Most reconciliation failures are not caused by a missing spreadsheet. They occur because the organisation has not defined what a completed reconciliation must prove. A balance can tie while the source is unreliable, the difference is unexplained, the reviewer has not challenged the work, or an old item has been carried forward without an accountable owner.
This guide sets a minimum control standard for balance-sheet and other general-ledger reconciliations. It is written for the controller or programme owner who must decide roles, evidence, materiality, ageing, escalation and sign-off. It does not replace the close calendar, prescribe accounting treatment or provide a bank-reconciliation tutorial.
Quick answer
A tied balance is not defensible unless reliable sources, explained differences, independent review and controlled open items support the sign-off.
Decision: Set the minimum ownership, evidence, materiality, ageing, exception and sign-off rules for the reconciliation programme.
Key takeaways
- A reconciliation needs six proofs: the right account population, reliable source data, a mathematical tie, supported reconciling items, independent review and a controlled closure state.
- Materiality, matching tolerance and reconciliation frequency are separate policy decisions; combining them hides risk.
- Every unresolved item needs a reason code, accountable owner, due date, age, resolution plan and escalation route.
- Review is a documented challenge process, not a signature added after preparation.
- Ageing and approval thresholds must be set for the organisation; another entity’s numbers are evidence of policy design, not universal benchmarks.
What an account reconciliation control must prove
An account reconciliation control compares a general-ledger balance with an independent or separately maintained source, explains the differences and records what must happen next. The control is stronger than the calculation itself. It also establishes who performed the work, what information was used, how exceptions were treated and why the reviewer accepted the result. The Revolut customer-migration control brief applies that standard to a bank cutover, where old and new statements, identifiers and in-flight transactions must bridge.
The 2025 GAO Green Book provides the broad control logic. It says control activities should be implemented through documented policies and procedures, with responsibilities, timing and corrective actions defined. It also describes quality information as appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate and timely. Those characteristics translate directly into a reconciliation evidence test.
The framework below synthesises general internal-control principles with public operating policies from several institutions. Their exact frequencies, approval levels and monetary thresholds apply to those organisations only. They are used here to show how a controller can turn principles into a local standard.
Coles’ FY26 provision roll-forward shows the same evidence test in practice: the opening balance, current-period addition, tax effect, profit bridge and later settlement records must remain traceable to separate sources.
| Proof | Minimum requirement | Evidence retained |
|---|---|---|
| Population proof | The account is in the controlled reconciliation register with an owner, risk tier, frequency and due date. | Account register entry, scope changes and approval of exclusions. |
| Source proof | The ledger and comparison source cover the same entity, account, currency and period, and the source is reliable enough for the control. | Report name, system, parameters, extract time, period and source owner. |
| Balance proof | The ledger balance, source balance and reconciling items mathematically bridge without an unexplained plug. | Reconciliation calculation, formula checks and source totals. |
| Item proof | Every reconciling item is identified, dated, classified, supported and assigned for resolution. | Item log, supporting documents, owner, due date and proposed treatment. |
| Review proof | An appropriately independent reviewer challenges the source, calculation, items, ageing and conclusion. | Reviewer identity, review date, challenge notes, rework and final disposition. |
| Closure proof | Adjustments are posted and referenced, or open items meet an approved controlled-open-item rule. | Journal references, resolution evidence, approved exception status and escalation record. |
The minimum reconciliation-control standard
A programme standard should state the rule, the evidence and the failure response for each control element. The Department of Veterans Affairs’ reconciliation policy is a useful operating example: it requires reconciliations to be timely, documented, reviewed, approved and retained, separates preparation from review, and requires workpapers detailed enough for an independent third party to understand the process, corrective actions and annotations.
| Control element | Minimum policy requirement | Failure response |
|---|---|---|
| Account population | Maintain a complete register of accounts, owners, risk tiers, methods, frequencies, preparers, reviewers and due dates. | Unassigned or excluded accounts are reported to the programme owner before the period starts. |
| Preparation | The preparer obtains approved sources, performs the tie, records all items and states a conclusion. | Missing sources, unexplained differences or incomplete item fields make the reconciliation incomplete. |
| Review | The reviewer is different from the preparer, has sufficient account knowledge and records challenge and disposition. | The reviewer rejects the reconciliation or invokes an approved compensating control where separation is impractical. |
| Evidence | Evidence is period-aligned, complete, accurate, verifiable, retained and sufficient for an independent person to understand the work. | Unsupported balances or items cannot be certified. |
| Materiality and tolerance | Define account risk, investigation thresholds, posting thresholds and matching tolerances separately. | Items outside policy are escalated; tolerances never authorise an unexplained write-off or plug. |
| Ageing | Age begins from a defined origin date and cannot be reset by rolling the item forward. | Overdue items enter an escalation band with a resolution plan and senior review where required. |
| Exceptions | Each exception has a type, cause, amount, period, owner, due date, status and evidence of resolution. | Material, recurring, unsupported, suspicious or reporting-blocking exceptions escalate immediately. |
| Sign-off | Use explicit completion states: complete, complete with controlled open items, or rejected/incomplete. | A signature cannot override a failed completion criterion. |
| Monitoring | The programme owner monitors completion, rejections, overdue items, recurring causes and unresolved exposure by risk tier. | Control design, training, source data or upstream processes are corrected when patterns repeat. |
Assign ownership beyond the preparer and reviewer
A two-name workflow is often too narrow. The person who prepares the reconciliation may not control the source system, approve the journal or fix the process that created the break. A defensible programme separates four accountabilities.
