Forensic accounting
Forensic data extraction from accounting systems
Forensic data extraction from Finbryn pulls a complete, audit-trail-intact transaction history out of QuickBooks Online, Xero or NetSuite before any tracing or fraud-indicator work starts. The export is read-only against the live file, includes voided and deleted entries the platform still retains, and reconciles to a control total first.
Management report
Illustrative client ยท August 2026
USD
| Line | Aug | Jul | |
|---|---|---|---|
| Revenue | 142,380 | 131,904 | +10,476 |
| Cost of sales | (51,260) | (48,115) | (3,145) |
| Gross profit | 91,120 | 83,789 | +7,331 |
| Payroll | (46,300) | (45,900) | (400) |
| SoftwareNoted | (6,480) | (5,490) | (990) |
| Rent | (8,000) | (8,000) | 0 |
| Other operating | (9,215) | (9,870) | +655 |
| Net income | 21,125 | 14,529 | +6,596 |
Reviewer's note
Software is up on last month after two seats were added mid-month. Revenue includes one milestone invoice that will not repeat next month.
Illustrative. An example of the document, not a client's figures.
Every forensic engagement runs on data, and the way that data comes out of the accounting system matters almost as much as what happens to it afterward. Pull an incomplete export, skip the audit trail, or work directly inside the live file, and the analysis built on top inherits that weakness whether anyone notices at the time or not. Extraction is the first thing we do, and we treat it as a distinct, documented step rather than a quick download folded into whatever comes next.
The mechanics differ by platform. QuickBooks Online keeps an Audit Log of user activity separate from the transaction ledger itself, so a deleted invoice or a changed check amount can often still be traced even after it disappears from the register the client sees day to day. Xero's audit trail works on a similar principle, and NetSuite's system notes track field-level changes across a longer retention window, which matters when a matter reaches back two or three years. We pull whichever export format preserves the most of that history rather than defaulting to the fastest one, because a fast export that drops voided entries or user attribution is not actually faster once someone has to go back for a second pull mid-engagement.
Before anything gets traced or tested, the export is reconciled to a control total, usually the reported cash or revenue balance in the live system at the date of extraction. That single check catches a partial pull, a missing bank feed, or a sub-ledger that never synced, and it catches it before hours go into analysis built on a gap. We log the reconciliation the same way we log everything else in a forensic file: dated, with the control figure shown next to the export figure, so the starting point of the whole engagement is itself documented.
None of this touches the live file. Extraction runs against a read-only export or a view-only connection, so the client's day-to-day bookkeeping keeps running through the engagement without interruption and without risk that the review itself becomes the thing that altered a record someone later asks about.
What is included
A full transaction-level export from the accounting system in use, pulled at the widest available detail level rather than a summary report. Where the platform retains a log of deleted, voided or edited entries, that log comes out alongside the transaction data, tagged to the user who made each change and when. The export is matched to a control total from the live system before it is handed off for tracing, fraud-indicator testing or reconstruction, and everything is delivered as a working file organized by account and period so the next phase of the engagement can start immediately.
How the process works
We start with view-level access to the accounting system, confirm the reporting period and accounts in scope with whoever engaged us, then run the export in the format that keeps the most detail, typically a full transaction listing plus the platform's own audit or activity log. QuickBooks Online, Xero and NetSuite each expose this differently, so the export method is chosen per platform rather than run the same way everywhere. Once pulled, the data is reconciled to a control total, organized into a working file, and a short extraction memo is written noting the date range covered, anything the platform could not retrieve, and the control totals used to confirm completeness.
Who this is for
Counsel or a business owner who has already scoped a forensic matter, whether that is a suspected diversion, a partner dispute or an insurance claim, and now needs the underlying data pulled cleanly before the substantive work begins. It also fits a board or audit committee opening an internal investigation who need a preserved, dated export before anyone else touches the file, and any situation where a system is about to be migrated, closed, or handed to a new bookkeeper and the transaction history needs to be captured first.
Common problems we fix
A prior export that was a summary report rather than transaction detail, which looks complete until someone tries to trace an individual payment and finds it was never broken out. An export pulled with edit access still open on the live file, leaving the door open to a later question about whether the record was touched during the review. A missing reconciliation step, so nobody can say with confidence the export matches what the system actually held on the extraction date. And gaps caused by a sub-ledger, a payroll processor feed or a payment gateway that syncs into the main system but was never pulled separately, leaving a hole in the transaction history that only shows up once tracing hits a dead end.
Software and integrations
Extraction runs against whichever system the business already uses: QuickBooks Online, Xero, NetSuite or, less often now, Sage Intacct. Each platform's own audit or activity log is pulled alongside the transaction data rather than relied on as a substitute for it. Where bank or card data sits outside the accounting system, in a bank's own portal or a payment processor's dashboard, that gets pulled as a separate, dated export and reconciled the same way. Microsoft Excel is where the combined working file gets organized once everything is out of the source systems.
What it costs
Extraction is quoted as part of the overall forensic engagement rather than as a standalone fixed fee, since the time it takes depends on how many systems and accounts are in scope, how far back the period runs, and how much of the audit trail the platform still retains at that age. A single-entity QuickBooks Online extraction covering one fiscal year is a small piece of a larger engagement; a multi-entity pull spanning several systems and several years is scoped and quoted on its own before work starts. See the rate card for how our standard monthly bookkeeping tiers are priced; forensic and investigative work is quoted separately after a scoping call.
