Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Internal Controls & Audit

Reconciliation Controls

Also known as: Reconciliation Control, Account Reconciliation Controls
Simply put

Reconciliation controls are checks that compare two sets of records covering the same activity to confirm they match and are accurate. A common example is comparing an organization's own accounting records against an external bank statement to catch errors or discrepancies. They are typically used within financial and accounting processes to help ensure records are complete and reliable.

Formal definition

Reconciliation controls are internal control activities that involve systematically comparing two or more independent sets of data recording the same transactions or balances to verify their accuracy, completeness, and consistency, and to identify and resolve discrepancies. Applied within financial and accounting systems, they commonly include verifying that transactions are promptly recorded and posted, reviewing supporting source documents, and matching internal ledger balances against external records such as bank statements. As a detective control, reconciliation typically identifies errors, omissions, or irregularities after they occur rather than preventing them, and forms part of broader unit-level and financial management control frameworks. The specific scope, frequency, and rigor of reconciliation controls vary by organization, process, and applicable policy or regulatory context.

Why it matters

Reconciliation controls are among the most widely relied-upon detective controls in financial and accounting processes because they provide independent verification that recorded activity is accurate and complete. When an organization's own ledger is compared against an external record such as a bank statement, discrepancies that would otherwise go unnoticed, posting errors, omitted transactions, timing differences, or potential irregularities, become visible for investigation and correction. Without such comparisons, errors can accumulate undetected and undermine the reliability of financial reporting.

Because reconciliation typically identifies issues after they occur rather than preventing them, its value depends heavily on frequency, timeliness, and the independence of the records being compared. A reconciliation performed promptly and reviewed by someone other than the person who recorded the transactions is generally more effective at surfacing problems than one performed infrequently or by the same individual responsible for the underlying entries. In this way, reconciliation controls often work alongside preventive controls and segregation of duties as part of a broader control framework.

It is important to note that reconciliation controls reduce, but do not eliminate, the risk of error or irregularity, and their design and rigor vary by organization, process, and applicable policy or regulatory context. The scope of what a given reconciliation covers, and what it does not, should be understood explicitly, and matters involving specific regulatory obligations may require professional advice.

Who it's relevant to

Accounting and Finance Teams
Staff responsible for maintaining ledgers and processing transactions perform reconciliations to confirm that recorded activity is accurate and complete, matching internal records against external sources such as bank statements and investigating any discrepancies they identify.
Internal Auditors
Auditors evaluate whether reconciliation controls are designed appropriately and operating effectively, assessing factors such as timeliness, independence of review, and how discrepancies are resolved, as part of testing the reliability of financial processes.
Controllers and Financial Management
Those overseeing financial management frameworks rely on reconciliation controls as part of unit-level control activities to help ensure records are complete and reliable, and to set the scope, frequency, and rigor appropriate to the organization's processes and applicable policy context.
Compliance and Governance Professionals
Where reconciliation supports adherence to internal policies or external requirements affecting financial reporting, compliance and governance stakeholders have an interest in confirming that these controls are documented and functioning, while recognizing that applicability varies by jurisdiction, sector, and organization.

Inside Reconciliation Controls

Source-to-Source Comparison
The core mechanism by which two or more independent records or data sets, such as a general ledger and a bank statement, are matched to confirm they agree. Discrepancies surfaced by the comparison are the primary output that triggers investigation.
Timing and Frequency
The cadence at which reconciliations are performed, which may be daily, monthly, quarterly, or event-driven depending on transaction volume, materiality, and the risk being addressed. Frequency is often calibrated to how quickly an error or irregularity could cause material harm.
Preparer and Reviewer Separation
A segregation-of-duties element in which the person preparing the reconciliation is typically different from the person who reviews and approves it, reducing the risk that errors or manipulation go undetected.
Exception and Discrepancy Handling
The defined process for identifying, documenting, investigating, and resolving differences, including thresholds for what constitutes a reportable discrepancy and escalation paths for unresolved or aging items.
Documentation and Evidence
The retained records demonstrating that the reconciliation was performed, reviewed, and resolved, which support auditability and may serve as evidence of control operation for internal audit, external audit, or regulatory examination.
Control Classification
Reconciliation controls are commonly categorized as detective controls, since they identify errors or irregularities after they occur rather than preventing them, though the deterrent effect of a known reconciliation process can carry a preventive dimension.

Common questions

Answers to the questions practitioners most commonly ask about Reconciliation Controls.

