Substantive testing · NetSuite TD3016323
Population analysis, risk stratification, and exception testing of every posted journal entry in the account, with five exceptions and one series that should not be called a beginning balance.
Scope: every posted journal entry in the account, 88 entries dated October 2024 to October 2026, 26.8 million dollars of debits, all balanced. Materiality for selection was set at $25,000 of total debits, which captures 59 entries and 99.8% of the value. The full population was tested, not a sample, because 88 entries is small enough to read.
The population divides into two groups that need different treatment. Forty-eight entries share the memo "Beg Balance Entries", one per month per subsidiary for 24 months, 62 or 63 lines each across about 50 accounts, 25.8 million dollars of debits, 96% of everything. They credit 19.8 million dollars to revenue, which is most of the revenue the account has ever recognized. All 48 were created on a single day, September 10, 2026, and are backdated by as much as 709 days. Whatever they are, they are not beginning balances. A beginning balance is posted once. These recur monthly and carry a full income statement each time.
The other forty are manual entries of the ordinary kind, 1.01 million dollars in total. Eleven have no description. Eight share the memo "Negative Cash Flow" and move round amounts between a bank account and equity. Three undescribed entries created on the evening of September 14 move $262,000 in round amounts between balance sheet accounts. Those eleven are the exceptions this test is designed to find.
Entries by transaction month. Two per month is the beginning-balance series; the rise from June 2026 is the manual entries, most of them created in September.
Risk indicators applied: period-end date (day 28 or later), creation outside 08:00 to 18:00, weekend creation, round amount above $10,000, description under ten characters, revenue credited without a cash or receivable debit, expense without cash or payable, P&L-only entries, and top-side keywords in the memo.
| Indicator | Entries | Note |
|---|---|---|
| After-hours | 32 | creation timestamps between 03:00 and 07:00 and after 20:00 |
| Inadequate description | 15 | 11 with no memo, 4 under ten characters |
| Weekend | 11 | all Saturday, September 12 |
| Round amount | 11 | 8 Negative Cash Flow entries plus 3 undescribed |
| Expense without cash or AP | 10 | accruals; expected for the type |
| P&L only | 4 | reclassifications between expense accounts |
| Period-end | 3 | day 28 or later |
The beginning-balance series does not trip the combination flags, because each entry touches bank, receivables, payables, and equity as well as the P&L. It trips the description test in substance rather than in length: the memo is present, and wrong. That is why the population summary, not the indicator table, is where this series shows up. A screen built on keywords would have passed it.
All 11 manual entries above materiality were tested in full. The 48-entry beginning-balance series was treated as one recurring population: the first, a middle, and the last entry were examined line by line and the remainder compared for structure. Five entries below materiality were read for description and account combination. Nothing was sampled at random, because nothing needed to be.
