The single most common feature of financial statement fraud, and the one no control design defeats — because the person overriding the control is the person who designed it.
What it looks like: a transaction processed outside the normal approval path, a system limit bypassed with management authorization, a period-end entry that skipped review, or a control the client explains was "handled directly" for a particular transaction.
Why it matters more than other control deficiencies: it makes the entire control environment unreliable for the transactions that matter most, which are precisely the unusual ones.
Response: treat identified override as a risk assessment change, not an isolated exception. Expand substantive testing on the affected assertions, test for other overrides rather than assuming the one you found is the only one, and document the override and its implications in the risk assessment rather than only in the exception log.
Journal entry testing is where fraud is most often found, and where it is most often performed superficially — a random sample of entries, tested for support, with no attention to which entries were worth selecting.
The population characteristics that matter:
Response: obtain the complete entry population and interrogate it on these characteristics rather than sampling randomly. This requires data capability — the Excel training for accountants and pivot table skills are directly applicable — and it is the highest-yield audit procedure available.
Cut-off manipulation is the most common revenue misstatement, and it is visible in the data.
What to look for: an unusual concentration of revenue in the final days of the period; shipments recorded before goods left; invoice dates preceding shipping documentation; unusually large orders from customers with no comparable history; sales with unusual terms, extended payment dates, or side agreements; and a spike in credits or returns in the following period, which is the reversal.
Response: test cut-off against the shipping records and the carrier documentation, not against the invoice, because the invoice is the thing being manipulated. Examine post-period credits and returns as a matter of routine — they are the audit trail of last period's overstatement.
Estimates are the most flexible instrument in financial reporting, and the flag is not any single estimate but the pattern across periods.
What it looks like: reserves that increase in strong periods and release in weak ones; allowance methodology changed in a period when the prior methodology would have produced a worse result; an estimate revised late in the close process; management's estimate consistently at the favorable end of a reasonable range; and warranty, returns, or obsolescence reserves that never require adjustment despite changing conditions.
Response: develop an independent expectation before receiving management's, and evaluate the estimate against the range rather than for reasonableness in isolation. Look at prior-period estimates against actual outcomes — an estimating history that is consistently optimistic is a finding about the process. And treat a change in methodology as requiring its own justification, documented.
The structural problem in this area: the primary source of the related party list is management, so an audit that relies on management's completeness assertion is circular.
What surfaces unidentified relationships: vendor and customer addresses matching employee addresses; entities with names echoing family names; a vendor with no web presence, a post office box, or a residential address; unusual payment terms with a single counterparty; loans to or from parties not described anywhere; transactions with no clear business purpose; and legal invoices referencing entities you have not seen.
Response: search independently. Public records, entity filings, employee address comparisons against vendor master files, and — very effectively — reading the legal invoices and board minutes rather than only the related party disclosure. Every significant unusual transaction should also be tested for business purpose, because a transaction lacking one is the recurring feature of related party abuse.
Deceptively mundane and one of the most reliable indicators of both error and fraud.
What it looks like: unreconciled differences described as immaterial and carried forward period after period; "on top" adjustments plugging a difference; aged items in a suspense or clearing account; reconciliations prepared but not reviewed; and the account that reconciles perfectly every month with no items ever outstanding, which is sometimes a sign that nobody is actually reconciling.
Response: examine the composition of unreconciled differences rather than accepting their aggregate as small. Aged items in clearing accounts frequently contain the residue of exactly what you are looking for, and a carried-forward difference that never resolves is not immaterial — it is unexplained.
A specific and telling pattern: the support you asked for did not exist until you asked.
What it looks like: a contract, approval, or memo produced days after the request with a date preceding the request; signatures that look recent on old documents; documents provided as fresh printouts or images rather than from a file; inconsistent fonts, alignment, or formatting within a document; and missing originals with explanations.
Response: note the timing in the workpapers — when it was requested and when it was received — because that sequence is evidence. Where authenticity is in question, seek external corroboration rather than examining the document more closely. And escalate: fabricated documentation is a different category of matter from a control deficiency.
The most underrated red flag, because it lives in conversation rather than in documents.
What it looks like: a different explanation from a different person for the same item; an explanation that changes after the auditor tests it; unusual specificity and detail in response to a simple question; irritation or deflection at routine inquiries; a client who volunteers information nobody asked for; and — the classic — an explanation that is plausible in isolation and inconsistent with something else in the file.
