12 Mar 2026 · Field notes

Tracing anomalies across ledgers without drowning in extracts

When three systems show three versions of “cash,” the temptation is to pull wider extracts. That usually creates more noise. Start by freezing the question: which balance, which date, which entity, which currency?

Next, pick a single spine — usually the GL trial balance — and treat every other file as a witness, not a competitor. Document the query parameters for each witness: posting date versus document date, open items versus cleared, including or excluding auto-reversals.

A workable sequence

  1. Hash or row-count the extract the moment it lands so later “refreshes” are visible.
  2. Reconcile high-level totals before drilling to lines; many “anomalies” are filter mistakes.
  3. Isolate timing bridges (in-transit, unapplied cash) before alleging system error.
  4. Only then sample individual lines that break the bridge logic.

Teams in our Financial Data Integrity Audit course practice this on synthetic multi-ledger packs. The point is not speed for its own sake — it is leaving a trail a second reviewer can re-perform without calling you at midnight.

← All insights