Resource

The ISA 240 journal entry testing guide

ISA 240 requires auditors to address the risk of management override of controls — and journal entry testing is the primary procedure for doing so. This guide explains what the standard expects and how JEFLAG operationalises it.

Why journal entries?

Because management can override controls precisely where automated controls end — through manual journal entries and other adjustments. Paragraph 32 of ISA 240 specifically directs auditors to test the appropriateness of journal entries recorded in the general ledger and other adjustments made in preparing the financial statements.

What the standard asks you to consider

  • Make inquiries of individuals involved in the financial reporting process about inappropriate activity.
  • Select journal entries and adjustments made at the end of a reporting period.
  • Consider the need to test throughout the period, not just at year-end.
  • Identify entries with characteristics of fraudulent or unusual activity.

How JEFLAG maps to the standard

JEFLAG evaluates every entry in the population — not a sample — against 22 weighted risk criteria grounded in ISA 240 characteristics and established fraud indicators. Each flag carries its rationale and standard reference, so the work is defensible on review.

Timing & posting behaviour

  • Entries posted on weekends or holidays
  • Entries at period-end or just after cut-off
  • Back-dated postings
  • Unusual posting times (out of hours)

Amount characteristics

  • Round-number amounts
  • Amounts just below approval thresholds
  • Unusually large relative to the account
  • Benford's Law first-digit anomalies

Account & structure

  • Rare or dormant account combinations
  • Revenue paired with non-standard accounts
  • Suspense and clearing account usage
  • Manual entries to sensitive estimates

User & authorship

  • Entries by unexpected or privileged users
  • Self-approved entries
  • High volume from a single author
  • Entries by users outside finance

Description & narrative

  • Blank or vague descriptions
  • Keywords suggesting adjustment or reversal
  • Duplicated narratives across entries

Pattern & population

  • Duplicate entries
  • Reversed shortly after posting
  • Seldom-used journal types

From detection to documentation

Detection is only half the job. JEFLAG captures reviewer conclusions and notes on each flagged entry and records them in an immutable audit trail, then exports a branded report that ties each conclusion back to the criteria that triggered it.

Put the guide into practice

Run the full 22-criteria analysis on sample data in under a minute.

Start Free