Revenue is the number the market reads first, the number executive compensation most often rides on, and the account external audit standards treat as a presumed fraud risk. It is also — since ASC 606 and its IFRS twin — an account built on estimates and judgments: what counts as a contract, how many promises it contains, what the variable parts will resolve to, and when the work is actually done. That combination — maximum pressure, maximum judgment — is precisely the habitat where misstatement lives, and most of it arrives not as fake invoices but as defensible-sounding answers to judgment questions, each shaded a few degrees toward the number management needs.
Internal audit’s job here is not to re-perform the external audit. It is to test the machinery that produces revenue judgments — the controls, the estimation discipline, the modification pipeline, the cutoff hygiene — and to detect bias early, while it is still a control conversation rather than a restatement. This guide turns the five-step model into that program: internal audit’s lane versus external audit’s, the risks that attach to each step, the judgment areas where the money hides, the management-bias indicators, a complete test program, and how to coordinate with your external auditors instead of colliding with them.
This guide was rewritten in September 2026 to add what the August version left out: a starter risk and control matrix for the revenue process, how to size and sequence the engagement, Brightwater Foods’ revenue recognition audit test by test, the findings that recur with wording that lands, and the links to the guides that cover the rest of the cycle. The five-step risk map, the judgment areas, the bias indicators, the twelve-test program and the coordination approach are unchanged. The ACFE’s Occupational Fraud 2026 report puts financial statement fraud in 6 percent of its 2,402 cases with a median loss of one million dollars and a median duration of 24 months, the longest of any category, and revenue is the account most of those cases run through; the financial statement fraud guide works the mechanisms case by case.
In this guide
- Internal audit’s lane — and external audit’s
- The five steps as a risk map
- The starter RCM: ten controls that carry revenue recognition
- The judgment areas where the money hides
- Management-bias indicators
- Sizing and sequencing the engagement
- The test program
- Worked example: Brightwater Foods’ revenue recognition audit
- The findings that recur, and wording that lands
- Scoping variants: subscriptions, over-time contracts, rebate-heavy channels, grants
- Coordinating with external audit
- Where to go next
Internal audit’s lane — and external audit’s
External audit exists to opine on whether the reported number is materially right; its revenue work is substantive, opinion-driven, and concentrated at period end. If internal audit simply re-runs a smaller version of that, it adds little and annoys everyone. The internal audit angle is different in three ways. Controls over the process: does the machinery that identifies contracts, tracks modifications, computes allocations, and books revenue operate reliably all year — not just survive a year-end cleanup? Judgment quality: are estimates governed — documented methodology, consistent application, back-testing against outcomes — or re-litigated each quarter to land where needed? Early warning: quarterly-cadence analytics that catch drift in Q2, when it is a finding, instead of Q4, when it is a disclosure event. Frame the engagement this way in the planning memo and with the audit committee; it also sets up the coordination conversation at the end of this guide.
The five steps as a risk map
ASC 606’s model is one sentence: recognize revenue when (or as) you satisfy performance obligations, in the amount you expect to be entitled to. The five steps operationalize it, and each step carries its own failure modes:
| Step | What can go wrong | What internal audit tests |
|---|---|---|
| 1. Identify the contract | Side agreements and unsigned or backdated contracts; collectibility asserted for customers who cannot pay; contract modifications handled informally by sales and never reaching accounting | Contract-intake completeness (how does accounting learn what sales agreed to — including amendments buried in email?); sample contracts against approval and signature controls; modification pipeline from CRM to revenue system |
| 2. Identify performance obligations | Bundles not unbundled (distinct goods and services recognized as one), or over-unbundled to accelerate; material rights — discounts and options that are themselves promises — missed entirely | Sample bundled arrangements against the documented PO analysis; test that new product launches and new deal structures trigger fresh assessment rather than inheriting old templates |
| 3. Determine transaction price | Variable consideration — rebates, returns, penalties, service credits — estimated aggressively; the constraint applied in words but not numbers; financing components and noncash consideration ignored | The estimation machinery: methodology documentation, input support, consistency across periods — and the back-test in the next section |
| 4. Allocate the price | Standalone selling prices stale, unsupported, or tuned so that revenue lands on the obligations that recognize soonest | SSP methodology and refresh cadence; re-perform allocations for a sample of multi-element deals; look for allocation patterns that systematically favor delivered elements |
| 5. Recognize when/as satisfied | Point-in-time vs. over-time misclassification; percentage-of-completion measures steered through cost-estimate revisions; bill-and-hold arrangements failing the criteria; plain cutoff errors around shipping terms | Classification decisions against the criteria; estimate-at-completion revision patterns on over-time contracts; bill-and-hold population testing; two-sided cutoff testing at period end |
Two scoping notes. Work by revenue stream, not by the standard: a company’s product, subscription, usage, and services revenue each fail differently, and one generic program tests none of them well — build a lane in your risk and control matrix per material stream. And weight the audit toward steps 3 and 5: step-level misstatement risk is not uniform, and the estimates (price) and timing (satisfaction) steps are where judgment concentrates — which is exactly where the next section goes.
