What a Month-End Close Audit Actually Does

A month-end close audit is an independent or semi-independent review of the accounting records used to close a reporting period. It is broader than checking whether the general ledger balances, because the objective is to determine whether reported balances are supported, complete, accurate, and prepared under the company’s accounting policies. The review can examine bank reconciliations, revenue schedules, accruals, fixed assets, inventory, intercompany accounts, tax files, journal entries, and the final trial balance. It does not necessarily replace a statutory financial-statement audit, although findings from a close audit may be used by the external auditor to reduce later work. A useful close audit tests the process as well as the number: a balanced ledger can still contain an unsupported balance, a premature revenue entry, or an incorrect journal entry that happens to leave the trial balanced. The practical goal is to identify discrepancies early enough to correct them before financial statements are issued.

Also worth reading: What Is Forensic Accounting Evidence, and How Does It Reveal Financial Discrepancies? · What Are the Best AP Control Testing Steps for Detecting Financial Discrepancies? · Where Do Financial Record Discrepancies Hide, and How Are They Found in 2026?

The distinction between monitoring and auditing matters. Monitoring asks whether close tasks were completed on schedule, while auditing asks whether the resulting information is reliable and supported by evidence. A close checklist showing 100% completion is not evidence that all 100% of entries are valid. For example, a bank reconciliation marked “complete” may omit the reconciliation date, outstanding-item aging, or independent review evidence. Likewise, an accrual schedule may reconcile to the general ledger while failing to match invoices, contracts, receipts, or subsequent payments. The strongest procedures connect source records to the ledger and then connect ledger balances back to the financial statements. This creates an audit trail that can be followed by an accountant, controller, auditor, lender, or regulator without relying on undocumented memory.

A month-end audit also evaluates whether controls operated consistently during the period. The review should identify who created, approved, and posted each material transaction, and whether exceptions were investigated. Companies with multiple ERP systems, payment platforms, payroll providers, or acquisition entities face additional matching risks. A payment may be recorded in one entity while the related revenue is recorded in another, or a Stripe balance may be confused with a Metronome subscription balance. The audit therefore needs clearly defined data owners and reconciliation rules, not merely another spreadsheet. The final conclusion should state whether exceptions were resolved, whether unresolved items were immaterial, and whether any control weakness could become material if repeated.

The Main Financial Areas Reviewed

The first priority is cash and near-cash balances because they are directly observable but can contain timing and completeness errors. Bank reconciliations should agree to bank statements, confirm deposits in transit, identify stale outstanding checks, and investigate reconciling items older than the company’s normal policy. The reviewer should also compare cash accounts across entities and verify restricted cash classifications. A reconciliation difference of $500 may be operationally small but can point to a larger control failure, particularly if the same process handles thousands of transactions. For payment-platform balances, the review should connect processor statements to bank deposits, fees, refunds, disputes, reserves, and settlement timing. Cash should not simply be forced to the bank balance without explaining every adjustment.

Revenue is another high-risk area because close procedures often depend on estimates, contract terms, and system-generated reports. Tests should sample invoices, subscription changes, credits, refunds, deferred revenue, contract liabilities, and usage-based billing. A 2% variance between the billing subledger and the general ledger should be quantified by customer, product, period, and cause. It should not be dismissed as rounding if the absolute amount is material or if it has persisted for several months. Revenue recognition rules can change with contract terms, even when the customer’s payment status does not change. A close audit should therefore verify both the numerical reconciliation and whether the accounting conclusion is supported by the contract and performance obligations.

The review should also test accruals, prepaid expenses, fixed assets, inventory, payroll, taxes, and intercompany transactions. Accruals require support from invoices, purchase orders, receipts, contracts, or subsequent cash payments; an accrual based only on an estimate should identify the method and assumptions used. Fixed-asset additions should be traced to invoices, asset tags, capitalization thresholds, depreciation start dates, and disposal records. Inventory counts should be compared to perpetual records, and differences should be investigated for shrinkage, timing, or system mapping errors. Intercompany accounts should be matched across legal entities and currencies, with any residual balance assigned an owner and resolution date. A close audit is most useful when it looks across accounts rather than treating each workpaper as an isolated exercise.

