,

How to Audit Accounts Receivable and Collections: Risks, Controls and a 14-Test Program

Accounts receivable is the half of the revenue cycle that auditors neglect, because revenue recognition gets the accounting attention and accounts payable gets the fraud attention, and receivables sit between them looking like arithmetic. They are not arithmetic. Receivables are where customers’ money is supposed to arrive, which makes them where it fails to arrive, arrives and is misapplied, arrives and is pocketed, or never existed in the first place. The classic receivable frauds are old because they work: lapping, where a clerk covers one customer’s stolen payment with the next customer’s remittance; skimming of receipts before they are recorded; credit memos issued to write off what was taken; and write-offs of balances that were collected and diverted. The ACFE’s Occupational Fraud 2026: A Report to the Nations puts asset misappropriation in 90 percent of its 2,402 cases, and the receivables side of the business, skimming, cash larceny and fraudulent write-offs, is one of its oldest homes. Add the error side, which costs more than the fraud side in most organisations (unapplied cash, unresolved deductions, credit limits nobody enforces, an allowance estimated by habit), and receivables become one of the few audits that improves cash flow while it is still in fieldwork.

This guide is the internal auditor’s version of the receivables audit, end to end: how the order-to-cash back half actually works and where the risk concentrates, a starter risk and control matrix, a fourteen-test program with attributes and sample sizes, the analytics that find lapping and leakage, a worked engagement at Brightwater Foods with every test’s result, the findings that recur with wording that lands, and how to scope the audit for a small shop, a large ERP estate and an outsourced or factored book. It pairs with the revenue recognition guide, which covers the front half of the cycle, and with the accounts payable guide, which is the mirror-image process on the disbursement side.

In this guide

Know the terrain: order-to-cash from invoice to cash

Receivables are the back half of order-to-cash: credit decision, order, shipment, invoice, cash application, collections, disputes and deductions, credit memos, write-offs, and the allowance that estimates what will never be collected. Four structural facts shape the audit. First, the customer master is the control point everyone ignores, exactly as the vendor master is on the payables side: credit limits, payment terms, remittance addresses and the bank accounts customers pay from all live there, and a weak change process converts every downstream control into decoration. Second, cash application is where fraud and error both hide, because it is high-volume, judgment-heavy (which invoice did this partial payment settle?), and usually performed by one or two people under time pressure; unapplied and misapplied cash is the single most common condition a receivables audit finds. Third, credit memos are the universal solvent: a credit memo can clear a stolen payment, a fictitious sale, an unauthorised discount, or a real dispute, and the system usually cannot tell which; who can issue one, at what value, with what evidence, is the question. Fourth, the allowance for credit losses is an estimate that, since ASC 326 (CECL) took hold for trade receivables, must be forward-looking and documented rather than a fixed percentage of the aging; it is also the number management adjusts when the quarter needs help.

Planning inputs worth an hour each: the aging by bucket and its trend over eight quarters (a lengthening tail is a collections problem, a sudden shortening is a write-off problem); days sales outstanding by business unit and by salesperson; unapplied and on-account cash by age; credit memo volume and value by reason code and by issuer; the deductions or chargebacks backlog and how old it is; concentration (what share of receivables sits with the ten largest customers); write-offs by approver; and the interfaces, which is where invoices come from (the billing system), where cash comes in (lockbox, ACH, card, cheque, portal) and what reconciles the sub-ledger to the general ledger and to the bank. Walk one invoice from order to cash and one disputed invoice from deduction to resolution with the credit manager before writing a test. The walkthrough will show you which of the controls below exist as designed, which exist as habits, and which are a report nobody reads.

