100% found this document useful (4 votes)
2K views15 pages

Guide Journal Entry Testing

Guía de testeo de asientos

Uploaded by

Jovis Joy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (4 votes)
2K views15 pages

Guide Journal Entry Testing

Guía de testeo de asientos

Uploaded by

Jovis Joy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Summary
  • Purpose and applicability of this guide

 

7 August 2015
Journal Entry Testing
Guide for selecting and testing journal entries Useful links
The objective of this guide is to explain the purpose of journal entry testing as part of our eData Center
financial statement audit as well as to provide professionals practical guidance how to KAM 33
select and test such journal entries.
SmartAnalyzer General
Ledger routines listing
Contents Directive DPP 2013_001 -
1.  Summary ................................................................................................................... 1  Rebuttable procedures
Coaching Guide – Journal
2.  Purpose and applicability of this guide ..................................................................... 2 
Entries
2.1  Purpose ..................................................................................................................... 2 
2.2  Applicability ............................................................................................................... 3 
3.  Journal Entry testing – step by step ......................................................................... 3 
3.1  Section I. Determine the criteria to identify high-risk journal entries....................... 3 
3.2  Section II. Evaluate the completeness of the relevant population .......................... 8 
3.3  Section III. Apply the high-risk criteria to the relevant population ........................... 9 
3.4  Section IV. Test identified high-risk journal entries ................................................. 9 
3.5  Section V. Examine material post-closing entries made during the financial
statement closing process (post-closing entries) ............................................................ 10 
4.  Putting into practice ................................................................................................ 10 

1. Summary
Management is in a unique position to perpetrate fraud because of management's ability to manipulate accounting
records and prepare fraudulent financial statements by overriding controls that otherwise appear to be operating
effectively. Although the risk of management override of controls will vary from entity to entity, the risk is nevertheless
present in all entities. Due to the unpredictable way in which such override could occur, this is a presumed fraud risk
(i.e. a significant risk) for the journal entries process.
As there is a fraud risk (i.e. significant risk) of management override of the controls associated with the journal entries
process, we shall evaluate the design and implementation of relevant controls, including whether and how management
responds to the fraud risk and whether control activities have been implemented to address the risks.
Irrespective of our assessment of the risks of management override of controls, we shall design and perform audit
procedures to test the appropriateness of journal entries recorded in the general ledger and other adjustments made in
the preparation of the financial statements. In designing and performing audit procedures for such tests, we shall:
 consider the need to test journal entries and other adjustments throughout the period, as determined in our planned
audit approach;
 make inquiries of individuals involved in the financial reporting process about inappropriate or unusual activity
relating to the processing of journal entries and other adjustments;
 obtain a complete listing of journal entries and other adjustments and determine the completeness of the listing;
 select journal entries and other adjustments, including standard and non-standard journal entries to record non-
recurring, unusual transactions or adjustments, consolidation adjustments, and other adjustments made at the end
of a reporting period. A factor for selecting high-risk journal entries are those accounts for which a fraud risk has
been identified.

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 1 of 14 trademarks of KPMG International.
 
We may summarize the above as follows:

As included in Directive DPP 2013-001, the use of Data & Analytics routines for journal entry testing is a rebuttable
procedure. Within this guide we discuss how to perform “Journal entry testing powered by Data & Analytics”.

2. Purpose and applicability of this guide


2.1 Purpose
This guide is to help to identify, select and test journal entries and other adjustments for evidence of possible material
misstatement due to fraud from management override of controls (“high-risk journal entries”) as required by KAM 33 -
Journal Entries.
We first explain the concepts in chapter 3 ‘Journal entry testing step by step’ and provide examples in chapter 4 ‘Putting
it into practice’.
We perform journal entry testing in response to the risk of material misstatement due to fraud from management
override of controls, as assessed in eAudIT activity 2.9.4 – Journal Entries. Management is in a unique position to
perpetrate fraud because of its ability to directly or indirectly manipulate accounting records and prepare fraudulent
financial statements and/or misappropriate assets by overriding established controls that otherwise appear to be
operating effectively.
As required at eAudIT activities 2.9.4 and 4.6.1 – Journal Entries, this guidance facilitates the documentation of:
a) our assessment of the risk of material misstatement due to fraud from management override of controls based
on our understanding of the entity’s financial reporting process and the results of our testing of controls over
journal entries (eAudIT activities 2.9.4 and 4.6.1)
b) our inquiries of individuals involved in the financial reporting process about inappropriate or unusual activities
relating to the processing of journal entries (eAudIT activity 4.6.1);
c) our evaluation of the completeness of the journal entry population that is the source for the selection of high-
risk journal entries (eAudIT activity 4.6.1); and
d) our selection and testing of high-risk journal entries and other adjustments during the period subject to audit
and our evaluation of such tests (eAudIT activity 4.6.1). A factor for selecting high-risk journal entries are those
accounts for which a fraud risk has been identified.
In addition, 3.5 - Section V of this guidance helps to document the testing of material journal entries and other
adjustments made during the course of preparing the financial statements (i.e., post-closing entries) as required by ISA
330.21 (eAudIT activity 4.6.1).
This guidance does not address the requirement to perform additional audit procedures in response to the risk of
management override of controls, specifically a retrospective review of significant accounting estimates for possible
bias and to evaluate the business rationale for significant unusual transactions that could be indicative of a risk of a
material misstatement due to fraud. These procedures are documented in eAudIT activities 4.5.1 – Management Bias
and 4.5.4 – Summary of Risks, respectively.

