What Is an Audit Discrepancy Investigation?

An audit discrepancy investigation is a structured effort to determine why financial records, supporting documents, or reported balances do not agree. The discrepancy may involve a missing invoice, duplicate payment, unreconciled bank account, unsupported journal entry, inventory difference, or conflict between an accounting system and another record. The objective is not merely to “make the numbers match”; it is to identify whether the difference arose from error, timing, misunderstanding, control failure, misconduct, or another plausible cause. As of September 29, 2026, organizations face overlapping obligations involving financial reporting, internal controls, tax, procurement, grants, public funds, and potential fraud. An investigation should therefore begin before anyone labels the discrepancy fraud or assumes that a clean audit opinion means every transaction was correct. A qualified audit opinion, adverse opinion, disclaimer of opinion, or report containing findings on internal control may create additional reporting and governance obligations, depending on the applicable framework and entity.

Also worth reading: How Should Finance Teams Test Month-End Close Controls and Find Financial Discrepancies? · How Does a Financial Discrepancy Investigation Work, and When Should Organizations Hire a Forensic Auditor? · What Is a Forensic Fraud Examination and How Does It Uncover Financial Discrepancies?

The first step is to define the discrepancy precisely. A $25,000 variance in a general ledger balance, a $25,000 unsupported payment, and a $25,000 possible overbilling are related only in amount; they are different allegations with different evidence and remedies. A defensible investigation separates the amount under question, the relevant period, the accounting accounts affected, the control owner, and the documents expected to explain the difference. It preserves the underlying evidence before participants “correct” the records or exchange informal explanations. Finally, it assigns an investigator who is independent enough to challenge the conclusion without treating suspicion as proof. The result should be a written explanation supported by contemporaneous records, not a narrative assembled from undocumented interviews alone.

How to Initiate a Discrepancy Investigation Properly

Management should open a written investigation record and identify its purpose, scope, authority, start date, and intended audience. The first 24 to 48 hours are usually best used to preserve records, secure systems, confirm the exact amount, and prevent ordinary business processes from erasing evidence. That does not mean freezing an entire organization; targeted preservation is more proportionate. Relevant materials may include ledgers, bank statements, purchase orders, receiving records, contracts, invoices, payroll files, inventory records, tax returns, board minutes, email, chat messages, and accounting-system logs. If litigation, regulatory exposure, or electronic deletion appears reasonably foreseeable, counsel may need to issue a hold before the collection effort begins.

The opening team commonly includes finance, internal audit, compliance, IT, and the manager responsible for the affected process. Legal counsel should participate where regulatory reporting, privilege, employment action, subpoena exposure, or cross-border records may be involved. A useful opening question is: “What specific evidence would confirm or disprove each possible explanation?” This converts an uncertain allegation into testable propositions. For example, if inventory differs by 400 units, investigators can test purchases, receipts, transfers, sales, shrinkage, period cut-off, and valuation. If payroll differs from the general ledger, they can test approved hires, salary changes, time records, deductions, terminations, and payment dates. The team should document both the facts that support an error and the facts that would make misconduct more plausible.

Independence must be assessed at the outset. An employee whose reporting line or incentive is tied to the questioned transaction may still provide records, but should not control the investigation or approve its final conclusion. Organizations with conflicts may use an external forensic accountant, investigator, or law firm. Public bodies may also need inspectors general, oversight committees, or independent auditors rather than the department whose funds are involved. The investigator’s mandate should expressly permit access to necessary records and authority to escalate. Without that mandate, a review can become a reconciliation exercise performed by the people who created the underlying control weakness.

Evidence Collection and Reconciliation Techniques

Reliable evidence is evidence that is relevant, sufficient, and obtained in a manner appropriate to the assertion being tested. Auditors commonly use invoices, confirmations, inspection, reperformance, recalculation, analytical procedures, inquiry, and comparison. Inquiry alone is weak evidence because people may forget, misinterpret, or intentionally misstate events. The strongest explanation usually corroborates the amount through at least two independent paths, such as matching a payment to both an approved contract and evidence that the contracted goods or services were received. The source system should also be identified, because a report exported from Excel may differ from the authoritative accounting platform.

