Account reconciliations are the control everyone has and almost nobody audits as a whole. Each reconciliation gets tested on its own, a bank reconciliation here, a suspense account there, usually because it belongs to a process somebody is already auditing. The program that decides which of three thousand accounts get reconciled, how often, by whom, to what standard, and what happens when a difference sits there for a year, is audited by nobody, because it belongs to nobody in particular. Yet the program is the control: a single missed reconciliation is an exception, but a reconciliation program that rates a wire suspense account as low risk, lets a preparer review her own work, and permits reconciling items to roll forward unexamined for six months is the condition that lets losses hide in the ledger indefinitely.
This guide audits reconciliations as a program. It covers what a reconciliation actually proves and the population it has to cover, a risk map, a ten-control starter matrix, the standard a complete reconciliation has to meet, how to size and sequence the engagement, a 14-test program, the analytics that profile a reconciliation population, Lakeshore Bancorp’s reconciliation program audit with every test’s result, the findings that recur with wording that lands, and scoping variants for banks, corporates, shared service centers and small organizations. It sits beside the cash and bank reconciliation guide, which covers the most important reconciliations in depth, and the financial close guide, which covers the process the reconciliations belong to.
In this guide
- Know the terrain: what a reconciliation proves, and the population
- The reconciliation program risk map
- The starter RCM: ten controls that make reconciliations a program
- The standard: what a complete reconciliation contains
- Sizing and sequencing the engagement
- The 14-test program
- The analytics that profile a reconciliation population
- Worked example: Lakeshore Bancorp’s reconciliation program audit
- The findings that recur, and wording that lands
- Common mistakes in reconciliation program audits
- Scoping variants: banks, corporates, shared services, small organizations
- Where to go next
Know the terrain: what a reconciliation proves, and the population
A reconciliation proves one thing: that a general ledger balance agrees to an independent source, with every difference identified, explained, aged and owned. The independence of the source is the whole point. A bank statement, a custodian’s report, a subledger maintained by a different system, a physical count, a counterparty confirmation: each is evidence that exists outside the ledger and outside the control of the person who posts to it. A “reconciliation” that compares the ledger to a spreadsheet maintained by the same person from the same postings proves nothing except that the person can add, and a surprising share of the reconciliations in any population are of that kind. The audit’s first question about every account is therefore not whether it is reconciled but what it is reconciled to.
The population is every balance sheet account, and in a bank or a large corporate that is thousands. A program handles the population by risk rating: each account rated by balance, activity, the nature of what flows through it and the history of differences, with the rating setting the frequency, the reviewer level and the clearance deadline. Daily for settlement, clearing and nostro accounts where a difference today is a loss tomorrow; monthly for most operating accounts; quarterly for the stable and the small. The rating is itself a control and the one most often wrong, because it is set once and the account changes: the low-risk account that became a suspense account for a new payment channel, the dormant account that started clearing wires. Reconciliation risk concentrates in three places the program’s design decides: suspense and clearing accounts, where differences park; intercompany and interface accounts, where two systems disagree; and any account whose preparer can also post to it, where a difference can be made to disappear.
The reconciliation program risk map
| # | Risk | What it looks like in the file | Where it hurts |
|---|---|---|---|
| R1 | Population gaps: accounts with balances that are in nobody’s program | Ledger accounts not in the reconciliation tool; accounts opened during the year never added; accounts marked not applicable with activity | Balances nobody has proven; the account a loss hides in |
| R2 | Risk rating by inertia: frequency and review level set at go-live and never revisited | Suspense and clearing accounts rated low; high-activity accounts on quarterly cycles; ratings unchanged for years | The most dangerous accounts reconciled least |
| R3 | Source not independent: the ledger reconciled to a spreadsheet, a report from the same system, or a balance the preparer controls | Reconciliations with no external document; sources described as “system report”; source and ledger always equal | The control exists on paper only |
| R4 | Aged and repeated differences: items rolled forward month after month, described as timing | Reconciling items past the clearance deadline; identical descriptions across months; growing gross with stable net | Losses and errors carried indefinitely; the plug waiting to happen |
| R5 | The plug: differences cleared by journal entry to an expense, suspense or intercompany account rather than resolved | Journals with “to clear reconciliation difference” descriptions; write-offs of differences without approval; suspense balances that reset at period end | Misstatement, and the concealment mechanism for theft through the ledger |
| R6 | Review as signature: reviewers who approve in bulk, in minutes, without a query | Reviewer velocity; zero queries over a year; reviews dated after certification | The second pair of eyes that never looked |
| R7 | Certification theater: quarterly owner certifications signed for accounts with open aged items or unreconciled status | Certifications at 100 percent with exceptions elsewhere in the tool | The board and the examiner told what is not true |
| R8 | Segregation: preparers who post to the accounts they reconcile; reviewers who prepare | Access extract joined to the preparer list; preparer equal to reviewer in the log | A difference that can be made to disappear by the person who created it |
The starter RCM: ten controls that make reconciliations a program
Ten controls turn a collection of reconciliations into a program. Build them in the RCM template; in a SOX or Provision 29 environment the reconciliation control is usually key or material, and the SOX scoping guide explains why the program-level controls, not the individual reconciliations, are the ones that decide whether the key control can be relied on.