The starter RCM: ten controls that carry revenue recognition
The five-step map above says where revenue can go wrong; the matrix below says what should stop it. Ten controls carry the process in most organizations, and the per-stream lane the scoping note recommends is built by taking these ten and asking, for each material stream, whether the control exists, who performs it and what evidences it. Build them in the RCM template; a control marked absent is a design finding before any contract is sampled.
| Control | Step | What it prevents or detects | How to test it |
|---|---|---|---|
| Contract intake: every customer agreement and amendment reaches accounting through one channel before revenue is recognized on it, with sales-side terms captured in the system | 1 | Side agreements, email amendments, backdated contracts | Trace a sample of amendments from CRM and sales email to the revenue system; count the ones that never arrived |
| Five-step assessment documented for each new contract type or deal structure, approved by someone outside sales, and refreshed on modification | 1 to 5 | Bundles inherited from old templates; material rights missed | Sample new deal structures in the year against a completed assessment; test that modifications triggered a refresh |
| Variable consideration estimated by a documented method from data, with the constraint applied in numbers, reviewed by someone who did not prepare it, and back-tested quarterly against outcomes | 3 | Aggressive estimates; the constraint applied in words | Re-perform the largest estimates; run the back-test; inspect the review evidence |
| Standalone selling prices supported by observable data, refreshed on a schedule, with changes approved and their effect on allocation quantified | 4 | Stale or tuned prices that front-load recognition | Inspect the SSP file and refresh log; re-perform allocation for a sample of multi-element deals |
| Recognition pattern (point in time or over time) determined per stream against the criteria and reviewed annually; over-time measures supported by estimates at completion reviewed by someone outside the project | 5 | Misclassification; EAC steering | Inspect the classification memos; trend EAC revisions by contract and quarter |
| Cut-off enforced by system from shipping terms and delivery evidence, with a two-sided cut-off review at each period end | 5 | Shipment-date recognition on destination terms; the last-day push | Two-sided cut-off test at two period ends; inspect the period-end review |
| Bill-and-hold and consignment arrangements identified at contract intake and recognized only against the documented criteria, with customer request evidence | 5 | Revenue on goods still in the warehouse | Full population of arrangements tested against the criteria |
| Credit memos, returns and deductions monitored against prior-period revenue, with the next-period echo reported to the controller | Bias | Pull-forward revealed by next-period reversals | Full-population echo analytic; inspect the monthly report |
| Manual journals to revenue and deferred revenue routed through the journal control with risk scoring, and reviewed by the controller each period | Bias | Override through the ledger | Journal analytics on the revenue accounts; sample the late, round and senior-posted entries |
| Deferred and unbilled revenue rolled forward and aged monthly, with unbilled balances older than a set period investigated | 3 and 5 | Revenue billing cannot support | Inspect twelve roll-forwards; trace aged unbilled items |
The judgment areas where the money hides
Variable consideration is the biggest lever. Rebates, expected returns, volume discounts, performance penalties, and service credits all reduce the transaction price by an estimate — and every dollar the estimate is shaved adds a dollar of current revenue. The single most powerful test internal audit can run here is the back-test: take the estimates recorded four, six, eight quarters ago and compare them to how the amounts actually resolved. A well-governed estimate misses in both directions; a biased one misses persistently in the direction that helped, and the pattern is unanswerable in a way no debate about this quarter’s assumptions can be — the same instrument we use against risk ratings in the RCSA guide, pointed at accounting estimates. Over-time measures are the second lever. On percentage-of-completion contracts, revenue follows the estimate at completion, so steering the cost estimate steers the revenue — trend EAC revisions by contract and by quarter, and treat clusters of favorable revisions at period end as exactly what they look like. Allocation and modification round out the set: standalone selling prices that drift stale (or converge on whatever front-loads recognition), and contract modifications — the pipeline through which a signed deal quietly becomes a different deal — handled by sales in email, reaching accounting late or never. For each area the audit question is the same: is there a documented methodology, applied consistently, supported by data, and reviewed by someone who did not produce the number?
