaction enters the financial statements. Moreover, they are the mechanism through which management can alter the financial statements — and often the only mechanism that bypasses every transaction-level control.

AS 2401 states that material misstatements of financial statements due to fraud often involve the manipulation of the financial reporting process by recording inappropriate or unauthorized journal entries throughout the year or at period end, or by making adjustments to amounts reported in the financial statements that are not reflected in formal journal entries, such as through consolidating adjustments, report combinations, and reclassifications.

Management occupies a unique position in the control environment. Unlike lower-level employees, management can authorize entries that override controls designed to prevent unauthorized transactions. Consequently, the very controls that appear to protect financial reporting provide limited protection against management-level manipulation.

This is why AS 2401 classifies management override of controls as a significant risk on every engagement — not a risk the auditor must assess and may conclude is low. Every public company audit requires journal entry testing procedures. The risk assessment merely determines the nature and extent of those procedures.


What AS 2401 Requires for Journal Entry Testing PCAOB Auditors Must Follow

AS 2401 establishes five specific requirements for journal entry testing. Each one addresses a different aspect of the management override risk.

Requirement 1 — Understand the Financial Reporting Process and Controls

Auditors must obtain an understanding of the entity’s financial reporting process and the controls over journal entries and other adjustments.

This understanding covers who can initiate, authorize, and record journal entries; what systems process those entries; what controls exist over the journal entry workflow; and how management’s adjustments flow through to the financial statements. Without this foundation, the auditor cannot design procedures responsive to the actual risks in the specific engagement.

Requirement 2 — Use Professional Judgment in Determining the Approach

Auditors must use professional judgment in determining the nature, timing, and extent of the testing of journal entries and other adjustments.

Journal entry testing is not a fixed procedure applied uniformly across all engagements. The nature of testing varies based on the size and complexity of the entity, the volume of journal entries, the level of automation in the accounting system, and the risks identified during the fraud risk assessment. Consequently, a standardized testing approach applied without engagement-specific tailoring fails the AS 2401 requirement regardless of the volume of entries tested.

Requirement 3 — Identify and Select Journal Entries Responsive to Fraud Risk

Identifying and selecting entries for testing requires the auditor to develop criteria that target entries most likely to reflect fraud. Effective criteria address the characteristics that distinguish fraudulent entries from routine ones.

AS 2401’s fraud risk presumption requires auditors to consider whether journal entries are being used to manipulate financial results. The PCAOB highlights that management override of controls remains a significant audit risk and underscores the need for targeted testing of journal entries, particularly those recorded at period-end, those involving unusual accounts, and those bypassing normal approval processes.

Additionally, the auditor must consider entries recorded by individuals who do not normally record journal entries, entries made to accounts rarely used in normal operations, entries lacking supporting documentation, and entries that round to unusual amounts suggesting estimation rather than transaction-based calculation.

Requirement 4 — Determine the Timing of Testing

Auditors must determine the timing of the journal entries selected for testing.

Period-end entries carry elevated risk because management faces the greatest pressure at financial close and has the most opportunity to influence reported results through adjustments, accruals, and reclassifications at that time. However, entries made throughout the year can also reflect fraud. Furthermore, interim testing alone does not satisfy the AS 2401 requirement where year-end entries create significant risk.

Requirement 5 — Inquire of Individuals Involved in Financial Reporting

Auditors must inquire of individuals involved in the financial reporting process about inappropriate or unusual activity relating to the processing of journal entries and other adjustments.

Inquiry extends beyond senior management. Individuals at various levels of the accounting function may observe unusual entry patterns, authorization circumventions, or instructions to record entries they consider inappropriate. However, inquiry alone never constitutes sufficient evidence. Each inquiry must be corroborated by the auditor’s independent testing.


Testing Population Completeness: A Non-Negotiable Step

One of the most technically demanding — and most frequently deficient — aspects of journal entry testing PCAOB inspectors evaluate is population completeness testing. Before the auditor can select entries for testing, the auditor must confirm that the population from which items are selected is complete.

Not testing the completeness of the population of journal entries is one of the most common deficiencies the PCAOB has observed on inspections.

Population completeness testing verifies that the journal entry listing includes every entry processed during the period — not just the entries management chose to include in the report provided to the auditor. Management-provided journal entry populations are inherently unreliable for this purpose. Consequently, the auditor must obtain the population directly from the general ledger system and independently verify that it is complete before relying on it as the basis for sample selection.

Where the auditor tests a sample from an incomplete population, the conclusions drawn from that sample cannot support a valid conclusion about the full population. Testing from a management-curated subset creates the precise gap that fraudulent entry concealment exploits.


Risk-Based Selection: The Critical Distinguishing Skill

Identifying which entries to test from the complete population is where professional judgment most directly affects journal entry testing quality. Risk-based selection produces a test population that targets entries most likely to reflect management override. Arbitrary or convenience-based selection produces a test population that reflects the auditor’s workload management rather than the actual fraud risk.

Effective risk-based criteria include:

Not evidencing an appropriate rationale for how certain factors in AS 2401 resulted in the identification of fraud risk criteria — including the consideration of manual versus automated journal entries — is a specific deficiency the PCAOB has observed.