| Control | Type | Risk | How to test it |
|---|---|---|---|
| A complete inventory of balance sheet accounts reconciled to the chart of accounts monthly, with every account assigned to the program, marked not applicable with a reason, or flagged as new | Detective | R1 | Reconcile the chart to the tool’s inventory at two dates; test every not-applicable account for activity |
| Risk rating by documented criteria (balance, activity, nature, history), setting frequency, reviewer level and clearance deadline, reviewed annually and on trigger | Preventive | R2 | Re-rate a sample of accounts from the criteria; compare to the tool; test the annual review and the triggers |
| A reconciliation standard requiring an independent source, itemized differences with age, reason and owner, and preparer and reviewer identity with timestamps | Preventive | R3, R4 | Sample reconciliations against the standard; classify sources for independence |
| Preparation and review by different people, with reviewers at the level the rating requires and review evidenced by queries where warranted | Preventive and detective | R6, R8 | Preparer against reviewer in the log for the year; reviewer velocity and query rate profiled |
| Clearance deadlines by risk rating, with aged items escalated to the controller and to the owner’s manager on a schedule | Detective | R4 | Aged item report at four period ends; escalation evidence for items past deadline |
| Write-off of differences only with approval at a level set by amount, by someone independent of the preparer, with the root cause recorded | Preventive | R5 | Full population of write-offs against the approval matrix; root causes inspected |
| Journal entries that clear reconciling items routed to the controller, with the reconciliation referenced and the counter-account justified | Preventive | R5 | Journal analytics on descriptions and counter-accounts; sample traced to the reconciliation |
| Quarterly certification by account owners that reads from the tool’s status and cannot be signed for accounts with open exceptions without noting them | Detective | R7 | Certifications joined to the tool’s status at the certification date |
| Preparers barred from posting rights on the accounts they reconcile, enforced through the ledger’s access model | Preventive | R8 | Access extract joined to the preparer assignment list |
| Program metrics reported monthly: completion, timeliness, aged items by bucket and owner, unexplained differences, write-offs, and reviewer query rates, with escalation to the audit committee quarterly | Entity-level | All | Twelve months of reporting; a metric that moved traced to an action |
The standard: what a complete reconciliation contains
Most reconciliation findings come down to a reconciliation that is missing one of the elements below, and most reconciliation policies fail to list them. The standard is short enough to be a page in the accounting manual and a checklist in the tool, and the audit tests every sampled reconciliation against it.
Reconciliation standard. 1. Identity: the account number and name, the entity, the as-of date, and the risk rating with its frequency and clearance deadline. 2. Ledger balance: the general ledger balance at the as-of date, taken from the ledger and not re-typed. 3. Source balance: the balance from the independent source, with the source document attached or referenced, and the source’s independence stated (bank, custodian, subledger system, count, confirmation). 4. Reconciling items: each difference listed separately with its amount, the date it arose, its age at the as-of date, its cause in one sentence, the action to clear it, the owner of that action and the expected clearance date; no item described only as “timing”. 5. Unexplained difference: the residual that no item explains, stated explicitly even when it is zero, with the threshold above which it must be escalated. 6. Preparation and review: the preparer’s identity and completion timestamp; the reviewer’s identity, timestamp and the queries raised, or a positive statement that none were warranted and why. 7. Aging summary: reconciling items by age bucket against the clearance deadline, with items past deadline flagged for escalation. 8. Conclusion: a statement that the ledger balance is supported by the source, or that it is not, and the amount by which it is not.
