Journal Entry Testing and Fraud Detection
Language / Taal: This document is the English version. Lees in het Nederlands
This document describes how Dutch auditors are required to test journal entries as part of a statutory audit, how fraud risk analysis is performed, and what data-analytic techniques (CAAT — Computer-Assisted Audit Techniques) are used to identify anomalous entries. The governing professional standards are NV COS 240 (fraud), NV COS 315 (risk assessment), NV COS 330 (risk response), and NBA Handreiking 1141 (data analytics in audit). Updated guidance on fraud risk analysis is provided in NBA Handreiking 1153 (March 2025).
1. The Mandatory Nature of Journal Entry Testing
NV COS 240 §32–33
NV COS 240 (De verantwoordelijkheid van de accountant voor fraude bij de controle van financiële overzichten) establishes the auditor's fraud-related obligations. Regardless of any other risk assessment conclusions, §32 requires the auditor to test journal entries and other adjustments for evidence of fraud risk as a mandatory procedure in every statutory audit. This is not an optional procedure triggered only when fraud is suspected — it is a baseline requirement in every controle.
Specifically, NV COS 240 §32 requires the auditor to:
"test journal entries recorded in the general ledger and other adjustments made in the preparation of the financial statements. In designing and performing these journal entry tests, the auditor shall: (a) make inquiries of individuals involved in the financial reporting process about inappropriate or unusual activity relating to the processing of journal entries and other adjustments; (b) select journal entries and other adjustments made at the end of a reporting period; and (c) consider whether there is a need to test journal entries and other adjustments throughout the period."
NV COS 240 §33 specifies that the tests should be designed to identify and select for further examination:
- Journal entries and adjustments that have characteristics indicative of possible fraud
- Other journal entries and adjustments that are significant or unusual
The practical result of §32–33 is that every Dutch statutory audit must include an explicit, documented journal entry testing procedure. In manual audits this historically involved reviewing a sample of journal entries. In data-driven audits, it involves systematic population-level analysis of all entries, which is more effective and is explicitly sanctioned by the NBA's Taskforce Datagedreven Controle and NBA Handreiking 1141.
2. Fraud Risk Analysis — NBA Handreiking 1153
NBA Handreiking 1153 (Frauderisicoanalyse, March 2025) provides current NBA guidance on how to perform the fraud risk analysis as part of the overall risk assessment under NV COS 240 and NV COS 315. It was issued following the NBA's own causal analysis ("Fraude vraagt een meer kritische grondhouding") and the AFM's report "Scherper op frauderisico's!" (June 2023), which found that Dutch auditors were assessing fraud risks too generically.
The fraud triangle
The handreiking structures fraud risk identification around the classic fraud triangle:
- Gelegenheid (opportunity): weaknesses in the internal control environment that create an opportunity for fraud — absent or circumvented segregation of duties, lack of management oversight, poor access controls in IT systems.
- Motief / druk (motive/pressure): incentives or pressures that drive individuals toward fraud — financial distress, compensation structures tied to reported results, high personal debt, pressure from lenders to maintain covenant ratios.
- Rationalisering (rationalization): attitudes or ethical climate that enable individuals to justify fraudulent behavior — management that treats rules as flexible, culture of "the ends justify the means," or prior unaddressed integrity incidents.
Frauderisicofactoren vs. frauderisico's
The handreiking draws a critical distinction:
- Frauderisicofactoren (fraud risk factors): the conditions, events, or circumstances that indicate a fraud risk may exist (items from the fraud triangle above).
- Frauderisico's (fraud risks): the specific risk of a material misstatement resulting from fraud. A fraud risk must be specific: it must name the account balance or transaction class at risk, the nature of the potential misstatement (fictitious revenues, overstated assets, understated liabilities, etc.), and be tailored to the specific client.
The auditor must convert identified fraud risk factors into specific, client-tailored fraud risks. Generic statements such as "there is always a risk of management override" are insufficient — the auditor must document what form that override might take at this client, in which account areas, and why.
Two presumed fraud risks under NV COS 240
Under NV COS 240 §26 and §31, two fraud risks are presumed to be present in every audit unless specifically rebutted:
- Revenue recognition: the risk that revenues are fraudulently overstated through fictitious customers, premature recognition, or channel stuffing. This presumption can be rebutted if the auditor documents specific reasons why revenue manipulation is unlikely for the entity in question (e.g., a non-profit with grant income rather than commercial sales).
- Management override of internal controls: this risk is never rebuttable. It is always present because management, by definition, has the ability and authority to override the controls the auditor may otherwise rely on.
3. Journal Entry Characteristics Associated with Fraud Risk
Based on NV COS 240 and practitioner guidance, the following journal entry characteristics are associated with elevated fraud risk. The auditor's journal entry testing procedure should specifically search for these patterns in the population:
Posting attributes
- Round-amount entries: amounts that are suspiciously round (€10,000, €100,000) may indicate estimates or invented figures rather than transaction-based amounts.