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 2 of 14 trademarks of KPMG International.
 
These procedures could be initiated and conducted during planning and risk assessment and completed at year end.

2.2 Applicability
This guide is to be used in conjunction with eAudIT, but does not address testing controls related to journal entries. It
does take into account the results of procedures performed in relation to the controls over journal entries tested in the
following eAudIT activities:
 eAudIT 2.9.4, under the section titled “Approach to Control Testing”;
 eAudIT 2.11.x, which addresses evaluating the design and implementation of controls, including controls over the
journal entry process; and
 eAudIT 3.1.x, (if relevant) which addresses testing the operating effectiveness of controls over the journal entry
process.
Note: we always understand the process activities of the journal entry process, identify the related “What could go
wrongs” and evaluate the design and implementation of controls over journal entries. If such controls do not exist or are
ineffective, we consider such as a material weakness of the internal control.

3. Journal Entry testing – step by step


The following steps can be recognized for journal entry testing:

Determine  Testing  Test Journal 


Assess risk, understand 
approach completeness  Selecting  entries and 
processes including JE 
and selection  of the  journal entries document 
process
criteria population results

Entire 
Population

Yes
Fraud Risks Throughout 
the year

No
Prior year Period
1‐12 High risk journal entries

ELCs
Conclusion

Entire 
GITCs Period Population
Year end
13
High risk journal entries

Process 
Activities

Internal  Population
controls JE  Post closing Post closing
Process High risk and Material 
post closing

1 Assess risk, Understand processes including the JE process and Determine planned audit approach is covered in
Section I. Determine the criteria to identify high-risk journal entries
2 Testing completeness of the population is covered in Section II. Evaluate the completeness of the relevant
population
3 Select journal entries is covered in Section III. Apply the high-risk criteria to the relevant population
4 Test Journal entries and document results is covered in Section IV. Test identified high-risk journal entries
5 The bottom part of the graphic is covered in Section V. Examine material post-closing entries made during the
financial statement closing process (post-closing entries)

3.1 Section I. Determine the criteria to identify high-risk journal entries


The purpose of these procedures is to determine entity-specific characteristics that will be used to identify, select and
test journal entries and other adjustments for evidence of possible material misstatement due to fraud from
management override of controls (“high-risk” journal entries). Significant auditor judgment will be required to identify
entity-specific characteristics. While the entity-specific selection characteristics may be applied to the entire population
of journal entries and other adjustments or to specific accounts at specific periods of time, the intent of applying these
entity-specific selection characteristics is to identify high-risk journal entries.
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 3 of 14 trademarks of KPMG International.
 
We may analyze a population of journal entries and other adjustments to help us understand the characteristics of
journal entries and other adjustments, to identify high-risk criteria and to refine potential high-risk criteria identified as
part of our other risk assessment procedures. This analysis should also include an evaluation of fraud risks (and related
assertions) identified during our risk assessment procedures in the planning phase of our audit.
This analysis to identify high-risk criteria may be done through a combination of screening the population of journal
entries and other adjustments using KPMG supported electronic data analysis tools and manually scanning the output
of these tools.
Data & Analytics (D&A) tools may be helpful in identifying journal entries with similar characteristics (e.g. similar
account combinations or posted on certain dates) for further analysis. This analysis may allow us to determine entity-
specific high-risk criteria. We may screen for generic characteristics that may result in screened output with common
characteristics that are not necessarily indicative of high-risk journal entries and other adjustments. Use of these D&A
tools may require several iterations to produce output from which the high-risk criteria may be identified ("layering").
This iterative approach is illustrated in the following diagram:

Journal entries and adjustments that are considered to be high-risk journal entries should be tested in their entirety
(100% testing).
We may involve a Forensic or IRM Specialist in the identification of these selection characteristics related to fraud and
management override of controls and or use D&A tools like IDEA SmartAnalyzer – general Ledger Routines. See for
more information on IDEA the eData Center on Alex.
3.1.1 Procedures - Reference [KAM 33.1015]
1) In performing procedures a-i below, determine the entity-specific selection characteristics that will be used to
identify high-risk journal entries. Although we may perform similar procedures elsewhere in the course of
conducting our audits, the procedures in this section are meant to be incremental and specific to evaluating and
responding to the risk of management override of controls.

Consider whether the results of these procedures and the results of our risk assessment procedures in the
planning phase of our audit have identified:
 a member of management or another individual with incentives/pressures, opportunity and attitude to commit
fraud or that has circumvented the internal control process and overridden controls;
 whether there are specific accounts that are more susceptible to material misstatement due to fraud from
management override of controls; or
 whether there is a period of time when journal entries and adjustments are processed that is more susceptible
to material misstatement due to fraud from management override of controls.

