Try it now, capture a real invoice
Your file is processed for the demo only and never stored.
The search for unrecorded liabilities is the audit procedure used to find payables that existed at the balance sheet date but were never recorded. It tests the completeness assertion, and it works mainly by reviewing cash disbursements and invoices processed after period end, tracing each one back to when the goods or services were actually received. If the obligation was incurred before the cutoff, it belonged in accounts payable.
Last updated August 2026.
Auditors call it SUL. Your AP team calls it the reason someone spends two days in February pulling January check registers. This guide covers what the procedure actually consists of, what your auditor will ask for, and why the invoices nobody has entered yet are the ones that cause the misstatement.
What is the search for unrecorded liabilities?
It is a cutoff procedure. The auditor is not checking whether the payables you recorded are real, which is an existence question. They are checking whether payables you should have recorded are missing, which is a completeness question, and understatement is much harder to spot than overstatement because there is no entry to look at.
The logic behind the test is simple: most liabilities that existed at year end get paid in the weeks right after year end. So if you look at what the company paid in January and February, and work backward to when each obligation was incurred, anything with a December service or receipt date should already be sitting in the December payables balance. If it is not, you have found an unrecorded liability.
What assertion does the search for unrecorded liabilities test?
Completeness. That is the assertion most at risk for liabilities and expenses, and it runs opposite to the risk on assets. Management has an incentive to overstate assets and revenue, and a matching incentive to understate liabilities and expenses, because leaving a bill unrecorded improves both the balance sheet and the income statement at the same time.
The procedure often picks up occurrence and cutoff evidence along the way, but completeness is the point. When an auditor writes up an SUL finding, what they are saying is that the payables balance was understated at the reporting date.
What audit procedures are used in the search for unrecorded liabilities?
SUL is not one test, it is a set of overlapping ones. A thorough auditor runs several, because each catches a different way an obligation goes missing.
| Procedure | What the auditor examines | What it catches |
|---|---|---|
| Subsequent disbursements review | Check registers, ACH files, and wire logs for the period after year end, above a scope threshold | Obligations incurred before cutoff and paid after it |
| Post-close voucher register scan | Invoices entered into the payables system after year end but not yet paid | Liabilities recorded in the wrong period |
| Unentered invoice file | The physical or electronic pile of invoices not yet keyed anywhere | The obligations no system knows about |
| Open purchase orders and unmatched receipts | Receiving reports with no matching voucher at period end | Goods received, invoice not yet arrived |
| Vendor statement reconciliation or confirmation | Supplier statements compared to your recorded balance | Missing invoices your largest vendors already billed |
The subsequent disbursements review is the core of it. Each selected payment gets traced back to the underlying vendor invoice and receiving report to establish when the obligation arose. A payment made in January for goods received in December belonged in December.
One nuance auditors get wrong more often than they should: sampling subsequent disbursements alone misses anything that was invoiced but has not been paid yet. The CPA Journal has argued for merging and deduplicating the post balance sheet payables journal population with the disbursements population, precisely so unpaid post-close invoices are not left out of scope.
How far past year end does the search for unrecorded liabilities go?
Conventional practice extends testing through the last day of fieldwork, or the audit report date. The risk-based view is that the period should be defined by how quickly the company actually pays, not by when the audit happens to finish.
A company that pays on net 30 and runs a weekly check run will have surfaced almost everything within six to eight weeks. A company stretching payments to preserve cash may still be sitting on December obligations in April, and during periods of financial stress that window needs to lengthen. Extending the test period arbitrarily has its own cost: errors projected from an overly long window come back overstated and unreliable.
What does the auditor ask AP for?
You can shorten fieldwork considerably by having these ready before anyone asks. All five come out of the AP system, and all five are questions about the same cutoff from different directions.
| Item | What it needs to show |
|---|---|
| Subsequent disbursements listing | Every payment after period end with vendor, amount, date, and invoice reference |
| Post-close invoice register | Invoices entered after cutoff, with the service or receipt date, not just the invoice date |
| Unprocessed invoice log | Anything received but not yet entered, with the date it arrived |
| Year-end accrual schedule | What you accrued, for which vendors, and the basis for each estimate |
| AP aging at period end | Tied to the general ledger control account |
The one that trips teams up is the second row. Auditors want the date the goods or services were received, not the date on the invoice, because a vendor can date an invoice January 4 for work finished December 12. If your system only stores the invoice date, someone is opening PDFs one at a time to find the service period, and the month-end close gets longer every quarter.
Why unentered invoices are where the misstatement hides
Here is the uncomfortable part. The accruals you booked deliberately are rarely the problem, because you thought about them. The problem is the invoice that arrived on December 28, went into a shared mailbox, and was still unopened on January 9.
It is not in the voucher register, so the post-close scan misses it. It is not paid, so the disbursements review misses it. It only shows up if the auditor asks for the unentered invoice file, or if a vendor statement flags it. Auditors are explicitly trained to be alert to invoices sitting unentered on someone's desk, and when a client has no reliable control over incoming invoices, extended procedures like payables confirmations become warranted. That is not a good outcome for you: confirmations mean more fieldwork hours and a control conversation you did not want to have.
The structural fix is to make receipt of an invoice an event the system records, separate from entry. If every invoice that lands in the AP mailbox is captured and timestamped on arrival, including the ones nobody has coded yet, the unentered pile stops being invisible. Teams that route supplier bills through a monitored address can pull the attachments and their data out of the mailbox automatically the moment they land, which turns a shoebox into a dated queue.
How to stop failing the test every year
Three controls do most of the work, and none of them require a new ERP.
Timestamp every invoice on arrival. Date received is a control field, not a convenience. It is what lets you prove the completeness of your accrual instead of asserting it.
Capture the service period, not just the invoice date. If line-level extraction pulls the period covered off the document, cutoff becomes a filter you can run rather than a manual review of PDFs.
Reconcile statements from your largest vendors monthly. If twenty vendors make up most of your spend, vendor statement reconciliation will find the missing invoice long before the auditor does, and it costs an hour a month.
Automating capture and approval is what makes all three practical at volume. When invoices are read on arrival, coded with their service dates, and routed through a queue with an audit trail, the subsequent disbursements review stops producing surprises, because there is nothing unrecorded left to find. That is the same evidence base auditors ask for in every other AP test, which is why accounts payable audit software and the controls behind it tend to pay for themselves during fieldwork rather than after it. If your last audit produced a deficiency around cutoff or approvals, the preventive side matters more than the detective side, and AP internal controls software is where that starts.
The short version
The search for unrecorded liabilities tests completeness by working backward from what you paid and processed after period end. It is beatable, but not by preparing better schedules in February. It is beaten in December, by knowing what invoices you are holding and when they arrived. Every hour AP spends reconstructing that after the fact is an hour the audit was always going to charge you for.
Related reading: accrued liabilities and how to book them, the accounts payable aging report, and accounts payable internal controls.
Stop keying invoices by hand
AutoPayables captures vendor, amounts and dates from any invoice with AI, routes approvals, and syncs to QuickBooks, Xero, NetSuite or Sage Intacct.
Keep reading
Accounts Payable Audit: Procedures and Checklist
An accounts payable audit checks your payables for accuracy, fraud, and control gaps. Learn the audit procedures, a checklist, and what auditors look for.
Internal Audit vs External Audit: Key Differences Explained
How internal audit and external audit differ in purpose, scope, reporting line, and standards, plus how the two work together and what each one tests in AP.
Accrued Liabilities: Meaning, Examples, and Journal Entry
Accrued liabilities are costs you incurred but have not yet paid or been billed for. See examples, the journal entry, and how they differ from accounts payable.