How the Audit Finds Discrepancies

A reliable audit begins with a reconciliation between the trial balance, reporting package, and supporting subledgers. The reviewer should not accept a total that agrees to another total unless the underlying populations are complete and the same definitions are used. For each account, the audit can compare opening balance plus approved activity to the closing balance, then investigate differences that exceed a defined tolerance. A dollar threshold alone is insufficient: a $10,000 variance may be material to a small entity but immaterial to a large one, while a $100 variance can still reveal a broken automated rule. Companies should combine absolute thresholds with percentage thresholds, historical variance ranges, and qualitative indicators such as related-party transactions or control overrides.

Testing should cover both individual items and populations. An auditor may select every journal entry above $25,000, all manual entries posted after close, and a statistical sample of smaller entries. If manual entries represent 8% of postings but 30% of total dollars, the sample should reflect that risk rather than selecting randomly without regard to exposure. The sample should be expanded when one error is found because that error may indicate a broader population issue. For recurring entries, the reviewer should inspect the original transaction and determine whether the same error would have occurred in prior months. A repeated $7,500 misclassification across 12 months becomes materially more important than a single isolated $7,500 item, even if each monthly entry appears small.

Technology can help compare millions of records, but an automated match does not prove correctness. Rules should identify exact matches, amount differences, date differences, duplicate invoices, missing documentation, unusual users, round-dollar journals, and entries posted outside business hours. Exceptions should be assigned for investigation, not automatically posted as adjustments. The reviewer should test whether the system flags the right exceptions and whether management resolves them appropriately. An exception queue with 400 items and no aging status is not a control; it is simply an unfinished task. By October 2026, companies may also use AI assistants to summarize close activity or draft anomaly explanations, but those tools still require controlled data access, documented prompts, validation, and human review of accounting conclusions.

A Practical Month-End Close Audit Process

The process should start before the close begins by defining the reporting perimeter, materiality, account ownership, and required evidence. The perimeter should identify every ERP, billing platform, bank account, legal entity, reporting currency, and manual spreadsheet that affects the close. Teams should establish a calendar that allows review before financial statements are finalized, rather than scheduling the audit after management has signed the numbers. For a 31-day month with a target close in five business days, the audit review might begin on day four, run through day seven, and finish before the reporting package is locked. If the company closes on the fifth business day, it may need daily evidence capture or a continuous-monitoring process. A late audit can still detect errors, but it increases the risk that external users receive corrected figures or that adjustments are made without adequate review.

The reviewer should obtain a close trial balance, account reconciliations, journal-entry reports, supporting schedules, approved policies, and the prior-period audit findings. Each reconciliation should identify preparer, reviewer, date, balance, and outstanding exceptions. The audit can then test high-risk balances and perform targeted analytics across months. Differences should be logged with amount, account, cause, owner, proposed correction, approval requirement, and due date. Management should decide whether an adjustment is required, but the reviewer should independently assess whether the proposed treatment is supported. The final report should distinguish corrected errors, unresolved errors, control observations, and improvements that are recommended but not necessarily accounting adjustments. This prevents a vague statement such as “several issues were noted” from being mistaken for a complete accounting conclusion.

A defensible process should include independent sign-off and a formal closure step. The reviewer should confirm that posted corrections agree to approved entries, that affected financial statements and management reports were updated, and that any recurring issue has a preventive action. If a balance remains unreconciled, the report should state the amount, reason, expected resolution date, and potential misstatement range. For example, an unresolved intercompany difference of $180,000 is more serious than a $180 item because it may affect both revenue and expenses. The organization should not hide the issue by reclassifying it to suspense indefinitely. A suspense account is acceptable only as a temporary holding area with active investigation, clear aging, and a limit approved by the controller.

