The bank reconciliation is the oldest detective control in accounting and the one most often performed as a ritual. A reconciliation that is prepared by the person who handles the cash, reviewed by nobody, and balanced each month by a reconciling item called “unidentified” is not a control; it is a monthly certificate that the books and the bank disagree by an amount someone has decided not to investigate. Yet when a reconciliation is designed and performed properly, by someone independent, from bank data rather than from the ledger, with every item aged and cleared, it catches almost everything that goes wrong with cash: the deposit that never reached the bank, the cheque altered after signing, the ACH debit nobody authorised, the wire released twice, the kited balance, the skimmed receipt. Cash management is the other half of the same subject: knowing every morning where the cash is, moving it to where it earns or is needed, protecting the accounts from unauthorised debits, and paying the bank no more than the contract says. Companies that manage cash badly do not usually lose it to fraud; they lose it to idle balances, unnecessary fees and borrowing they did not need, which is smaller per month and larger per decade.
This guide is the internal auditor’s version of the cash management and bank reconciliation audit: how the cash structure and the reconciliation actually work and where they fail, a starter risk and control matrix, a fourteen-test program, an anatomy of a reconciliation that is a control rather than a ritual, the analytics that find kiting and plugs, a worked engagement across MidState Beverage’s twenty-three bank accounts with every test’s result, the findings that recur with wording that lands, and scoping variants for a multi-entity group, a retailer with store cash, and a company whose treasury function owns the accounts. It sits between the treasury guide, which covers the function that owns the accounts, and the payment operations guide, which covers the channels through which money leaves them.
In this guide
- Know the terrain: the cash structure and where it fails
- Anatomy of a reconciliation that is a control, not a ritual
- The cash risk map
- The starter RCM: ten controls that carry the process
- The 14-test program
- The analytics that find kiting, plugs and leakage
- Worked example: MidState Beverage’s cash and bank reconciliation audit
- The reviewer’s checklist: ten questions
- The findings that recur, and wording that lands
- Scoping variants: multi-entity groups, store cash, treasury-owned accounts
- Where to go next
Know the terrain: the cash structure and where it fails
Every organisation has a cash structure whether or not anyone designed it: a set of bank accounts with purposes (operating, disbursement, payroll, deposit or lockbox, concentration, local accounts at sites, legacy accounts from acquisitions), the arrangements that move money between them (zero-balance sweeps, concentration transfers, manual transfers), the protections on each (positive pay for cheques, ACH debit blocks and filters, dual control on the portal, account alerts), and the reporting that tells someone where the cash is each morning. The structure fails in predictable ways. Accounts accumulate and nobody closes them, so a dormant legacy account with a balance and a stale mandate sits unreconciled for years. Sweeps are configured once and drift as the business changes, so a depot account carries idle cash while the operating account overdraws. Protections are bought and not switched on, so the positive pay service the bank sells is not enabled on the account that issues the cheques. Deposits are made by the people who collect the cash and reconciled by the same people, which is the condition behind most cash-receipt frauds. And the daily cash position is a spreadsheet the controller fills in from six online banking logins, which is a key-person risk and a fraud window.
Planning inputs worth an hour each: the bank account inventory from the banks rather than from finance, with signatories; the account purposes and the sweep configuration; the protection services enabled per account (positive pay, ACH filters, alerts); a year of bank fees against the fee schedule in the contract; the reconciliations for three month-ends with their reconciling items aged; the cash-positioning process and who performs it; the deposit process at every site that receives cash or cheques; and the interfaces, meaning how bank data reaches the reconciliation (statement download, bank file, re-keyed) and how the reconciliation reaches the ledger. Walk one deposit from collection to bank statement and one month-end reconciliation from bank file to sign-off with the person who prepares it. The walkthrough will show you whether the reconciliation starts from the bank data or from the ledger, which is the single most informative fact in the audit, because a reconciliation prepared from the ledger will only ever find the differences the ledger already knows about.
