A $2 million suspense account and a $40,000 operating account shouldn’t consume the same amount of review time simply because both appear on the reconciliation checklist. Yet in many financial close processes, they do. A stable bank account with a clean history can receive the same scrutiny as a volatile suspense account that’s been drifting for months. While the process may be consistent, the risk isn’t. This article, originally penned by Shagun Malhotra, Founder and CEO of SkyStem, delves into the critical need for a risk-based approach to financial reconciliations, arguing that a tiered review system is not only more efficient but also a stronger defense against financial irregularities and fraud.
The Hidden Costs of Undifferentiated Review
The core of Malhotra’s argument rests on the inefficiency and potential dangers of treating all financial accounts with uniform review intensity. In many organizations, the financial close process operates on a checklist mentality. Every account, regardless of its inherent risk profile, undergoes the same procedural steps. This "paper control," as Malhotra terms it, fulfills a procedural requirement but fails to adequately address the actual financial risks present.
The consequence of this undifferentiated approach is a misallocation of valuable reviewer time. Low-risk accounts, which are typically stable and exhibit predictable behavior, are subjected to the same detailed scrutiny as high-risk accounts. This means that a volatile suspense account, which might have significant outstanding variances or a history of unpredictable movements, could be rushed through the review process simply because the reviewer’s time is constrained by the need to address numerous other items on the checklist.
This oversight has tangible, often delayed, repercussions. A missed error or an undetected anomaly in a high-risk account might not surface immediately. Instead, it often manifests weeks later as a post-close adjustment, requiring extensive backtracking and analysis. In more serious cases, these issues can emerge months later as audit findings. By this point, the trail leading back to the initial rushed review is often cold, making it exceedingly difficult to pinpoint the source of the problem and implement corrective actions effectively.
Data-Driven Insights: The ACFE Report and Fraud Reduction
Malhotra’s call for a more risk-aware approach is bolstered by compelling data from external research. A significant report by the Association of Certified Fraud Examiners (ACFE) highlights the direct correlation between proactive data monitoring and a reduction in financial losses due to fraud. According to the ACFE’s findings, proactive data monitoring was linked to a remarkable 53% reduction in median fraud loss. This statistic underscores the power of actively scrutinizing financial data, rather than passively checking off tasks.
The same ACFE report identified three prevalent weaknesses that contributed to a staggering 70% of the fraud cases examined. These weaknesses were: a lack of internal controls, the overriding of existing controls, and insufficient management review. An undifferentiated reconciliation process directly contributes to the latter two. When controls are not robustly applied or are bypassed due to time pressures, and when management review is superficial because it’s applied uniformly across all accounts, the environment becomes ripe for fraudulent activity or significant errors to go unnoticed.
The Principle of Reconciliation Triage
To combat these inefficiencies and risks, Malhotra advocates for "reconciliation triage." This concept involves segmenting financial accounts based on their actual behavior and risk profile, rather than adhering to established habits or checklists. The variables that should dictate this segmentation are not complex, but they are often overlooked. These include:
- Variance Frequency: How often does an account produce a discrepancy between expected and actual balances?
- Variance Magnitude: What is the typical dollar amount of these variances?
- Account Volatility: How much does the account’s activity fluctuate relative to its historical baseline?
By analyzing these factors, financial teams can categorize accounts into tiers. For example, an account with a stable history and no unexplained variances over several reporting cycles poses a significantly lower risk. Such accounts can follow a streamlined review path: confirming the balance, verifying consistency with historical patterns, and closing.
Conversely, an account that consistently generates variances, regardless of their size, or exhibits unusual volatility, demands a deeper, more focused review. This tiered approach ensures that limited reviewer time is directed where it is most needed, allowing for a thorough investigation of potential issues without diverting attention from low-risk items that require minimal oversight.
Optimizing Resource Allocation for Maximum Impact
The principle of allocating review time based on risk is fundamentally about optimizing the use of limited resources. When reviewer time is spread too thinly across all accounts, the risk of overlooking critical anomalies increases. A process that dedicates the same five minutes to a low-volatility account as it does to a high-turnover account with a history of adjustments is effectively allowing real issues to become lost in the "noise" of routine financial activity.