Management-bias indicators
Bias rarely announces itself; it accumulates in patterns. These are the ones worth computing every quarter, not just at audit time:
- One-sided estimates: variable-consideration and EAC revisions that resolve unfavorably (against the original estimate) far more often than favorably — the back-test’s smoking gun.
- Quarter-end gravity: revenue, estimate revisions, and manual adjustments clustering in the final days of the period; compare the last-five-days share of quarterly revenue across quarters and streams.
- The credit-memo echo: credit memos and returns issued early in the next period against revenue booked late in the prior one — the classic pull-forward signature, testable at full population.
- Manual journal entries to revenue accounts: especially late, round-dollar, or posted by senior personnel — route these through the full framework in our journal entry testing guide, because revenue is where management override goes to work.
- Threshold-hugging outcomes: quarters that land just over guidance or bonus triggers repeatedly; improbable smoothness is itself a signal.
- Estimate methodology churn: assumptions or SSP methods that change whenever the old method would have produced a worse number — change is legitimate, correlated change is not.
Sizing and sequencing the engagement
Revenue audits are sized by streams and by the state of the estimates. One stream with clean data is 200 hours; four streams, an over-time contract portfolio and a deductions backlog are 320 to 400, most of the difference in the back-tests, which need several quarters of estimates and outcomes joined at the customer and program level. The ranges below assume two or three material streams, an ERP that holds contracts and billing, a CRM that holds the sales side, and an auditor with the journal entry analytics already built. Time the engagement for the second or third quarter, for the reason the coordination section gives: findings in Q2 are control conversations, findings in Q4 are disclosure events.
| Phase | What happens | Hours |
|---|---|---|
| Planning and the streams | Revenue disaggregated by stream; materiality by stream; the per-stream RCM drafted; the external auditor’s plan and prior points read | 30 |
| Walkthrough per stream | One contract per stream from intake to recognition; the modification path and the estimate path walked separately | 30 to 40 |
| Data acquisition and joins | Contracts, amendments, billing, shipments and delivery evidence, estimates by quarter with outcomes, credits and deductions, journals, deferred and unbilled roll-forwards | 40 to 50 |
| Analytics and back-tests | The back-tests, the echo, the cut-off profile, the EAC trend and the journal scoring, on full populations | 60 to 80 |
| Control and judgment tests | The twelve-test program, with the contract samples aimed by the analytics | 90 to 120 |
| External audit coordination | Plan shared, RCM aligned, findings protocol agreed, results handed over in time for reliance | 20 |
| Reporting | Findings written to the control and the estimate, with the back-test charts; base rates on every number | 40 |
| Total | 310 to 380 |
Sequence the walkthrough first, per stream, because the estimate path in particular is never where the process document says it is; the back-tests second, because they choose which estimates the judgment tests examine; and the coordination conversation before the fieldwork rather than after, because the scope should lean toward what the external team will not do.