Anatomy of a reconciliation that is a control, not a ritual
A bank reconciliation that operates as a control has seven properties, and the audit tests each of them. It starts from the bank: the bank statement or bank file is the population, and every bank transaction is matched to a book entry, so that unrecorded bank activity (an ACH debit, a fee, a returned deposit) surfaces as an unmatched item rather than being invisible. It is prepared by someone who neither handles cash nor posts cash entries, and reviewed by someone who does neither and outranks the preparer; where the organisation is too small for that, the owner or CFO reviews it against the bank statement they obtained themselves. It is timely: prepared within a few business days of month-end, because the value of a reconciliation halves with every week it waits, and the recall window on a fraudulent debit closes in days. Its reconciling items are specific: deposits in transit listed by deposit with the date they cleared, outstanding cheques listed by number, errors identified by transaction, and nothing called “unidentified” surviving more than one cycle. Its reconciling items are aged and cleared: an item that appears on three consecutive reconciliations is a finding in itself, and outstanding cheques older than the dormancy period are unclaimed property, not float. Its review is evidenced in a way that shows the reviewer read it: initials on the cover sheet are not review, notes on specific items are. And it reconciles both directions: the adjusted bank balance equals the adjusted book balance, and the book balance equals the general ledger, not a sub-ledger or a spreadsheet. Written as a control description that passes the handoff test in the RCM guide: “Within five business days of month-end, the financial accountant, who has no cash-handling or cash-posting duties, reconciles each bank account from the bank statement file to the general ledger, lists every reconciling item individually with its date, investigates any item older than 30 days, and the controller reviews the reconciliation, annotates the items reviewed, and signs it.”
The cash risk map
| # | Risk | Where it lives | Error or fraud? |
|---|---|---|---|
| R1 | Receipts skimmed or deposits diverted: cash and cheques collected but not deposited, or deposited to another account | Collection and deposit | Fraud |
| R2 | Unauthorised debits: ACH debits, cheques altered or forged, wires released without authority, card-on-file charges | Disbursement channels and account protections | Fraud (external and internal) |
| R3 | Reconciliation failure: not prepared, not independent, prepared from the ledger, plugged, or reviewed by initial only | Month-end | Error; conceals R1 and R2 |
| R4 | Kiting and float manipulation: transfers between accounts timed to inflate balances or cover a shortfall | Inter-account transfers | Fraud |
| R5 | Idle cash and unnecessary borrowing: sweeps not configured, balances trapped in site accounts, positioning not performed | Cash management | Error (cost) |
| R6 | Unknown, dormant and legacy accounts: accounts outside the inventory, with stale mandates and unreconciled balances | Bank relationship | Enabler of R1, R2 |
| R7 | Bank fees and terms: fees charged above contract, services paid for and unused, earnings credit not applied | Bank relationship | Error (cost) |
| R8 | Stale and unclaimed items: outstanding cheques past the dormancy period not escheated; stale deposits in transit | Reconciliation | Compliance and error |
| R9 | Cheque stock and signature custody: blank stock unsecured, signature plates or e-signature rights uncontrolled | Disbursement | Fraud |
| R10 | Segregation and access: one person can collect, deposit, post, reconcile and transfer; online banking rights unreviewed | Access model | Enabler of everything above |
The starter RCM: ten controls that carry the process
| Ctrl | Control (condensed) | Type / frequency | Answers risk |
|---|---|---|---|
| C1 | Bank accounts are opened and closed only with CFO approval; a complete inventory with purposes and signatories is maintained, confirmed with the banks annually, and mandates are updated within five business days of a leaver | Preventive-detective / each event, annual | R6, R10 |
| C2 | Receipts are deposited intact and daily by someone who does not post cash or reconcile; the deposit listing is prepared at the point of collection and independently agreed to the bank credit | Preventive / daily | R1 |
| C3 | Every disbursement account carries positive pay (payee-name match) for cheques, ACH debit blocks or filters with an authorised-originator list, and dual control on the online portal; exceptions are decisioned daily by someone outside payables | Preventive / continuous, daily | R2 |
| C4 | Each bank account is reconciled monthly from the bank file to the general ledger by a preparer independent of cash handling and posting, within five business days, with every reconciling item listed, aged and cleared, and a documented reviewer sign-off | Detective / monthly | R3, R1, R2, R4 |
