Accounting close and controls | October 1, 2026

An AI risk score is triage evidence, not accounting evidence

Use AI to apply a consistent first pass across the journal population, surface structural breaks, and prepare a review packet. Keep completeness, source support, accounting judgment, segregation of duties, exact-version approval, and posting with named people.

Complete population Source-bound review Maker-checker gate Sources checked Oct 1

One-click AI pack

Build the journal-entry review packet

Paste this into ChatGPT, Claude, Gemini, or an enterprise-approved AI tool with minimized, authorized inputs. It prepares a complete evidence and exception packet without granting correction, approval, or posting authority.

AI can widen first-pass coverage without becoming the control owner

Journal-entry review is vulnerable to a familiar close problem: the population grows, the deadline does not, and review becomes selective even when the policy says otherwise. FloQast's September 16 announcement makes one practical pattern visible. Its AI Assistant can run structural checks, identify duplicates and missing fields, detect unexpected account and dimension combinations, score audit risk, explain findings, and suggest a fix. The vendor also says the system does not post, correct, or decide on behalf of the accountant.

That boundary is more important than the feature list. A model score is useful for triage, especially when it applies one first pass consistently across hundreds of entries. It is not evidence that the entry belongs in the ledger. Accounting evidence comes from a complete population, exact source support, valid policy, re-performed calculation, appropriate classification and cut-off, resolved exceptions, segregation of duties, and a named reviewer exercising judgment on one exact version.

PCAOB AS 2401 explains why journal entries receive special attention in fraud-risk work. Management override can use inappropriate or unauthorized entries, particularly around period end. The standard directs auditors to understand the reporting process and controls, identify entries for testing, consider timing, inspect supporting evidence, and apply professional judgment to characteristics such as unusual accounts, atypical preparers, weak explanations, round numbers, estimates, unreconciled accounts, and nonstandard activity. Management's review control is not the auditor's test, but a strong internal workflow should preserve the population and evidence that an auditor may later need to evaluate.

Current practitioner discussion is consistent with that boundary. Controllers in a September r/CFO thread rejected black-box entries and asked for reviewable workpapers tied to source transactions and approvals. Accountants discussing complex AI-generated journals said the time spent feeding and checking the model can exceed doing the entry manually. The design implication is not “avoid AI.” It is to deploy AI where it increases consistent coverage and reduces assembly work, while measuring whether reviewer effort and correction risk actually improve.

Use the model to find where a reviewer should look. Never use the score to decide that the reviewer no longer needs to look.

The control object is one exact entry plus its evidence packet

complete journal population + control totals
                |
       deterministic structural checks
                |
     source lineage + calculation reperformance
                |
       AI risk features and explanations
                |
       owned exceptions and judgments
                |
   independent review of exact entry version
                |
 separate posting authority + ledger receipt

Freeze the population: preserve the extraction query, entity, ledger, period, cutoff, row count, debit total, credit total, journal status, and immutable reference. Include rejected, deleted, reversed, late, post-close, recurring, system-generated, and manual entries. If the tool sees only entries sent for review, it cannot prove that a high-risk entry was not omitted upstream.

Run deterministic checks first: debits equal credits; required fields exist; accounts and dimensions are active; the period is open; currency and units are valid; reversal logic is complete; duplicates and near-duplicates are surfaced; the approval route reflects segregation rules; and source-system totals tie. A model may explain a failed check, but the pass/fail result should not depend on generative confidence.

Build source lineage: link every material line to the invoice, contract, schedule, subledger record, calculation, approval, reconciliation, or other source that supports it. Record exact identifiers and versions. A source list without line-level mapping is not enough when one journal allocates costs across entities, departments, products, or periods.

Reperform the calculation: reproduce rates, allocations, accruals, amortization, estimates, reversals, currency conversions, and debit-credit logic with a deterministic spreadsheet or script. Keep the inputs and formulas visible. An AI-generated calculation is a proposal; independent reperformance is the evidence that the arithmetic follows the supplied rules.