By implementing a tiered system, finance departments can ensure that high-risk accounts receive the necessary attention. This not only helps in identifying and rectifying errors promptly but also serves as a powerful deterrent against fraudulent activities. The ability to demonstrate that resources are being allocated strategically based on risk is a hallmark of a mature and effective financial control environment.
The Defensibility of a Tiered Review Model Under Audit
Beyond operational efficiency and risk mitigation, a tiered reconciliation review process offers a significant advantage in audit engagements. Auditors are increasingly focused on the rigor and risk-assessment capabilities of a company’s internal controls. A well-documented, risk-based review process is inherently more defensible than a flat, undifferentiated approach.
The Public Company Accounting Oversight Board (PCAOB), for instance, has established standards such as AS 2110, which explicitly directs auditors to scale the nature, timing, and extent of their procedures based on the assessed risk of material misstatement. This means that auditors are not only expecting but are mandated to apply more scrutiny to areas identified as higher risk.
A financial close process built on the same risk-tiering logic as audit standards mirrors this requirement. When auditors inquire about the reconciliation process, a tiered model allows for a clear and logical explanation of why certain accounts receive more attention than others. This demonstrates a proactive understanding and management of financial risk, which is far more persuasive than a claim of uniform rigor that is not borne out by the allocation of resources. Auditors do not expect every account to be treated identically; they expect the treatment to align with the inherent risks, and they expect the company to be able to articulate the rationale behind its approach.
Practical Steps Towards Implementing Tiered Reconciliations
Implementing a more effective, risk-based reconciliation process does not necessarily require an immediate investment in new software. Malhotra suggests a practical, phased approach that can be initiated by most finance teams:
- Data Collection and Analysis: Begin by gathering at least twelve months of historical reconciliation data. This data should then be analyzed to identify variance frequency, dollar impact, and account volatility.
- Account Segmentation: Based on the data analysis, segment accounts into distinct risk tiers (e.g., low, medium, high). This segmentation process itself can be an eye-opening exercise, as many teams may not have previously quantified these risk factors.
- Review Calendar Adjustment: Once accounts are segmented, the review calendar can be adjusted accordingly. Low-risk items can be placed on a lighter review cadence, while high-risk items can be scheduled for more frequent and in-depth reviews.
This initial segmentation, even if performed manually or using spreadsheets, lays the groundwork for a more strategic approach. As an organization’s financial volume grows and becomes more complex, spreadsheet limitations may become apparent. At this stage, specialized financial close management software, like that offered by SkyStem, can automate and sustain the segmentation and tiered review process, ensuring consistency and scalability. However, Malhotra emphasizes that the diagnostic phase—understanding the risk profile of accounts—should precede automation to avoid automating a flawed process.
The Broader Impact: Strengthening the Control Environment
The implications of adopting a tiered reconciliation review system extend beyond mere efficiency gains. It represents a fundamental strengthening of the internal control environment. By proactively identifying and addressing high-risk areas, organizations can:
- Reduce the Likelihood of Fraud: Enhanced scrutiny of volatile accounts makes it more difficult for fraudulent activities to go undetected.
- Improve Accuracy and Reliability of Financial Reporting: Prompt identification and resolution of variances lead to more accurate financial statements.
- Enhance Audit Readiness: A defensible, risk-based process simplifies audit engagements and reduces the potential for audit adjustments.
- Foster a Culture of Risk Awareness: The process encourages finance teams to think critically about risk rather than simply following procedures.
Ultimately, implementing these changes allows controllers to build a financial close process that actively guides their attention to where it is most needed. In many organizations, the current close process operates reactively, prompting investigation only after an issue has surfaced. By adopting a tiered, risk-based approach, finance teams can move towards a proactive model, identifying potential problems before they escalate. This upgrade to the control environment can be achieved without the immediate need to expand headcount, making it a highly cost-effective strategy for enhancing financial integrity.
About the Author
Shagun Malhotra, CEO of SkyStem, brings over two decades of experience in finance and accounting technology. SkyStem is a leading provider of financial close management software, serving mid-market and enterprise organizations. Her insights are rooted in a deep understanding of the challenges faced by finance departments in optimizing their close processes and strengthening internal controls.