Does performing a reconciliation eliminate the risk of errors or fraud in the underlying accounts?
No. A reconciliation is a detective control that modifies risk rather than eliminating it. It typically identifies discrepancies between two independent records after transactions have occurred, which means errors or irregularities are generally caught after the fact rather than prevented. Residual risk often remains, including the possibility that both records share a common error, that reconciling items are cleared without adequate investigation, or that the control is performed superficially. Reconciliation controls are usually most effective when combined with preventive controls and other monitoring activities rather than relied upon in isolation.
Is a reconciliation the same thing as simply matching two figures and confirming they agree?
Not necessarily. Agreement of two totals is only part of a reconciliation. A reconciliation control typically involves comparing two independent sources, identifying and explaining any differences (reconciling items), investigating those differences, and taking corrective action or escalating where appropriate, with evidence of review. A comparison that shows the balances match but does not investigate or resolve differences may provide limited assurance. The rigor, independence, and follow-up around reconciling items are often what determine whether the control operates effectively.
How frequently should reconciliations be performed?
Frequency is generally driven by the risk associated with the account or process, transaction volume, and how quickly errors could accumulate or cause harm. Higher-risk or high-volume accounts, such as cash or clearing accounts, are often reconciled more frequently, sometimes daily, while lower-risk accounts may be reconciled monthly or at another periodic interval. Organizations commonly document the rationale for chosen frequencies and align them with reporting cycles. Appropriate frequency varies by organization, sector, and applicable requirements, so it should be assessed against the specific control objective.
Who should perform and who should review a reconciliation to support segregation of duties?
A common practice is to separate the preparation of a reconciliation from its independent review, and to keep both distinct from the individuals who originate or record the underlying transactions. This separation is intended to reduce the risk that an error or irregularity goes undetected because the same person created and checked the record. Where full segregation is not feasible, for example in smaller organizations, compensating controls such as heightened management review may be considered. The specific arrangement depends on available resources and the assessed risk.
How should reconciling items be handled to keep the control effective?
Reconciling items are the differences identified between the two sources. Effective handling typically includes documenting the nature and cause of each item, investigating within a defined timeframe, resolving or correcting items promptly, and escalating aging or unexplained items. Persistent or unexplained reconciling items, or a growing backlog, can indicate that the control is not operating as intended. Many organizations set thresholds and aging criteria to prioritize investigation and to signal when management attention is required.
What evidence supports that a reconciliation control operated effectively?
Evidence commonly includes the completed reconciliation showing the sources compared, a listing of reconciling items with explanations, documentation of investigation and resolution, and evidence of independent review such as a sign-off or approval with a date. Auditors and reviewers often look for whether the review was timely, whether reconciling items were adequately supported, and whether corrective actions were taken. The nature and retention of evidence may be shaped by internal policy and applicable regulatory or audit expectations, which vary by context.

Common misconceptions

A reconciliation control eliminates the risk of error or fraud in the underlying records.
A reconciliation is a detective control that typically identifies discrepancies after they arise; it modifies risk but does not eliminate it. Residual risk remains, for example where both records share a common error, where collusion defeats segregation of duties, or where an item falls below the discrepancy threshold.
Simply performing a reconciliation satisfies the control objective.
The control depends not only on the comparison being performed but on discrepancies being investigated, resolved, and reviewed. A reconciliation that is completed but leaves aging or unexplained items unaddressed may be operating in name only and is often flagged as a control deficiency.
Reconciliation controls are purely a finance or accounting concern.
While reconciliations are prominent in financial reporting, the same logic of comparing independent records applies across data integrity, IT, inventory, and operational domains. The concept spans control activities relevant to multiple objectives, not only financial statement accuracy.

Best practices

Set reconciliation frequency and discrepancy thresholds based on the materiality and velocity of the underlying risk, rather than applying a uniform cadence across all accounts or data sets.
Maintain clear separation between the preparer and the independent reviewer, and confirm that the reviewer's role includes challenging unexplained or aging items rather than merely confirming completion.
Define and enforce an escalation path and resolution timeframe for exceptions, so that discrepancies do not accumulate unresolved between reconciliation cycles.
Retain sufficient documentation of the comparison, the review, and the resolution of exceptions to support auditability and to evidence that the control operated as designed.
Periodically assess whether the two sources being reconciled are genuinely independent, since a shared source of error can undermine the assurance the control is intended to provide.
Verify specific regulatory or framework expectations for reconciliation against the applicable primary sources and professional guidance, as requirements vary by jurisdiction, sector, and organization size.
Promotional banner for the Penetration Report Template Kit