Programme owner
The controller or reconciliation programme owner sets the account population, risk model, policy fields, calendar, ageing bands, escalation routes, reviewer requirements and monitoring measures. This role also approves policy exceptions and decides when a recurring item has become a control-design problem rather than a routine reconciling item.
Account owner
The account owner is accountable for the economic substance of the balance and for the completeness of upstream records. The owner confirms that the account belongs in the stated business process, that the source is appropriate and that corrective actions are carried out by the right process or system team.
Preparer
The preparer performs the reconciliation, preserves the source parameters, explains differences, identifies unusual activity, assigns proposed exception owners and states whether the reconciliation meets the completion criteria. Preparation should not end with “difference below threshold”; the file must still show what the difference is and why the policy allows its treatment.
Reviewer
The reviewer independently assesses the source, calculation, reconciling items, ageing, proposed entries and conclusion. Yale’s reconciliation and certification procedure requires different people to prepare and approve, and expects approvers to have account knowledge. It also frames certification around completeness, accuracy, appropriate controls, unusual-activity reporting and adequate support.
Exception owner
The exception owner is the person who can remove the cause of the difference. That may be a business-process owner, system owner, treasury team, billing team, shared-service centre or another accounting group. The preparer may coordinate the case, but ownership should sit with the person who has authority to correct it.
| Activity | Primary owner | Required handoff | Evidence of acceptance |
|---|---|---|---|
| Set account scope and risk tier | Programme owner | Account owner confirms purpose and source | Approved register entry |
| Prepare reconciliation | Preparer | Reviewer receives complete evidence packet | Submission timestamp and preparer conclusion |
| Challenge and approve or reject | Reviewer | Rework returns to preparer; accepted exceptions go to named owners | Review notes and disposition |
| Resolve reconciling item | Exception owner | Preparer validates the correction; account owner accepts process action | Journal, corrected source or other resolution evidence |
| Escalate overdue or significant item | Programme owner | Senior finance, process owner or specialist receives the case | Escalation decision and revised plan |
When full separation is impractical
Small teams may not be able to separate every incompatible duty. The answer is not silent self-approval. The GAO Green Book says management should design alternative control activities where segregation is impractical. Examples include a higher-level review, independent review of source extracts and journals, periodic controller re-performance, or rotation of review responsibilities. The compensating control, its frequency and its evidence should be written into the policy.
Define evidence sufficiency before the close starts
Evidence is sufficient when a competent person who did not prepare the file can understand the balance, reproduce the tie, inspect each material or unusual item, see the actions taken and reach a conclusion without relying on oral explanation. This is a programme rule, not a document-count test. Treasury Wine’s inventory and impairment case illustrates why a material adjustment needs separate source, item, review and closure evidence by asset class.
The broader month-end close control framework should identify where this evidence packet enters the critical path and how unresolved items affect the close state.
The evidence sufficiency test
- Identity: the file states the entity, account, currency, period, ledger balance, source balance and reconciliation method.
- Provenance: the source system, report, parameters, extraction date and owner are visible. A spreadsheet derived from another report preserves the original report and transformation logic.
- Completeness: report totals, record counts or control totals show that the selected population is complete for the stated scope.
- Accuracy: formulas are checkable, the ledger balance agrees to the ledger, and the comparison balance agrees to its source.
- Item support: every difference has an amount, origin date, description, cause, expected treatment, owner, due date and supporting document.
- Action traceability: adjustments show journal identifiers and approval; non-journal resolutions show the corrected source, settlement or other outcome.
- Review traceability: the reviewer’s questions, rework, overrides and final decision are retained.
Evidence that should trigger rejection
- A screenshot with no report name, filters, period or source owner.
- A copied prior-period file with dates changed but no fresh source extraction.
- An unexplained plug, forced balance or hard-coded formula.
- A line labelled only “timing” without an origin date, expected clearing event or owner.
- An adjustment proposed without accounting support, approval route or journal reference.
- A reviewer sign-off with no evidence that exceptions, unusual activity or old items were examined.
