AS | Ankit Sarawagi|Founder, CFOmatrix·July 2026·9 min read | Right-sized SOP |
- Manual JVs are the hotspot. Routine, system-generated entries are low risk; manual, top-side journal entries are where error and manipulation sit, and where auditors look first.
- The control is three things. Every manual JV needs a narration explaining why, a supporting document attached, and a second person who reviews and approves it.
- Restrict who can post. Only the finance owner (and later a controller) should have JV posting rights in the software; everyone else works through invoices and bills.
- Review at month-end. The founder or reviewer runs through the month’s manual JVs during the close, reading narrations and checking support, and signs off.
- Keep the audit trail on. The MCA now requires accounting software to keep an edit log that cannot be disabled; auditors check it. It is subject to current law.
| 3 Things every manual JV needs: narration, support, review | 1 Owner with JV posting rights in the software | On The audit trail your software must keep, always |
01What a Journal Entry Control Is, and Why Manual JVs Matter
A journal entry control is simply the rule you put around manual journal vouchers so the books cannot be adjusted quietly by one person. Most of your ledger is safe without much fuss, because most entries are routine: they come from a source transaction and an external document. The control exists for the entries that do not, the manual, typed-in adjustments where a single person can move a number with nothing external to check it against.
The rule itself is short. For every manual JV you want three things: a narration that says why the entry is being passed, a supporting document attached to it, and a second person who reviews and approves it. Add to that a restriction on who can post journal entries and a live audit trail in the software, and you have the whole control. The reserved matters and accounting policies themselves usually live in your finance policy; see the CFOmatrix policy library for the rules, and this SOP for the process. This post is one of the process SOPs in the right-sized finance SOPs and controls guide.
02Routine Automated Entries vs Manual JVs
The first thing to get straight is what actually needs the control. Not every entry does. An automated entry is generated by the system from a source transaction and is backed by a document. A manual JV is typed straight into the ledger by a person. Keep controls light on the first and tight on the second.
- Sales invoice raised to a customer
- Purchase bill recorded from a vendor
- Bank payment or receipt
- Payroll run posted from the payroll tool
- Accruals and prepaids
- Depreciation and amortisation
- Provisions: created, adjusted or released
- Reclassifications and revenue or expense adjustments
The point of the split is efficiency: you do not want to smother routine, high-volume entries in approvals, and you do not want manual adjustments slipping through with none. Concentrate the control where the risk is.
03Why Auditors Focus on Manual, Top-Side JVs
Auditors do not test manual journal entries out of habit. They test them because that is where financial-statement misstatement is most likely to live. A sales invoice moves revenue in a predictable, documented way. A manual JV can move any number, in any direction, often with no external trigger: release a provision to flatter profit, defer an expense, or book an accrual that should not exist. Auditing standards on the risk of management override direct the auditor to examine journal entries, especially large, unusual or period-end manual ones. A due-diligence team does the same: it pulls the journal register and asks for the support behind each manual entry.
“When an auditor or a diligence team comes in, the first thing they pull is the journal register, and they zero in on the manual entries. A routine invoice is fine. It is the top-side JV, the one someone typed at year-end, that they want to see the support and the approval for.”
Ankit Sarawagi, from running finance for early-stage teamsThe good news is that this is entirely defusable. If every manual JV already carries a narration, a supporting document and a documented review, the auditor’s test becomes a formality: they ask, you show, it is done. Startups get caught here not because the entries are wrong, but because they were passed and never documented.
04The Control: Support, Post, Review
Here is the whole process for a manual JV, run by one finance owner and one reviewer. Three steps, and each one leaves a record in your tool by design.
Even if finance is one person, that person never blesses their own manual JVs. Finance posts the entries; the founder is the second set of eyes who reviews and approves them at month-end. It is the same principle as everywhere else in these SOPs: one person does the action, one other person checks it. For manual journal entries that check is the difference between a clean audit and an awkward one, and it costs the founder perhaps an hour a month.
05Restrict Who Can Post Journal Entries
The cheapest half of this control is a settings change. In your accounting software, restrict manual journal-entry rights to the finance owner only (and, once you scale, a controller). Everyone else works through invoices, bills and payment workflows, they never touch the journal directly. The fewer people who can post a manual JV, the smaller the surface for both mistakes and manipulation, and the shorter the list of people whose entries the reviewer has to check.
Both Zoho Books and QuickBooks let you set user roles so that only chosen users can create manual journals. Set it once. It is far more reliable than an unwritten understanding of who “should” pass entries, and it means the audit trail shows a short, expected list of names against every manual JV, which is exactly what makes a reviewer’s and an auditor’s job quick.
06What Auditors Look For, and the MCA Audit-Trail Rule
When an auditor or a buyer tests your journal entries, they want the same things every time. The checklist below is what they run through, and it maps one-to-one onto the control above. Keep it in mind and the review is a non-event.
The Ministry of Corporate Affairs requires companies to use accounting software with an audit-trail (edit-log) feature, to keep it switched on through the year, and not to tamper with it, and the auditor is required to check and report on whether it was functioning. For journal entries this is the whole ball game: the log shows who posted, edited or deleted each manual JV and when. Use Zoho Books or QuickBooks with the audit trail enabled and, crucially, do not disable it. The requirement and its dates are subject to current law, so confirm the current position.