| C5 | Inter-account and inter-entity transfers require approval and are matched both sides on the day; transfers outstanding at month-end are investigated | Preventive-detective / each transfer, monthly | R4 |
| C6 | A daily cash position is prepared from bank data (not from the ledger) by finance or treasury, with sweeps and concentration configured to policy and reviewed quarterly for drift | Detective / daily, quarterly | R5 |
| C7 | Bank fees are reconciled to the contract fee schedule quarterly; services paid for are reviewed for use; earnings credit and interest are verified | Detective / quarterly | R7 |
| C8 | Outstanding cheques older than 90 days are investigated and voided or reissued; items past the state dormancy period are reported and escheated under unclaimed property law | Detective / quarterly, annual | R8 |
| C9 | Blank cheque stock is secured with a sequence log; signature authority (manual, plate or electronic) is restricted to the delegation and reviewed quarterly | Preventive / continuous | R9 |
| C10 | Online banking rights (view, initiate, approve, administer) are assigned by role, reviewed quarterly against HR, and administered by someone outside finance operations | Preventive-detective / continuous, quarterly | R10, R2 |
Load the matrix into the RCM Workbench and rebuild it against the walkthrough, following the RCM template guide; in a company with an automated reconciliation tool, C4 becomes partly configuration (matching rules, tolerances, ageing) and partly the human review of what the tool could not match, and both halves need testing.
The 14-test program
Sample sizes follow the standard conventions; selections go in the sampling memo; tests marked with a triangle are full-population analytics and run first. Obtain bank confirmations and statements directly from the banks.
- Account inventory and mandates. Confirm with every bank the accounts open and the signatories; compare with finance’s inventory and HR’s leavers. Attributes: every account approved and purposed; every signatory current and within the delegation; dormant accounts closed or justified; annual confirmation performed.
- Reconciliation design. For every account, inspect who prepares, who reviews, what the starting population is, and the timing. Attributes: preparer independent of handling and posting; reviewer independent and senior; prepared from the bank file; within five business days; both-direction proof to the general ledger.
- Reconciliation reperformance. Sample 25 account-months across accounts and dates (all months for high-risk accounts). Reperform from the bank statement: every bank transaction matched to a book entry, every reconciling item traced to its clearance in the following period. Attributes: items specific, aged, cleared; no unidentified plug; review annotated.
- ▲ Persistent and rolling reconciling items. Full population of reconciling items across the year: items recurring on three or more reconciliations, items whose amount changes but whose description does not, and “unidentified” or “other” items by account.
- Deposit integrity. Sample 25 deposits at sites that receive cash or cheques. Attributes: deposit listing prepared at collection; deposited intact (no cash withheld) and within one business day; bank credit agrees to the listing; agreed by someone other than the depositor.
- ▲ Deposit-lag and deposit-in-transit aging. Full population: days from collection to bank credit by site and by depositor; deposits in transit at month-end older than three days; deposits listed but never credited.
- Account protections. Inspect per-account configuration with the bank’s confirmation. Attributes: positive pay with payee match on every cheque-issuing account; ACH debit blocks or filters with an originator list; portal dual control; alerts configured; exceptions decisioned daily and outside payables. Sample 25 positive-pay and ACH exceptions.
- Inter-account transfers and kiting. Full population of transfers between the company’s own accounts; match both sides by date and amount; list transfers outstanding at month-end; look for transfers around month-end that reverse in the first days of the next. Sample 25 for approval.
- Cash positioning and sweeps. Inspect twenty daily positions and the sweep configuration. Attributes: prepared from bank data; balances at site accounts against the sweep target; idle balances quantified; overdrafts and intraday borrowing explained; configuration reviewed in the year.
- Bank fees. Reperform one quarter’s fee analysis against the contract schedule for the three largest accounts. Attributes: fees charged agree to the schedule; unused services identified; earnings credit applied; disputes raised.
- Stale items and unclaimed property. Full population of outstanding cheques and stale deposits in transit at year-end. Attributes: items over 90 days investigated; items past the dormancy period escheated or in the escheat process; voided cheques reissued under control.