Item 3 is where most reconciliations fail the standard and item 4 is where most of the risk is found. A reconciliation that lists “timing difference, 41,200 dollars” every month for a year is not reconciled; it is a running record of an unexplained difference, and the audit reads it as one.
Sizing and sequencing the engagement
A program audit is sized by the population and by whether a reconciliation tool exists. With a tool, the population analytics take a day and the engagement is 220 to 300 hours; without one, the inventory has to be built from the chart of accounts and a shared drive, and the first sixty hours are spent finding out what is reconciled at all. The ranges below assume a tool, a population of a few thousand accounts, and an auditor who can join the tool’s export to the ledger and the access model. Record the stratification in the sampling memo: the re-performance sample is weighted toward suspense, clearing, interface and high-activity accounts, and a reviewer will ask why it is not random.
| Phase | What happens | Hours |
|---|---|---|
| Planning and criteria | Reconciliation policy, risk-rating criteria, the standard, the approval matrix for write-offs, and the tool’s configuration obtained; the RCM drafted | 20 |
| Inventory and rating | Chart of accounts reconciled to the tool at two dates; every not-applicable account tested for activity; a sample re-rated from the criteria | 40 to 50 |
| Population analytics | The profile below run on the tool’s export for twelve months: timeliness, aging, repetition, reviewer velocity, sources, write-offs, plugs | 40 to 50 |
| Re-performance | Twenty-five to forty reconciliations re-performed against the standard, weighted to suspense, clearing, interface and high-activity accounts and to every account with aged unexplained differences | 70 to 100 |
| Program controls | Certification, write-off approvals, clearing journals, segregation, metrics and escalation tested | 40 to 50 |
| Reporting | Findings at program level with the population quantified; account-level exceptions listed in an appendix for the controller | 30 to 40 |
| Total | 240 to 310 |
Sequence the inventory first, because a program that misses accounts cannot be tested on the accounts it has; the analytics second, because the aging and repetition profiles choose the re-performance sample; and the certification test last, after the aged items are known, because the finding is not that certifications were signed but that they were signed over open exceptions the certifier could have seen.
The 14-test program
| # | Test | Population and method | Risk |
|---|---|---|---|
| 1 | Walk the program: from account opening to rating, assignment, preparation, review, escalation, certification and reporting; redraw the RCM | One account per rating level | All |
| 2 | Inventory completeness: chart of accounts against the tool at two dates; accounts opened in the year; not-applicable accounts tested for balances and activity | Full chart, two dates | R1 |
| 3 | Risk rating: a sample re-rated from the criteria; suspense, clearing, interface and intercompany accounts checked for rating and frequency; the annual review and triggers evidenced | Sample 40; all suspense and clearing accounts | R2 |
| 4 | Source independence: sources classified for every reconciliation in the re-performance sample and profiled for the population where the tool records source type | Sample; population profile | R3 |
| 5 | Re-performance: reconciliations re-performed against the standard, with reconciling items traced to support and subsequent clearance | Sample 25 to 40, weighted | R3, R4 |
| 6 | Timeliness: preparation and review timestamps against due dates by rating for twelve months | Full population | R4, R6 |
| 7 | Aging and repetition: reconciling items past clearance deadline at four period ends; identical items across months; escalation evidence | Full population, four dates | R4 |
| 8 | Write-offs of differences: full population against the approval matrix; root causes inspected; recurrence by account | Full population | R5 |
| 9 | Clearing journals: journal analytics for descriptions and counter-accounts indicating differences cleared by entry; sample traced to the reconciliation and its approval | Full journal file; sample 25 | R5 |
| 10 | Review quality: reviewer velocity and query rate by reviewer; reviews dated after certification; reviewer level against rating | Full population | R6 |
| 11 | Certification: quarterly certifications joined to the tool’s status at the certification date; certifications over open exceptions listed | Four quarters | R7 |
| 12 | Segregation: preparer and reviewer assignments joined to the ledger’s posting rights and to each other | Access extract | R8 |
| 13 | Tool configuration: auto-certification rules, roll-forward settings, threshold parameters and change history inspected | Configuration | R4, R7 |
| 14 | Metrics and prior points: twelve months of program reporting; a metric that moved traced to an action; prior internal and external audit points on reconciliations re-tested | Twelve months; all prior points | All |
The analytics that profile a reconciliation population