Internal Audit, External Audit, and Software Options

The best option depends on whether the objective is operational control testing, statutory assurance, fraud investigation, or improved close speed. An internal audit program can examine the close process across periods and entities, while a controller or finance team may perform a targeted close audit each month. A statutory external auditor follows professional standards and provides an opinion on the financial statements as a whole; it does not become a monthly close-management service. A forensic review is appropriate when there is suspected fraud, concealed liabilities, unauthorized payments, or deliberate manipulation, and it requires a different evidence standard. Software can automate matching and anomaly detection, but it cannot decide whether a complex accounting judgment is appropriate without accountable human involvement. The organization should compare tools by workflow and control requirements, not by the number of features shown in a product demonstration.

FeatureInternal or external close auditAutomated reconciliation and audit software
Main purposeIndependently challenge balances, evidence, and controlsMatch data, flag exceptions, preserve activity
Typical coverageSelected accounts, entities, samples, and control testsHigh-volume transactions and recurring close tasks
Human judgmentRequired for materiality, estimates, and conclusionsNeeded for exception review and accounting treatment
EvidenceAuditor workpapers, confirmations, contracts, and approvalsSystem logs, match results, approvals, and exception histories
Time profileScheduled review, often monthly or quarterlyContinuous or near-continuous monitoring
Main limitationCan be costly and dependent on access to evidenceFalse matches and poor master data can hide issues
Best useAssurance and accountabilitySpeed, consistency, and early detection
Pricing varies substantially because software may be priced by entity, account, transaction volume, user, or module. A simple spreadsheet-based review may cost little in license fees but require substantial employee time to prepare, refresh, and review. Enterprise reconciliation software can cost tens of thousands of dollars annually, while broader financial close platforms may require implementation, integration, and consulting fees that push total cost into six figures. These figures are planning ranges rather than universal list prices; contracts commonly vary. The buyer should calculate total cost of ownership, including data integration, subscription or license fees, implementation, training, support, audit evidence, and the time saved during close. A tool costing $20,000 per year is not economical if it reduces reconciliation work by only one day and still leaves manual evidence gathering in place.

The right choice is often a layered approach rather than a single product. Automated matching can handle complete bank and subledger populations, while internal audit tests judgment and control design. Existing ERP reporting may be adequate for stable, low-risk reconciliations, but it may not support detailed historical evidence across 38 systems. The supplied research context describes Sixthfin moving UK month-end account justification out of Excel with reconciliation review, audit trails, and multi-ERP control; that example illustrates a practical need, not proof that one vendor’s control design is universally superior. Similarly, KPMG’s October 2026 announcement regarding an AI digital assistant for month-end close indicates a direction toward assisted work, but AI should not be treated as an independent assurance opinion. Management must test data lineage, access controls, model errors, and the audit trail before relying on generated analyses.

Common Mistakes and Weak Controls

One common mistake is treating the trial balance as proof of accuracy. The trial balance proves only that debits equal credits; it does not prove that the right debit and credit accounts were used, that transactions belong in the period, or that all transactions were recorded. Another mistake is allowing a preparer to review their own reconciliation without independent evidence. Self-review may be acceptable for routine controls in a small business, but the organization should document compensating procedures when segregation is impractical. A controller can review a bank reconciliation after the fact, but the review should compare the statement, outstanding items, and general-ledger entries rather than merely initialing the schedule. The most serious pattern is repeated tolerance without analysis, particularly when small discrepancies are carried forward month after month.

Other weaknesses involve spreadsheets, duplicate logic, and unclear ownership. A workbook may contain broken external links, hard-coded totals, hidden rows, or formulas overwritten by manual values. Spreadsheets are not inherently unacceptable, but each important file should have an owner, version control, protected formulas, documented assumptions, and an archived final copy. The reviewer should test whether totals recalculate and whether copied prior-month balances are supported. Duplicate invoices can arise when source systems assign different identifiers, so matching by invoice number alone may miss them. Conversely, matching only by amount can falsely identify transactions that happen to be equal. Data definitions should be standardized before automation is expected to produce dependable results.

