Auditing with Bank Statements: Procedures, Tests and Workpapers
How auditors and reviewers use bank statements: confirmations, reconciliation testing, cut-off, proof of cash, unusual items and efficient data extraction.
Short answer
Bank statements are core audit evidence for cash, and they also support testing of revenue, expenses and completeness of liabilities. Typical procedures include obtaining bank confirmations, re-performing year-end bank reconciliations, checking that reconciling items cleared after year-end, testing cut-off, performing a proof of cash, and scanning for unusual transactions such as round sums, related parties and transfers near period end.
Key takeaways
- Cash is usually tested with external evidence: bank confirmations and statements obtained directly where possible.
- Re-perform the client's year-end reconciliation and vouch reconciling items to subsequent statements.
- A proof of cash ties receipts and payments in the ledger to the bank for a whole period, not just the closing balance.
- Extracting statements to a spreadsheet makes full-population scans for unusual transactions practical.
Cash looks like the simplest balance on a balance sheet. There is one number per account and the bank has an independent record of it. Yet cash is where many frauds and errors surface: unrecorded accounts, money moved between entities at year-end, payments to fictitious suppliers and receipts that never arrived. Bank statements are therefore some of the most important evidence an auditor, reviewer or internal auditor uses, not only for cash but as a way into revenue, expenses and liabilities.
This guide describes common audit and review procedures that rely on bank statements, explains why each one matters, gives worked examples, and shows how converting statements into structured data allows more thorough testing in less time. Auditing standards differ between jurisdictions and engagement types, and firms have their own methodologies, so use this as practical context alongside the standards and methodology that apply to your engagement.
Why bank statements are strong evidence
Audit evidence is generally more reliable when it comes from an independent external source, when it is obtained directly by the auditor, and when it exists in documentary form. Bank records meet the first and third conditions naturally. The second depends on how they are obtained:
| Source | Reliability | Comments |
|---|---|---|
| Bank confirmation sent and received directly by the auditor | Highest | Standards such as ISA 505 and PCAOB AS 2310 cover confirmation procedures |
| Statements downloaded by the auditor from online banking with client present | High | Auditor controls the retrieval |
| Original PDF statements provided by client | Moderate | Could be altered; check integrity |
| Photocopies or scans provided by client | Lower | Harder to detect alteration |
| Client's ledger or reconciliation | Internal evidence | Must be corroborated |
Where statements come via the client, apply integrity checks: balances should roll forward, running balances should add up and file properties should be consistent. Our guide to spotting a fake bank statement lists the checks.
Procedure 1: Bank confirmations
A bank confirmation asks the bank to confirm directly to the auditor, as at the period end:
- Account balances for all accounts in the entity's name, including ones the client did not list.
- Loans, overdrafts and facilities, with interest rates and security.
- Guarantees, letters of credit and other contingent liabilities.
- Authorised signatories, in some formats.
Confirmations address existence and rights over cash, and help with completeness of borrowings. Practical points:
- Send requests early. Banks can take weeks to respond.
- Control the process. The auditor, not the client, should send and receive the confirmation, often through an electronic confirmation platform where the bank supports one.
- Ask about all accounts, not just those on the client's list. An unexpected account in a confirmation response is a significant finding.
- Follow up non-responses and consider alternative procedures, such as reviewing statements obtained directly.
Procedure 2: Re-perform the year-end bank reconciliation
The client's reconciliation explains the difference between the bank statement balance and the general ledger cash balance at year-end. A typical reconciliation:
| Item | Amount |
|---|---|
| Balance per bank statement at 31 December | 184,320.55 |
| Add: deposits in transit | 12,480.00 |
| Less: outstanding cheques and payments | (21,905.30) |
| Adjusted bank balance | 174,895.25 |
| Balance per general ledger | 174,895.25 |
| Difference | 0.00 |
Audit steps:
- Agree the bank balance to the confirmation and to the statement.
- Agree the ledger balance to the trial balance.
- Check the arithmetic and the list of reconciling items.
- Vouch deposits in transit to the next period's statement. They should clear within a few business days. A deposit in transit that clears weeks later, or never, is a red flag for teeming and lading or fictitious receipts.
- Vouch outstanding payments to subsequent clearance and to supporting documents. Cheques written before year-end but held back can inflate year-end cash; very old outstanding cheques may need to be written back or treated as unclaimed property where rules require.
- Investigate unusual reconciling items, such as unexplained adjustments, round sums or items labelled "difference to be investigated".
Our article on how to reconcile a bank statement explains reconciliation mechanics in more detail, and the deposit in transit and outstanding check glossary entries define the terms.
Worked example: a late-clearing deposit
The December reconciliation above includes a deposit in transit of 12,480 dated 31 December. The January statement shows a deposit of 12,480 on 19 January. Nineteen days is far longer than normal clearing. Enquiry reveals the cheque was received from a customer on 18 January and backdated in the cash book to reduce the receivables ageing at year-end. The result: cash is overstated and receivables understated at year-end by 12,480, and there is a control weakness over cash receipts.
