Auditing a set of financial statements for discrepancies is a structured process of comparing what a company claims against independent evidence, then testing whether the numbers reconcile. The goal is not to prove the books are right; it is to try, systematically, to prove them wrong before someone else does. Below is the definitive walkthrough of how a competent auditor or analyst approaches this in 2026, including practical steps, thresholds, tools, costs, and the mistakes that cause most audits to miss real problems.

What an Audit Actually Is (and Is Not)

Also worth reading: Which is better for financial auditors: SHAP or LIME when explaining AI model discrepancies? · How do blockchain forensic accounting techniques identify financial discrepancies in digital asset audits? · What are the essential internal controls for SMBs to prevent fraud and financial discrepancies?

A financial audit is an independent examination of financial statements performed under standards such as Generally Accepted Auditing Standards (GAAS) in the United States or International Standards on Auditing (ISA) elsewhere. The auditor's objective is to obtain reasonable — not absolute — assurance that the statements are free of material misstatement, whether caused by error or fraud. Reasonable assurance is defined by risk thresholds: auditors typically design procedures to reduce detection risk so that overall audit risk stays around 5 percent or lower.

This matters because it sets expectations correctly. An unqualified (clean) opinion is not a guarantee that no fraud exists; it means no material misstatements were found using the procedures performed. History proves the point repeatedly. The US Government Accountability Office has documented that the Department of Defense has never passed a clean audit — its FY2010 statements were deemed unauditable, and decades of remediation efforts have cost billions without full resolution. In 2025, GAO also flagged material errors in claimed government savings figures, showing that even well-resourced reviews catch mistakes only when they look for them properly.

An audit is also not a forensic investigation. A standard audit samples transactions and tests controls; a forensic audit digs into specific suspected wrongdoing, often with legal consequences in mind. If you suspect deliberate concealment, a standard audit may not be sufficient — Fort Thomas, Kentucky, for example, approved a forensic audit specifically to trace a $322,000 discrepancy, and Connecticut officials called for a rigorous independent financial audit after Hartford Public Schools reported a budget discrepancy. Those are different engagements from routine annual audits, priced and scoped differently.

The Direct Answer: The Seven-Step Process

The core workflow for finding discrepancies follows seven steps, adapted from standard change-management and audit methodology:

  1. Plan and understand the entity. Learn the business model, revenue streams, key systems, and where money enters and leaves. Identify accounts where misstatement is most likely.
  2. Assess risk. Rank accounts by inherent risk (complexity, estimates, cash) and control risk (weaknesses in approval processes, segregation of duties).
  3. Test internal controls. Walk through approval chains, reconciliations, and access rights. Weak controls raise the amount of substantive testing required.
  4. Perform substantive procedures. Confirm balances with third parties (banks, customers), recompute figures, inspect documents, and perform analytical procedures comparing current figures against prior periods and expectations.
  5. Investigate anomalies. Every variance beyond your threshold gets explained with evidence, not management assurances alone.
  6. Evaluate misstatements. Aggregate all found errors and compare against materiality.
  7. Report. Issue findings, adjust entries, or qualify the opinion if problems are material and uncorrected.

Each step feeds the next. Skipping control testing to jump straight into transaction testing is the most common shortcut, and it usually backfires because you end up testing far more transactions manually at higher cost.

Setting Materiality and Thresholds: Where Discrepancies Get Found

Materiality is the single most consequential number in any audit. Public company auditors commonly set overall materiality at roughly 5 percent of pre-tax income, 0.5 to 1 percent of revenue, or 1 to 2 percent of total assets, depending on which benchmark drives user decisions. Performance materiality is typically set at 50 to 75 percent of overall materiality to allow room for undetected errors. Anything below the clearly trivial threshold — often 5 percent of overall materiality — is generally not pursued individually but must still be aggregated.

These thresholds explain why small discrepancies slip through clean audits. A company with $100 million in revenue might have $500,000 materiality; a recurring $40,000 monthly leakage would sit below the line unless analytical procedures flag the pattern. This is why trend analysis matters more than single-period testing. Compare each line item month over month and year over year, compute ratios (gross margin, days sales outstanding, expense-to-revenue), and investigate anything moving more than about 10 percent without a documented reason.