- Cheque stock and signatures. Observe stock custody; inspect the sequence log and the signature authorities. Attributes: stock secured, sequence complete, voids retained; signature rights within the delegation; electronic signature and plate access restricted and logged.
- Online banking access. Reconcile portal users and rights to HR and the delegation, following the user access review guide. Attributes: roles by function; administrators outside finance operations; leavers removed within one business day; quarterly review evidenced; multi-factor authentication enforced.
- Ledger integrity. Trace cash balances from every reconciliation to the general ledger and the financial statements; inspect manual journals to cash accounts. Attributes: reconciliations agree to the ledger without a bridging spreadsheet; manual cash journals approved and explained, following the journal entry testing guide.
The analytics that find kiting, plugs and leakage
| Analytic | Logic | What a hit means |
|---|---|---|
| Rolling reconciling items | Items appearing on three or more consecutive reconciliations; items whose description repeats with a changing amount; “unidentified” items by account and preparer | A difference nobody will investigate; a plug; something being hidden |
| Deposit lag by depositor | Days from collection to bank credit, by site and person; deposits listed and never credited; deposits credited for less than listed | Cash held back; a depositor with a pattern; skimming at the point of deposit |
| Kiting signature | Transfers between own accounts near period-end, reversing early in the next period; balances that spike on the last day; both sides of a transfer not matching on the same day | Float manipulation to inflate cash or cover a shortfall |
| Unauthorised debit scan | ACH debits from originators not on the approved list; cheques cleared for amounts or payees differing from the register; debits on accounts that should have none | Fraudulent debits the protections should have blocked; protections not enabled |
| Idle cash | Average daily balances by account against sweep targets and the borrowing rate; days with overdraft and surplus on the same day in different accounts | Sweeps not working; a cost the CFO can quantify |
| Fee variance | Fees billed by service line against the contract schedule; volumes billed against volumes processed | Overbilling; services nobody uses |
| Stale cheque aging | Outstanding cheques by age band and payee type; cheques over 180 days and past dormancy | Unclaimed property exposure; cheques that were never meant to be cashed |
| Manual journals to cash | Journals posted to cash accounts by user, amount and timing, especially at period-end | Cash balances adjusted to match the bank rather than reconciled to it |
Worked example: MidState Beverage’s cash and bank reconciliation audit
MidState Beverage is the three-state drinks distributor used across this site: twelve depots, three hundred routes, about 31 million dollars a year of cash and cheques collected by drivers, a 2013 ERP, two acquired distributors, and a six-person internal audit function. Its FY27 route cash audit, written up through the TOD versus TOE guide and the Domain V guide, had rated the process Unsatisfactory: reconciliations not independent at nine of twelve depots, overrides self-approved, deposit listings re-keyed at seven depots. The cash and bank reconciliation audit in the FY28 plan was the finance-side complement, budgeted at 300 hours: not the depots’ handling of cash, which the route cash actions were fixing, but the bank accounts the cash landed in and the reconciliations that were supposed to prove it had. The population was twenty-three accounts: twelve depot deposit accounts, a concentration account, an operating and disbursement account, a payroll account, two lockbox accounts, two legacy accounts inherited from the acquisitions, and three imprest accounts. The senior ran it with the staff auditor; the analytics auditor built the deposit-lag and rolling-item tests from twelve months of bank files obtained directly from the two banks.