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 4 of 14 trademarks of KPMG International.
 
a) Inquire of those individuals who have responsibilities for initiating, preparing or authorizing journal entries
during the year or at period end whether there was inappropriate or unusual activity related to the processing
of journal entries and other adjustments, such as:
 journal entries or other adjustments recorded without adequate support or explanation;
 any instances of management override of controls through recording journal entries or other adjustments;
 journal entries or other adjustments initiated by management outside of the normal course of business.
To be effective in identifying opportunities for management override and evaluating the high-risk characteristics
of accounts and journal entries, inquiries should be directed to those individuals with responsibility for actually
preparing and recording the journal entries, such as accounting clerks.
[Inquiries are documented at eAudIT activity 4.6.1]
b) Obtain an understanding of the information systems, including related business processes relevant to financial
reporting, which includes:
 the processing of journal entries and other adjustments, which may consist of manual, automated and/or a
combination of manual and automated procedures;
 controls surrounding standard and recurring journal entries;
 controls surrounding non-standard journal entries used to record non-recurring, unusual transactions or
adjustments.
Based on this understanding, consider areas susceptible to management override, which may include areas
where controls over journal entries and other adjustments were found to be non-existent or deficient.
[Our understanding of information systems including related business processes relevant to financial reporting
is documented at the following eAudIT activities:
• 2.6.10 – Understanding IT
• 2.9.3 – Financial Reporting Process
• 2.11.x.1 – Process Activities
• 2.13.1 – IT Applications and Environments]
A way to obtain an understanding of the business processes relevant to financial reporting is to analyze the
journals used with D&A tools. As an example, Excel can be used to create a pivot table including (aggregated)
accounts and journals. This overview can be used to compare the actual journal entry transactions made to
our understanding of the business processes.

Example

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 5 of 14 trademarks of KPMG International.
 
An example of findings based on this screenshot above:

 2 Journals are used for sales (51 Sales booking and 52 Sales invoice booking) – it might be
interesting for the engagement team to understand what the difference is. This could
indicate there are 2 different processes in place for recognizing sales transactions.
 Tax recorded (CU 427k) in 51 Sales booking is 19% of revenues (CU 2,250k) – it might be
interesting for the engagement team to verify whether this is in line with the general
understanding of the split between domestic and foreign sales.
 Cost of sales CU 50k was recorded in 51 Sales booking – it might be interesting for the
engagement team to understand this entry.
 The amounts in this pivot table are netted amounts. It could be interesting to split debit and
credit amounts.

 From the recorded receivables in the 51 Sales Booking (CU 2,610k), the majority is
received through 53 Sales invoice payment (CU 2,138k), which gives some information of
the collection process.

c) Consider the adequacy of design, implementation and, if applicable, the operating effectiveness of GITCs and
application controls including interface controls, as they relate to the initiation and processing of automated
transactions, journal entries and other adjustments. Assess whether management could inappropriately
override automated processes and what detection procedures are in place to identify such occurrences.
[Automated journal entries may be excluded from the consideration of journal entry selection characteristics.
Such depends on our assessment of risk of material misstatement due to fraud from management override of
controls in connection with the initiation, preparation and authorization of a journal entry or other adjustment to
an acceptably low level. For such assessment we take into account amongst others the control environment,
nature of the information systems used and the design, implementation and operating effectiveness of relevant
GITCs and applications controls, including interface controls.]
d) Consider the design, implementation and operating effectiveness of controls as they relate to the initiation,
preparation and authorization of manual journal entries and other adjustments recorded to accounts assessed
as having a low risk of management override of controls. If controls are properly designed, implemented and
operating effectively, manual journal entries and adjustments recorded to these accounts may be excluded
from the consideration of high-risk journal entry selection characteristics if such accounts are not in the scope
of other specific journal entry selection characteristics.
e) Consider the assertions identified in Risk Assessment as having a fraud risk (these items are documented at
eAudIT Tracker and at activity 4.5.4 – Summary of Risks).
[It is expected that assertions identified as having a fraud risk would be included as a specific journal entry
selection characteristic. If these accounts are excluded from the selection characteristics because the risk of
material misstatement due to fraud from management override of controls has been tested in another audit
procedure and inclusion here would be duplicative, the rationale for excluding such entity-specific fraud risks
from journal entry selection characteristics should be documented.]
[Auditors are reminded that if a risk of material misstatement due to fraud is determined to be pervasive
throughout the entity, procedures designed to identify and test high-risk journal entries related to that fraud risk
would be expected to be performed covering all components of the entity. However, "the auditor may eliminate
from further consideration locations or business units that, individually or when aggregated with others, do not
present a reasonable possibility of material misstatement [due to fraud or error] to the company's consolidated
financial statements". Further, if the fraud risk is limited to certain locations within the entity, then the
procedures designed to identify and test high-risk journal entries related to that fraud risk may be limited to
those locations. In these situations, the fraud risk would not be described as pervasive across the entity or as
an entity-wide fraud risk.]
f) Consider whether certain accounts are more likely to contain inappropriate journal entries. Those accounts
might include the following:
 accounts that contain transactions that are complex or unusual in nature;
 accounts used for post-closing entries and period-end adjustments (note that material post-closing journal
entries and adjustments are required to be examined as set out in Section V of this Guidance);
 accounts that are seldom-used or that may include journal entries or other adjustments processed outside
the normal course of business;
 accounts that contain significant estimates;

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 6 of 14 trademarks of KPMG International.
 