The receivables risk map

#RiskWhere it livesError or fraud?
R1Fictitious or inflated receivables: invoices for goods not shipped, sales to customers that do not exist, or bill-and-hold arrangements booked as salesOrder entry, shipping, invoicingFraud (financial reporting) or cut-off error
R2Skimming and lapping: customer payments diverted before recording, or one customer’s remittance applied to cover another’s stolen paymentCash receipt and cash applicationFraud
R3Unapplied, misapplied and on-account cash: payments not matched to invoices, so the aging overstates delinquency and customers are chased for money already paidCash applicationMostly error, conceals R2
R4Credit memo abuse: credits issued without a valid dispute to clear diverted receipts, reward favoured customers or hide fictitious salesCredit memo issuance and approvalBoth
R5Unauthorised write-offs: balances written off that were collected and diverted, or written off to relieve a salesperson’s accountWrite-off approvalBoth
R6Credit limits and terms not enforced: shipments to customers over limit or on hold, terms extended without authority, orders released by salesCredit management and order releaseError, policy abuse
R7Deductions and disputes unresolved: customer short-pays and chargebacks left open, aged and eventually written off without recovery reviewDeductions managementValue leakage
R8Allowance misstatement: the credit loss allowance estimated mechanically, biased to smooth earnings, or not updated for known customer deteriorationPeriod-end estimateError or earnings management
R9Customer master integrity: duplicate customers, remittance details changed without verification, credit limits edited by salesCustomer master maintenanceEnabler of R2, R4, R6
R10Segregation failures: one person can invoice, apply cash, issue credits and write offAccess modelEnabler of everything above

Use the map to argue scope with yourself. R2, R4, R5 and R10 are the fraud chain and can be tested together through cash application, credit memos, write-offs and the access model in a week; R3 and R7 are where the recoverable cash hides and are best found by analytics across the whole population; R1 and R8 matter enormously at period-end and are shared ground with the external auditor, so coordinate rather than duplicate. A tiered engagement that goes deep on cash application, credits and the master, and lighter on the estimate, beats uniform coverage of all ten.

The starter RCM: ten controls that carry the process

CtrlControl (condensed)Type / frequencyAnswers risk
C1New customers and credit limits are approved by credit management, independent of sales, on documented criteria (credit report, financials, references); limits are system-enforced and changes are logged and reviewed monthlyPreventive / each customer, monthly reviewR6, R9
C2Customer master changes, especially remittance instructions, bank details for refunds and billing addresses, require a second approval and a call-back for payment-related fields; a complete change report is reviewed monthlyPreventive / each change, monthlyR9, R2
C3Invoices are generated only from shipped or delivered orders (system-triggered from proof of delivery or shipment confirmation); manual invoices require controller approval and are trendedPreventive / each invoiceR1
C4Receipts are received through a lockbox, ACH or portal, never handled by the cash-application clerk; remittance data is imported, not re-keyed; any cheques received on site are logged at the mailroom before AR sees themPreventive / each receiptR2
C5Cash application is performed daily from remittance data; unapplied and on-account cash is aged, escalated at 30 days and reported to the controller monthly with an explanation per item over a thresholdDetective / daily, monthlyR3, R2
C6Credit memos require a reason code and evidence, approval by someone other than the customer’s salesperson or the cash-application clerk, and second approval above a threshold; credits by issuer and reason are reviewed monthlyPreventive-detective / each credit, monthlyR4, R2
C7Write-offs require documented collection effort, approval independent of sales and cash application, and a threshold above which the CFO approves; written-off accounts are retained on a watch list for subsequent receiptsPreventive-detective / each write-offR5, R2
C8Deductions and disputes are logged with a reason code on receipt, worked to resolution within an SLA, and either recovered or approved for credit by someone other than the person who worked themDetective / continuousR7
C9Segregation is enforced in the system: invoicing, cash application, credit memo issuance, write-off approval and customer-master maintenance are mutually exclusive roles; conflicts are monitoredPreventive / continuousR10
C10The receivables sub-ledger is reconciled to the general ledger and cash receipts to the bank monthly; the allowance is recalculated quarterly on a documented CECL methodology, with specific reserves for known deteriorations, and reviewed by the controllerDetective / monthly, quarterlyR8, R3, R1

This is a starter matrix. In ERP-mature shops C1, C3, C6 and C9 are configuration and get tested once as configuration plus a test of one per scenario; in smaller shops they are people and get sampled. Load it into the RCM Workbench and adjust it against what the walkthrough actually shows, following the RCM template guide. The map from risk to control to test is the audit; everything after this table is execution.

