risk
Manual journal entries and management-override risk
Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- financial_reporting
- domain
- Financial Reporting Controls (SOX)
- Logging, Monitoring & Detection
- taxonomy
- sox-rmm-assertion
- inherent_rating
- high
Details
- risk_id
- fin-journal-entry-management-override
- category
- financial_reporting
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- sox-rmm-assertion
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-20 — Ensure complete, accurate, and authorized data processing mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- Input edit checks catch journal-entry transposition and format errors before posting.
- UC-FIN-04 — Authorize transactions with attributable approvals mitigates Manual journal entries and management-override risk
- strength
- primary
- rationale
- Journal entries require authorized approval bound to the individual, controlling top-side override entries.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Manual journal entries and management-override risk
- strength
- primary
- rationale
- Restricting privileged access to the GL/ERP directly limits unauthorized journal entries and top-side management override.
- UC-FIN-06 — Validate completeness and accuracy of system inputs mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- Input edit checks catch journal-entry transposition and wrong-account errors.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- Monitoring privileged/admin sessions detects management override executed via back-channel privileged access that bypasses application-level journal-entry controls.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- SoD separating request from approve limits any one person posting and approving unauthorized journal entries.