Manual entries carry higher fraud risk than automated entries because they require deliberate human action rather than system-driven processing. Consequently, risk-based selection must specifically address whether the auditor’s criteria distinguish between manual and automated entries — and why each category receives the testing it does.


Common Journal Entry Testing Deficiencies PCAOB Inspectors Identify

The PCAOB’s January 2025 Audit Focus publication identified the most persistent deficiency patterns across inspections. Understanding them precisely helps engagement teams avoid replicating them.

Not obtaining an understanding of controls over journal entries. Designing responsive testing requires understanding the actual control environment — who authorizes entries, what system processes them, and what manual adjustments bypass automated controls. Without this foundation, the auditor cannot identify the highest-risk entry types.

Not identifying and selecting entries that address the fraud risk criteria. Selecting a representative sample of routine entries does not satisfy the AS 2401 fraud risk requirement. Testing must specifically target entries meeting criteria designed to detect management override — not entries selected for convenience or statistical balance.

Not testing population completeness. Relying on a management-provided journal entry listing without independently verifying its completeness is a fundamental failure. Moreover, it is the failure that makes every other journal entry testing step meaningless — because the population from which items are selected may exclude the most problematic entries.

Not testing entries meeting the fraud criteria. Limiting procedures to certain journal entries meeting the auditor’s fraud criteria — without having an appropriate rationale for that limitation — is a specific deficiency the PCAOB has observed. Where criteria identify high-risk entries, the auditor must test those entries. Identifying risk and then excluding the entries that meet the risk criteria defeats the purpose of risk-based selection entirely.

Testing only a subset of the journal entry population without adequate rationale. Some auditors limit their journal entry testing to year-end entries, to entries above a certain dollar threshold, or to a single system-generated report — without documenting why these limitations are appropriate given the fraud risks identified. Each limitation requires explicit justification tied to the specific risk assessment.


Technology in Journal Entry Testing

Data analytics tools have significantly improved the auditor’s ability to perform effective journal entry testing. Where auditors previously tested manual samples, technology now allows auditors to analyze entire journal entry populations — identifying outliers, unusual patterns, and entries meeting risk-based criteria across hundreds of thousands of transactions.

To aid in testing the completeness of the journal entry population and identifying journal entries for testing, audit firms employ software audit tools. Structured templates and practice aids assist engagement teams in determining and documenting the basis for selecting journal entries to test.

However, technology does not eliminate the judgment requirements of AS 2401. The auditor must still understand the financial reporting process, develop risk-based criteria, evaluate the reliability of the data underlying the analysis, and apply professional skepticism to the results. Furthermore, auditors must apply professional skepticism and adopt a targeted, risk-based approach to assess high-risk entries and potential management override.

An automated tool that analyzes an incomplete population, applies generic criteria, or produces results the auditor accepts without critical evaluation does not satisfy AS 2401 any more than a manual sample that never reaches the high-risk entries.


Documenting Journal Entry Testing

Documentation of journal entry testing must demonstrate the entire chain of the auditor’s work — from understanding the control environment through population completeness testing, criteria development, sample selection, individual entry testing, and conclusions.

Specifically, the workpapers must show the criteria the auditor developed and why those criteria address the fraud risks identified for the specific engagement. They must demonstrate that population completeness testing occurred and produced a reliable population. Furthermore, they must show that entries meeting the fraud criteria were actually tested — not excluded without rationale. Where entries required investigation, the workpapers must record the investigation and its outcome.

Generic journal entry testing documentation — where every engagement uses the same template and the same criteria regardless of the specific fraud risks identified — fails AS 2401’s tailoring requirement. Consequently, every journal entry testing workpaper must reflect the specific entity, the specific fraud risks assessed, and the specific entries selected based on those risks.


What Issuers and Finance Teams Should Know

Journal entry testing places demands on finance teams beyond what substantive testing of account balances typically requires. Auditors need complete access to the general ledger system — not a curated extract. They need documentation supporting every entry selected for testing. Moreover, they need timely access to individuals who can explain the business rationale for unusual entries.

Finance teams strengthen the journal entry testing process by maintaining complete, system-generated journal entry logs accessible to auditors directly rather than through management-prepared extracts. Supporting documentation for all significant manual entries — particularly period-end adjustments — should be organized and available before fieldwork begins. Additionally, clear documentation of who authorized each entry and what business purpose it served supports the auditor’s ability to evaluate whether entries are appropriate.


The Bottom Line

Journal entry testing PCAOB inspectors evaluate is not a routine substantive procedure. It is a required fraud-risk procedure targeting the most direct mechanism through which management can manipulate financial statements. Every public company engagement requires it. The risk assessment determines how extensive it must be — not whether it must occur.

In 2026, with the PCAOB’s January 2025 Audit Focus publication reinforcing specific deficiency patterns and inspectors continuing to find journal entry testing failures across all firm categories, every registered firm must treat this area as a primary execution discipline — not a secondary consideration handled with generic templates.

Shah Teelani & Associates (PCAOB Reg. No. 7161) builds risk-responsive journal entry testing into every public company engagement. We work with US-listed and OTC public companies that understand what genuine fraud-risk procedures require.

If your organization requires a PCAOB-registered auditor with strong fraud-risk testing methodology, we welcome the conversation.


Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States

Leave a Reply

Your email address will not be published. Required fields are marked *