Close teams also make the mistake of auditing too late or failing to follow through. If the review starts after the package is issued, corrections may require amended reports, lender notifications, tax amendments, or restatement. An audit finding should have an owner and deadline, and repeated findings should trigger a root-cause analysis rather than another reminder. Management should track at least four metrics: percentage of reconciliations completed by the deadline, percentage of material differences resolved before sign-off, age of the oldest open exception, and number of repeated audit findings. A target of 95% on-time completion is meaningful only if the remaining 5% is explained. A 100% closure rate achieved by suppressing exceptions is not a positive result; it is a reporting distortion. Controls should reward transparent escalation, not cosmetic completeness.

When to Escalate and What It May Cost

A discrepancy should be escalated immediately when it could affect reported revenue, profit, cash, debt covenants, tax, regulatory reporting, or management compensation. Repeated errors, unauthorized journal entries, missing invoices, related-party balances, unexplained bank transfers, and evidence of deleted or overwritten files warrant prompt review. The materiality decision should consider both quantitative size and qualitative factors. An error below the company’s materiality threshold may still require action if it suggests fraud, breaches a contract, affects an executive’s compensation, or exposes a weakness in a key control. Companies should document the threshold and the reasoning rather than waiting for an external auditor to define materiality. A 1% pretax variance may be material in some periods but not others, especially near a loss or a covenant limit where a small swing changes compliance status.

Escalation should move from operational correction to executive review when the amount, age, or pattern indicates more than a routine reconciliation issue. The controller can assign an adjustment and monitor completion; the audit committee or board should be informed when suspected fraud, material misstatement, sanctions issues, or repeated control failures are involved. The organization should preserve records before making changes, because deleting the original entry can destroy evidence. If fraud is suspected, external forensic or legal support may be needed. An audit should never encourage employees to “make the balance work” by creating unsupported entries, backdated invoices, or artificial accruals. A transparent unresolved difference is safer than a polished but false close.

The cost of correcting an issue depends on the cause and when it is found. A $50,000 revenue cut-off error caught before publication may require one adjustment, one revised schedule, and limited communication. The same error found after audited statements are issued may require customer or investor notifications, auditor consultation, tax review, covenant analysis, and potentially amended filings. Operational costs can also include staff overtime, delayed reporting, customer credits, penalties, and management distraction. Automation can reduce recurring labor and detect errors earlier, but implementation costs and integration work must be included. Before purchasing software, finance leaders should quantify current close labor, exception rates, error frequency, and the financial impact of late corrections. Those numbers provide a stronger business case than a general promise that a platform will make the close “transformational.”

The Minimum Standard for a Credible Close Review

A credible month-end close audit should be reproducible by someone who was not involved in preparing the close. The reviewer should be able to identify the population, select items, rerun comparisons, inspect source documents, follow approvals, and arrive at the same conclusion. This means retaining the close package, query parameters, exports, version history, reviewer notes, approvals, and subsequent adjustments. The final report should state the scope, period, entities, systems, materiality considerations, procedures performed, exceptions, corrections, and limitations. It should not imply that every transaction was tested if the work relied on sampling or automated reports. Transparency about coverage is more useful than an exaggerated assurance claim.

The audit should also connect current results to historical trends. A 3% monthly variance in cloud expenses may be acceptable when business activity is stable but suspicious if it follows a contract renewal or unused subscription. A recurring $40,000 intercompany mismatch is more concerning after six months of aging than a one-time item. Trend analysis should include account volatility, close-cycle days, manual journal percentages, unresolved exceptions, and repeated customer disputes. Thresholds can be revised as the business changes, but they should be approved and applied consistently. By October 2026, finance teams are increasingly using AI and continuous auditing, yet the basic evidence standard remains unchanged: source data must be trustworthy, transformations must be visible, exceptions must be resolved, and conclusions must be independently challenged.

For most organizations, the sensible target is not zero errors at any cost. It is a controlled close in which material misstatements are prevented, smaller errors are detected promptly, and unresolved items are visible to decision-makers. A monthly review focused on the highest-risk balances, supported by automated matching and clear ownership, will usually provide more value than an expensive full audit of every routine process. The process should become more detailed as risk increases, especially with multiple ERPs, complex revenue contracts, acquisitions, or prior audit findings. Ultimately, the success of a month-end close audit is measured by the quality of the evidence and the speed of credible correction, not by how many checks were marked complete.