Separate risk features from judgment: late timing, unusual accounts, a new preparer, a round-number amount, or a historical deviation can prioritize review. None proves fraud or error. Recognition, measurement, classification, cut-off, tax, estimate, impairment, and disclosure questions belong to qualified owners who can interpret policy and facts.

Release one version: the reviewer records procedures against an entry hash and packet hash. Any later change to amount, account, date, dimension, description, support, preparer, or attachment invalidates that approval. A separate posting authority verifies the approved version in the ledger workflow and captures the system receipt.

Design risk features as explainable routing, not hidden scoring

A single “87% risk” label invites anchoring. Reviewers need the feature, evidence, comparison set, and limit. Historical patterns can reveal deviations, but history can also normalize a recurring error or encode a past workaround. New entities and reorganizations make normal combinations look unusual. A trusted preparer can still make a mistake, and a new preparer can prepare a correct entry.

FeatureEvidence to showReviewer question
Duplicate or near-duplicateCandidate entry IDs, amounts, dates, sources, descriptions, and reversal state.Same obligation, valid correction, or duplicate posting?
Unusual account/dimension pairCurrent combination, comparison window, frequency, and organization changes.Valid new business pattern or misclassification?
Late or post-close timingCreation, modification, approval, and requested posting timestamps.Expected close adjustment or override risk?
New or atypical preparerRole, access, normal journal classes, and approval route.Authorized preparer with suitable independent review?
Missing reversalJournal class, policy, expected reversal date, and subsequent-period effect.Permanent entry or incomplete temporary accrual?
Round number or vague narrativeAmount precision, source calculation, description, and supporting schedule.Supported estimate or unsupported management adjustment?
Low-dollar patternAggregate count, common accounts, preparers, and cumulative effect.Individually small but systematic or concealed?

PCAOB guidance warns against excluding low-dollar entries in a way that misses frequent fraudulent activity. The lesson for management is broader: materiality and thresholds must come from authorized policy and risk assessment, not a vendor default. Preserve below-threshold entries in the population and monitor their aggregate patterns even when they do not receive the same review depth.

Worked example: a quarter-end marketing accrual

An entry records a $480,000 marketing accrual across four regions on the last evening of quarter close. The preparer uses a new global marketing cost center. The description says “campaign true-up,” and the journal reverses on the first day of the next quarter. The AI Assistant flags the new account-dimension combination, late timing, round allocation percentages, and a supporting workbook with hard-coded totals.

Review layerObserved evidenceDisposition
PopulationEntry is present in the complete period extract; debit and credit control totals tie.Pass.
StructureValid accounts and entities; required reversal exists; preparer cannot approve or post.Pass.
SourceThree approved insertion orders total $420,000; one $60,000 estimate lacks vendor support.Blocking exception for unsupported estimate.
CalculationWorkbook allocates 25% to each region, but supplied campaign data shows 40/30/20/10.Reperform allocation and propose corrected lines.
JudgmentAccounting policy owner must decide whether the unsupported portion meets accrual criteria.Route; AI cannot conclude.
ApprovalOriginal entry hash changes after source and allocation correction.Invalidate earlier review; issue a new packet.

The AI risk score helped route attention. It did not establish the liability, choose the allocation driver, or approve the entry. The final packet should retain the original journal, flags, missing evidence, owner decisions, corrected calculation, changed lines, reviewer procedures, exact approval, posted journal number, and ledger receipt.

Define what counts as human review

A review click proves workflow completion, not professional review. The record should identify the reviewer, their authority and independence, exact entry and packet versions, procedures performed, source items inspected, calculations re-performed, policy or specialist consultations, questions raised, corrections required, exceptions accepted or rejected, and conclusion.

Weak review evidenceStronger review evidence
“Approved” with timestampReviewer, authority, procedures, exact hashes, exceptions, conclusion, and timestamp.
AI score below thresholdStructural checks, source mapping, reperformance, and judgment challenge.
Second model agreesDeterministic tie-out and qualified reviewer conclusion.
Attached workbookInput lineage, formulas, version, control totals, and difference analysis.
Trusted preparerSegregated approval and risk-based procedures regardless of reputation.