Evidence depth should scale with risk, but the minimum fields should not disappear. A low-risk account may need fewer supporting documents; it still needs an identifiable source, a tie, ownership and a review trail. The Northern Trust–Lukka reporting agreement illustrates why broad source connectivity still requires separate evidence of completeness, reconciliation, lineage and exception handling before accounting reliance.
Set materiality, tolerance and frequency as separate decisions
Materiality asks whether an error or control failure could matter to reporting or decision-making. Tolerance sets the difference a matching rule may accept or route differently. Frequency determines how often the control runs. One value should not stand in for all three.
For public-company internal control over financial reporting, PCAOB AS 2201 applies financial-statement materiality and a top-down risk approach when selecting controls to test. A reconciliation programme can borrow that risk logic, while recognising that the auditing standard does not prescribe the organisation’s operating timetable or tolerance settings.
Stanford’s current balance-sheet reconciliation guidance provides a practical example. It determines frequency using risk, materiality and history, and expects reconciling items to be documented and resolved, unusual activity to be identified, aged items to be monitored and balances to be supported.
| Risk tier | Typical indicators | Control response |
|---|---|---|
| High | Material balance or flow, cash exposure, high volume, manual journals, estimates, complex interfaces, fraud susceptibility, prior issues or major system change. | Reconcile each reporting close or more often; senior or specialist review; lower investigation tolerance; immediate escalation of unusual or unsupported items. |
| Standard | Recurring activity with stable sources, moderate judgement and no significant recent control failure. | Reconcile at the approved reporting cadence; independent review; full item log; normal ageing and escalation rules. |
| Low or inactive | Low exposure, little activity, predictable balance and reliable source, with no adverse history. | Reduced frequency only when the account register, activity check and periodic risk reassessment remain in force. |
The policy should also define qualitative triggers that override monetary thresholds. An unsupported balance, suspected fraud, management override, unusual related-party item, failed interface or recurring error may require escalation even when the amount is small.
Run exceptions as controlled cases, not spreadsheet comments
A reconciling item is a known difference between the ledger and comparison source. An exception is an item or condition that breaches the expected control, matching rule, evidence requirement or completion criterion and requires managed action. A legitimate timing item may be controlled; an unsupported or repeatedly rolled item is not.
The exception lifecycle
- Detect and log: record the difference or control failure with a unique case reference.
- Classify: use a controlled reason code such as timing, posting error, missing or duplicate transaction, source or interface failure, unsupported balance, approval failure, unusual activity or suspected misconduct.
- Assess: evaluate amount, qualitative significance, age, recurrence, reporting impact and whether the issue indicates a wider control deficiency.
- Assign: name the exception owner, due date, required action and escalation route.
- Resolve: correct the ledger, source, interface, master data, process or policy as appropriate.
- Validate: the preparer or another designated person confirms the outcome against fresh evidence; the reviewer accepts closure.
- Learn: recurring reason codes are analysed for root cause and control redesign.
Ageing and escalation
The ageing clock should have a fixed origin, such as the period end or the date the item first became unresolved. Rolling an item into a new worksheet must not reset its age. Each band should change the required action, not merely the colour of the row.
| Status | Trigger | Required action | Escalation |
|---|---|---|---|
| Open | Valid case within its approved due date. | Owner investigates and updates evidence and expected resolution. | Preparer monitors. |
| Overdue | Due date passed or promised action not completed. | Owner provides cause, revised date and interim control. | Account owner and reviewer. |
| Escalated | Policy age or value threshold reached, repeated across periods, or likely to affect reporting. | Formal resolution plan, root-cause action and senior approval for continued open status. | Programme owner and senior finance. |
| Critical | Material or unsupported balance, suspected fraud, management override, source integrity failure or reporting blockage. | Immediate containment, specialist assessment and decision on reporting or close impact. | Controller, CFO and other required governance channels. |
| Closed | Resolution completed and independently validated. | Attach final evidence, closure date and any root-cause action. | Reviewer accepts closure. |
There is no universal 90-day or monetary rule. UADA’s balance-sheet reconciliation policy, for example, requires senior approval and a resolution plan for items over $10,000 and over 90 days. That is a useful example of combining age and value, but the numbers should not be copied without local risk, accounting and governance review.
Make review and sign-off a challenge process
The reviewer’s job is to decide whether the evidence supports the reconciliation conclusion. A checklist helps, but the review must respond to the account’s risk and the items in front of the reviewer.
Reviewer challenge questions
- Is this the correct account, period, entity, currency and approved method?
- Are the source reports complete, reliable and period-aligned?
- Do the ledger and source balances agree to the retained evidence?
- Does the bridge recalculate, and are there hard-coded values or hidden plugs?
- Are all reconciling items supported, correctly aged and assigned?