The test program
| # | Test | Focus |
|---|---|---|
| 1 | Walk order-to-cash for each material revenue stream — contract intake through billing to recognition — and update the per-stream RCM before testing | All |
| 2 | Sample contracts per stream against the five-step documentation: contract criteria, PO analysis, price determination, allocation, recognition pattern | Steps 1–5 |
| 3 | Test the modification pipeline: trace a sample of amendments from CRM/sales records into the revenue system; hunt for amendments that never arrived | Step 1 |
| 4 | Back-test variable consideration: prior-period estimates vs. actual resolution, by stream and estimate type; assess directional bias | Step 3 |
| 5 | Review SSP methodology, support, and refresh dates; re-perform allocation for a sample of multi-element arrangements | Step 4 |
| 6 | Trend estimate-at-completion revisions on over-time contracts by quarter; inspect contracts with favorable period-end revisions | Step 5 |
| 7 | Two-sided cutoff test: shipments/deliveries in the last and first N days vs. recognition period, honoring shipping terms; per your sampling standard or at full population where data allows | Step 5 |
| 8 | Full-population credit-memo echo analytic: next-period credits mapped to prior-period revenue, by customer and salesperson | Bias |
| 9 | Test manual journal entries to revenue and deferred-revenue accounts (risk-scored selection per the JE guide) | Bias / override |
| 10 | Pull the complete bill-and-hold population; test each against the recognition criteria and customer-request evidence | Step 5 |
| 11 | Roll forward deferred and unbilled revenue; investigate aging unbilled balances (revenue recognized that billing cannot support) | Steps 3/5 |
| 12 | Tie disclosure inputs — disaggregation categories, remaining performance obligations — back to system data for accuracy and completeness | Reporting |
Worked example: Brightwater Foods’ revenue recognition audit
Brightwater Foods, the 180-million-dollar food manufacturer with three plants and about 600 staff used across this site, sells to grocery chains, distributors and foodservice operators, about 1,900 active accounts, and runs a small co-packing stream for other brands billed monthly on volumes. Its revenue is 181 million dollars in the year, recognized at delivery for product and monthly for co-packing, and reduced by trade promotions, volume rebates and deductions that the receivables audit had found running to a 3.1 million-dollar backlog. The revenue recognition audit was scheduled for the second quarter after that engagement, so that anything it found would be a control conversation rather than an audit adjustment, and it took 280 hours, sixty of them the co-source specialist’s back-tests.
| Test | What it found | Disposition |
|---|---|---|
| 1. Walkthrough by stream | Product and co-packing walked separately; the trade-promotion accrual was maintained by the sales finance analyst from a spreadsheet of agreements that the controller received quarterly; contract amendments lived in sales email. | RCM redrawn per stream; intake and estimate controls marked as absent by design |
| 2. Five-step documentation | Of 25 contracts sampled across the three customer types, 19 had a documented assessment; six distributor agreements with volume rebates had inherited a template that treated the rebate as a period expense rather than variable consideration. | Finding, Medium: assessment coverage for rebate-bearing agreements |
| 3. Modification pipeline | Of 40 amendments traced from sales records, 14 had not reached accounting at the quarter end following signature; nine changed pricing or promotion terms. | Finding, Medium: contract intake |
| 4. Variable consideration back-test | The trade-promotion accrual was under-estimated in six of the last eight quarters, by 180,000 to 420,000 dollars each, and over-estimated in none; the resolution pattern matched the deductions backlog the receivables audit had found. | Finding, High: a one-sided estimate |
| 5. Standalone selling prices | Not material: product sales are single-element; two bundled co-packing and warehousing agreements allocated on observable rates. | No finding |
| 6. Over-time measures | Co-packing recognized monthly on volumes processed with no estimate at completion involved; no EAC exposure. | No finding; stream documented as point-in-time equivalent |
| 7. Two-sided cut-off | At the March and June quarter ends, 1,100 invoices for deliveries on destination terms were recognized at shipment in the last three days, 2.4 million dollars, with delivery in the next period for 380 of them, 810,000 dollars. | Finding, Medium: cut-off on destination terms |
| 8. Credit memo echo | Credits in the first two weeks of each quarter against prior-quarter revenue ran at 1.9 times the historical rate in the two quarters after a sales incentive change, concentrated in one distributor channel. | Finding, Medium: incentive design, routed to sales management with the analytic |