 accounts that have been prone to errors in the past;
 accounts that have not been reconciled on a timely basis or contain unreconciled differences;
 clearing accounts that have not been aged;
 accounts that are otherwise associated with a fraud risk.
g) If D&A tools such as IDEA SmartAnalyzer, LUCA, KAAP or K-DAT are used, the auditor should understand the
nature and characteristics of the screened output in order to develop the entity-specific selection
characteristics that will be used to apply high-risk criteria for testing in Section III.
[Consider using D&A tools such as IDEA SmartAnalyzer, LUCA, KAAP or K-DAT to gain an understanding of
the nature, the characteristics, the number of journal entries and other adjustments that are made by the entity.
D&A tools such as IDEA SmartAnalyzer, LUCA, KAAP or K-DAT may be helpful in isolating journal entries with
similar characteristics (e.g., similar account combinations or posted on certain dates) for further analysis. This
analysis may allow us to determine entity-specific characteristics of high-risk journal entries and other
adjustments.]
h) Consider introducing an element of unpredictability into our journal entry test work.
i) Based on the procedures performed above (1a. – 1h.), identify the entity-specific characteristics of high-risk
journal entries.
[Such characteristics may include entries (a) made to unrelated, unusual, or seldom-used accounts, (b) made
by individuals who typically do not make journal entries, (c) recorded at the end of the period or as post-closing
entries that have little or no explanation or description, (d) made either before or during the preparation of the
financial statements that do not have account numbers, or (e) containing round numbers or a consistent
ending number.]

Example
For a low risk entity, we may consider to identify the following journal entries as high-risk journal entries:

 All Journal entries above PM1 and


 Other journal entries
 Made by the CEO, CFO and (group) controller; and/or
 Journal entries of aggregated accounts for which a risk of fraud has been identified; and/or
 Back postings with a significant difference between posting date and effective date; and/or
 Journal entries made in other than expected journals.

2) Document the selection characteristics


a) Document the selection characteristics determined in performing procedures 1.a.- 1.i. of high-risk journal
entries and why such characteristics are considered high-risk in the circumstances.
[Engagement teams are reminded that they should not exclude from the population from which we will select
high-risk journal entries amounts that are below an arbitrary quantitative threshold, for example Performance
Materiality or the Audit Misstatement Posting Threshold, as fraud can be perpetrated by recording numerous
low-dollar entries. We should assess the risk of material misstatement due to fraud from management
override of controls occurring in low-dollar value entries.]
b) If the high-risk selection characteristics exclude journal entries tested through other audit procedures,
document the rationale for excluding these characteristics from identifying journal entries at risk of material
misstatement due to fraud from management override of controls. Testing performed as part of other audit
procedures should address how all high-risk journal entries have been addressed.
c) If IDEA SmartAnalyzer, K-DAT, or other D&A tools were used, document the following, where applicable:

                                                            
1
 We may include items above a certain amount in combination with selection of journal entries based on
qualitative criteria. We do not exclude journal entries just because of a monetary threshold.
Refer to KAM 33.2385: It may not be appropriate to identify high-risk journal entries and other adjustments
strictly based on their amount (for example items greater than performance materiality or the audit
misstatement posting threshold) as fraud can be perpetrated by recording numerous low-value entries.  

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 7 of 14 trademarks of KPMG International.
 
 the description of the screening process that was followed and how the high-risk journal entries that were
selected for testing were identified;
 the explanation to support the exclusion of any of the screened output as not being indicative of high-risk
journal entries.

In Section III, we apply the selection characteristics identified above to the population of journal entries and other
adjustments from all accounts or relevant accounts, as applicable, to determine high-risk journal entries.

3.2 Section II. Evaluate the completeness of the relevant population


As part of the documentation included at eAudIT activity 4.6.1, we document procedures performed over completeness
of the population of journal entries.
3.2.1 Procedures - Reference [KAM 33.1045/33.1090]
3) Obtain the population of journal entries and other adjustments that will be the source of selection of high-risk
journal entries in an electronic format (i.e., the selection characteristics in Section I will be applied against this
population).
4) Evaluate the completeness of the population of journal entries and other adjustments that are the source for
selection and testing of high-risk journal entries using one of the following approaches:
a) Roll-forward account balances:
 Obtain a trial balance by account number for the prior period end and the end of the period subject to
audit. The electronic file of journal entries and other adjustments should be used to roll forward relevant
accounts as determined below from prior period end or beginning of year to the end of the current period.
 Determine that the number of accounts listed in the electronic file reconciles with the chart of accounts.
 Document the rationale used for the extent of testing related to the evaluation of completeness.
 Document the procedures performed to verify the completeness of the journal entries in a CAAT’s
document or in the relevant activity screen in eAudIT.
Select one of the following options to roll forward account balances:
i) Roll-forward all accounts to evaluate the completeness of the entire population.
[We may evaluate the completeness of all accounts if high-risk journal entries selected for testing are widely
distributed throughout the chart of accounts, if initial testing of selected accounts identified errors, or if testing
of all accounts is performed efficiently (i.e., easy to do).]