- Entries posted outside normal business hours: journal entries posted late at night, on weekends, or on public holidays (feestdagen) fall outside normal operating hours and may indicate manual overrides without oversight.
- Entries posted in the final days of the reporting period: clustering of entries in the last 5–10 working days of the financial year, particularly entries that affect key metrics (profit, solvency ratios).
- Entries with unusually brief or generic descriptions: descriptions such as "correctie," "memo," "diverse," "PM," or no description at all offer less transparency and warrant scrutiny.
- Entries reversing prior period adjustments: systematic reversal of entries posted at period-end may indicate the underlying entry was not substantively supported.
Account combinations
- Entries involving unusual account combinations: postings between accounts that would not normally interact (e.g., a cash account debited with a credit to a reserve account, bypassing the income statement).
- Entries to accounts rarely or never used in other periods: activity in dormant accounts may indicate concealment.
- Entries where the same account appears on both the debit and credit side (in split entries): self-dealing entries that net to zero at the account level but move amounts between sub-accounts.
User and authorization attributes
- Entries posted by users without normal posting rights: system administrators or IT staff posting financial entries, or users posting to accounts outside their normal function.
- Entries posted using temporary or shared user accounts: bypasses individual accountability.
- Entries that are not matched to any source document in the ERP system's document-linking functionality (if available).
Period-end and top-side adjustments
- Top-side adjustments (boventallige journaalposten): manual journal entries made at consolidation or reporting level that do not flow through the entity's regular transaction processing. These are a specific risk category under NV COS 240 because they can be made by senior management and may not be visible in the ERP's normal transaction history.
4. Data Analytics in Journal Entry Testing — NBA Handreiking 1141
NBA Handreiking 1141 (Data-analyse bij de controle: uitdagingen en vooral kansen, 2019; practical case study updated September 2024) is the NBA's primary guidance document on applying data analytics in statutory audits. It positions data analytics on a spectrum:
- "Doing things differently" (anders uitvoeren): using data tools to perform existing audit procedures more efficiently. Example: instead of selecting a 25-item sample of journal entries, extracting and filtering all 50,000 journal entries in the population to identify every entry that matches a specific risk characteristic (round amounts, weekend postings), then directing testing at the risk-relevant subset. This is more effective than sampling.
- "Doing different things" (andere dingen doen): redesigning audit procedures from the ground up around data-driven insights. Example: rather than testing individual transactions, building a predictive model of expected balances and investigating deviations beyond a threshold.
NBA Handreiking 1141 emphasizes three prerequisites before any data analytics result can be used as audit evidence:
- Data completeness and integrity: the auditor must confirm that the data population extracted from the ERP or XAF file is complete (all entries are present) and has not been modified in transit. This typically involves agreeing totals from the extracted file to control totals in the system (total debit equals total credit; beginning + movements = ending balance).
- Data relevance: confirming that the data covers the correct period, entity, and ledger sections.
- Data accuracy: spot-checking extracted entries against the underlying source data in the ERP.
These three steps are documented as a data validation procedure and form part of the controle-informatie under NV COS 500.
The 2024 practical case study (based on a fictional company "Digi Jazz") works through how to extract journal entry data, validate it, run specific analyses (duplicate transactions, round amounts, weekend postings), and document the results and follow-up actions within the controledossier.
5. Statistical Techniques — Benford's Law and Outlier Detection
Benford's Law
Benford's Law describes the expected frequency distribution of the first significant digit in naturally occurring numerical datasets. In a large population of legitimately recorded financial transactions, approximately 30.1% of amounts begin with the digit 1, 17.6% begin with 2, 12.5% begin with 3, and so on down to 4.6% beginning with 9. This pattern arises from the multiplicative nature of how real-world numbers scale.
Fabricated numbers tend to deviate from this distribution. When employees invent amounts (fictitious expense claims, unauthorized payments), they tend to choose psychologically comfortable numbers — often starting with digits 5, 6, 7 — rather than the digit 1, which dominates naturally occurring data. A significant deviation from the Benford distribution in a population of journal entries or transactions can flag the population for closer inspection.
Important limitation: Benford's Law works best on large populations of freely occurring numbers. It is less meaningful for populations that are structurally constrained — for example, all transactions in a salary account, where amounts cluster in known pay-band ranges. The auditor must assess whether the Benford test is appropriate for the specific population before using the result as a risk indicator.