Every manual JV produces a complete record and a place it lives: the narration and attachment (on the entry in Zoho Books), the poster and timestamp (the software edit log), and the review sign-off (on the month-end close checklist or a captured email). That is the exact paper trail an auditor or a buyer asks for, produced as a byproduct of passing the entry properly, not as extra work at audit time. Tie it into your wider paper trail in the audit-readiness SOP.
07Lean Version, and When to Add a Step
The support-post-review control carries a lean team a long way. Do not add bureaucracy for its own sake; add a step only when headcount and transaction volume make the current one thin. Here is the maturity path.
|
FAQFrequently Asked Questions
What is a journal entry control?
The rule you put around manual journal vouchers so the books cannot be adjusted quietly by one person. In a lean startup it comes down to three things for every manual JV: a clear narration explaining why the entry is passed, a supporting document attached to it, and a second person who reviews and approves it. On top of that, you restrict who can post journal entries and keep the audit trail in your accounting software switched on. Routine, automated entries like a sales invoice or a bank payment do not need this; the control is aimed at the manual, top-side entries where errors and manipulation actually hide.
Why do auditors focus on manual journal entries?
Because manual, top-side journal entries are where financial-statement errors and manipulation are most likely to sit. A sales invoice or bank payment is a routine, system-generated entry backed by an external document. A manual JV can move a number anywhere: reclassify an expense, create or release a provision, book a year-end accrual, or adjust revenue, often with no external trigger. That is why auditing standards direct auditors to test journal entries, especially large, unusual or period-end manual ones, and why a diligence team pulls the journal register and asks for the support behind each manual entry. Get support, narration and review right and it becomes a non-event.
Who should be allowed to post journal entries?
Keep the list short. Only the finance owner (and, once you scale, a controller) should have rights to post manual journal entries in the accounting software; everyone else works through invoices, bills and payment workflows. Even then, the person who posts a manual JV should not be the only one who blesses it: a second person, the founder or reviewer, checks and approves it, usually at month-end. Restricting posting rights in the tool plus a second-person review is the whole control. It stops both honest mistakes and any single person quietly adjusting the books.
What support does a journal entry need?
Every manual JV needs two things attached to it: a narration that explains in plain words why the entry is being passed, and a supporting document or working that backs the number. The support depends on the entry: a depreciation or amortisation schedule, a prepaid or accrual working, a provision calculation, a payroll reconciliation, a bank-charge statement, or an email approval for a reclassification. The test is simple: could a reviewer, or an auditor a year later, understand and agree with the entry from the narration and the attachment alone, without asking you? If not, the support is not good enough.
What is the MCA audit-trail requirement?
The Ministry of Corporate Affairs requires companies to use accounting software with an audit-trail (edit-log) feature, to keep it switched on through the year, and not to tamper with it; the auditor checks and reports on whether the software had a functioning audit trail. In practice, use software such as Zoho Books or QuickBooks with the audit trail enabled, so every journal entry, edit and deletion is logged with who did it and when. That is exactly what an auditor and a buyer ask to see for manual JVs, so keep it on and do not disable it. The requirement and its dates are subject to current law.
How should manual journal entries be reviewed?
Review them at month-end, as part of the close. The finance owner posts the manual JVs for the month; the second person, usually the founder or reviewer, then goes through the list of manual entries, reads each narration, checks the supporting document, and approves them in a documented month-end financials review. Focus on the ones that matter: large amounts, unusual accounts, round-number entries, anything posted to revenue or provisions, and anything dated at period-end. Capture the sign-off, in the tool, on the close checklist, or on email, so the review leaves a record. That review plus the software audit trail is what an auditor tests.
What is the difference between a manual JV and an automated entry?
An automated or routine entry is generated by the system from a source transaction: raising a sales invoice, recording a purchase bill, a bank payment or a receipt. It is backed by an external document and follows a fixed pattern, so the risk is low. A manual journal voucher is typed directly into the ledger by a person, usually for accruals, prepaids, depreciation, provisions, reclassifications and other period-end adjustments. Because a manual JV can move any number without an external trigger, it carries far more risk and is where your journal entry controls should concentrate. Distinguishing the two lets you keep controls light on routine entries and tight on manual ones.
This is general educational information for founders, current to mid-2026, and is not legal, tax or audit advice. References to the MCA audit-trail requirement, auditing standards on journal-entry testing and internal financial controls are indicative and subject to current law; applicability depends on company type and thresholds. Verify the current position or consult your auditor before acting on a specific matter.
Internal Financial Controls for Startups
Audit Readiness and the Paper Trail
AS | Founder, CFOmatrix | Finance Strategy & Equity Compliance CFOmatrix is a knowledge platform focused on how finance actually works inside growing companies. This SOP draws on hands-on experience building right-sized controls for lean startups: journal entry support, second-person review and an audit trail that stands up to diligence, without big-company bureaucracy. |