A bank reconciliation is one of the earliest practical procedures, but it is not a complete investigation. An examiner should review outstanding checks, deposits in transit, bank fees, electronic transfers, restricted cash, reconciling items older than a defined threshold, and manual journal entries. Aging schedules can show whether a “temporary difference” persisted for 30, 60, 90, or more days. A policy might permit unreconciled differences below, for example, $500 for no more than five business days, but that tolerance is an example rather than a universal accounting rule. Repeated breaches of the entity’s own threshold are still control exceptions. Investigators should test whether management used year-end estimates or unsupported plugs to force the subsidiary ledger to agree with the consolidated ledger.

For transactions, the review should follow the full lifecycle from authorization through recording and payment. That may mean tracing a sample of payments to approved purchase orders, contracts, receiving evidence, invoices, ledger entries, and bank statements. The sample can be risk-based, but smaller populations may warrant 100% testing, particularly when invoices, payroll, grants, related-party transactions, or manual journal entries are involved. Data analytics can identify duplicate invoice numbers, round-dollar weekend payments, vendors sharing addresses or bank accounts, payments just below approval thresholds, unusual users, and ledger changes after period close. Analytics identify candidates for testing; they do not independently establish fraud because false positives arise from legitimate batch payments, recurring invoices, and temporary overrides.

Investigation featureInternal-led reviewIndependent forensic review
Best suited toRoutine reconciliation, limited errors, and control remediationMaterial variances, suspected misconduct, regulatory exposure, or conflicts of interest
Typical scopeA process, account, branch, or defined transaction populationMultiple systems, entities, periods, vendors, officers, or control environments
Evidence accessDepends on internal authority and management cooperationFormal engagement terms, dedicated data requests, and independent reporting lines
Cost and speedOften faster and less expensive, but can be biased or constrainedUsually more expensive, but stronger when credibility and defensibility matter
OutputExplanation, adjustment, control recommendation, and management responseFindings graded by risk, evidence map, calculation, root-cause analysis, and formal report
EscalationSuitable first step when the matter appears isolatedAppropriate where legal duties, public funds, senior management, or possible fraud are involved
## Root-Cause Analysis Versus Simply Fixing the Variance

Correcting the balance does not necessarily correct the process that produced the discrepancy. A bookkeeper may post an accrual to make cash receipts and revenue agree, but that entry may still be unsupported or outside closing deadlines. Root-cause analysis asks why the control did not prevent or detect the issue, while addressing the immediate financial correction. The two efforts should remain connected. An unsupported $100,000 payment may be reclassified, but the deeper cause could be that the owner of the account can both create vendors and release payments without independent approval. Removing that access may prevent recurrence more effectively than training the same person to be more careful.

A practical method is to separate the event from the conditions, the conduct, and the control system. The event is the incorrect or missing entry. Conditions may include a high volume month, a remote site, rapid growth, obsolete software, or staff turnover. Conduct may include deliberate override, work-around, or an error caused by ambiguous instructions. The control system may lack segregation of duties, review evidence, exception reporting, or a meaningful follow-up mechanism. Investigators should not settle for the first plausible explanation. For example, a missing receiving document does not prove non-receipt; it may reflect scanning practices, but repeated missing documents can still show that the control did not operate as designed.

Management actions should be specific, assigned, and timed. “Improve controls” is not a corrective action. A stronger action is to require electronic purchase approval routed by dollar threshold, with a monthly report of all manual vendor additions and overrides sent to an independent controller. Where a local rule is appropriate, the organization might state that payments above $10,000 require two approvals and vendor-bank changes require callback verification using a previously known contact. The existing policy’s monetary limits should govern; $10,000 is an illustrative operating choice, not a generally accepted fraud-detection threshold. Each action should identify the responsible executive, completion date, testing method, and evidence retained. Without those details, the remediation plan is a statement of intent rather than evidence that the risk has been reduced.

When a Discrepancy Becomes More Than an Audit Finding

A discrepancy becomes a formal investigation when the facts suggest possible deception, concealed records, unauthorized benefit, falsified support, or deliberate control circumvention. Indicators include altered invoices, conflicting dates, impossible transaction sequences, repeated “lost” records, unexplained side agreements, access to systems after termination, related-party payments not disclosed, and explanations that contradict established evidence. Such indicators do not prove wrongdoing, but they justify a more independent and formally documented process. Reports in 2026 involving police funds, public expenditure, campaign finances, towing programs, and municipal utilities illustrate that apparently small accounting differences can become governance, procurement, and public-trust issues when the responsible process is weak.

