Direct answer: A trust reconciliation audit trail should reconstruct which source files were used, who prepared and reviewed the work, how each reported balance was calculated, what exceptions were found, which corrections changed the result, and which exact packet version the attorney approved. It should be append-oriented, attributable, timestamped, exportable, and protected from silent alteration.
Key takeaways
- Retain immutable source identifiers and hashes where practical.
- Record calculation inputs, not only the final three numbers.
- Preserve exception history and correction reasons.
- Bind approval to an exact report version and invalidate it after material changes.
Source and preparation events
Record the account, period, source filenames, file sizes, creation or export dates, ingestion time, and a stable checksum or version identifier. Capture validation failures such as missing columns, mismatched periods, duplicate records, or incomplete client-ledger populations.
Preparation events should identify the operator and explain manual choices. A generic 'updated reconciliation' event is too vague when the changed amount may affect a client balance or approval decision.
Calculation and exception events
The trail should support recalculation of the adjusted bank balance, journal balance, and client-ledger total. Each reconciling item and exception needs a stable identifier, evidence link, status history, owner, and resolution note.
If a source is corrected, keep the prior version and show the relationship between runs. A reviewer should be able to see that version two replaced version one and why.
Review, approval, and export
Record review completion, reviewer comments, unresolved exceptions, attorney approval, and the report digest or version approved. Administrative access should not allow someone to rewrite those events without leaving evidence.
Export matters because the firm's recordkeeping duty should not depend on permanent access to one vendor. The packet and event history should be available in durable, understandable formats.
Frequently asked questions
Is an application activity log enough?
Only if it contains the source, calculation, exception, revision, and approval detail needed to reconstruct the close. Login and page-view logs alone are not a reconciliation audit trail.
Should administrators be able to delete audit events?
A strong control prevents silent deletion or alteration of consequential events and records any authorized retention action separately.
Sources and further reading
This article is operational education, not legal advice. Trust-account rules and retention requirements vary by jurisdiction. Confirm the requirements that apply to your firm and accounts.