Using the QuickBooks Desktop Audit Trail After Discontinuation
When Intuit support ends, the built-in Audit Trail becomes your primary forensic tool for tracing who changed or deleted transactions and documenting discrepancies for auditors.
The Audit Trail is a persistent log that QuickBooks Desktop maintains inside the company file itself. It records every transaction that is created, modified, or deleted, along with the user who performed the action and the timestamp. After Intuit ends connected services and direct support, this log becomes the primary internal mechanism for investigating discrepancies, tracing unauthorized changes, and assembling documentation for an accountant or external auditor.
What the Audit Trail Captures
The Audit Trail is active by default in every modern QuickBooks Desktop release and cannot be disabled through the user interface. Each time a user enters, edits, voids, or deletes a transaction, QuickBooks writes a record that includes the user name, the date and time of the change, the transaction type, and the before-and-after values of modified fields. Deleted transactions are retained in the log with a deletion marker rather than being purged, which means the historical record of what was removed remains visible.
Why the Audit Trail Matters More After Discontinuation
When Intuit support is no longer available, there is no external escalation path for investigating unexplained account balance changes or missing transactions. The Audit Trail becomes the first and often only source of forensic detail. It allows an administrator to determine whether a discrepancy stems from accidental edits, a misunderstanding of workflow, or unauthorized activity. For organizations subject to internal controls or external audit requirements, the log provides the documentation needed to reconstruct a chain of events.
Accessing the Audit Trail Report
Open the report by selecting Reports from the top menu, then choosing Accountant & Taxes, followed by Audit Trail. The report defaults to the current date range, which can be narrowed using the Dates filter at the top of the report window. For a targeted investigation, set the date range to bracket the period when the discrepancy is believed to have occurred.
Use the Filter button to narrow results further. Common filters include Transaction Type (invoices, bills, journal entries, checks), Name (a specific customer, vendor, or employee), and Entered/Last Modified date. Filtering by the Last Modified By field isolates changes made by a specific user, which is useful when multiple people share the file or when a former employee's activity is under review.
Interpreting the Results
Each row in the report represents a single state of a transaction. A transaction that was edited three times appears as three separate entries, each with its own timestamp and user. The most recent entry reflects the current state of the transaction in the live file. Earlier entries show the prior values, allowing a reviewer to see exactly which fields changed and what the original amounts were.
Deleted transactions appear with a notation indicating deletion. The original transaction detail remains visible in the log, including the amounts, accounts, and name entries that were on the transaction before removal. This is particularly important when reconciling accounts that no longer balance, because a deleted check or bill payment may be the cause.
Establishing Preventive Controls
Beyond investigation, the Audit Trail supports a broader internal control framework. Our engineers recommend reviewing the log on a recurring schedule, such as monthly, rather than only when a discrepancy surfaces. Regular review helps identify patterns, such as repeated edits to prior-period transactions or deletions concentrated in specific accounts, that may indicate a process weakness rather than intentional manipulation.
For organizations that want a stronger approval layer, restricting user permissions is the most effective complement to the Audit Trail. Users with full editing rights can change any transaction in an open period. By configuring role-based access so that only designated users can modify or void transactions, an administrator reduces the volume of changes that require later investigation. Setting a closing date password for prior periods adds another barrier, since any attempt to edit a transaction dated on or before the closing date triggers a password prompt that is itself logged.
Preserving the Audit Trail During Repairs
If the company file becomes damaged and requires repair, preserving the Audit Trail is essential. A QuickBooks file repair that rebuilds the database must retain the audit log intact, otherwise the forensic history is lost. Before any repair or recovery process, always work from a copy of the file and verify that the Audit Trail report runs cleanly on the result. If transactions were lost due to file corruption and recovery from the .TLG transaction log file is necessary, confirm afterward that the recovered entries appear correctly in the Audit Trail with their original user and timestamp data.
Documenting Findings
When preparing findings for an accountant or auditor, export the filtered Audit Trail report to Excel or PDF. Include the date range, the filters applied, and the report basis (cash or accrual). Pair the export with a written summary identifying the specific transactions in question, the changes observed, and the users associated with each modification. This package provides the evidentiary record needed to close an investigation and, if necessary, adjust the books with confidence.