| Analytic | Logic | A hit usually means |
|---|---|---|
| Inventory gap | Chart of accounts with balances or activity, less accounts in the tool, less approved not-applicable accounts | Balances outside the program |
| Rating mismatch | Accounts whose activity, nature or history score above their assigned rating | Suspense and clearing accounts reconciled less often than they should be |
| Aged unexplained | Reconciling items past deadline by age bucket, with the unexplained residual, by account and owner | The accounts to re-perform first; the losses waiting to be found |
| Repeated item | Reconciling items with the same description and amount across consecutive months | Roll-forward without investigation; a difference being carried |
| Reviewer velocity | Reconciliations approved per reviewer per hour, and the share with any query recorded | Review as signature |
| Plug detector | Journals whose description contains clear, reconcile, difference, balance or adjust, posted to suspense, expense or intercompany counter-accounts near period end | Differences resolved by entry rather than by cause |
| Write-off recurrence | Write-offs of differences by account over eight quarters | An account whose differences are written off rather than fixed |
| Certification conflict | Certifications signed for accounts with open aged items or unreconciled status at the certification date | Certification theater |
Worked example: Lakeshore Bancorp’s reconciliation program audit
Lakeshore Bancorp is the 9-billion-dollar public regional bank used across this site, with a 22-person internal audit function and a national bank as its lead subsidiary. Its reconciliation program covered about 3,100 general ledger accounts in a reconciliation tool: 420 reconciled daily (settlement, clearing, nostro and wire accounts), 1,860 monthly, and the rest quarterly or annually by risk rating, prepared by 41 people and reviewed by 19, with quarterly certification by account owners. The wire operations audit had found 86,000 dollars of suspense older than sixty days the year before, and the audit committee had asked whether the wire suspense account was an exception or an example. The program audit was the answer, and it took 300 hours.
| Test | What it found | Disposition |
|---|---|---|
| 1. Walkthrough | New accounts were added to the tool by request from the account owner; nothing added them automatically, and nothing rated them until a controller noticed. | RCM redrawn with the inventory control marked absent |
| 2. Inventory completeness | 96 accounts in the chart with balances or activity were not in the tool; eleven were active with year-end balances totaling 14 million dollars, including two clearing accounts opened for a new payment channel eight months earlier. | Finding, Medium: population completeness |
| 3. Risk rating | 140 accounts rated low carried suspense or clearing characteristics or activity above the criteria’s threshold; the ratings had not been reviewed since the tool’s implementation four years earlier. | Finding, Medium: rating maintenance |
| 4. Source independence | Of 40 re-performed reconciliations, six were reconciled to a report from the same system that posts the ledger, and two to a spreadsheet maintained by the preparer. | Inside the re-performance finding |
| 5. Re-performance | 40 reconciliations re-performed against the standard: 28 met it; twelve failed on itemization, source or aging; three carried unexplained differences the preparer had netted into a single timing line. | Finding, High, combined with tests 7 and 9 |
| 6. Timeliness | Daily reconciliations late 6 percent of days, monthly 3 percent; the late daily reconciliations concentrated on the two new clearing accounts. | Finding, Low |
| 7. Aging and repetition | 312 reconciling items older than ninety days at year-end, 8.7 million dollars gross; 41 unexplained, 1.1 million dollars; 19 accounts with identical items for six months or more; the wire suspense item from the prior audit cleared, replaced by two new ones. | Inside the High finding |
| 8. Write-offs | 41 differences written off in the year, 312,000 dollars; nine above the preparer’s approval level with no higher approval; the same four accounts wrote off differences in six of eight quarters. | Inside the High finding |
| 9. Clearing journals | 27 journals in the year with descriptions indicating a reconciliation difference cleared, 640,000 dollars, posted to a general expense account or to intercompany; eleven had no reconciliation reference and no approval above the preparer. | Finding, High: differences cleared by entry |
| 10. Review quality | One reviewer approved 210 monthly reconciliations in 40 minutes with no query recorded; three reviewers accounted for 61 percent of approvals; queries recorded on 2 percent of reviews across the year. | Finding, Medium: review quality |
| 11. Certification | Certifications signed for 100 percent of accounts in all four quarters; 22 owners certified accounts that had unexplained differences older than ninety days at the certification date without noting them. | Finding, Medium: certification |
