QuickBooks Desktop Forensic Audit Playbook: Investigating Missing Data and Unauthorized

Use the Audit Trail report and forensic techniques to identify who modified or deleted transactions, pinpoint when discrepancies arose, and implement approval controls to prevent recurrence.

When transactions go missing, account balances drift without explanation, or figures on a report do not match what was visible days earlier, the QuickBooks Desktop Audit Trail is the primary tool for determining what happened, who did it, and when. This playbook covers how our engineers structure a forensic audit of a QuickBooks company file, from isolating a clean copy through interpreting the Audit Trail log and implementing controls that prevent a recurrence.

Phase 1: Secure and Isolate the Company File

Before any investigation begins, create a forensic copy of the file so that the review itself does not alter the evidence. Have an administrator sign in to QuickBooks in single-user mode and create a full backup (.QBB) of the company file. Store that backup on separate media. All analysis is performed on a restored copy, never on the live working file. Confirm the QuickBooks Admin password is available, as administrator credentials are required to open the file and access the full Audit Trail without filters.

Phase 2: Establish the Scope and Timeline

Gather basic facts before touching the report: the date range in which the discrepancy was noticed, the accounts or transaction types involved, and the list of users who had access during that window. If data loss coincided with a crash or network interruption, the transaction log (.TLG) file may contain records of entries written after the last good backup. In cases involving suspected data corruption rather than user action, our engineers may also review the .TLG alongside the .QBW file for recovering transactions from the TLG file that have not yet been committed to the main database.

Phase 3: Run the Audit Trail Report

Open the restored copy and navigate to Reports > Accountant & Taxes > Audit Trail. Set the date filter to cover the period established in Phase 2 — widen it by at least one week on either side to catch late entries. The Audit Trail captures every transaction event: creation, modification, and deletion. Sort by the Last Modified By column to group activity by user, and by Date Last Modified to establish a chronological sequence. Pay attention to entries marked Deleted in the event type, as these represent transactions that once existed and were later removed.

Phase 4: Cross-Reference Against Supporting Reports

The Audit Trail alone does not explain the financial impact. Run the relevant standard reports — Trial Balance, General Ledger, and the specific register for the affected account — for the same date range and compare them against the audit log. If a check was deleted, confirm whether it reappears on the uncleared transactions list. If an invoice was modified, compare the current balance to the original amount shown in the Audit Trail entry. This cross-referencing is what separates a user error from a data-integrity problem.

Phase 5: Identify Patterns and Pinpoint Responsibility

Look for patterns: a single user modifying transactions outside business hours, a cluster of deletions on one date, or repeated edits to the same vendor or customer. The User column identifies the logged-in credentials at the time of each change. If multiple users share credentials, that practice must end — it makes attribution impossible. Document each finding with the transaction ID, timestamp, user, before-and-after values, and the nature of the change.

Phase 6: Implement Preventive Controls

Once the source of the discrepancy is understood, tighten permissions so the same event cannot recur. In QuickBooks Desktop, the Admin can edit user roles under Company > Set Up Users and Passwords > Set Up Users. Restrict delete rights to a small number of trusted users. For environments where segregation of duties matters, create a role that allows transaction entry but not deletion or editing of prior-period entries. If the file has grown large enough that performance is suffering during these reviews, consider whether a SuperCondense is warranted to reduce the file size before running extended forensic reports.

Rollback Points

At each phase, the working copy can be discarded and the process restarted from the Phase 1 backup without affecting the live file. If the investigation reveals that the live file itself is damaged rather than simply modified, stop the audit and escalate to a file repair specialist before making any further changes.

Clean Outcome

A completed forensic audit produces a dated report listing every relevant modification and deletion, the responsible user for each action, the financial impact on affected accounts, and a set of implemented permission changes that close the gap going forward.

Keep going

Your Desktop doesn’t have to end when Intuit says so.

Start with the master survival guide, or jump straight to the fix you need.