Procedure 3: Cut-off testing
Cut-off tests check that transactions are recorded in the correct period. With bank statements:
- Receipts: compare deposits in the last few days of the year and the first few days of the next with the cash book and sales records. Receipts recorded in the old year but deposited in the new year deserve scrutiny.
- Payments: compare cleared payments in the first weeks of the new year with the ledger. Payments for goods or services received before year-end should usually be accrued as liabilities. This also supports the search for unrecorded liabilities.
- Inter-account transfers: transfers between the entity's own accounts, or between group entities, around year-end should be recorded on both sides in the same period. If the sending account records it in December and the receiving account in January, cash is double-counted. This is sometimes called kiting when deliberate.
Worked example: transfer timing
On 30 December the entity transfers 50,000 from Account A to Account B. Account A's ledger records the payment on 30 December. Account B's ledger records the receipt on 2 January, when it appeared on that statement. At year-end, Account A is reduced by 50,000 but Account B does not yet show the receipt in the ledger. Total cash in the ledger is understated by 50,000, unless the receipt is shown as cash in transit. In the reverse case, with the receipt recorded early and payment late, cash would be overstated. A schedule of all inter-account transfers around year-end, taken from bank statements for every account, catches both cases.
Procedure 4: Proof of cash
A year-end reconciliation proves the balance at one date. A proof of cash, sometimes called a four-column reconciliation, proves receipts and payments for a whole period:
| Opening balance | Receipts | Payments | Closing balance | |
|---|---|---|---|---|
| Per bank statement | 120,000 | 1,480,000 | 1,415,680 | 184,320 |
| Deposits in transit: opening | 8,000 | (8,000) | ||
| Deposits in transit: closing | 12,480 | 12,480 | ||
| Outstanding payments: opening | (15,000) | (15,000) | ||
| Outstanding payments: closing | 21,905 | (21,905) | ||
| Per ledger | 113,000 | 1,484,480 | 1,422,585 | 174,895 |
Columns and rows should both add up. The proof shows that total receipts and payments in the ledger agree with the bank, after timing differences. It detects problems that a single-date reconciliation misses: for example, receipts recorded in the ledger but never banked, offset by an equal fictitious payment.
Building a proof of cash needs period totals of bank receipts and payments, which are easy to get when statements are converted into a spreadsheet and summed, and tedious when added up from paper.
Procedure 5: Scanning for unusual transactions
With statements in a structured format, you can examine the full population rather than a sample. Useful filters:
- Large transactions above a threshold.
- Round-sum amounts, such as exact thousands.
- Payments to individuals rather than companies, especially if not on payroll.
- Related parties: directors, shareholders, family members and connected companies.
- Unusual timing: weekends, holidays, just before or after year-end.
- Duplicate payments: same payee, same amount, close dates.
- Payees not in the supplier master file.
- Cash withdrawals and cash deposits.
- Reversals and returned payments.
Each flagged item should be investigated: vouched to supporting documents, discussed with management and assessed for misstatement or fraud risk. Journal entry testing often benefits from the same data, since manual entries to cash can be compared with bank movements.
Procedure 6: Using bank data to test revenue and expenses
Bank statements are also evidence for other areas:
- Revenue: compare total customer receipts in the bank with recorded revenue adjusted for movements in receivables. Large unexplained differences suggest overstated or understated revenue.
- Expenses: payments to major suppliers can be matched to invoices and ledger entries, including testing that payments go to the bank details on file.
- Payroll: net pay transfers can be compared with payroll reports for the same period.
- Loans and interest: loan receipts and repayments, and interest charges, can be agreed to loan agreements and the ledger.
For small entities, especially in review or compilation engagements, an analytical comparison of bank flows with the financial statements can be particularly effective. Our bank statement analysis guide explains how to classify flows.
Extracting bank statements for audit work
Many clients provide statements as PDFs, sometimes hundreds of pages for a year across several accounts. Typing them is not realistic, and sampling a few pages misses the benefits of full-population testing.
A bank statement converter extracts all transactions into Excel. For audit use, the important features are:
- Balance checks, so you know the extracted data is complete. StatementPilot verifies that opening balance plus transactions equals closing balance for every statement and highlights any that do not reconcile.
- Handling of scanned statements through OCR.
- Reviewable output that can be compared with the source page.
- Data protection: audit files contain confidential data; check security and retention settings.
Keep the source PDF and the extracted file together in the workpapers, with a note of the tool used and the completeness check performed. Our audit preparation use case describes a typical workflow.
Fraud schemes that bank statement procedures expose
Understanding common schemes helps decide which filters and tests to run.