| 12. Segregation | No preparer reviewed her own work; eight preparers held posting rights to accounts they reconciled, three of them on suspense accounts. | Inside the High finding |
| 13. Tool configuration | Auto-certification enabled for accounts with a zero net balance, which included accounts with large offsetting gross entries; roll-forward of reconciling items permitted without re-dating. | Finding, Low; configuration changed during fieldwork |
| 14. Metrics and prior points | Monthly reporting showed completion percentage only; no aging, write-off or query metrics; the wire audit’s suspense point closed on the item and open on the cause. | Metrics finding combined with the certification finding; prior point reopened |
The report carried seven findings, one High, four Medium and two Low, and an overall rating of Needs Improvement. The High finding combined the unexplained aged differences, the write-offs and the clearing journals into one statement, because they were one mechanism: differences that were not resolved were carried, then written off or cleared by entry, and eight of the people doing the carrying could post to the accounts they reconciled. The answer to the audit committee’s question was that the wire suspense account had been an example. Three things generalize. Every one of the eleven unrated active accounts was found by the simplest test in the program, the chart against the tool, and two of them were the clearing accounts for the bank’s newest payment channel, which is where a bank’s reconciliation risk always moves first. The reviewer who approved 210 reconciliations in forty minutes was not negligent by the program’s standard, because the program had no standard for what a review was; the finding was written about the program. And the certification finding was the one the audit committee reacted to, because certifications are the document they see, and 22 of them had been signed over exceptions the certifier’s own tool showed.
The findings that recur, and wording that lands
Program findings are written about the program, with the account-level exceptions in an appendix for the controller, and with the population quantified: not “some reconciliations were incomplete” but “twelve of forty re-performed failed the standard, and the population profile shows the same three failure types in 19 accounts”. The two below recur in most engagements, in the five-Cs form.
Differences carried and cleared rather than resolved. Condition: at year-end 312 reconciling items were older than ninety days, 8.7 million dollars gross, of which 41 items totaling 1.1 million dollars had no explanation; 19 accounts carried identical reconciling items for six months or more; 41 differences totaling 312,000 dollars were written off in the year, nine above the approver’s authority; and 27 journal entries totaling 640,000 dollars cleared reconciliation differences to expense or intercompany accounts, eleven with no reconciliation reference or approval above the preparer. Eight preparers hold posting rights to accounts they reconcile. Criteria: the reconciliation policy requires differences to be itemized, explained and cleared within the deadline for the account’s rating, write-offs to be approved by amount, and clearing entries to be approved by the controller with the reconciliation referenced; preparers may not post to accounts they reconcile. Cause: the tool permits reconciling items to roll forward without re-dating, the aged-item report is produced but not escalated, and the write-off and clearing-entry approvals are not enforced in the workflow. Consequence: 1.1 million dollars of balances with no support, 640,000 dollars of differences removed from view by entry rather than resolved, and a mechanism through which an error or a loss in any of the eight preparers’ accounts could be concealed. Corrective action: management will disable roll-forward without re-investigation, route write-offs and clearing entries through workflow approval by the controller, remove posting rights from preparers on their own accounts, and resolve the 41 unexplained items by the half-year; internal audit will re-perform those accounts at that date.
Certification over open exceptions. Condition: quarterly certifications were signed for 100 percent of accounts in all four quarters; in the fourth quarter 22 account owners certified accounts that, at the certification date, carried unexplained differences older than ninety days according to the reconciliation tool, without noting an exception. Criteria: the certification confirms that the owner’s accounts are reconciled to the standard and that any exception is disclosed. Cause: the certification form is a list of accounts and a signature, does not display the tool’s status, and is completed by the owner’s delegate in most business units. Consequence: the audit committee and the bank’s examiners receive a quarterly assurance that does not reflect the program’s own records. Corrective action: management will generate certifications from the tool with open exceptions pre-populated and require an explicit acknowledgment of each, and will report the count of certifications with exceptions to the audit committee quarterly.