ii) Roll-forward a sample of accounts to evaluate the completeness of the entire population. Accounts that
we might roll forward include significant accounts for which we have identified a fraud risk and other
accounts selected from the chart of accounts. Document the rationale for selecting the specific accounts
to roll forward and why we believe it is not necessary to roll forward the remaining accounts.
[We may choose to roll-forward a sample of accounts because the entity is not aware of the accounts that we
are testing for completeness and we have an element of unpredictability in our selection. We also test the
significant accounts identified as having a fraud risk.]

iii) Roll forward the specific accounts affected by the high-risk journal entries. Document the rationale for
selecting the specific accounts to roll forward and why we believe it is not necessary to roll forward the
remaining accounts.
[If in our judgment, high-risk journal entries are selected using characteristics that were limited to certain
accounts, then we only need to evaluate the completeness of journal entries and adjustments affecting those
accounts.]

b) System query and effective GITC and other controls:


In circumstances where we obtained the total population of journal entries and other adjustments by running a
query against the entity’s information systems and we have tested the operating effectiveness of controls over
the information systems, integrated application systems, database management systems and interfaces

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 8 of 14 trademarks of KPMG International.
 
through to the general ledger, we may choose to assess the completeness of the population in conjunction
with the testing of GITCs and the information systems in question.
Steps we may perform include:
i) Observe entity personnel execute a system query to obtain all relevant journal entries and other
adjustments.
ii) To test the reliability of a system query, we will need to consider and document the following:
- Whether the underlying database(s) represent a complete population of relevant journal entries.
Obtaining an understanding of the entity's approach to determining the completeness of the information
will assist in developing an effective audit approach to obtain audit evidence about the completeness of
the information.
- Whether the nature of the query appropriately captures all journal entries for the relevant period(s).
- Whether the application controls relevant to the system query are effective.
- Whether the interface controls relevant to the system query are effective.
- Whether the GITCs relevant to the application(s) and database(s) from which the information is extracted
are effective.
[We need to be satisfied that members of the engagement team with appropriate competence and capabilities
are involved in carrying out audit procedures [KAM 33.1200]. Upfront involvement of IRM Specialists in this
assessment and documentation will be useful to address all of the considerations effectively and efficiently.]

3.3 Section III. Apply the high-risk criteria to the relevant population
As part of the documentation included at eAudIT activity 4.6.1, we document how the journal entries were selected for
testing.
3.3.1 Procedures - Reference [KAM 33.1065/33.1110]

5) Apply the entity-specific selection characteristics identified at Section I to the population of journal entries and other
adjustments that will be the source of our selections in order to identify high-risk journal entries for testing.
When selecting journal entries for testing, we may select all items (entire population) (100% examination), select
specific items and/or select items using data analysis. Specific items testing (in combination with data analysis) is
generally most effective in addressing fraud risks. It allows us to select items which are more likely to be
susceptible to intentional misstatement, for example, non-routine transactions and top-side journal entries.
Sampling of the whole population of journal entries and other adjustments is not efficient.
It may be appropriate to apply the characteristics to the entire population of journal entries and adjustments,
individually or in combination with each other in order to identify high-risk journal entries, which will be subject to
testing.
Document the selection process used to apply high-risk journal entry selection characteristics to the relevant
journal entry population, including the screening process and rationale for excluding any screened output from the
high-risk journal entries as also required at step 2.c. herein, if applicable.
[Methods for applying characteristics to the relevant journal entry population include but are not limited to the
following:
 Manually
 With the assistance of Forensic Specialists and K-DAT
 With D&A tools such as IDEA SmartAnalyzer, LUCA, KAAP.]
For each identified high-risk journal entry, perform testing consistent with Step 6 of this guidance document (i.e.,
100% testing).

3.4 Section IV. Test identified high-risk journal entries


As part of the documentation included at eAudIT activity 4.6.1, we document procedures performed over journal entries
selected for testing.
3.4.1 Procedures - Reference [KAM 33.1075/33.1120]
6) We may perform the following for high-risk journal entries (as applicable):

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 9 of 14 trademarks of KPMG International.
 
 Make inquiries of management to understand the nature of the journal entry or other adjustment, if necessary;
 Obtain appropriate supporting evidence;
 If the item is a recurring journal entry or other adjustment, compare to the prior period and assess whether it
remains appropriate;
 Assess and document whether the journal entry or adjustment:
o Was initiated by an authorized individual;
o Was reviewed and approved by an appropriate individual consistent with entity or group policy;
o Reflects the underlying events and transactions;
o Has been recorded in the correct accounting period at appropriate amounts;
o Has been recorded to the correct general ledger accounts (or has been included in the appropriate
financial statement captions);
o Is consistent with the entity’s accounting policies;
o Is indicative of management override of internal controls.
If there is any indication of fraud from management override of internal controls, engagement teams should refer to
KAM-topics – Fraud, for procedures to perform in response to the identification of an actual or suspected fraud.
In addition to the documentation requirements in the KAM topic, Journal Entries, engagement teams are reminded of
our documentation requirements in KAM topic, Audit Documentation.

3.5 Section V. Examine material post-closing entries made during the financial
statement closing process (post-closing entries)
3.5.1 Procedures - Reference [KAM 33.1130]
7) Agree material period end post-closing journal entries and other adjustments that are not recorded in the general
ledger to the appropriate document supporting the financial statements (such as an extended trial balance or a
consolidating schedule). Examples of post-closing journal entries and other adjustments may include consolidating
adjustments, reclassifications to the general ledger accounts and late changes to account balances and amounts.
8) Make inquiries of management to understand how material post-closing journal entries and other adjustments are
processed and accounted for.
9) Examine material post-closing journal entries and other adjustments made during the course of preparing the
financial statements.