The severity of escalation depends on amount, nature, period, control override, management involvement, and legal exposure. A $500 rounding error caused by a documented system defect is not comparable to a $500,000 unreconciled account controlled by a senior official. Repetition can also change the assessment. Twenty errors of $200 may indicate a systemically weak process, while one $100,000 item may indicate a significant individual transaction. Regulators, auditors, lenders, insurers, donors, or boards may have different reporting deadlines, so managers should not assume that silence always resolves the legal issue. The entity’s auditor, tax adviser, securities counsel, insurer, or regulator may need separate notice under a contract, statute, grant condition, or accounting framework.

Organizations should also avoid retaliation and premature conclusions. A good-faith employee who reports a suspected error should be protected from inappropriate treatment, subject to applicable law and policy. At the same time, confidentiality should be maintained on a need-to-know basis, and access should be logged for sensitive evidence. Management may place an employee on administrative leave or change system permissions when there is a documented risk, but those actions should be proportionate and legally reviewed. A criminal referral, civil claim, employment action, and accounting adjustment are related but distinct outcomes. An investigation can support each, yet the organization must use the proper standard and forum for each decision.

Common Mistakes That Can Invalidate or Weaken the Review

The most common mistake is starting with a conclusion instead of a question. Statements such as “the CFO stole the money” or “it is obviously a system error” narrow the inquiry before the evidence is collected. Another common error is allowing the questioned employee to perform the reconciliation, select the documents, and approve the final adjustment. Even where no misconduct occurred, that arrangement weakens credibility. Managers may also use a vague “system issue” explanation without testing whether the system behaved as configured or whether users bypassed it. A system error remains an error, but the organization must also determine whether the error was accidental, foreseeable, ignored, or intentionally exploited.

Premature destruction, overwriting, or “cleaning up” records is especially damaging. Investigators should preserve originals, metadata where relevant, and audit logs, while working from verified copies. Converting a discrepancy into a large unsupported journal entry is another warning sign. A year-end plug may make the trial balance balance, but it does not establish the correct account, period, or economic substance. Reviews can also become too narrow by testing only a sample even though a population may be incomplete. If five omitted invoices are found, investigators should determine whether the same source or process produced additional omissions rather than extrapolating without evidence.

Documentation should distinguish observation from inference. “The invoice was dated March 31, while the purchase order was dated April 2” is an observation. “The manager backdated the approval” is an inference requiring further evidence. Similarly, a conclusion that fraud occurred should rest on a defined standard, contrary evidence considered, and a clear explanation of why benign alternatives were rejected. A final report can state that the organization could not obtain sufficient evidence rather than forcing certainty. That candor is more useful than a confident but unsupported conclusion, particularly when regulators, courts, insurers, or future auditors may review the work.

Timing, Escalation Thresholds, and Decision-Making

An initial triage can occur within 1 to 3 business days, while a focused reconciliation may take 1 to 2 weeks and a multi-system forensic review may require 6 to 12 weeks or longer. These are planning ranges, not guaranteed durations, and a regulatory or criminal matter can extend well beyond them. The first response should confirm the balance, identify potential reporting deadlines, preserve evidence, and assign owners. If the organization cannot explain a material variance through ordinary operations, it should notify the appropriate audit committee, legal counsel, or board promptly. A materiality threshold should not be based only on percentage of annual profit; public-interest, fraud, compliance, liquidity, and qualitative factors can make a smaller amount important.

One practical triage framework considers the amount as a percentage of the account and the entity’s materiality measure, then separately tests whether the item is qualitatively sensitive. A $75,000 variance might be immaterial to a large organization under its financial-statement threshold but material to a small grant program because donor restrictions apply. Likewise, $10,000 may be below an income-tax materiality threshold yet important to a procurement policy or criminal referral obligation. Escalation levels can include routine correction by the process owner, controller review, internal-audit referral, independent forensic investigation, or immediate legal and regulatory response. The organization should define who can authorize each level and what evidence triggers movement between levels.

