25 TERMS

Audit, Controls & Evidence glossary

Auditors don't take a number's word for it. They ask where it came from, who checked it and whether they can get the same answer themselves. The terms below are the vocabulary of that conversation: the controls a company runs, the evidence it keeps and the tests an auditor performs. If your close uses automation or AI, these terms matter more, not less, because each automated step becomes something an auditor needs to understand and, ideally, reperform. For a practical starting point, read the 9 questions your auditor will ask about AI reconciliations (/blog/ai-reconciliation-audit-questions).

Audit trail

Definition. A chronological record of who did what, when and with what data, detailed enough to reconstruct how a number was produced.

In practice. For a journal entry: preparer, timestamp, source documents, approver and every edit. For AI-prepared work, add the inputs, the rules or instructions used, and the version of the output.

What a reviewer checks. No gaps, and no way to change a record after the fact without leaving a trace.

The Yoraito angle. The query behind each number is part of the trail, not a separate document. See our 16-field checklist: /blog/ai-audit-trail-checklist.

PBC list

Also called: prepared-by-client list · request list

Definition. The auditor's list of schedules, reconciliations and documents the company must provide, each with a due date.

In practice. A year-end PBC list often runs to 100+ items: bank confirmations, reconciliations, rollforwards, contracts, board minutes.

What a reviewer checks. Each schedule ties to the trial balance, and the version sent is the final one.

Audit evidence

Definition. The information auditors use to reach their conclusions: documents, records, confirmations, recalculations and observations. For PCAOB audits, AS 1105 sets the requirements.

In practice. A bank confirmation received directly from the bank is stronger evidence than a bank statement provided by the company.

What a reviewer checks. Relevance and reliability. For reports the company produces, that means evidence of completeness and accuracy too.

ICFR

Also called: internal control over financial reporting

Definition. The processes that give reasonable assurance that financial statements are reliable and prepared in line with GAAP.

In practice. Required for US public companies under SOX. Many PE-backed companies build ICFR a year or two before an IPO or sale.

What a reviewer checks. Whether each key control is designed well and operates as described.

SOX 404

Definition. Section 404 of the Sarbanes-Oxley Act. 404(a) requires management to assess and report on ICFR each year. 404(b) requires the external auditor to attest to ICFR for accelerated and large accelerated filers.

In practice. Pre-IPO companies usually start SOX readiness well ahead of listing: documenting processes, identifying key controls and testing them.

What a reviewer checks. Control documentation, testing evidence and how deficiencies were evaluated.

Key control

Definition. A control that addresses a risk of material misstatement and is relied on, and tested, for SOX or audit purposes.

In practice. "The controller reviews and signs each bank reconciliation within 10 business days of month-end and investigates any reconciling item over $5,000."

What a reviewer checks. The description says who, what, when, how precisely, and what evidence is kept.

Segregation of duties

Also called: SoD

Definition. Splitting incompatible duties (authorizing, recording, holding assets and reconciling) between different people, so one person can't make an error or fraud and also hide it.

In practice. The person who sets up new vendors doesn't approve payments. Small teams use detailed review as a compensating control.

What a reviewer checks. System access matches the SoD matrix. An AI tool with write access counts as a user in that matrix.

Preparer and reviewer

Also called: maker-checker

Definition. A two-step sign-off where one person prepares the work and a second, independent person reviews and approves it.

In practice. When AI prepares a reconciliation, a named person remains the reviewer of record.

What a reviewer checks. Different people, a review date on or after the prep date, and review evidence such as notes or tick marks, not just a signature.

Management review control

Also called: MRC

Definition. A control where management reviews information, such as a flux analysis or budget-to-actual report, to catch misstatements.

In practice. The CFO reviews monthly flux above $25,000 and documents follow-up on each item.

What a reviewer checks. Precision: what threshold triggers follow-up, what was investigated, and whether the data reviewed was complete and accurate.

Journal entry testing

Also called: JE testing

Definition. Audit procedures that select and examine journal entries for signs of error or management override. For PCAOB audits, AS 2401 (the fraud standard) requires it.

In practice. Common selection criteria: entries posted after period-end, at weekends or by unusual users, round amounts, rarely used accounts and vague descriptions. Try our free skill: /claude-skills/journal-entry-testing.

What a reviewer checks. The full JE population was used, and each selected entry was traced to support.

Audit sampling

Definition. Testing less than 100% of a population to reach a conclusion about the whole, using a statistical or non-statistical method.

In practice. Testing 25 of 1,200 vendor invoices for three-way match. Data tools now let teams test entire populations for some checks.

What a reviewer checks. The population is complete, selection is unbiased, and exceptions are evaluated against the whole population.