The 14-test program

Each test names its objective, population and core attributes. Sample sizes follow the standard attribute conventions in the sample size guide (25 for a control operating many times daily at a 90 percent confidence and low expected deviation; larger where the walkthrough suggested weakness); selections are recorded in the sampling memo so a reviewer can reperform them. Tests marked with a triangle are full-population analytics rather than samples, and they run first, because their hits become the judgmental selections for the tests that follow.

  1. Customer onboarding and credit limits. Population: customers created or limit-changed in the period. Sample 25. Attributes: credit evaluation documented on the policy’s criteria; approver independent of sales; limit in the system equals the approved limit; terms per policy. The kill shot: for five, re-perform the credit evaluation from the same sources and see whether you would have set the same limit.
  2. Customer master changes. Population: changes to remittance, refund bank, billing address and contact fields. Sample 25, or all if fewer. Attributes: second approval before the change took effect; call-back evidence for payment-related fields; change report reviewed and signed. Accept no “the customer emailed us”; that is the fraud, not the control.
  3. ▲ Invoices without shipment. Full population: invoices with no matching shipment, delivery confirmation or service acceptance, and manual invoices by creator. Every hit is a cut-off error, a bill-and-hold arrangement, or a fictitious sale; disposition all three ways in writing.
  4. Invoice accuracy and cut-off. Sample 25 invoices around period-end plus 25 through the period. Attributes: price and quantity agree to the order and the shipping document; terms agree to the master; invoice date within one day of shipment; revenue recorded in the right period.
  5. Receipt handling and lockbox. Observe the mail and the receipt process; inspect the lockbox agreement and the list of people with access to the cash-application queue. Attributes: no cheques handled by cash-application staff; mailroom log reconciled to the deposit; portal and ACH remittance files imported, not re-keyed.
  6. ▲ Lapping and misapplication. Full population of cash application: payments applied to a different customer than the remitter; payments applied more than N days after receipt; applications reversed and reapplied; partial applications with the remainder left on account. Then trace ten of the oddest to the remittance advice and the bank.
  7. Unapplied and on-account cash. Population: the unapplied and on-account balance at three month-ends. Attributes: aged; items over threshold explained; escalation at 30 days evidenced; reconciliation of the total to the sub-ledger. Sample 25 items across the three dates and trace each to its eventual application or refund.
  8. Credit memos. Sample 25 from the full population plus every credit above the second-approval threshold. Attributes: valid reason code with evidence (return, pricing dispute, damage); approver independent of the customer’s salesperson and of cash application; no credit memo applied to an invoice already paid unless a refund follows. Run the analytics below first: credits issued by one person to one customer are your judgmental picks.
  9. Write-offs. Population: all write-offs in the period; test all above threshold and sample 25 below. Attributes: collection effort documented (dunning history, agency referral); approval independent of sales and cash application; CFO approval above threshold; subsequent receipts on written-off accounts monitored. The kill shot: match written-off customers to receipts in the twelve months after write-off.
  10. Deductions and disputes. Population: open and closed deductions. Sample 25 closed and inspect the open aging. Attributes: reason coded on receipt; worked within SLA; recovery pursued before credit; approval of the eventual credit independent of the person who worked it; the backlog trended monthly.
  11. Segregation of duties. Pull actual access, not the policy: who can invoice and apply cash; apply cash and issue credits; issue credits and write off; maintain the master and apply cash. For every conflict, test whether the compensating review actually ran on that person’s transactions, following the segregation of duties guide.
  12. Collections effectiveness. Inspect the dunning process and the collector workload. Attributes: overdue accounts contacted on the policy cadence; promises to pay logged and followed; accounts over 90 days escalated; agency referrals approved. Not a control test in the strict sense, but the finding it produces (the tail nobody works) is usually the largest number in the report.
  13. The allowance for credit losses. Inspect the quarterly calculation. Attributes: methodology documented and consistent with ASC 326 (or IFRS 9’s expected credit loss model), historical loss rates supported, forward-looking adjustments explained, specific reserves for known deteriorations, controller review evidenced, and movements explained against the aging. Re-perform one quarter.
  14. Reconciliation discipline. All twelve monthly sub-ledger-to-GL reconciliations and cash-receipts-to-bank reconciliations. Attributes: timely, reviewed, reconciling items aged and cleared; the detective net under everything above, built on the model workpaper structure.