| Test | Population and sample | What it found | Where it went |
|---|---|---|---|
| 1. Inventory and mandates | Confirmations from two banks; 21 signatories | 23 accounts confirmed against 21 on finance’s list; six signatories had left, and the two legacy accounts still carried the acquired companies’ former owners as signatories; one legacy account was dormant with 41,000 dollars in it. | Finding, High |
| 2. Reconciliation design | All 23 accounts | Head office reconciled 20 accounts from bank files; the three depot accounts at the spreadsheet depots were still reconciled by the depot managers who made the deposits, a year after the route cash finding. | Finding, High (repeat; escalated to the audit committee) |
| 3. Reperformance | 25 account-months | Twenty-two reperformed cleanly. At one depot account a reconciling item described as “timing” grew from 2,100 dollars to 12,400 dollars over five months; reperformance showed deposits credited short of the listings. | Referred under the allegation protocol; finding on review quality |
| 4. Rolling reconciling items | Full year | 41 items on three or more consecutive reconciliations, 29 of them at the three depot-reconciled accounts; four “unidentified” items at head office, all under 500 dollars. | Combined with test 3 |
| 5. Deposit integrity | 25 deposits at five depots | Twenty-one deposited within a day and intact; four deposited two to four days after collection at two depots. | Finding, Medium (route cash action partially effective) |
| 6. Deposit lag | Full year, all depots | Median one day; one depot median three days; 214,000 dollars of deposits in transit older than three days at year-end. | Combined with test 5 |
| 7. Account protections | Bank confirmation of services per account | Positive pay offered in the 2024 banking contract and never enabled on the disbursement account; no ACH debit filter on the operating account; two unauthorised ACH debits of 6,800 dollars in the year, one recovered. | Finding, High |
| 8. Transfers and kiting | Full population of 1,600 transfers; 25 approvals | All matched both sides within a day; no period-end pattern; approvals evidenced. | No finding |
| 9. Cash positioning and sweeps | 20 daily positions; sweep configuration | Position prepared by the controller from six online-banking logins; sweeps configured at seven of twelve depots; the other five carried an average 1.1 million dollars above the sweep target while the operating account used its overdraft line on 31 days. | Finding, Medium (cost quantified at about 50,000 dollars a year) |
| 10. Bank fees | One quarter reperformed on three accounts | Fees on the largest account 22 percent above the contract schedule, driven by analysis charges for a lockbox service cancelled a year earlier; 11,000 dollars recovered. | Finding, Medium |
| 11. Stale items and unclaimed property | Year-end outstanding cheques | 214 cheques older than 180 days totalling 48,000 dollars, 60 of them past the state dormancy period; no escheat process. | Finding, Medium |
| 12. Cheque stock and signatures | Observation; logs; authorities | Stock secured and sequenced; the electronic signature file accessible to three users including the AP supervisor. | Finding, Low |
| 13. Online banking access | Portal users vs HR | Two leavers retained view-only access; the controller was the portal administrator and an approver. | Finding, Medium |
| 14. Ledger integrity | All reconciliations to the ledger; manual cash journals | Two legacy accounts bridged to the ledger through a spreadsheet; 14 manual journals to cash, all approved. | Finding, Low |
The report carried ten findings, three High, five Medium and two Low, an overall rating of Needs Improvement, and one referral. The referral was the reconciling item that grew: the depot manager at one of the three spreadsheet depots had been depositing short and describing the difference as timing on a reconciliation he prepared himself, which is the exact condition the FY27 route cash report had said would happen if the three depots stayed on local reconciliation. The audit committee’s response was to fund the integration of the three depots into head-office reconciliation immediately rather than in the next budget year. The positive pay finding was fixed by a phone call to the bank; the ACH filter took a week; the sweeps at the five depots were configured in a month and the overdraft line was not used for the rest of the year. Three things generalise. Confirm accounts and services with the bank, not with finance: the dormant legacy account, the former owners on the mandate and the positive pay never enabled were all invisible from inside. Rolling reconciling items are the analytic that finds the fraud: it took one query across twelve months to surface the item that grew, and it would have taken years of monthly reviews to notice. And a repeat finding escalated is worth more than a new one: the report’s most important paragraph said that a High finding from the previous year was still open at three sites, and named the decision that had left it open.
The reviewer’s checklist: ten questions before signing a reconciliation
Most reconciliation failures are review failures, and the reviewer is usually a controller with forty minutes and twenty reconciliations. The checklist below is what a review that counts as a control actually asks; put it on the cover sheet so the answers are recorded, and the audit test becomes a test of whether the questions were answered rather than whether the initials are present.