| 9. Manual journals to revenue | 62 manual entries to revenue and deferred revenue in the year; nine posted in the last two days of a quarter, four of them round; all supported on inspection, two prepared and approved by the controller. | Segregation observation; entries added to the quarterly journal program |
| 10. Bill-and-hold | Three arrangements at year-end, 410,000 dollars; two met the criteria with customer request evidence; one, 140,000 dollars, had no customer request and the goods were still in Brightwater’s warehouse at the next count. | Finding, Medium; reversed before year-end close |
| 11. Deferred and unbilled roll-forward | Unbilled co-packing revenue aged past sixty days for two customers, 96,000 dollars, arising from volume reports received late. | Finding, Low |
| 12. Disclosure inputs | Disaggregation by customer type tied to the billing system within rounding; remaining performance obligations not applicable to the product stream and documented for co-packing. | No finding |
The report carried seven findings, one High, five Medium and one Low, and an overall rating of Needs Improvement. The High was the back-test, and it was written as a chart and a sentence: six of eight quarters under-estimated, none over, and the reason the deductions backlog existed. The finding landed with the audit committee because the same money had appeared in the receivables report as a backlog and now appeared in the revenue report as an estimate, and the committee understood that they were one thing seen from two sides. Three things generalize. The back-test found what no contract sample could have, because every quarter’s accrual was individually defensible and only the pattern was not. The cut-off finding was a shipping-terms problem, not an intent problem, and the fix was a system rule that read the terms; the report said so, and the sales team, who had expected to be accused, helped design the rule. And the whole engagement was over before the external auditor’s interim visit, which converted a High finding into a remediation the auditor tested rather than an adjustment the auditor booked.
The findings that recur, and wording that lands
Revenue findings carry the hazard of the word fraud, and the discipline of the five Cs keeps it out: the condition is a pattern, the cause is a method, and the consequence is a number with a direction. The two below recur in most engagements.
One-sided variable consideration. Condition: the trade-promotion accrual, which reduces product revenue for retailer promotions and volume rebates, has been under-estimated in six of the last eight quarters by between 180,000 and 420,000 dollars and over-estimated in none, against an accrual balance of 2.1 to 2.6 million dollars; the under-estimates resolved as deductions in the following quarters and account for most of the 3.1 million-dollar deductions backlog. Criteria: the revenue policy requires variable consideration to be estimated by a documented method from agreement data, constrained to the amount not probable of significant reversal, and back-tested against outcomes each quarter. Cause: the accrual is maintained by the sales finance analyst from a spreadsheet of promotion agreements that does not capture amendments made in sales email, is not reviewed against outcomes, and is reduced at quarter end when the forecast requires it. Consequence: product revenue has been overstated by 180,000 to 420,000 dollars in six quarters and the pattern is consistent in direction, which is the signature the financial statement fraud guide describes; the external auditor’s interim visit would have found it. Corrective action: the accrual will be calculated in the ERP’s rebate module from agreement data loaded at intake, back-tested quarterly by the controller with the results reported to the audit committee, and any quarter-end reduction approved by the chief financial officer with the reason recorded (controller, by the third quarter).
Cut-off on destination terms. Condition: at two quarter ends, 1,100 invoices for deliveries on destination shipping terms were recognized at shipment in the last three days of the quarter, 2.4 million dollars; for 380 of them, 810,000 dollars, delivery occurred in the following period. Criteria: the revenue policy recognizes product revenue when control transfers, which on destination terms is at delivery. Cause: the billing system recognizes revenue at the shipment event for every order regardless of the terms on the customer master, and the period-end cut-off review examines shipment dates rather than delivery dates. Consequence: revenue is recognized one to four days early on destination-term deliveries at every period end, 810,000 dollars at the June quarter, which is below materiality and systematic. Corrective action: the billing system will be configured to recognize revenue at the delivery event for destination-term customers, and the period-end review will test delivery dates for the last five days (controller, by quarter end).
Scoping variants: subscriptions, over-time contracts, rebate-heavy channels, grants
The program above is written for a product business with a modest service stream, and the weight moves with the model. Subscription and software businesses move the risk to steps 2 and 4: the bundle of licence, support, implementation and usage has to be unbundled into obligations, the standalone selling prices carry the allocation, and the deferred revenue roll-forward is the population the audit lives in; the modification pipeline matters more still, because upgrades, downgrades and renewals are all modifications, and the back-test is run on usage estimates and renewal assumptions rather than on rebates. Over-time contracts, construction, engineering, long-term services, move everything to step 5: the estimate at completion is the revenue, the trend of its revisions is the bias indicator, and the audit adds a project-by-project review of the largest contracts with the project managers, because the cost estimate is where the steering happens and the accountant only records it. Rebate-heavy channels, consumer goods sold through retailers and distributors, look like Brightwater, and the back-test of trade promotion and volume rebate accruals is the whole engagement’s center of gravity; the receivables audit’s deductions backlog is the same money seen later, and the two engagements should share a data set. Grant and contract revenue in the public and non-profit sectors follows different standards but the same shape: eligibility of costs stands in for performance obligations, the drawdown against the award stands in for billing, and unbilled and deferred balances carry the risk. In every variant, the instruments are the same: the walkthrough per stream, the back-test of whatever estimate drives the number, the two-sided cut-off, the echo, and the journal scoring on the revenue accounts.
Coordinating with external audit
Revenue is the one audit where your external auditors are guaranteed to be working the same ground, so coordinate deliberately — the Standards expect it, and the practice pays. Share the plan early: which streams, which controls, which quarters, so their reliance decisions can account for your work and your scope can lean toward what they will not do (the year-round control cadence, the back-tests, the bias analytics) rather than duplicating year-end substantive testing. Align on the control universe — handing over your per-stream RCM beats letting two teams maintain two divergent maps of the same process — and agree the protocol for findings that touch the financial statements, because an internal audit finding on revenue controls that surprises the external team in March damages exactly the credibility that makes reliance possible. Timing is the quiet win: internal audit work landing in Q2–Q3 gives management runway to remediate before the external testing window, converting potential audit adjustments into closed findings — which is the most useful thing an internal audit function can do for a revenue cycle all year.
Where to go next
Revenue misstatement in the ASC 606 era is mostly an estimates story: pressure meets judgment, and the judgments drift. That is why the program leans on back-testing, revision trending and full-population bias analytics, instruments that measure the drift itself rather than the paperwork around it. Build the per-stream matrix from the ten controls, write the program to the five-element standard in the work program guide, run the analytics quarterly rather than annually, and coordinate with the external team so both functions compound. The back half of the cycle, from invoice to cash, is in the receivables guide; the whole cycle as one chain is in the order-to-cash guide; the entries that override the estimates are scored in the journal entry analytics catalog; and the schemes revenue testing exists to catch are worked through case by case in the financial statement fraud guide.
Related guides
- How to audit accounts receivable and collections — the back half of the cycle, with Brightwater’s receivables engagement
- How to audit order-to-cash end to end — the cycle as one chain, with MidState’s engagement
- Financial statement fraud — the five mechanisms, with Pennine’s quarterly program
- How to audit journal entries — the management override lens
- The journal entry analytics catalog — risk-scoring the revenue accounts
- How to audit the financial close — where the cut-off and the estimates are booked
- SOX scoping and risk assessment — why revenue is a presumed fraud risk in scoping
- Management review controls — the estimate reviews, evidenced
- The RCSA process — the back-test instrument in its original setting
- The risk and control matrix template — where the per-stream matrix lives
- Writing the audit work program — the five-element procedure standard
- The sampling memo template — documenting the contract sample by stream
- The 5 C’s of audit findings — the form the two findings above are written in
- The finding and issue log template — tracking seven findings to the external auditor’s timetable
- The ACFE fraud tree explained — financial statement fraud in context
- Fieldwork and testing guides and regulation and compliance guides — the full collections
Leave a Reply