QuickBooks Online Attachment Audit Trail Evidence Review
August 24, 2026
Bottom line: an attachment audit trail proves that every QuickBooks Online transaction that should carry a document actually links to a legible, correctly matched source file with a reviewer checkpoint.
Sidebar: Attachments do not create accounting support by themselves. The review tests presence, match, and readability.
Why attachments deserve a separate audit trail
Small business files often hold the invoice, receipt, bill, statement, or agreement in a folder, an inbox, or a drive while QuickBooks Online holds the transaction that summarizes it. When those two holdings stay connected, a reviewer can answer whether a bill was approved, whether a receipt supports an expense, or whether a customer payment matches an invoice. When the link is missing, a reviewer must ask for the source again, which delays the close and the accountant handoff. An overdue question at that point often turns into a write off or an adjustment without evidence.
QBOAssistant VAs frequently manage attachment work. The VA can upload the file, confirm that it matched the right transaction, note when a document is missing or illegible, and build an exception queue for the owner. The audit trail review organizes that work so that a bookkeeper does not present a file as complete when half its bills carry no visible receipt.
Set the scope and the attachment standard
Define the review scope by transaction type, date range, and dollar or risk threshold. A practical scope includes bills, expenses, vendor credits, credit card transactions, and sales receipts where the business policy says an attachment is required. State whether the scope includes every transaction in that population or a threshold such as reviewed when prior policy requires attachments above an internal materiality line.
Define what counts as an acceptable attachment. A legible image or pdf that shows vendor name, date, amount, payment terms where relevant, and approval where required is generally acceptable. A file that is a delivery confirmation, a shopping cart screenshot without a final amount, or a duplicate of another transaction's file is not. Record the naming and storage convention if one exists. If the business keeps originals in a drive, the review should check that the QuickBooks link points to a file in that approved location rather than to a temporary download that may be deleted.
Include the preparation date and the reviewer name, and save the starting population export before sampling. That freeze lets a later reviewer reproduce the same test from the same report.
Build a sample that reveals match failures
A good sample tests each document class and each error type. For a monthly review, select every transaction above a stated review threshold, a random set of smaller transactions by vendor, every transaction that was entered by a bank feed rule, and every transaction that was later edited. Also select any high risk set such as travel, meals, or reimbursements where the policy requires extra evidence.
For each sampled transaction, pull the QuickBooks line and the attachment side by side. Record transaction ID, date, vendor or customer, amount, account or category, attached file name and location, file date, legibility note, and whether the file amount matches the transaction amount. Check four conditions. The file exists and opens. The vendor or customer on the file matches the transaction party. The amount on the file matches the transaction amount or the difference is explained and approved. The file date is consistent with the transaction date within the business policy tolerance.
Mark the result with a narrow status: supported, missing, illegible, mismatched party, amount variance, wrong transaction, duplicate file, or unapproved copy. Keep a free text field only for the variance explanation. The status itself should be selectable so the exception queue stays sortable.
Work the exception patterns
Missing is the obvious case. No file is attached. Record the transaction and the expected source type, then route it to the person who can supply the file. Do not substitute a typed memo that says per receipt. The reviewer needs the actual document.
Illegible is more subtle. A file is attached but a key field cannot be read. That may be a low resolution photo, a cropped scan, or a glare-heavy image. Note the legibility issue and who will provide a clearer copy. An illegible file is not support.
Mismatched party happens when the attached file belongs to a different vendor or customer than the transaction. Bank feed matching and batch uploading often cause this. An expense for Vendor A carries a receipt from Vendor B. Preserve both IDs so the reviewer sees the swap rather than deleting the file to make the queue look correct.
Amount variance is sensitive. The transaction is 420 and the receipt is 380 before tax. That may be tax handling, a partial payment, or an amount error. Record the variance, describe the likely handling, and keep the original amounts rather than editing the transaction to match the file before approval. Tax and discount handling should be consistent and documented where the business keeps that policy.
Wrong transaction occurs when a valid receipt is attached to the wrong QuickBooks entry, leaving both the correct entry and the incorrectly tagged entry with poor evidence. This pattern often hides duplicates. Keep both transaction IDs in the exception note so the reviewer can resolve the duplication with both entries visible.
Duplicate file is often missed. The same file is attached to two transactions. That may indicate a true duplicate expense or a shared delivery that was uploaded twice. Flag duplicates and let the owner decide whether one transaction is a duplicate entry or whether the file was reused incorrectly.
Prepare an owner-ready packet
The packet includes a cover sheet with scope, period, preparation and reviewer names, a population summary that counts total scoped transactions and attached versus missing, the sampled exception table, and a resolution section. The population summary shows progress over time because the same report run monthly reveals whether missing attachments are falling or drifting.
The exception table should carry transaction ID, date, party, amount, expected file type, current status, file name if present, and the next owner. The resolution section shows how many items were closed by providing the missing file or correcting the match and how many remain open with a due date.
Add retention and access notes. Attachments contain vendor details, amounts, and sometimes account numbers. Store files in the approved location, use the approved retention schedule, and restrict access to the reviewers who need it. Avoid pasting long account numbers into the review notes when a masked reference and transaction ID already identify the item.
Cadence
A weekly sample keeps small errors from accumulating. A monthly roll up proves the period is ready for the accountant packet. At that point, no scoped transaction above the review threshold should remain in a missing or mismatched status without an explicit owner and a due date. Archive the packet with the period exports so a later review can show that the period's attachments were actually tested, not just assumed to be there.
What good looks like
Good looks like a reviewer answering how many scoped transactions were tested, how many are supported, which vendors or expense types produce the most missing files, and which duplicates or mismatches are still open. The VA keeps the evidence organized. The owner decides whether to resubmit a file, accept a variance with a note, or hold an item for further review. That pairing keeps QuickBooks Online files both usable and credible.
Next step
Select one vendor with high bill volume and one month of credit card transactions. Run the attachment audit trail on that population, mark each sampled transaction with a status, and route open items to the person who can supply the file. Review whether the exception table drives a clear action. Reuse what works for the next month.
QuickBooks VA workflow table
| Workflow area | What the VA prepares |
|---|---|
| Daily queue | Invoices, receipts, bank feeds, and open QuickBooks questions |
| Weekly review | Owner approvals, exception list, and unresolved transaction notes |
| Monthly packet | Reports, missing documents, and accountant-ready source material |
Related resources
Compare the service fit on the QuickBooks VA services page, then use the free consultation form to map the first handoff. For platform context, review QuickBooks Online.