Speed is valuable, but haste can destroy evidence or preempt legitimate review. Before contacting a vendor, employee, regulator, or law-enforcement agency, counsel should consider whether contact could alter testimony, generate retaliation, tip off a subject, or violate a contractual reporting process. External communications should be factual and narrowly tailored. Board and audit-committee materials should distinguish verified facts, open questions, estimated exposure, actions taken, and decisions required. This allows decision-makers to respond without treating every allegation as established. A staged response often works best: contain immediate operational risk, validate the ledger, complete the evidence review, assess reporting duties, remediate controls, and monitor for recurrence.

Cost, Scope, and Choosing the Right Investigation Option

The lowest-cost appropriate method is not always a full forensic audit, and the highest-cost option is not automatically justified. A limited discrepancy may be resolved with a controller-led reconciliation supported by transaction testing and management approval. Internal-audit involvement becomes appropriate when the process spans departments or the internal control environment appears weak. A forensic accountant is generally more suitable when complex reconciliations, data analysis, tracing of funds, or financial-statement impacts require specialized work. A law firm or private investigator may be needed when the matter involves suspected criminal conduct, interviews, privilege strategy, digital evidence, or litigation. These roles can overlap, but one provider should clearly lead the scope so evidence is not duplicated or contradictory.

Cost varies materially by number of entities, years, systems, data volume, locations, language, document quality, and stakeholder needs. A quote should disclose assumptions, hourly or phase-based rates where appropriate, travel and data expenses, expert use, and the number of deliverables. It is prudent to include a 15% to 30% contingency for incomplete records or expanding scope, but the consultant should explain what assumptions justify it rather than presenting the percentage as an accounting standard. Organizations should compare written proposals on credentials, relevant experience, independence, chain-of-custody procedures, communication cadence, deliverable detail, and ability to explain calculations, not merely on the lowest total price. Saving $5,000 by using an unqualified reviewer can be expensive if the result cannot withstand audit, regulatory, or court scrutiny.

The engagement letter should also state who pays disputed invoices, who owns the work product, who may receive it, and whether communications with management are privileged under applicable law. A final report should include the objective, period, criteria, scope, limitations, evidence relied upon, findings, calculation of the discrepancy, root causes, recommended actions, and management responses. Any unresolved uncertainty should remain visible. For a definitive engagement, procurement may want a 10-page executive report supported by longer schedules rather than assuming that a short report proves the work was complete.

Turning the Findings Into Corrective Action and Assurance

An investigation is not complete merely because a report was delivered. Management should accept, reject, or modify each recommendation through a documented process, and the board or audit committee should oversee higher-risk actions. Corrective actions commonly include enforcing segregation of duties, restricting system privileges, validating vendor master changes, adding independent receipt evidence, improving bank reconciliation, automating journal-entry review, strengthening grant expenditure testing, and training staff. The control owner should not be the sole person who tests the control, because self-testing can reproduce the original independence problem. Evidence of operation might include an approved workflow, an exception report showing 100% review, a sample tested by an independent function, and a log of corrective follow-up.

Some issues require more than improved controls. A policy should define who can investigate, who can authorize access to evidence, when external counsel is engaged, and how findings are communicated to those charged with governance. The organization should establish deadlines for closing an item, such as 30 days for routine actions and 90 days for system changes, while recognizing that complex technology projects may take longer. Aging overdue actions should be reported, not quietly rolled forward. A repeated exception over 12 months may demonstrate that the first correction failed and should trigger reassessment of the control design and ownership.

Finally, the organization should determine whether audited or previously issued financial information needs correction or whether regulators, donors, insurers, lenders, or affected parties must be informed. That decision depends on the applicable accounting standards, audit findings, contract terms, and legal advice; it should not be made from a generic checklist. External auditors may need to evaluate the discrepancy, expand testing, revise fraud-risk assessment, or consider subsequent events. Investors or the public may need disclosure if the information is material and required by securities law. The strongest outcome combines an accurate financial correction, a credible account of what happened, a control change that addresses the cause, and transparent governance that can demonstrate both correction and prevention.