| Entry | Date | Created | Debits | Description | Account types | Indicators |
|---|---|---|---|---|---|---|
| JE155 | 2026-06-01 | 2026-09-12 03:32 | $175,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE152 | 2025-11-01 | 2026-09-12 03:29 | $120,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE158 | 2026-09-01 | 2026-09-16 07:31 | $120,000 | Negative Cash Flow | Bank, Equity | After-hours, Round amount |
| JE162 | 2026-09-14 | 2026-09-14 21:14 | $112,000 | none | Bank, OthCurrAsset | After-hours, Round amount, Inadequate description |
| JE153 | 2026-01-01 | 2026-09-12 03:30 | $100,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE160 | 2026-09-01 | 2026-09-14 20:57 | $85,000 | none | AcctRec, OthCurrAsset | After-hours, Round amount, Inadequate description |
| JE161 | 2026-09-01 | 2026-09-14 21:00 | $65,000 | none | AcctPay, OthCurrAsset | After-hours, Round amount, Inadequate description |
| JE151 | 2025-10-01 | 2026-09-12 03:28 | $50,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE154 | 2026-05-01 | 2026-09-12 03:30 | $50,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE156 | 2026-07-01 | 2026-09-12 03:33 | $50,000 | Negative Cash Flow | Bank, Equity | After-hours, Weekend, Round amount |
| JE150 | 2026-03-03 | 2026-09-10 18:18 | $33,700 | 00000005/1-12102024-181841 | AcctPay, Bank | After-hours |
| ID | Type | Name | Handle | Scope | Used for | Complete |
|---|---|---|---|---|---|---|
| DL-001 | SuiteQL | Journal headers | transaction (type = Journal) | All 88 entries | Population, dates, memos, preparer, approval | Yes |
| DL-002 | SuiteQL | Journal lines | transactionline join transactionaccountingline join account | 3,076 posted lines | Debits, credits, account types, combinations | Yes |
| DL-003 | SuiteQL | Creation timestamps | transaction, TO_CHAR(createddate, HH24:MI) | All 88 entries | After-hours and weekend tests | Yes |
Adaptations from the prompt's templates: amounts come from transactionaccountingline (debit and credit columns) rather than transactionline.amount; account.accttype rather than acctype; transaction.subsidiary is not exposed, so subsidiary comes from the line; the JSON returned for createddate carries no time, so the hour was fetched separately with TO_CHAR; the preparer join to employee was dropped because the creator field is empty on 79 entries; LISTAGG was replaced by aggregation in code.
SELECT t.id, t.tranid, t.trandate, t.createddate, BUILTIN.DF(t.createdby), t.memo, BUILTIN.DF(t.approvalstatus), t.posting, BUILTIN.DF(t.postingperiod), t.lastmodifieddate, BUILTIN.DF(t.lastmodifiedby) FROM transaction t WHERE t.type = 'Journal' SELECT tl.transaction, tl.id, tl.subsidiary, a.acctnumber, a.fullname, a.accttype, tal.debit, tal.credit, tal.amount, tl.memo, BUILTIN.DF(tl.department), BUILTIN.DF(tl.entity) FROM transactionline tl JOIN transaction t ON t.id = tl.transaction JOIN transactionaccountingline tal ON tal.transaction = tl.transaction AND tal.transactionline = tl.id JOIN account a ON a.id = tal.account WHERE t.type = 'Journal' AND tal.posting = 'T' SELECT id, TO_CHAR(createddate, 'YYYY-MM-DD HH24:MI'), TO_CHAR(createddate, 'DY') FROM transaction WHERE type = 'Journal'
| Assumption | Category | Rationale | Sensitivity | Impact if wrong |
|---|---|---|---|---|
| All journals are in the transaction table with posting = T | Data | System constraint | High | Population completeness |
| Materiality $25,000 of debits | Business logic | Roughly 0.1% of total debits; captures 99.8% of value | Low | Sample selection only; the population was fully tested |
| Period-end = day 28 or later | Business logic | Prompt definition | Low | Three entries |
| After hours = before 08:00 or from 18:00 | Business logic | Prompt definition | Low | 32 entries |
| Creation timestamp reflects entry time | Data | System field | High | Timing indicators; the account's history was loaded in September 2026, so timing describes the load |
| Test | Objective | Result |
|---|---|---|
| G1-001 | Population complete | Pass 88 headers, 3,076 lines, every header has lines |
| G1-002 | Entries balance | Pass debits equal credits on all 88 |
| G1-003 | Timestamps present | Pass creation timestamp on all 88 |
| G2-001 | Indicator logic | Pass computed in code from dates, amounts, memos, and account types |
| G2-002 | Approval and preparer testable | Fail no approval status on any entry; preparer on 9 |
Confidence: 95% in the population figures and the indicator counts; 85% that E2 and E3 are undocumented rather than fraudulent, given the account's evident use as a demonstration environment; the characterization of the beginning-balance series is reported, not concluded, and requires management's explanation.