Do not ask one person to play every role. The source owner confirms extracts. The preparer explains purpose and support. The accounting reviewer challenges the entry. Policy, Tax, Treasury, or valuation specialists own their judgments. The Controller or delegated authority approves the exact version. A separately authorized person or controlled interface posts. Internal Audit or SOX can challenge design and operating evidence without becoming the control owner.

This guide addresses management's workflow. External auditors decide their own population, selection, timing, procedures, and evidence under applicable standards. An exported AI review packet can improve traceability; it cannot bind the auditor to management's score or conclusion. Pair this process with the external-audit evidence workflow when preparing a broader request package.

Failure modes that a polished risk dashboard can hide

FailureWhy it hidesControl
Incomplete populationEvery received entry was analyzed.Reconcile extract to source-system counts and debit-credit totals.
Historical bias becomes normalRepeated combinations score as low risk.Policy checks and recurring-exception analysis outside anomaly score.
Low-dollar entries disappearIndividual amounts sit below threshold.Preserve population and test aggregate patterns.
Explanation without supportThe model produces a convincing business purpose.Require exact source references and preparer attestation.
Hard-coded workpaperTotals tie on the visible sheet.Trace inputs and formulas; independently reperform.
Preparer self-approvesWorkflow identity is ambiguous.Enforce maker-checker segregation in the ledger, not the prompt.
Correction bypasses reviewThe status remains “approved.”Hash exact version and invalidate approval on any change.
Posted entry differsThe approved PDF and ledger are separate artifacts.Compare posted lines to approved hash and capture receipt.
Model update shifts flagsVendor UI looks unchanged.Version the workflow, freeze fixtures, and compare flag/correction deltas.

Run a 30-day read-only pilot

Week 1: choose one journal class with stable source support and manageable judgment, such as a recurring accrual or standard allocation. Map the complete population, source systems, control totals, policies, preparers, reviewers, posting roles, deterministic checks, and existing exceptions.

Week 2: build the frozen review manifest, source-to-entry ledger, deterministic test suite, risk-feature schema, exception register, reviewer procedure template, exact-version approval, and approved-to-posted reconciliation. Keep AI read-only.

Week 3: seed duplicate entries, missing reversal, inactive dimension, altered support, late entry, low-dollar pattern, new preparer, valid new account combination, hard-coded schedule, unsupported description, post-approval change, and segregation conflict. Confirm the workflow distinguishes deterministic failure, risk feature, and accounting judgment.

Week 4: run beside the current process. Measure population coverage, false-positive and false-negative review findings, material corrections, reviewer time, exception aging, overrides, post-approval changes, and posting differences. Compare with the existing control rather than a demo baseline.

Scale only when the team can reproduce a material entry from source, explain why every feature was raised, demonstrate reviewer procedures, and prove the posted journal equals the approved version. If the pilot merely adds a dashboard and another queue, it has moved work rather than improved control.

FAQ

Can an AI risk score approve a journal entry?

No. It can prioritize review. Approval depends on support, policy, calculations, segregation, exceptions, and professional judgment by an authorized person.

Should AI post journal entries automatically?

Not in this workflow. Keep the AI read-only. A separately authorized person or controlled posting process verifies the exact approved version and captures the ledger receipt.

What must the review packet contain?

Population evidence, entry version, preparer and route, debit-credit lines, source support, business purpose, policy mapping, deterministic checks, risk features, exceptions, reviewer procedures, approval, correction history, posting receipt, and approved-to-posted reconciliation.

Does this replace auditor journal-entry testing?

No. Management controls and auditor procedures have different objectives. Auditors determine their own risk assessment, selection, timing, testing, and sufficient appropriate evidence.

Sources and further reading

Sources were checked on October 1, 2026. This is a vendor-neutral management workflow, not accounting, audit, tax, fraud, legal, or regulatory advice. FloQast is treated as a current catalyst, not proof of independent accuracy, control effectiveness, audit acceptance, or productivity.