For each journal entry or other adjustment selected for test work, we perform the procedures at step 6.

4. Putting into practice

Example 1 – Determination of Entity‐Specific Selection Characteristics 
 
Airlines, Inc. (“the Issuer”) is a regional air carrier that operates in 15 cities in the United States 
and  is  headquartered  in  Colorado.    The  Issuer  has  one  airline  reservation  system,  which 
records reservations and payments, one maintenance system for the air carriers and related 
procurement  system,  and  one  general  ledger  system.    The  reservation  and  maintenance 
systems automatically post journal entries and other adjustments to the general ledger.  After 
making  inquiries  of  individuals  involved  in  the  financial  reporting  process  and  obtaining  an 
understanding of the entity’s financial reporting process and controls over journal entries as 
set  out  in  Section  I  of  the  Audit  Program,  no  control  deficiencies  were  identified  over 
automated or manual processes that provided an opportunity  for management override of 
controls and the ability to introduce a fraudulent journal entry.   

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 10 of 14 trademarks of KPMG International.
 
 
The engagement team tested GITCs and application controls over all three systems and the 
related  interface  with  the  general  ledger  and  concluded  that  GITCs  and  the  applications 
systems were designed and operating effectively to mitigate the risk of management override 
to manipulate an automated entry.  Based on the engagement team’s understanding of the 
financial  reporting  process  and  the  effectiveness  of  the  GITCs  around  the  application  and 
related  interfaces,  the  engagement  team  determined  that  the  possibility  of  a  material 
misstatement  due  to  fraud  due  from  management  override  was  low  and  accordingly,  the 
automated journal entries were not identified as high‐risk journal entries.    
 
During  Risk  Assessment,  the  engagement  team,  in  discussion  with  IRM,  Forensics  and  Tax 
specialists, considered the following related to management override of controls which could 
influence the determination of high‐risk journal entries: 
 

1. The Issuer is close to not meeting analysts’ expectations of earnings for the fiscal 
year as a result of a decline in commercial charter sales in the fourth quarter.  The 
CEO and CFO are under significant pressure from the controlling shareholder to meet 
earnings forecasts.  This pressure could cause the CEO and/or CFO to take more 
aggressive positions or exert undue influence on the Commercial Charter Sales 
Manager in the area of commercial charter revenue cutoff and the recognition of 
maintenance accruals.  There is an increased risk of management override of 
controls in the last month of the year, particularly related to these specific accounts. 
 
2. Commercial charter revenue and maintenance expense were considered to have a 
fraud risk in the eAudIT tracker. 
a. For revenue, transactions are homogenous pools related to either commercial 
charters or individual consumer travel.  Inherent risk of error was considered 
significant and control risk was determined to be lower; therefore, the risk of 
material  misstatement  at  the  assertion  level  (ROMM)  was  assessed  as 
moderate.    However,  when  the  engagement  team  performed  substantive 
procedures, they utilized high ROMM to incorporate procedures specifically 
related  to  the  fraud  risk  in  accordance  with  PPL  12‐020.    The  engagement 
team  reviewed  some  journal  entries  in  connection  with  audit  procedures 
performed  in the revenue section  and determined the journal entries were 
appropriate and supported.  However, these procedures did not specifically 
address the commercial charter manual journal entries in the last quarter and 
the related fraud risk of management override of controls. 
 
b. For maintenance accruals, no fraud specific procedures were performed 
related to management override of controls of maintenance accrual journal 
entries. 
 
3. There were certain suspense accounts that were not reconciled by management. 
 
4. The initiators and authorizers of journal entries and other adjustments disclosed no 
instances of pressure or requests to record journal entries or other adjustments 
identified based on our inquiries. 
 

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 11 of 14 trademarks of KPMG International.
 
Based on the above, the engagement team considered certain combinations of the following 
characteristics to be indicative of high‐risk journal entries and other adjustments: 
 

1. Manual journal entries and other adjustments recorded in the last month of the fiscal 
period to maintenance accruals and commercial charter revenue. 
2. Manual journal entries and other adjustments initiated and/or posted by the CEO, CFO 
and Commercial Charter Sales Manager. 
3. Manual journal entries and other adjustments posted to credit maintenance expense 
and debit a balance sheet suspense account. 
 
The engagement team chose to apply the selection characteristics in the following manner to 
identify two buckets of high‐risk journal entries and other adjustments as follows: 
 

- Manual journal entries and other adjustments created by the CEO, CFO and 
Commercial Charter Sales Manager related to all maintenance accrual accounts and 
commercial charter revenue accounts in the last month of the fiscal year. 
‐ Manual journal entries and other adjustments posted to credit maintenance expense 
and debit a balance sheet suspense account anytime during the fiscal year.   

Example 2 ‐ Reassessment of Selection Characteristics
 
The  engagement  team  applied  the  preliminary  data  analysis  CAAT  screening  criteria  to  the 
journal  entry  population  with  the  intention  of  producing  preliminary  screened  output  that 
would  require  further  analysis  to  identify  high‐risk  journal  entries  based  on  selection 
characteristics.   
 