1. Does the bank balance agree to the bank statement I obtained, not to a figure the preparer typed? 2. Does the book balance agree to the general ledger account, not to a spreadsheet? 3. Is every reconciling item listed individually with a date, a reference and an amount? 4. Has any item appeared on the previous two reconciliations, and if so, what happened to it? 5. Is there an item described as unidentified, other, timing or adjustment, and what is it really? 6. Are the deposits in transit all cleared in the following month’s statement? 7. Are there outstanding cheques older than 90 days, and what is being done about them? 8. Did the preparer handle cash, post cash entries or make deposits for this account this month? 9. Were there any bank debits the books did not know about (fees, returned items, ACH debits, adjustments), and were they investigated before being booked? 10. Was this reconciliation prepared within five business days of month-end, and if not, why?
The findings that recur, and wording that lands
Five findings account for most cash reports, and each lands in five-Cs form with a number the CFO can check. Independence (“bank reconciliations for three depot accounts are prepared by the depot managers who make the deposits; policy requires preparation by finance staff with no cash-handling duties; a reconciling item on one of these accounts concealed short deposits for five months”). Protections (“the disbursement account has no positive pay service and the operating account no ACH debit filter, although both are available under the banking contract; two unauthorised ACH debits totalling 6,800 dollars cleared in the year”). Mandates (“six of 21 authorised signatories have left the company; the former owners of both acquired businesses remain signatories on the legacy accounts”). Idle cash (“five depot accounts carried an average of 1.1 million dollars above their sweep target while the operating account used its overdraft on 31 days, at a cost of about 50,000 dollars a year”). Stale items (“214 outstanding cheques older than 180 days, 48,000 dollars, remain on the reconciliation; 60 are past the state dormancy period and have not been reported as unclaimed property”). Write the cause as the decision behind the condition (the integration that left three depots local; the contract nobody read after signing; the sweep configured once) and follow the root cause guide.
Scoping variants: multi-entity groups, store cash, treasury-owned accounts
Multi-entity group with hundreds of accounts: the account inventory becomes the audit, with a reconciliation-status dashboard (prepared, reviewed, aged items) by entity as the first deliverable; sample account-months by risk (accounts with rolling items, local reconciliation, or no activity) rather than by size, and test the automated reconciliation tool’s matching rules and tolerances as configuration. Retailer with store cash: add the store layer (safe counts, till reconciliation, cash-in-transit contractor reconciliation, deposit slip to bank credit by store) and use deposit-lag analytics by store as the selection engine for visits, in the same way the inventory guide uses shrink analytics. Company where treasury owns the accounts: split the audit so that account governance, mandates and protections are tested under the treasury program and the reconciliation and ledger integrity under this one, with the interface between them (who tells finance an account was opened) as a specific test. Companies with outsourced accounting: the reconciliation is performed by the provider, so obtain their SOC 1 report, map the complementary user controls, and reperform a sample yourself; the provider’s reconciliation is evidence, not assurance, until you have tested it.
Where to go next
Audit cash by confirming with the banks, reperforming the reconciliations from the bank side, and running the rolling-item and deposit-lag analytics across the year before you sample anything. The fraud, when there is one, is in the item that will not go away; the money, when there is money, is in the sweeps, the fees and the protections nobody switched on. The program above is a complete starting position; size it with the sampling grid, build the file like the model workpaper, and report it with the report template. The accounts’ owners are covered in how to audit treasury, the channels in how to audit payment operations and wire transfers, and the receipts that feed the deposits in how to audit accounts receivable.
Related guides
- How to audit treasury — the function that owns the accounts
- How to audit payment operations and wire transfers — the channels money leaves through
- How to audit accounts receivable and collections — the receipts that become deposits
- How to audit accounts payable — the disbursements the reconciliation proves
- Test of design vs operating effectiveness — MidState’s route cash reconciliation failures
- How to audit journal entries — manual journals to cash accounts
- Risk and control matrix template — the reconciliation control written to the handoff standard
- Control description examples — more five-element descriptions
- User access reviews — online banking rights
- Segregation of duties — collect, deposit, post, reconcile
- Audit sample sizes: 25, 40, 60 — the sampling conventions
- Fraud red flags — skimming and kiting from the fraud side
- The five Cs of audit findings — the structure the findings above follow
- Audit issue log template — where the actions go
- All fieldwork and testing guides and all internal controls guides
Leave a Reply