The analytics that find lapping and leakage

Receivables data is complete, digital and full of timestamps, which makes it good analytics terrain, and the tests below can be built in SQL or, for a mid-sized book, in a spreadsheet. Three tables carry them: the invoice table (customer, date, amount, salesperson, order and shipment references), the receipts and application table (remitter, amount, date received, date applied, applied-to invoice, applying user, reversals), and the adjustments table (credit memos and write-offs with reason, issuer, approver, date). Prove completeness before believing any of it: tie invoices to the revenue ledger, receipts to the bank, and adjustments to the movement in the sub-ledger, following the IPE testing guide.

AnalyticLogicWhat a hit means
Lapping signaturePayments applied to a customer other than the remitter; applications more than five days after receipt; reversal-and-reapply chains; a customer whose payments are always applied to its oldest invoice regardless of the remittance detailDiverted receipts being covered by later ones; or a cash-application process so weak it would hide lapping if it happened
Credit memo concentrationCredits by issuer, by customer and by issuer-customer pair against the population; credits issued within days of a receipt on the same account; credits with generic reason codesA clerk clearing diverted receipts, a salesperson buying favour, or a reason-code system nobody uses
Write-off then receiptWritten-off customers with receipts in the following twelve months, and receipts on written-off accounts applied to other customersBalances written off and then collected by someone else; the classic diversion
Unapplied cash agingUnapplied and on-account items by age band and by applying user; the same amount unapplied at three consecutive month-endsApplication failures; a receipt nobody wants to explain; customers overpaying and never refunded
Over-limit shipmentsOrders released to customers over their credit limit or on credit hold, by releaserSales overriding credit; limits that are decorative
Deduction aging and dispositionOpen deductions by age and reason; closed deductions by outcome (recovered, credited, written off) and by the person who closed themLeakage: customers short-paying and never being pursued; a clerk crediting everything to clear the queue
Customer-employee overlap and duplicate customersCustomer addresses, phones and refund bank accounts against the employee master; normalised-name and address duplicates in the customer masterFictitious customers, undisclosed relationships, or duplicate records used to move balances
Salesperson DSO and dispute rateDays sales outstanding, credit memos and deductions per salesperson against the populationSide agreements, channel stuffing, or a rep whose customers systematically dispute the invoices
Period-end invoice spikes and reversalsInvoice value in the last five days of a period against the daily average; invoices reversed or credited in the first ten days of the next periodCut-off manipulation; sales booked to hit a number and unwound afterwards

Two disciplines keep the analytics honest. Disposition every hit in writing, including the boring ones, so that the finding rests on a count of confirmed cases and a count of cleared false positives rather than on a list of anomalies. And run the lapping signature before selecting any sample, because a random sample of twenty-five cash applications from forty thousand will tell you the average application is fine, and the average application is.

Worked example: Brightwater Foods’ receivables audit

Brightwater Foods is the 180-million-dollar food manufacturer used across this site: three plants, about 600 staff, a co-sourced internal audit function that its first chief audit executive took over and rebuilt (the story is in the first-90-days guide), and a customer base of grocery chains, distributors and foodservice operators, about 1,900 active accounts. The receivables audit was the second engagement of the rebuilt plan, chosen because the finance director’s own numbers told the story: days sales outstanding had drifted from 39 to 46 over two years, unapplied cash sat at 1.4 million dollars, and the deductions backlog, mostly retailer trade-promotion and shortage claims, had reached 3.1 million dollars with 41 percent of it older than ninety days. The population was twelve months: 31,800 invoices totalling 181 million dollars, 26,400 receipts, 4,100 credit memos worth 6.8 million dollars, write-offs of 296,000 dollars, and a year-end receivable of 22.5 million dollars against an allowance of 520,000 dollars. The engagement took 300 hours: the CAE and the new in-house auditor did the walkthrough, the control tests and the report, and the co-source firm’s analytics specialist ran the population tests in three days. The table gives the fourteen tests, what each found, and where it went.