Response: corroborate explanations rather than accepting them, which is the concrete content of professional skepticism. Ask the same question of a second person. Document the explanation received, from whom, and what corroborated it — because "management represented" alone is not audit evidence, and an explanation the file records without corroboration is exactly what post-mortems identify.
Confirmations are only evidence if the auditor controls the process, and the failures are consistent.
What it looks like: responses returned from a personal email domain or a generic address; a reply-to address the client can access; responses arriving by an unusual route; the client offering to obtain the confirmation or to "follow up" with a non-responder; addresses the client provided that differ from those in public records; responses with matching handwriting or formatting across supposedly different respondents; and non-responses concentrated among the balances that matter most.
Response: control the entire process — the auditor addresses, sends, and receives. Independently verify the counterparty's address for significant balances. Treat a non-response as requiring alternative procedures rather than as a matter for the client to resolve, and treat a client's offer to help obtain a confirmation as a flag in itself.
The quiet one, and the one implicated in a striking number of frauds.
Bank statements printed by the client, vendor invoices from the client's file, brokerage statements forwarded by the client, and lender confirmations obtained through the client are all subject to alteration, and altering a PDF requires no sophistication whatsoever.
Response: obtain significant confirmations and statements directly from the source, whether through direct confirmation, a bank portal the auditor accesses, or a third-party service. Where a client-provided document must be relied upon, corroborate it — vendor invoices against payment records and receiving documentation, bank statements against confirmations.
Not evidence themselves, and they change how heavily each item above should weigh:
Pressure — covenant thresholds approaching, an earnout or bonus tied to a metric, a pending transaction or financing, a covenant already breached, or a stated target that must be met.
Opportunity — one person controlling a complete cycle, a dominant executive whom nobody contradicts, weak or absent segregation of duties, or an accounting function without competent oversight.
Rationalization and behavior — an employee who never takes vacation or resists transferring duties, lifestyle changes inconsistent with compensation, high turnover in accounting, a history of aggressive positions, or contempt expressed toward controls and auditors.
Audit-relationship signals — scope limitations, delays in providing information, restricted access to personnel, a recent auditor change with an unclear reason, and pressure on fees or timing in a period when the business became more complex.
The list is the easy part. Four disciplines convert noticing into an audit that holds up.
Change the risk assessment, in writing. A red flag that does not alter the documented risk assessment has not been acted upon. This is the specific gap post-mortems identify.
Extend procedures in response to the specific risk, not generically. More sampling of the same population is not a response to a management override.
Corroborate every significant explanation, and document what corroborated it.
Communicate. Identified fraud risks, control override, and suspected fraud carry communication obligations to those charged with governance, and the threshold for communicating a suspicion is lower than the threshold for concluding one exists.
And do not explain it away. The most common single sentence in a failed audit file is an explanation from management, recorded without corroboration, that turned out to be false. Recording the explanation is necessary. Stopping there is the failure.
Structured coverage is available through the Certificate in Forensic Accounting, Fraud Examination, the fraud and forensic accounting training catalog, the audit training courses listing, internal auditing training, and ethics training and professional conduct.
Not missing something invisible, but noticing something, accepting management's explanation, and not documenting why. Post-mortems consistently find an explanation recorded in the file without corroboration that later proved false — which is why professional skepticism has to take the form of documented actions rather than an attitude.
Journal entry testing, when the population is interrogated rather than randomly sampled. The characteristics worth targeting are manual entries in an automated environment, entries posted after period end but dated within it, round-dollar amounts, entries by users who do not normally post, entries with no meaningful description, and entries reversed shortly after period end.
Because management is the primary source of the related party list, so relying on their completeness assertion is circular. Independent searching — public records, comparing employee addresses to the vendor master, and reading legal invoices and board minutes rather than only the disclosure — is what surfaces relationships management did not identify.
By controlling the entire process: the auditor addresses, sends, and receives. Independently verify counterparty addresses for significant balances, treat non-responses as requiring alternative procedures rather than client follow-up, and treat a client's offer to obtain or chase a confirmation as a red flag in itself rather than as helpfulness.
Because altering a document requires no sophistication, and client-provided documents are implicated in a striking number of frauds. Significant statements and confirmations should be obtained directly from the source, and where a client-provided document must be used it should be corroborated against payment records, receiving documentation, or a direct confirmation.
Change the documented risk assessment, extend procedures in response to that specific risk rather than generically, corroborate the explanation received and record what corroborated it, and communicate identified fraud risks or control override to those charged with governance — noting that the threshold for communicating a suspicion is lower than for concluding fraud occurred.