Specific high-yield checks include: bank reconciliations that have not been performed monthly; receivables aging showing sudden spikes in old balances; journal entries posted at period-end or by unauthorized users (a classic fraud indicator per ACFE data); round-dollar manual adjustments; and vendor master files containing duplicate bank accounts. Occupational fraud studies from the Association of Certified Fraud Examiners consistently show median losses around $145,000 per case, with schemes running a median of roughly 12 months before detection — meaning most fraud survives at least one annual audit cycle.

Practical Steps: Auditing Financials Yourself Without a CPA Firm

If you are reviewing a small business's books, a nonprofit's statements, or your own records, you can run a meaningful discrepancy hunt in 20 to 40 hours using this sequence:

Step one: tie everything to the bank. Download 12 months of statements and reconcile every account to the general ledger. Unreconciled differences are the fastest route to real findings. Reconciliation software and even spreadsheet-based matching can clear most items quickly; anything left over deserves scrutiny.

Step two: verify revenue independently. Match recorded revenue to bank deposits, invoices, and contracts. Look for revenue recognized before cash or contractual entitlement exists — the most common aggressive accounting practice. For subscription businesses, check deferred revenue balances move logically with billing cycles.

Step three: test expenses against authorization. Sample 25 to 50 disbursements across vendors and confirm each had approval, a matching invoice or contract, and a legitimate business purpose. Duplicate payments and ghost vendors show up here. AI-assisted bill review has become practical: CNET's 2025 testing of AI tools on medical bills found real errors, illustrating that automated line-item comparison catches mistakes humans skim past.

Step four: recompute estimates. Depreciation schedules, allowance for doubtful accounts, inventory reserves, and accruals are judgment areas where manipulation hides. Recompute depreciation independently and compare reserve percentages year over year.

Step five: check related-party transactions. Loans to owners, above-market rent paid to affiliated entities, and intercompany balances that do not eliminate cleanly are frequent sources of both error and abuse.

Document every exception with amounts, dates, and explanations. An unexplained variance is a finding; an explained one backed by evidence is closed. Management verbal assurances close nothing.

Comparison: Standard Audit vs. Forensic Audit vs. DIY Review vs. AI-Assisted Review

FeatureStandard Financial AuditForensic AuditDIY Internal ReviewAI-Assisted Review
Primary purposeOpinion on fair presentationInvestigate suspected fraudFind obvious errorsFlag anomalies at scale
Typical cost (small/mid firm)$10,000–$75,000+$150–$400/hour; $25,000–$250,000+Staff time only ($0–$5,000 software)$50–$500/month tools plus review time
Duration4–12 weeks2–6 months1–4 weeks internallyDays to weeks
CoverageSampling-basedFull-population targetedLimited by reviewer capacity100% of digitized transactions
Legal usabilityLimitedCourt-ready reportsNoneSupporting evidence only
Best forLenders, investors, complianceLitigation, theft, disputesSmall businesses, nonprofitsHigh-volume AP/AR, medical bills, expenses
False sense of security riskModerateLowHighModerate — output still needs human verification
No option dominates. A standard audit gives credibility with outsiders but will not necessarily surface sub-materiality leakage. A forensic audit is powerful but expensive and usually requires a trigger event. DIY review is cheap but shallow. AI-assisted tools excel at full-population screening — duplicate invoices, price variances, unusual patterns — but their outputs require human confirmation, and vendors' accuracy claims should be tested on your own data before being trusted.

Common Mistakes That Cause Audits to Miss Discrepancies

The first mistake is over-reliance on sampling. If fraud is concentrated in a handful of transactions, random samples of 25 items can easily miss it entirely. Modern practice increasingly uses full-population analytics precisely for this reason; if you are still sampling blindly, you are accepting blind spots deliberately.

The second mistake is anchoring on prior-year figures. Auditors who treat last year's numbers as the baseline inherit last year's errors. Independent recomputation and third-party confirmations break that chain. Confirmation bias is related: once management offers a plausible explanation, many reviewers stop digging. Require documentary support, not narratives.