TestPopulation and sampleWhat it foundWhere it went
1. Onboarding and credit limits96 new customers; sample 25; 5 evaluations reperformedNineteen of 25 had a credit evaluation on file; six were opened by sales with the limit set later. Two reperformed limits would have been lower.Finding, Medium (combined with test 12)
2. Customer master changes310 changes; 41 to remittance or refund fields, all testedRefund bank details changed for 9 customers with no call-back evidence; one refund of 38,000 dollars had gone to a changed account, later confirmed genuine.Finding, High
3. Invoices without shipmentFull population212 invoices with no shipment confirmation; 196 were service and freight recharges billed manually; 16 were December invoices for January shipments to one distributor.Cut-off finding, Medium, shared with the external auditor
4. Invoice accuracy and cut-off50 invoicesAll priced to the order; three shipped-late invoices dated on order date rather than shipment date.Combined with test 3
5. Receipt handlingObservation; lockbox agreement; access listLockbox for cheques operating; 14 percent of receipts arrived by ACH with no remittance detail and were applied from emailed advices re-keyed by the clerk.Observation; root of the unapplied cash problem
6. Lapping and misapplicationFull population; 10 tracedNo lapping signature. 1,140 applications made more than five days after receipt, concentrated in the ACH-without-remittance stream; 61 cross-customer applications, all explained by group remittances.No fraud finding; process finding on application timeliness
7. Unapplied and on-account cashThree month-ends; 25 items traced1.4 million dollars unapplied at year-end, 610,000 dollars older than 60 days, 140,000 dollars older than a year; eleven customers had been sent to collections for invoices they had paid.Finding, High
8. Credit memos25 sampled plus all 38 above the 25,000-dollar threshold612 of 4,100 credits were approved by the customer’s own salesperson under a delegation nobody remembered granting; 4 of 38 large credits had no supporting dispute record.Finding, High
9. Write-offsAll 27 above threshold; 25 belowCollection effort documented for 21 of 27; two written-off customers made payments totalling 22,000 dollars in the following year that were applied to unrelated accounts.Finding, Medium; the two receipts recovered to the right accounts
10. Deductions and disputesOpen aging; 25 closed items3.1 million dollars open, 41 percent older than 90 days; of 25 closed items, 18 were credited in full with no recovery attempt, including 6 shortage claims the carrier’s proof of delivery contradicted.Finding, High; recovery routine started during fieldwork
11. Segregation of dutiesActual accessTwo cash-application clerks could also issue credit memos; the compensating monthly credit review had not been performed since the previous controller left.Finding, Medium
12. Collections effectivenessDunning history; collector workloadTwo collectors carrying 1,900 accounts; accounts over 90 days contacted on average once; 27 percent of active customers over their credit limit with orders released by sales.Finding, Medium (with test 1)
13. AllowanceFour quarterly calculations; one reperformedMethodology a fixed percentage by aging bucket unchanged since 2021; no forward-looking adjustment; no specific reserve for a distributor 120 days past due on 410,000 dollars.Finding, Medium, shared with the external auditor
14. ReconciliationsAll 12 monthsSub-ledger to GL reconciled monthly; reconciling items over 90 days included the unapplied cash. Bank to cash receipts reconciled by the same clerk who applied cash.Observation folded into test 11