- All manual journal entries and other adjustments created by the CEO, CFO and 
Commercial Charter Sales Manager related to all maintenance accrual accounts and 
commercial charter revenue accounts in the last month of the fiscal year; and 
‐ Journal  entries  and  other  adjustments  posted  to  credit  maintenance  expense  and 
debit a balance sheet suspense account anytime during the fiscal year.   

 
The preliminary data analysis using the IDEA CAAT tool identified approximately 100 journal 
entries  and  other  adjustments.    The  auditor  reviewed  the  journal  entries  and  other 
adjustments and identified the following: 
 

1. 38  of  the  journal  entries  and  other  adjustments  related  to  a  journal  entry  code  of 
“TRA.” 
2. The  remaining  62  journal  entries  and  other  adjustments,  met  the  selection 
characteristics, and were considered high‐risk journal entries.  
 

The engagement team performed the following procedures: 

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 12 of 14 trademarks of KPMG International.
 
 

1. For the 38 journal entries and other adjustments with a “TRA” code, the engagement 
team met with the IT systems personnel and identified that the “TRA” code relates to 
entries  that  are  automatically  posted  from  an  in‐house  travel  agent  system.    The 
selection of these journal entries was caught by the screening criteria because we did 
not limit the second screen to manual journal entries and these entries were posted 
to the incorrect account.  The engagement team validated the information provided 
by  the  IT  systems  personnel  and  confirmed  the  automated  nature  of  the  entries 
without exception.   
 
The engagement team concluded that the TRA journal entries do not have a high risk 
of  fraud  and  therefore  would  be  excluded  from  further  testing  for  management 
override of internal controls.  This explanation was documented in the workpapers as 
support  for  the  exclusion  of  the  TRA  journal  entries  as  high‐risk  journal  entries.  

2. The auditor identified 62 journal entries and other adjustments, as high‐risk journal 
entries and examined 100% of the journal entries and other adjustments and obtained 
audit evidence to support there was no indication of fraud and that the journal entries 
were appropriately recorded in the general ledger. 

Example 3 – Testing for Completeness
 
As outlined in Example 1, the engagement team determined the following accounts would be 
the  source  for  selecting  high‐risk  journal  entries;  other  accounts  were  excluded  from  the 
source of selection because they were considered not to be high‐risk: 

o Commercial charter revenue accounts 
o Suspense accounts not reconciled 
o Maintenance accrual and expense accounts 
 
‐ The above accounts comprised nine accounts in the chart of accounts, which agreed 
to  the  accounts  in  the  detail  of  journal  entries  obtained,  (five  commercial  charter 
revenue accounts, two suspense accounts and two maintenance accrual and expense 
accounts). 
 
‐ The engagement team tested completeness using the roll‐forward method for these 
nine accounts since the high‐risk journal selection characteristics were limited to these 
accounts. 
 
‐ The engagement team had previously obtained a trial balance and mapped the trial 
balance to the financial statements without exception. 
 

Once  selected,  the  engagement  team  could  roll‐forward  these  accounts  through  various 
means, including: 

1. The  engagement  team  could  obtain  the  listing  of  journal  entries  and  other 
adjustments  in  Excel.    If  the  number  of  accounts  and  journal  entries  and  other 
adjustments is relatively small, the engagement team could determine that the 

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 13 of 14 trademarks of KPMG International.
 
most efficient manner to test the journal entries and other adjustments in the nine 
accounts is to filter the Excel file by account number and manually reconcile to the 
trial  balance  (since  the  trial  balance  was  previously  agreed  to  the  financial 
statements). 
 
2. The  engagement  team  could  obtain  the  listing  of  journal  entries  and  other 
adjustments  (in  a  number  of  formats)  and  upload  into  the  IDEA  tool.    This 
approach  is  most efficient when dealing with  a  larger organization  with  a  large 
number of accounts and journal entries and other adjustments.  
 
3. The engagement team could utilize KPMG Forensics to obtain the listing of journal 
entries and other adjustments (in a number of formats) and upload into the K‐DAT 
tool.  This approach is most efficient when dealing with a large organization with 
a large number of accounts and journal entries and other adjustments. 
 

Note ‐ For illustrative purposes, this example assumes the identification of a limited number of 
accounts used as the source for selecting high‐risk journal entries.  Engagement teams should 
exercise  professional  judgment  when  identifying  those  accounts  potentially  associated  with 
high‐risk journal entries and consequently the extent of completeness testing performed.   
 

Example 4 – Application of Specific Selection Characteristics 
 
The  engagement  team,  as  noted  in  Example  1,  determined  the  following  selection 
characteristics  were  to  be  applied  against  the  population  of  journal  entries  and  other 
adjustments: 

- Manual  journal  entries  and  other  adjustments  created  by  the  CEO,  CFO  and 
Commercial Charter Sales Manager related to all maintenance accrual accounts and 
commercial charter revenue accounts in the last month of the fiscal year. 
‐ Manual journal entries and other adjustments posted to credit maintenance expense 
and debit a balance sheet suspense account anytime during the fiscal year.   
 