Common mistakes in reconciliation program audits
Sampling reconciliations at random from the tool, which tests the boring middle and misses every suspense account. Accepting the tool’s completion percentage as the program’s health, when the tool only knows about the accounts someone told it about. Testing whether a reconciliation exists rather than what it reconciles to, so that a ledger-to-report comparison from the same system counts as a control. Reading “timing” as an explanation instead of as the absence of one. Treating the reviewer’s signature as evidence of review without profiling velocity and queries. Testing the certification by confirming it was signed rather than by joining it to the tool’s status on the day it was signed. Reporting the account-level exceptions as the finding, which produces a list the controller fixes account by account while the mechanism that produced them continues. Closing the prior audit’s suspense point on the item rather than the cause, so that the next audit finds the same account with two new items. And skipping the access join, which is the only test that shows whether a difference could be made to disappear by the person who created it, and which takes an hour.
Scoping variants: banks, corporates, shared services, small organizations
Banks carry the largest and most time-sensitive reconciliation populations, and their examiners treat the program as a safety-and-soundness control: daily reconciliations of settlement, clearing, nostro and wire accounts are the core, suspense aging is a standing examination question, and the program audit should be timed so that its results reach the audit committee before the next examination cycle. Corporates have smaller populations and a different concentration of risk: intercompany, interface accounts between operational systems and the ledger, and the accrual and provision accounts where the “independent source” is a schedule prepared by the same team, which the audit reads as an estimate test rather than a reconciliation. Shared service centers concentrate preparation and leave ownership with the entities, which makes the certification the critical control, because the entity controller who certifies has not seen the reconciliation; test whether the center’s status reaches the certifier and whether the certifier can see exceptions. Small organizations reconcile a few dozen accounts with one or two people and cannot separate preparer, reviewer and poster; the compensating control is the owner or finance director reviewing the reconciliations with the source documents, and the program audit for a small organization is a re-performance of every material account and a test of whether that review happened. In every variant, the bank accounts are audited in the depth the cash and bank reconciliation guide describes, because they remain the reconciliations where a difference is most likely to be money that has already gone.
Where to go next
Audit the program before the reconciliations: the inventory, the ratings, the standard, the review, the escalation, the certification and the metrics are what decide whether three thousand reconciliations mean anything. Then re-perform where the profile points, weighted to suspense, clearing, interfaces and every account with an aged unexplained difference, and write the findings about the mechanism rather than the accounts. The process the reconciliations belong to is covered in the financial close guide; the entries that clear differences are scored in the journal entry analytics catalog and tested in the journal entry testing guide; and when a pattern of cleared differences starts to look like concealment, the first 48 hours protocol takes over from the program.
Related guides
- How to audit cash management and bank reconciliations — the most important reconciliations in depth, with MidState’s 23 accounts
- How to audit the financial close — the process the reconciliations belong to, with Pennine’s engagement
- How to audit journal entries — the management override lens
- The journal entry analytics catalog — the plug detector’s parent
- Management review controls — what a review has to evidence
- How to audit payment operations and wire transfers — Lakeshore’s wire suspense, where this engagement started
- SOX scoping and risk assessment — why the program controls decide the key control
- Evaluating control deficiencies — rating what the program audit finds
- Financial statement fraud — concealment through the ledger, in context
- When internal audit finds fraud: the first 48 hours — when a cleared difference is not an error
- The risk and control matrix template — where the ten-control matrix lives
- Writing the audit work program — the five-element procedure standard
- The sampling memo template — the weighted re-performance sample, documented
- Segregation of duties beyond the ERP — preparer, reviewer and poster kept apart
- How to perform a user access review — finding the posting rights from effective access
- The 5 C’s of audit findings — the form the two findings above are written in
- The finding and issue log template — tracking seven findings and the appendix of accounts
- Fieldwork and testing guides and internal controls guides — the full collections
Leave a Reply