The report carried nine findings, four of them High, and an overall rating of Needs Improvement. No fraud was found, which is the usual result and worth saying plainly in the report, because a board that has just funded an audit function expects the first process audits to catch someone, and the value here was cash: 1.4 million dollars of unapplied receipts resolved within a quarter (about 290,000 dollars of it refunded to customers who had overpaid, the rest applied), 22,000 dollars of diverted-in-error receipts corrected, and a deductions recovery routine that pulled back 340,000 dollars of contradicted shortage claims in its first ninety days. The finance director disputed the credit-memo finding for a fortnight on the ground that salespeople know their customers, and accepted it when the analytics showed that the 612 self-approved credits were concentrated with four reps and two customers. Three things about the engagement generalise. The ACH-without-remittance stream was the single root cause behind the unapplied cash, the late applications and the misdirected collections, and the fix, a remittance portal and a rule that unapplied cash over 30 days goes to the controller, cost less than one collector’s salary. The deductions backlog was not a collections problem but a control-design problem: nobody was required to attempt recovery before crediting, so nobody did. And the allowance finding, the least exciting in the report, is the one the audit committee asked most about, because it was the one that touched the financial statements.

The findings that recur, and wording that lands

Six findings account for most receivables reports ever written, and each lands only when it carries a numerator, a denominator and a named criterion, following the five Cs. Unapplied cash (“1.4 million dollars of customer receipts, 6 percent of the year-end receivable, was unapplied at year-end, 610,000 dollars of it for more than 60 days; policy requires application within five business days and escalation at 30; eleven customers were referred to collections for invoices they had paid”). Credit memo approval (“612 of 4,100 credit memos, 15 percent, were approved by the customer’s own salesperson under a delegation not in the approval matrix; four credits above 25,000 dollars had no dispute record”). Deductions leakage (“3.1 million dollars of customer deductions were open at year-end, 41 percent older than 90 days; 18 of 25 closed deductions tested were credited without a recovery attempt, including six shortage claims contradicted by the carrier’s proof of delivery”). Master-data changes (“refund bank details were changed for 9 customers without the call-back verification treasury policy requires”). Credit enforcement (“27 percent of active customers exceeded their approved credit limit; 84 orders were released by sales staff against credit holds”). And the allowance (“the credit loss allowance has been calculated as fixed percentages of aging buckets since 2021 with no forward-looking adjustment and no specific reserve for a distributor 120 days past due on 410,000 dollars, which is not consistent with ASC 326”). Write the cause as a decision that can be reversed, not as a training gap, and the action with an owner and a date; the root cause guide covers the step most receivables reports skip.

Scoping variants: small shop, big ERP, outsourced and factored books

Small organisation (one person invoices, applies cash and issues credits): segregation is structurally impossible, so shift the weight to detective controls the owner or CFO performs and to your own analytics across everything: the lapping signature, credit memo concentration, write-off-then-receipt and unapplied aging are the whole audit, plus the monthly bank-to-receipts reconciliation performed by someone other than the clerk. Mature ERP: tests 1, 3, 6 and 11 become configuration testing (credit-hold logic, invoice-from-shipment triggers, application rules, role design), evidenced once with a test of one per scenario plus change control over the configuration; spend the recovered hours on the deductions and allowance work, which no ERP does for you. Outsourced collections or a shared-service centre: the program applies, with a third-party layer on top, meaning what the provider’s SOC 1 report covers (cash application and credit issuance are usually in scope; collections judgment usually is not), which complementary user controls you are supposed to operate, and whether the service levels in the contract match your policy’s control expectations; the SOC 1 review guide covers the reading. Factored or securitised receivables: add the eligibility and covenant layer, because the lender’s borrowing base depends on the aging and the concentration figures you are testing, and an error in either becomes a covenant breach rather than a control finding; coordinate with treasury, and read the facility agreement before the fieldwork, not after.

Where to go next

Audit receivables with the structure they deserve: master first, cash application second, credits and write-offs third, analytics across everything, and the estimate last with the external auditor in the loop. Done that way the audit pays for itself in applied cash and recovered deductions before the report is issued, and the findings it produces are the kind a finance director can fix in a quarter. The program above is a complete starting position; tune it with the walkthrough, size it with the sampling grid, build the file like the model workpaper, and report it with the report template. The front half of the cycle is in how to audit revenue recognition; the process that pays the money out is in how to audit accounts payable; and the cash that arrives outside the lockbox, by hand, is the subject of the route cash example that runs through the TOD versus TOE guide.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading