By the Foxnut team · Updated
Comparison
Journal entries and what the audit trail has to show
Which journal entries already post themselves, which ones the audit standard names by profile and tells an auditor to go find, and what a posting system has to leave behind either way.
By the Foxnut team · Updated
Most of a ledger writes its own entries
A journal entry is nothing more than a debit and a credit that changes the general ledger, and the overwhelming majority of them never involve a person deciding anything. An invoice posts from accounts payable, a receipt posts from accounts receivable, a payroll run posts from the payroll system, a bank line posts from the feed that reconciles it - each one arrives at the ledger already decided by the transaction that caused it, with the account, the amount and the date fixed by the source document. What is left over, after every subledger has done its own posting, is a much smaller and much more interesting population: the general journal, entered directly against the ledger rather than derived from a subledger transaction. Accruals for work done but not yet invoiced, corrections to a prior period’s error, consolidating and eliminating entries, depreciation and amortisation schedules, reclassifications between accounts, one-off adjustments nobody automated because nobody expected to need them twice. That second population is what “journal entry automation” almost always turns out to mean once the question gets specific, and it is what this page is about. Whether either population is worth automating turns out to depend less on how much it costs to key an entry and more on what has to be true of the entry afterward, which is why the record a posting system has to leave behind is worth settling before the software question.
The two populations are also why the search term collapses two very different buyers into one query. One is asking whether a machine can post at all - the honest answer is yes, and it already does, for the subledger-driven majority, without anyone calling it automation. The other is asking about the residual manual population, where the honest answer is narrower: some of it can be templated into the same shape as the subledger case, and the rest of it is exactly the population an auditor is required to go looking for, by name, on every audit.
What an auditor is already required to go looking for
Both the US and international audit standards single out journal entries for a specific, mandatory procedure that most other processes in this pillar do not carry. The international standard states it as an obligation that does not depend on the auditor’s own risk assessment: irrespective of the assessed risk of management override of controls, the auditor must test the appropriateness of journal entries recorded in the general ledger and other adjustments made in preparing the financial statements. The US standard runs the same procedure in more operational detail, and it names the profile of an entry worth selecting rather than leaving it to intuition: entries posted to accounts that are unrelated, unusual or seldom used; entries made by people who do not typically make them; entries recorded at or after period end that carry little or no explanation; entries drafted before they carry an account number; and entries containing round numbers or a repeating ending digit.
That list is not a hypothetical concern dressed up as a compliance procedure. In a 2026 study of 2,402 occupational fraud cases across 143 countries and territories, financial statement fraud - a deliberate misstatement of the reported figures - was the rarest of the three main categories of occupational fraud, present in only 6% of cases, and by a wide margin the costliest: a median loss of $1,000,000, against $150,000 for corruption and $100,000 for asset misappropriation, and a median 24 months before anyone caught it, the longest of the three. The same study asked how fraud of every kind was concealed, and the ledger itself was one of the answers: creating fraudulent journal entries was named as a concealment method in 9% of all cases, altering journal entries in 6%, and deleting or omitting journal entries in 5% - smaller shares than altering a physical document, but shares that land directly on the accounting record rather than on the paperwork sitting beside it.
None of that is an argument against automating journal entries. It is the reason the question of what the record shows cannot be answered after the fact. An entry’s audit trail has to be able to show who or what initiated it, on what basis, when, and - if it does not look like the entries around it - why, whether or not that particular entry is ever actually selected for testing. Outside the strictly accounting context the same requirement shows up wherever an entry supports an invoice: EU rules require a taxable person to be able to demonstrate “a reliable audit trail between an invoice and a supply of goods or services”, and the European Commission’s own guidance on the point describes that trail as a documented, checkable link running from the source document through to its recording in the accounts and back again, achieved through business controls that can include internal controls such as segregation of duties. Different regulator, same underlying object: an entry has to be traceable to something outside itself.
Four ways an entry reaches the ledger
| A subledger posts it | A person keys it directly | A recurring or templated journal repeats it | A rule or model proposes it for approval | |
|---|---|---|---|---|
| What decides it should exist | The originating transaction - an invoice, a payment, a timesheet - before the ledger is touched at all | A person, applying judgment to a fact no system holds: an estimate, a write-off, a reclassification | A template set up once, for an account combination and amount logic that does not change month to month | A pattern in the source data that a rule or model was built to recognise, held for a person to release |
| How it reads against the auditing profile above | Standard account, standard preparer, mid-period, fully described by the originating document - outside every named characteristic | The profile the standard is built to find, by construction: a person, a judgment call, often at period end, described only as well as the preparer chose to describe it | Same account and preparer every period, which is why a control that has been reviewed once stays low-exception thereafter | Depends entirely on whether the reason the rule fired is recorded with the entry; a system that posts a number without recording why reproduces “little or no explanation” mechanically, at volume |
| What happens when the underlying facts change after posting | A correcting entry flows through the subledger again | Another manual entry, by the same or a different person, with its own description | The template is edited going forward; periods already posted need a manual correcting entry like any other | The rule or model is re-parameterised or retrained, and already-posted entries need the same manual correction - the fix does not reach backward |
| Who can explain it a year later | The originating document, unchanged | Whoever wrote the description, if the description said anything | Whoever set up the template, or anyone who can read its logic | Whoever can reproduce the rule’s basis or the model’s inputs at the time it fired, which is a harder thing to preserve than the entry itself |
The third row is the one worth reading twice, because it is where a project either earns or loses the audit trail it is being built to keep. A subledger and a well-built template both degrade gracefully: the fix is another entry of the same well-understood shape. A rule or model that proposes an entry without recording the basis for it degrades badly, because the thing that would explain the entry a year later was never captured in the first place, and a retrained model cannot reconstruct what its earlier version was thinking.
What the decision turns on
Six structural dimensions decide whether a process is worth automating. Journal entries split unusually cleanly along the same line that already separates the two populations above: the mechanical majority reads as a commodity, and the manual minority reads as the exact object two different auditing standards were written to examine.
| Dimension | What it reads on journal entries | Source |
|---|---|---|
| Exception variance | Named by characteristic rather than discovered by size. The auditing standards do not ask which entries are large; they name a profile - unrelated or seldom-used accounts, an atypical preparer, period-end or post-closing timing with little or no description, no account number at draft stage, round numbers or a repeating ending digit - and require every audit to test against it regardless of the assessed risk. A recurring or templated entry is, by construction, outside that profile: same account, same preparer, same shape every period. The exception population is therefore definable in advance, which is unusual for this pillar, and it is exactly the population this page calls manual. | PCAOB AS 2401.61; ISA (IFAC) 240.32(a) |
| Volume | Not the number of transactions the business runs and not its revenue. What grows the workload is the count of lines that reach the ledger outside the subledgers that already post themselves, and that count tracks the number of legal entities, currencies and one-off events a close has to absorb rather than the size of any single figure. A general ledger built around named journal purposes - one name for intercompany, one for accrual adjustments, one for error correction - is itself evidence that the population is organised by type of event, not by size. | Microsoft, Dynamics 365 Finance, 'General journal processing' |
| Cost of an error | Concentrated at the rare, expensive end. Financial statement fraud was the rarest of the three main occupational-fraud categories in a 2026 study of 2,402 cases - present in 6% of cases - and the costliest by a wide margin, with a median loss of $1,000,000 against $100,000 for asset misappropriation and $150,000 for corruption, and a median 24 months before detection, the longest of the three. The same study found journal-entry manipulation named as a concealment method in a meaningful share of all cases studied: creating fraudulent entries in 9%, altering them in 6%, deleting or omitting them in 5%. An error here is rarely a wrong sum; it is a right-looking sum that nobody can explain when it is finally asked about. | ACFE, Occupational Fraud 2026: A Report to the Nations, figures 2, 10 and 12 |
| Reversibility | High before a period closes, low after. An unposted journal can be corrected freely. One documented general ledger locks a journal's name and protects its batch number from deletion the moment its header is committed, specifically to preserve the record, while still offering an automatic-reversal pattern for the standing accrual case. Once a period is closed and its figures sit in an issued financial statement, the same fix is not an edit: it is a second, dated, equally visible entry, and both auditing standards direct their attention precisely at entries recorded after that door has closed. | Microsoft, Dynamics 365 Finance, 'General journal processing'; PCAOB AS 2401.62 |
| Regulatory exposure | The highest in this pillar in one specific sense: testing journal entries is not risk-based. Both the US and international auditing standards require the procedure on every audit regardless of the auditor's own assessment of risk, which few other processes here carry. Separately, where an entry supports an invoice, EU rules require a demonstrable audit trail between the invoice and the underlying supply, and US federal tax rules require permanent books and records sufficient to establish the figures reported, retained for as long as they may become material. Three different regulators, three different mechanisms, and one shared requirement: the entry has to be traceable to something outside itself. | ISA 240.32(a); European Commission, Explanatory notes on EU VAT invoicing rules, Topic 'Reliable audit trail'; 26 CFR 1.6001-1 |
| Vendor market maturity | Settled for the mechanical case and silent on the judgment case. Recurring and periodic journal templates, voucher templates, workflow approval keyed to a materiality limit, and a spreadsheet add-in for bulk entry are documented, shipped features of at least one major ERP's general ledger module, and the same documentation locks a committed journal's name and protects its batch number from deletion. That maturity covers exactly the recurring, templated population described in the first row and stops there - the documentation has nothing to say about which excluded entry deserves a person's judgment, because that was never a configuration question. | Microsoft, Dynamics 365 Finance, 'General journal processing' |
Two rows carry the argument in opposite directions. The exception-variance row says the manual population is defined by a named profile, not discovered by trial - which means it is knowable in advance which entries belong there. The regulatory-exposure row says that population is also the one every audit is required to examine regardless of risk. Put together, they describe a process where the safe part of the automation decision and the risky part sit on opposite sides of the same, clearly drawn line, which is not true of most of the processes elsewhere in this pillar.
What this comparison usually gets wrong
The first error is treating “journal entries” as one population worth one verdict. The subledger-driven majority is not a live decision - it is already automated, by definition, the moment the invoice or the timesheet posts - and the recurring, templated slice of the general journal is a solved, shipped ERP feature. The only open question is what happens to the entries left over once both of those are set aside, and a business case that quotes a percentage of “all journal entries” as the automation opportunity is quoting a number that mostly describes work nobody was going to touch.
The second error is automating the description rather than the judgment. A system that generates a plausible caption for an entry - “period-end adjustment” repeated on every line - produces exactly the profile the auditing standards are built to catch: little or no genuine explanation, dressed in words instead of silence. The description an auditor is looking for is a reason a named person can stand behind under questioning, not a caption a machine attaches after the fact.
The third error is treating a successful post as the deliverable. Both auditing standards test entries after they are already in the ledger, often well after the period they belong to has closed, which means the moment that matters is not whether the entry went through cleanly but whether it will still read, months later, like something other than the profile in row one. A pilot that reports zero posting failures has measured the wrong thing.
The fourth error is underestimating what a locked, non-deletable record does to the shape of a mistake once a journal-name lock is in place. A wrong automated entry cannot be quietly removed - it has to be countered by a second entry that is itself visible and dated - which turns an automation project’s error rate into a doubled-entry problem rather than a silent-correction problem, and that changes how conservative the release criteria for an automated posting rule need to be.
The verdict
Automate the recurring, templated population without hesitation, and keep a named person on everything that arrives without a template.
The case for the first half is not close. The exception-variance and vendor-maturity rows agree that the recurring case is a defined, shipped, low-risk pattern: same account, same preparer, same shape, already a licensed feature in at least one major general ledger, with the reversal and lock behaviour that keeps it safe already built in. There is no reading of those two rows that argues for building a bespoke system to replicate a feature that already exists and already carries the controls this page has been describing.
The case for the second half rests on the two rows that point the other way. The regulatory-exposure row says the manual, judgment-bearing population is not a risk-managed sample - both the US and international audit standards test it on every audit regardless of assessed risk - and the cost-of-error row says the rare, expensive failure mode in this pillar concentrates in exactly that population: the smallest category of occupational fraud by frequency and the largest by loss and by time to detection. A system may prepare a manual entry, attach the source evidence, and hold it for a named reviewer to authorise. It should not post one unattended, because the entries the standard is written to find are, by its own definition, the entries nobody can yet show were reasoned about correctly.
For a team weighing this, two cheap checks settle more than a demonstration would. Pull last month’s general journal - not the subledger postings, the entries keyed directly against the ledger - and sort each line into two piles: the account, preparer and amount logic match something that repeats every period, or they do not. The second pile is the actual size of the automation decision, and for most entities it is far smaller than “journal entries” as a category suggests. Then check whether the accounting system already installed has its recurring-journal, voucher-template and workflow-approval features switched on, because the more common finding is not that the feature is missing. It is that it was licensed years ago and nobody configured it. If you have run both checks and still think there is a real build here, tell us what you found.
The part most pages leave out
When not to choose Foxnut Studios
Situations where another option is the better call, and where we say so in the first conversation rather than the fourth.
- The entries in question are standing accruals, depreciation, amortisation schedules and standard reversals - the same account combination, the same preparer role and the same amount logic every period, with nothing left to decide once the template was reviewed once. The accounting system's own recurring or periodic journal feature and its voucher templates, which already ship this pattern with the workflow approval and posting controls attached, and the honest recommendation is to switch that feature on rather than commission a new one.
- The design has a rule or a model post an entry directly to a period that has already been closed, or to an account an auditor has already tested and signed off for the year, on the reasoning that the entry is small and the change is easy to make. A human control point placed before the post, not after it. In a documented general ledger, a journal's name and batch number are locked once its header is committed specifically so a mistake cannot be quietly removed - the only route back is a second, dated, equally visible correcting entry, which is a materially bigger event than an edit and belongs to a named person to authorise.
- The ledger structure has not settled - a recent acquisition, a restructuring, or a mid-year system migration - so most of what reaches the general journal in a given month is a one-off correction or a fix to a mapping error rather than a repeating line. A redesigned chart of accounts and mapping process, not an automated posting layer. Automating the correction of a structure that keeps producing corrections only posts the same mess faster and leaves a longer trail of entries that fit the exact profile auditors are told to select.
- The fact behind an adjustment - a dispute with a customer, a balance written off by agreement, a decision taken in a meeting - exists only in an email thread or a person's memory, and the ledger shows only the debit and the credit. The organisation itself, recording the reason before the entry is posted. A system can generate the two lines and a plausible-sounding caption, but it cannot manufacture the explanation that both the US and international audit standards look for when an entry carries little or no genuine description - and a caption is not the same thing as a reason.
- The volume is a handful of general-journal lines a month, prepared by the person who also reviews the trial balance before the books close, at an entity with no subsidiaries and no consolidation to manage. The person already doing it, unchanged. The condition worth watching is not a fixed count of entries: it is the number of legal entities, currencies and one-off events a close has to absorb, because that is what makes the manual population grow, not the size of the business measured any other way.
Sources
- Public Company Accounting Oversight Board, AS 2401 'Consideration of Fraud in a Financial Statement Audit', paragraphs .58 through .62 - the requirement to test journal entries and other adjustments for evidence of fraud, the four-step procedure, and the named characteristics of an entry worth selecting (unrelated or seldom-used accounts, an atypical preparer, period-end or post-closing timing with little or no description, no account number at draft stage, round numbers or a repeating ending digit) Retrieved
- IFAC/IAASB, International Standard on Auditing (ISA) 240 (Revised), 'The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements', paragraph 32(a) - the requirement, stated as applying irrespective of the auditor's assessment of the risk of management override of controls, to test journal entries recorded in the general ledger and other adjustments made in preparing the financial statements. Read in the IAASB Handbook PDF Retrieved
- Association of Certified Fraud Examiners, 'Occupational Fraud 2026: A Report to the Nations' - a study of 2,402 cases from 143 countries and territories; figure 2 (financial statement fraud present in 6% of cases, the rarest of the three main categories, with the highest median loss at USD 1,000,000 against USD 100,000 for asset misappropriation and USD 150,000 for corruption), figure 10 (concealment methods, including creating fraudulent journal entries at 9%, altering journal entries at 6%, and deleting or omitting journal entries at 5%), and figure 12 (financial statement fraud's case count, quartiles and mean, and its 24-month median duration to detection, the longest of the three categories). Read as text extracted from the association's own report PDF Retrieved
- European Commission, Directorate-General for Taxation and Customs Union, 'Explanatory notes on the EU VAT invoicing rules' (Council Directive 2010/45/EU), 2011 - Topic 'Reliable audit trail', Article 233(1) second subparagraph: the requirement that authenticity, integrity and legibility be ensured through business controls creating a reliable audit trail between an invoice and a supply, and the Commission's own description of an audit trail as a documented, checkable link from a source document through to its recording and back, appropriate to the size and activity of the taxable person. Read as text extracted from the Commission-hosted PDF Retrieved
- 26 CFR 1.6001-1, 'Records' - paragraph (a), the requirement to keep permanent books of account or records sufficient to establish the amounts required to be shown on a return, and paragraph (e), the requirement that such records be retained for as long as their contents may become material to the administration of an internal revenue law. Read through the Electronic Code of Federal Regulations renderer Retrieved
- Microsoft, 'General journal processing', Dynamics 365 Finance product documentation - journal-name-scoped workflow approval keyed to a materiality limit, the rule that a committed journal's name is locked and its batch number protected against deletion, automatic reversal for accrual-type entries, the Excel add-in for bulk journal-line entry, and account-level posting controls including a do-not-allow-manual-entry restriction and user-level posting validation Retrieved
Foxnut Studios works on briefs like this one from Bengaluru and Paris. If you want the shape of that before you talk to anyone, here is what an AI engagement covers and what you keep.