- Were unusual transactions, manual journals and prior-period items examined?
- Are proposed adjustments appropriate, approved and referenced?
- Do open exceptions meet policy, with owners, due dates and escalation?
- Does any item indicate a wider process, system or control problem?
- Is the stated completion status honest?
Three completion states
- Complete
- The six proofs are present and no unresolved item remains outside normal settlement or posting timing.
- Complete with controlled open items
- The policy permits sign-off, each open item is supported and owned, ageing and escalation are current, and no material, suspicious or unsupported issue blocks the conclusion.
- Rejected or incomplete
- A required source, tie, item explanation, review step, approval, corrective action or escalation is missing.
“Complete with controlled open items” should be a governed state, not a way to clear the queue. The policy should specify which risk tiers may use it, which items are prohibited, who approves it and what happens if the item survives another reporting period.
Use this reconciliation-control matrix
| Stage | Primary owner | Required input | Control evidence | Completion test | Exception trigger |
|---|---|---|---|---|---|
| 1. Scope | Programme owner | Chart of accounts, ownership and risk assessment | Approved account register | Every in-scope account has a method, cadence, preparer and reviewer | Unassigned, excluded or newly created account |
| 2. Source acquisition | Preparer | Ledger and approved comparison source | Report parameters, timestamps and control totals | Sources are complete, reliable and period-aligned | Missing data, failed interface or unverifiable extraction |
| 3. Preparation | Preparer | Source data and prior open-item log | Mathematical bridge and item schedule | Balance ties without unexplained difference | Plug, formula error or unsupported balance |
| 4. Item assessment | Preparer and account owner | Reconciling items and transaction evidence | Reason, age, significance, owner, due date and treatment | Every item is controlled or escalated | Material, unusual, recurring, suspicious or overdue item |
| 5. Corrective action | Exception owner | Assigned case and approved action | Journal, corrected source, settlement or process evidence | Action completed and validated | Missed due date or ineffective correction |
| 6. Review | Reviewer | Complete evidence packet | Challenge notes, rework and disposition | All six proofs pass or the file is rejected | Missing evidence, weak explanation or inappropriate treatment |
| 7. Sign-off | Reviewer or designated approver | Reviewed reconciliation and exception status | Completion state, approval and date | Conclusion matches policy and open-item exposure | Attempted approval outside authority or policy |
| 8. Monitoring | Programme owner | Completion and exception data | Dashboard, escalation log and remediation actions | Recurring causes are assigned for control improvement | Rising overdue exposure, repeat rejections or unresolved control issue |
Implement and monitor the standard
Implementation should start with policy and account data, not with a tool selection.
- Build the account register. Record purpose, owner, source, method, risk tier, cadence, due date, preparer and reviewer for every account in scope.
- Approve the policy decisions. Set investigation thresholds, posting thresholds, matching tolerances, ageing origin, status bands, escalation routes and controlled-open-item rules.
- Define the evidence packet. Make the minimum fields and source requirements consistent across manual and automated reconciliations.
- Pilot by risk tier. Test high-, standard- and low-risk accounts, then adjust review depth and evidence requirements where the first design is either weak or needlessly burdensome.
- Train by role. Preparers, reviewers, account owners and exception owners need different instructions and authority.
- Monitor the control, not only completion. Track on-time preparation and review, rejection rate, open-item count and amount, aged exposure, recurring reason codes, reopened items and time to validated resolution.
- Change upstream causes. When one reason code repeats, assign a process, data or system action rather than accepting the same manual repair each period.
The programme owner should review both individual failures and patterns. A reconciliation may be completed on time while the control environment is weakening through repeated overrides, growing aged exposure or reviewers who never reject work. The standard is working only when the evidence, ownership and exception data make those conditions visible and force a decision. Once matching runs automatically the visible metric becomes the match rate, so it is worth setting out the control outcomes worth measuring once matching is automated in place of it.
Frequently asked questions
How often should accounts be reconciled?
A reconciliation’s frequency should follow account risk rather than one universal calendar. Materiality, transaction activity, susceptibility to error and the consequences of a delayed difference should inform the cadence, while unusual activity and aged items still require review. The chosen frequency should be documented separately from matching tolerance and investigation thresholds.
What evidence makes an account reconciliation defensible?
A defensible reconciliation identifies the population and source, proves the balance tie, explains material or unusual items, records corrective action and shows independent review. The evidence should be current, complete, accurate, accessible, verifiable and understandable to a competent reviewer without an oral explanation from the preparer.
Can the same person prepare and review a reconciliation?
Preparation and review should normally be assigned to different knowledgeable people because incompatible duties weaken independent challenge. When staffing makes full separation impractical, the organisation should document an alternative review or other control activity that addresses the risk; one person should not silently prepare, approve and close the same reconciliation.