Third, ignoring non-financial signals. Sudden lifestyle changes in finance staff, refusal to take vacation (a classic sign someone is hiding ongoing schemes), unusually long system access hours, and high turnover in accounting roles correlate strongly with fraud findings. Behavioral red flags cost nothing to observe.

Fourth, treating the audit as an annual event rather than continuous monitoring. Fraud runs a median of about 12 months before detection; quarterly reconciliation reviews and monthly variance analysis cut that window dramatically. Fifth, misunderstanding tool limitations. AI bill-audit tools find genuine errors, but they also generate false positives, and GAO's finding of material errors in DOGE's claimed savings figures is a useful reminder that automated analysis without verification produces confident wrong answers. Verify every machine-flagged item against source documents before acting on it.

Finally, scope creep in reverse: many organizations define the audit too narrowly, excluding subsidiaries, related parties, or certain accounts. The DoD experience shows what happens when scope and complexity outrun methodology — unauditable statements despite enormous budgets.

When to Act: Triggers That Demand an Audit Now

Certain events should trigger an immediate audit or forensic review rather than waiting for the annual cycle. These include: an unexplained variance exceeding roughly 2 to 5 percent of revenue or a specific budget line; a whistleblower complaint; abrupt departure of a finance executive; discovery of missing documents or altered records; lender or investor due-diligence requests; regulatory inquiries; and preparation for a sale or merger, where undisclosed liabilities directly reduce deal value.

Timing also has a compliance dimension. Public companies face SEC filing deadlines (10-K within 60 days for large accelerated filers), and nonprofits generally need audits or reviews above state-specific thresholds — many states require audits for charities receiving over $500,000 to $2 million in contributions, depending on jurisdiction. Hedge funds and other investment vehicles face year-end audits under their regulators' custody rules, typically completed within 120 days of fiscal year-end. If you are approaching any of these deadlines with unreconciled books, start remediation immediately; auditors charge premium fees for compressed timelines, and rushed work misses things.

For ongoing protection, institute monthly bank reconciliations, quarterly analytical reviews, and an annual independent audit as the baseline cadence. Organizations handling public funds — school districts, municipalities — should consider rotating audit firms every five years or so to preserve independence and fresh eyes.

Costs, Pricing, and Return on Investment

Audit pricing scales with revenue, complexity, entity count, and control quality. Rough 2026 benchmarks: a simple single-entity small business audit runs $10,000 to $25,000; mid-market companies with multiple entities pay $30,000 to $100,000; complex organizations exceed $150,000. Forensic work bills hourly at $150 to $400 depending on seniority and region, with typical engagements starting near $25,000. Review engagements (lower assurance) cost roughly 40 to 60 percent of an audit; compilations less still.

Weigh these costs against expected recovery. Accounts payable audit firms typically work on contingency, keeping 25 to 50 percent of recovered duplicate payments and overcharges, and routinely recover 0.05 to 0.2 percent of spend — meaningful for companies spending tens of millions annually. Medical bill auditing frequently finds error rates cited between 1 and 5 percent of billed charges. Against those recovery rates, even a modest internal review pays for itself quickly, while a formal audit delivers value through credibility: clean opinions lower borrowing costs, satisfy covenants, and support fundraising.

The honest caveat: an audit is insurance and credibility infrastructure, not a profit center. Its ROI shows up in avoided losses, better financing terms, and earlier detection — benefits that are real but hard to attribute precisely. Budget accordingly, and do not let the pursuit of a perfect assurance product crowd out cheaper continuous monitoring that actually catches day-to-day leakage.

Final Assessment

Finding discrepancies in financial statements comes down to disciplined comparison: books versus banks, claims versus contracts, current periods versus trends, and assertions versus documents. Set explicit materiality thresholds, test full populations where technology makes it affordable, demand documentary evidence instead of explanations, and escalate to forensic specialists when intent is suspected. The process is neither glamorous nor foolproof — reasonable assurance leaves gaps, and history from the Pentagon to local school districts shows discrepancies survive even expensive oversight. But a methodical reviewer following the steps above will find the majority of material errors and a substantial share of deliberate ones, at a fraction of the cost of discovering them through crisis.