As noted in Example 3, from the file containing the complete population of journal entries and 
other  adjustments,  the  engagement  team  extracted  all  manual  journal  entries  and  other 
adjustments representing the following accounts (nine accounts in total): 

‐ Commercial charter revenue accounts 
‐ Suspense accounts not reconciled 
‐ Maintenance accrual and expense accounts   
 
The engagement team then used the IDEA CAAT tool using a layering approach to apply the 
selection characteristics.  All journal entries identified after the  application of  the selection 
criteria were determined to be high‐risk journal entries and were selected for testing.  

Example 5 – Post‐closing Journal Entries and Other Adjustments 
 

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 14 of 14 trademarks of KPMG International.
 
Airlines, Inc. has a four step closing process.  

1. The first set of financial statements is utilized to reconcile the general ledger accounts.
2. The second set of financial statements is utilized by Management to perform a review 
and analytics. 
3. The  third  set  of  financial  statements  is  provided  to  the  auditors  and  the  audit 
committee. 
4. The  fourth  set  of  financial  statements  is  the  final  version  which  is  distributed  to 
investors. 
 
Therefore, the engagement team obtains the second set of financial statements utilized by 
Management and all entries posted beyond the second set of financial statements. 
 
The engagement team rolls forward the second set of financial statements to the fourth set of 
financial statements to ensure that all post‐closing journal entries and other adjustments were 
obtained.    The  engagement  team  performs  test  work  over  all  material  post‐closing  journal 
entries and other adjustments specifically to determine if these journal entries were recorded 
appropriately and to conclude on any monetary error caused by these journal entries. 
 
Note ‐ This example describes a regimented closing process that may not be as clearly defined 
for all entities in the preparation of financial statements.  Engagement teams should exercise 
professional  judgment  when  identifying  material  post‐closing  journal  entries  and  other 
adjustments for examination.  

© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlands under
number 33263683, is a member firm of the KPMG network of independent member firms affiliated
with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved.
Printed in the Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered
Guide Journal Entry Testing – page 15 of 14 trademarks of KPMG International.
 

Common questions

Powered by AI

The application of selection characteristics directly affects the identification of high-risk journal entries by providing a framework to consistently evaluate entries based on pre-defined risk factors, such as who initiated the entry, the nature of the accounts involved, and the timing of the entries. This structured approach facilitates the detection of entries that pose a significant fraud risk and ensures comprehensive testing of these high-risk areas .

Management's ability to override controls is significant because it enables them to manipulate accounting records and prepare fraudulent financial statements despite controls that appear to be operating effectively. This potential to perpetrate fraud is a presumed risk for all entities, requiring auditors to design and perform procedures to evaluate and address this risk, particularly in the context of journal entries .

Auditors face several challenges when testing post-closing journal entries, such as ensuring the completeness and correctness of entries that often involve complex adjustments. These entries, made during the financial statement closing process, may be subject to manipulation and require detailed scrutiny to assess their impact on the financial statements accurately .

Excluding certain accounts from high-risk journal entry testing can have significant implications if it leads to oversight of potential fraud indicators. It's crucial that auditors exercise professional judgment in identifying accounts that are susceptible to misstatement due to fraud. Failure to include all relevant accounts could result in incomplete audit procedures and an increased risk of undetected fraud .

KPMG's guidance on journal entry testing primarily aims to identify, select, and test journal entries for evidence of possible material misstatement due to management override of controls. The approach includes evaluating the entity’s financial reporting process, the completeness of journal entries, and testing high-risk journal entries, using data analytics as a key tool in the process .

Auditors use several criteria to identify high-risk journal entries, such as manual entries made at the end of a financial period, entries made by high-level executives like the CEO or CFO, and entries that involve accounts prone to fraud risk like maintenance expenses or suspense accounts. Additionally, the use of data analytics tools aids in identifying these high-risk transactions .

The completeness of the journal entry population is assessed by obtaining a full listing of journal entries and verifying it against the financial statements. Techniques like the roll-forward method and data analytics tools (e.g., IDEA) are used to ensure every entry is included. This process is crucial to ensure that no potential high-risk entry is overlooked during the selection process for testing .

Involving forensic specialists in journal entry testing is necessary because they bring expertise in identifying unusual patterns or characteristics associated with fraud. Their skills complement the regular audit process by focusing specifically on indicators of management override and fraud, which are critical in effectively addressing the significant risk of fraudulent financial reporting .

Data analytics tools play a crucial role in journal entry testing by enabling auditors to sift through vast amounts of data to identify high-risk entries. These tools, such as the IDEA SmartAnalyzer, help screen for generic characteristics that indicate high-risk entries, allowing for an iterative evaluation process to pinpoint entries most susceptible to fraud .

High-risk periods during a reporting cycle are determined by identifying times when journal entries are more likely to be manipulated for fraudulent purposes. This often includes the period just before the fiscal year-end, during which manual journal entries and unusual adjustments are more common as management attempts to influence the financial results .

Guide Journal Entry Testing – page 1 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 2 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 3 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 4 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 5 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 6 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 7 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 8 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 9 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherlan
Guide Journal Entry Testing – page 10 of 14 
© 2015 KPMG Accountants N.V., registered with the trade register in the Netherla

You might also like