- Lapping (teeming and lading). An employee steals a customer's receipt and covers it with a later customer's payment. Signs: deposits in transit that take unusually long to clear, receipts applied to the wrong customers, and growing unexplained differences in receivables.
- Fictitious suppliers. Payments go to a bank account controlled by an employee. Signs: supplier bank details that match an employee's, suppliers with no address or tax number, round-sum invoices and payments just under approval limits.
- Altered payees or amounts. A legitimate payment is redirected or inflated. Signs: payee names on the bank statement that differ from the ledger, and payments larger than approved invoices.
- Payroll fraud. Ghost employees or inflated pay. Signs: more net pay transfers than employees on the payroll report, or transfers to accounts shared by several employees.
- Kiting. Exploiting the timing of transfers between banks to inflate balances. Signs: frequent, round transfers between accounts near period end, recorded inconsistently.
- Personal expenses through the business. Signs: payments to retailers, travel and entertainment with no business pattern, especially around holidays.
Many of these leave patterns visible only when you look at the whole year, across all accounts, which is why full extraction is so valuable.
Considerations for small entities and nonprofits
Smaller organisations often have limited segregation of duties: one person may receive money, bank it, record it and reconcile the account. That increases the importance of bank-based procedures:
- Obtain statements directly where possible rather than from the person who keeps the books.
- Perform a proof of cash for the whole year, not just a year-end reconciliation.
- For charities and clubs, compare donations, grants and membership income in the bank with records of what was expected.
- Review payments to trustees, committee members and their families.
- Check that restricted funds received through the bank have been recorded and used as required.
These steps are affordable even on small engagements once statements are converted to data.
Documenting the work
Good workpapers for cash usually include:
- A lead schedule of all bank accounts with balances per ledger, statement and confirmation.
- The confirmation requests and responses.
- The re-performed reconciliation with vouching evidence for reconciling items.
- Cut-off and inter-account transfer schedules.
- A proof of cash where performed.
- The unusual transactions analysis with filters used, items selected and conclusions.
- A conclusion on whether cash is fairly stated.
Each schedule should show its source and who prepared and reviewed it.
Internal audit and management reviews
Not every review is a statutory audit. Internal auditors, finance managers and owners can apply the same techniques:
- Monthly review of all bank reconciliations, with ageing of reconciling items.
- Quarterly scans for duplicate payments and payments to new payees.
- Annual confirmation that all bank accounts are known and authorised signatories are current.
- Segregation checks: the person who reconciles the bank should not also make payments.
These controls catch errors early and deter fraud. They are also exactly what external auditors hope to find when they assess controls.
Common pitfalls
- Relying on client-provided statements without integrity checks.
- Not confirming all accounts, including closed accounts and those with zero balances.
- Vouching reconciling items to the client's records rather than the bank.
- Ignoring old outstanding items that are carried forward year after year.
- Missing inter-account transfers because only the main account was reviewed.
- Testing only the year-end balance and missing problems in flows during the year.
- Poor documentation of how extracted data was checked for completeness.
Frequently asked questions
What do auditors look for in bank statements?
Auditors check that balances agree with the ledger and bank confirmations, that reconciling items are genuine and clear promptly, that transactions are recorded in the right period, and that there are no unusual or unauthorised transactions. They also use bank data to corroborate revenue, expenses and liabilities.
What is a proof of cash?
A proof of cash reconciles opening balance, receipts, payments and closing balance between the bank and the ledger for a whole period. It detects discrepancies in flows that a single year-end reconciliation can miss.
What is the difference between a bank reconciliation and a proof of cash?
A bank reconciliation explains the difference between the bank and ledger balances at one date. A proof of cash also reconciles the receipts and payments for the whole period between two dates, so it can reveal offsetting errors in the flows that a balance-only reconciliation would not show.
Why do auditors send bank confirmations?
Confirmations provide evidence directly from the bank, independent of the client. They confirm balances and can reveal accounts, loans, guarantees or other arrangements that the client did not disclose.
How long after year-end should deposits in transit clear?
Normally within a few business days. Deposits that take much longer to appear on the bank statement need investigation, as they may indicate receipts recorded in the wrong period or misappropriation concealed by later receipts.
Can auditors use converted bank statement data?
Yes, provided the auditor is satisfied the data is complete and accurate. Checking that extracted transactions reproduce the opening and closing balances of every statement, and spot-checking against the PDF, provides that comfort. Document the tool and checks in the workpapers.
Summary
Bank statements give auditors external evidence for cash and a powerful lens on the rest of the financial statements. The core procedures are confirmations, reconciliation re-performance, cut-off and transfer testing, proof of cash and full-population scans for unusual items. Converting statements into reconciled spreadsheet data turns hours of reading into minutes of filtering.
Create a free StatementPilot account to extract client statements with automatic balance checks, ready for your audit workpapers.