Walkthrough

Definition. Following one transaction from start to financial statements through the real documents and systems, to confirm the process and its controls work as described.

In practice. An auditor follows one customer order from contract to invoice to cash receipt to revenue.

What a reviewer checks. That the documented process matches what actually happens.

Control deficiency

Definition. A control that is missing, badly designed or not operating, so misstatements may not be prevented or caught in time.

In practice. Severity runs from deficiency, to significant deficiency, to material weakness.

What a reviewer checks. How likely and how large the possible misstatement is.

Material weakness

Definition. A deficiency, or combination of deficiencies, in ICFR such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.

In practice. Public companies must disclose material weaknesses. Common causes include too few qualified accounting staff, weak review controls and failed IT general controls.

What a reviewer checks. The root cause and whether remediation has been tested over enough time.

Leadsheet

Definition. An audit working paper that summarizes an account or group of accounts, with current and prior balances and adjustments, linking to the supporting detail.

In practice. A cash leadsheet lists each bank account's balance, its reconciliation and its confirmation.

What a reviewer checks. The leadsheet totals tie to the trial balance.

Rollforward

Definition. A schedule that moves a balance from opening to closing: opening + additions − reductions ± adjustments = closing.

In practice. Used for fixed assets, prepaids, deferred revenue, reserves and equity. Try the free prepaid rollforward skill: /claude-skills/prepaid-rollforward.

What a reviewer checks. The opening balance equals last period's closing, and the closing balance equals the GL.

Substantive procedures

Definition. Audit tests that look directly for misstatements in balances and transactions, through tests of detail and substantive analytics.

In practice. Vouching a sample of revenue invoices to shipping documents and cash receipts.

What a reviewer checks. That the tests address the specific risks identified for each account.

IPE

Also called: information produced by the entity

Definition. Any report or data set the company generates that auditors use as evidence, such as an aging report, a system query or a spreadsheet.

In practice. For an AR aging pulled from the ERP, auditors ask for the report parameters, the logic behind it and a tie to the GL.

What a reviewer checks. Evidence that the report is complete and accurate.

The Yoraito angle. When every figure comes with the SQL that produced it, the report logic is visible, which is the part IPE testing usually has to rebuild by hand.

Reperformance

Definition. The auditor independently carries out a control or calculation to see whether they get the same result.

In practice. Recalculating depreciation, or rerunning a reconciliation from source data.

What a reviewer checks. The result matches the company's result exactly.

The Yoraito angle. A saved query is reperformance-ready: run it against the same data and the result must match.

Completeness and accuracy

Also called: C&A

Definition. Two tests applied to data used as evidence: everything that should be there is there (completeness), and the values are right (accuracy).

In practice. Row counts and control totals checked from the source system to the final report.

What a reviewer checks. The C&A evidence covers the exact report version used.

SOC 1 report

Definition. An independent auditor's report, under AICPA attestation standard SSAE 18, on a service organization's controls that matter to its customers' financial reporting.

In practice. Type 1 covers design at a point in time. Type 2 covers design and operating effectiveness over a period, usually 6 to 12 months. Common for payroll providers and fund administrators.

What a reviewer checks. The complementary user entity controls (CUECs) the customer itself must run.

SOC 2 report

Definition. An independent report on a service organization's controls relevant to the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.

In practice. Type 1 and Type 2 work as with SOC 1. Many finance teams ask for a SOC 2 Type 2 before connecting a vendor to financial data.

What a reviewer checks. The period covered, any exceptions noted and the scope of systems included.

COSO framework

Also called: COSO Internal Control–Integrated Framework

Definition. The internal control framework from the Committee of Sponsoring Organizations of the Treadway Commission, built on five components: control environment, risk assessment, control activities, information and communication, and monitoring.

In practice. Most US companies use the 2013 framework for SOX. In 2026 COSO published guidance applying it to generative AI. Read: /blog/coso-generative-ai-controls-month-end-close.

What a reviewer checks. That each relevant principle is present and functioning.

ITGC

Also called: IT general controls

Definition. Controls over the systems financial data runs through: access, change management and IT operations.

In practice. Weak ITGCs undermine any reliance on automated controls or system reports. For AI tools, "who can change the prompts, rules or model" is a change-management question.

What a reviewer checks. User access reviews, approved changes and job monitoring.

Audit adjustment

Definition. A correction to the financial statements proposed by the auditor. Booked adjustments are recorded; passed adjustments are left unrecorded as immaterial and listed in the summary of unadjusted differences.

In practice. The number and size of audit adjustments is a direct signal of close quality.

What a reviewer checks. Whether the same adjustments recur year after year.

Want these terms applied to your close?

Book a 30-min call