AUD exam skill

Management override: design journal entry testing that follows the risk

Respond to the presumed override risk through journal entries, estimate bias, unusual transactions, and risk-based exception follow-up.

The decision that earns the point

Identify the engagement facts and governing framework

Management override is a fraud risk in every audit because management can bypass controls that otherwise appear effective. The response includes testing journal entries and other adjustments, reviewing accounting estimates for bias, and evaluating whether significant unusual transactions have a valid business purpose. Journal entry selection must follow risk characteristics, not a convenient random sample alone.

Exam use

AUD can ask which override procedures are required, how to obtain and test a complete journal-entry population, which entries deserve selection based on preparer, account, timing, source, or description, and how one exception changes fraud risk and further work.

Check the official exam scope

Your scratch-paper plan

Solve it in three moves

  1. 1

    Treat override as a presumed fraud risk

    Design the required override response even when tested controls appear effective or no prior override has been found.

    PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
  2. 2

    Select entries from the way fraud could occur

    Understand the financial-reporting process, test population completeness, and choose entries using account, preparer, timing, source, description, and other risk characteristics.

    PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
  3. 3

    Connect exceptions to the full override response

    Inspect support, investigate authorization and business purpose, review estimates for bias, evaluate unusual transactions, and revise procedures when results indicate broader risk.

    PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit

Worked problem

Work the facts before choosing the answer

A PCAOB issuer has 94,000 annual journal entries. The auditor identifies manual entries posted after 10 p.m. in the final three days, entries prepared and approved by the same senior employee, and postings to revenue against a miscellaneous receivable with vague descriptions.

CPAPass exam analysis using the stated assumptions

Show the work

The auditor validates the complete entry population, selects the overlapping high-risk entries rather than relying only on random selection, inspects contracts and shipping evidence, verifies authorization, interviews appropriate personnel, and searches for similar entries and reversals after year-end.

Rule source: PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit

Answer

An unsupported late revenue entry is evaluated as a possible fraud indicator, not an isolated clerical error. The auditor expands testing, reassesses risks and management integrity, examines estimate bias and unusual transactions, and communicates as required.

Rule source: PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit

Do it now

Test the same decision with a fresh question

Start with free AUD practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.

The trap and the repair

Common trap

Choosing a random sample of ordinary entries and calling journal entry testing complete ignores the risk-based selection required for a presumed override risk.

Repair

Start with how management could manipulate the close, prove the population complete, and build selections around the resulting risk characteristics.

Authority and scope boundary

PCAOB AS 2401 controls the issuer illustration and its required override response. Current AU-C 240 is the separate nonissuer fraud standard. This route owns override-specific work, while the broad audit-procedures and internal-controls pages retain their umbrella topics.

2026 Uniform CPA Examination Blueprints and PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.

Override-risk filter

Risk characteristics should explain why each entry was selected

A defensible journal entry test traces the fraud hypothesis through population completeness, selection, support, and expanded response.

Selection signalWhy it mattersFollow-up evidenceAuthority
TimingLate, weekend, post-close, or rarely used posting windows can indicate an attempt to bypass normal reviewSystem timestamp, close calendar, approval log, reversal searchPCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
Preparer and approverSenior access, unusual users, or self-approval can concentrate override capabilityUser-access listing, workflow history, authorization, interview evidencePCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
Account combinationUnusual revenue, reserve, suspense, or intercompany combinations can conceal the intended effectAccount detail, contracts, subledger support, related entriesPCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
Narrative and sourceBlank descriptions, round numbers, nonstandard sources, or rapid reversals can signal unsupported adjustmentsSource documents, business-purpose evidence, subsequent reversal and cash activityPCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit

After a miss

Repair an override-response miss

  1. 1

    Write the fraud hypothesis, complete entry population, and three selection characteristics before naming a sample size.

  2. 2

    Rework the illustration after learning that the entries were automatically generated and separately approved, then identify which risks remain.

  3. 3

    Answer a fresh override question and state the required procedure, selected population, exception follow-up, and risk reassessment.

Your exam workflow

  1. Step 1Identify the requirementDesign the required override response even when tested controls appear effective or no prior override has been found.PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
  2. Step 2Classify the factsUnderstand the financial-reporting process, test population completeness, and choose entries using account, preparer, timing, source, description, and other risk characteristics.PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
  3. Step 3Apply the authorityInspect support, investigate authorization and business purpose, review estimates for bias, evaluate unusual transactions, and revise procedures when results indicate broader risk.PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit
  4. Step 4Check the outputAn unsupported late revenue entry is evaluated as a possible fraud indicator, not an isolated clerical error. The auditor expands testing, reassesses risks and management integrity, examines estimate bias and unusual transactions, and communicates as required.PCAOB AS 2401: Consideration of Fraud in a Financial Statement Audit

Quick questions

What is the key rule?

Management override is a fraud risk in every audit because management can bypass controls that otherwise appear effective. The response includes testing journal entries and other adjustments, reviewing accounting estimates for bias, and evaluating whether significant unusual transactions have a valid business purpose. Journal entry selection must follow risk characteristics, not a convenient random sample alone.

How can this topic be tested on the CPA Exam?

AUD can ask which override procedures are required, how to obtain and test a complete journal-entry population, which entries deserve selection based on preparer, account, timing, source, or description, and how one exception changes fraud risk and further work.

What mistake most often changes the result?

Choosing a random sample of ordinary entries and calling journal entry testing complete ignores the risk-based selection required for a presumed override risk. Start with how management could manipulate the close, prove the population complete, and build selections around the resulting risk characteristics.

Where should I practice the decision?

After the worked example, open the AUD free-practice link and work a fresh question that tests the same decision. If the miss depends on Audit procedure selection, review that handoff before trying another set.

Sources behind the rule