Outlier detection
Outlier detection identifies entries that are statistically unusual relative to the rest of the population — entries with amounts, frequencies, or account-attribute combinations that fall far outside the normal range. Common approaches:
- Z-score analysis: entries with amounts more than two or three standard deviations from the mean for their account or period
- Interquartile range (IQR) method: entries outside 1.5× the IQR from the upper or lower quartile
- Time-series analysis: comparing posting volumes or amounts by period (week, month) to identify unusual spikes
Outlier detection is a complement to, not a replacement for, the fraud-characteristic filtering described in section 3. An outlier is not necessarily fraudulent — it may be a one-off large legitimate transaction. The auditor must follow up each outlier with inquiry and/or corroborating evidence.
Duplicate transaction testing
Duplicate transaction testing searches for entries that are identical or near-identical in key attributes: amount, supplier/customer, date, description, and account combination. In accounts payable, duplicate invoices paid twice are a common control weakness; in journal entries, duplicated general ledger entries may indicate either a system error or intentional double-counting.
6. The CAAT Workflow in Practice
A structured CAAT-based journal entry test in a Dutch SME audit would typically follow these steps:
- Extract the full population from the ERP or XAF file. For a Dutch entity, this is typically the journal entry file (journaalposten) from Exact Online or AFAS, or the
transactions section of the XAF file.
- Validate data completeness and integrity: total debits = total credits; beginning balance + total movements = ending balance per the trial balance; entry count matches the ERP's own report.
- Apply filters to identify entries with risk characteristics (see section 3): round amounts, weekend/holiday postings, year-end concentration, unusual account combinations, missing descriptions.
- Run Benford test on the full population of journal entry amounts (where population characteristics support this).
- Run outlier detection on amount distributions by account.
- Run duplicate test on key fields.
- Select entries for detailed testing: from the flagged sub-populations, select a risk-based subset for detailed vouching — obtaining and inspecting the underlying supporting documentation (invoices, approvals, board minutes).
- Document results: record the procedures performed, the filters applied, the number and nature of entries flagged, the entries selected for testing, the evidence obtained, and the conclusions reached.
- Conclude: state whether the journal entry testing resulted in findings that require additional procedures, adjustments, or reporting in the controleverklaring.
Step 9 is where the auditor's professional judgment operates. The data analysis produces candidates for investigation — not findings in their own right. The accountant evaluates each candidate against the supporting evidence and forms a conclusion.
7. Fraud Findings and the Controleverklaring
If the journal entry testing identifies evidence of actual or likely fraud, the auditor's response is governed by NV COS 240 §35–42: determining whether the fraud is material, communicating with those charged with governance, considering whether to communicate to regulators, and evaluating the implications for the audit opinion.
Whether or not fraud is identified, the auditor must describe their fraud risk audit approach in the controleverklaring under the section "Controleaanpak frauderisico's." NBA Handreiking 1150 (October 2022) provides the step-by-step framework for this section, including:
- Describing the specific fraud risks identified
- Explaining the procedures performed in response (including JET, if performed)
- Noting the approach to management override of controls
- Where findings were made: describing them in sufficient detail without compromising confidentiality
The fraud section of the controleverklaring is a public document. Auditors are required to describe their actual approach for the specific client — generic, template-based language is not compliant with NBA Handreiking 1150.
8. Professional Skepticism and Human Accountability
NBA Leidraad 2: AI Toegepast (June 2026, published jointly by NBA Accounttech and NOREA) states explicitly that AI tools used in audit must never be a "black box" — they must be transparent, reproducible, and subject to human oversight. The leidraad names fraudedetectie as a legitimate use case for AI in audit practice.
The AFM's November 2025 supervisory statement is unambiguous: "De accountant blijft eindverantwoordelijk" — the accountant remains finally and non-delegably responsible for all audit conclusions, including those where data analytics tools surfaced the candidates for testing. The accountant cannot delegate this judgment to any automated system. Every output from a CAAT or data analytics tool is controle-informatie under NV COS 500 — evidence to be evaluated by the auditor, not a conclusion in its own right.
Sources
- NV COS 240 §26, §31, §32, §33, §35–42 (fraud standard — journal entry testing requirement)
- NV COS 315 (risk assessment, including fraud risk factor identification)
- NV COS 330 (risk response — designing procedures for fraud risks)
- NV COS 500 (audit evidence — CAAT outputs as controle-informatie)
- NV COS 520 (analytical procedures — data analytics as substantive procedures)
- NBA Handreiking 1141 (Data-analyse bij de controle, 2019/2024)
- NBA Handreiking 1150 (Rapporteren fraude in controleverklaring, October 2022)
- NBA Handreiking 1153 (Frauderisicoanalyse, March 2025)
- NBA Leidraad 2: AI Toegepast (June 2026)
- AFM report "Scherper op frauderisico's!" (June 2023); AFM statement November 2025
docs/research-dutch-audit-standards.md (Section 6 — AI/technology in Dutch audits)
Reacties