How we measure quality
The test is simple: does the extracted total tie to the control total from the live system, and can every figure in the export be traced back to the system it came from. A senior reviewer reviews the reconciliation before the export moves to the next phase of the engagement, and reviews the extraction memo for completeness. If a platform cannot retrieve a piece of history, deleted user-activity records older than the platform's retention window, for example, we say so in writing rather than let a gap pass unnoted.
Preserving admissibility from the first pull
A workpaper only holds up in front of counsel, a mediator or an insurer if the chain from source system to finished exhibit is unbroken, and that chain starts at extraction. We date every export, note who pulled it and from what access level, and keep the original export file untouched once it is in hand so any later question about what the data looked like on a given date can be answered from the file itself rather than from memory. This matters most in matters that may eventually involve a testifying expert, where the underlying extraction is exactly the kind of detail opposing counsel will ask about first.
How we work
The process
- 1
Scope and access
Confirm which accounts, entities and time period are in scope, then request view-level access to the live accounting system rather than edit rights.
- 2
Platform-specific export
Run the widest available transaction export for the platform, plus its audit log or user-activity log where the platform retains one.
- 3
Control total reconciliation
Match the exported total to a control figure from the live system at the extraction date, flagging any variance before proceeding.
- 4
Gap check
Confirm no sub-ledger, payment processor feed or payroll feed was left out of the pull, and pull any that were separately.
- 5
Working file build
Organize the reconciled export into a working file by account and period, ready for tracing, testing or reconstruction.
- 6
Extraction memo
Document the date range, method, control totals and any retrievability limits in a short memo attached to the working file.
Forensic data extraction from accounting systems
Common problems we fix
The problem
How we fix it
- A prior export was a summary report, not transaction detailRe-pull at full transaction level so individual payments can be traced instead of only account totals.
- Extraction was run with edit access still openMove to view-only access before pulling, so the live file cannot be altered during the review.
- No reconciliation was done against a control totalReconcile the export to the live system's reported balance at the extraction date before analysis starts.
- A payment processor or payroll feed was left out of the pullPull the outside feed separately and reconcile it into the same working file.
- Deleted entries were assumed gone with no check of the audit logCheck the platform's own retained audit log before concluding a deleted entry is unrecoverable.
By the numbers
3
Source: irs.gov/businesses/small-businesses-self-employed/how-long-should-i-keep-records, September 2026
Pricing
Extraction is scoped as part of the overall forensic engagement rather than sold as a fixed add-on, since cost depends on how many systems, entities and years are in scope. See the rate card for how standard monthly bookkeeping is priced; a forensic extraction and the work that follows it are quoted separately after a short scoping call.
Forensic data extraction from accounting systems
Glossary
- Audit log
- A record, kept by QuickBooks Online and similar platforms, of who created, edited or deleted an entry and when.
- Control total
- A reported balance from the live system used to confirm an export is complete before analysis begins.
- Chain of custody
- A dated record of who accessed a data export, from where, and what was done with it.
- Read-only export
- A copy of transaction data pulled without edit rights, leaving the live accounting file untouched.
Questions
Frequently asked questions: Forensic data extraction from accounting systems
Does pulling this data change anything in the live accounting file?
No. Extraction runs read-only against the live file. We work from an exported copy, so the original record in QuickBooks Online, Xero or NetSuite is never altered by the review itself.
Can you recover entries that were deleted before the engagement started?
Sometimes, where the platform's own audit log or activity log still retains a trace of the deletion. We check what is recoverable at the start rather than promise a specific result before looking.
What access do you need to run an extraction?
View-level access to the accounting system is typically enough. We do not need edit rights to pull a complete transaction and audit-trail export, and we ask for the narrowest access that gets the job done.
How do you know the extraction is complete?
We reconcile the exported data to a control total from the live system at the extraction date before any analysis begins, so a partial or incomplete export is caught immediately rather than discovered mid-engagement.
What if the business uses more than one accounting or payment system?
We pull and reconcile each system separately, then combine them into one working file. A payroll processor or payment gateway that feeds the main ledger but is not part of it gets its own dated export.
How far back can an extraction reach?
That depends on what the platform itself retains. QuickBooks Online, Xero and NetSuite each keep different retention windows for audit and activity logs, and we confirm what is actually available for the period in question before quoting the scope.
Do you need the client's login, or can IT provide access separately?
Either works. We can use a view-only user added by the client's admin, or a temporary export provided by their IT or bookkeeping team, whichever the scoping call and the sensitivity of the matter calls for.
Is the extracted data itself something we can hand to an insurer or investigator?
Yes, once reconciled to a control total and organized into a working file, the extraction and its accompanying memo are built to be handed to whoever the engagement requires, an investigator, an insurer's adjuster or opposing counsel through your attorney.
Related services
- Forensic accountingFraud-indicator reviewScreening a set of books for the patterns that tend to accompany fraud: Benford's Law deviations, duplicate payments, round-dollar entries and vendors that do not hold up to a closer look.
- Forensic accountingTransaction tracing and funds-flow analysisTracing how money actually moved through a business's accounts, bank to bank and entity to entity, so a transfer that looked ordinary on a statement is laid out step by step for counsel or an investigator.
- Forensic accountingInternal investigation bookkeepingBookkeeping-level support for an internal investigation opened by a board, an owner or counsel: pulling and organizing the financial records a fact-finder needs without altering the underlying accounting file.
Industries
- Crypto and web3Bookkeeping for businesses holding, trading or earning cryptocurrency across wallets and exchanges.
- SaaSBookkeeping and reporting for subscription software businesses tracking recurring revenue, deferred revenue and burn.
- ManufacturingBookkeeping for small and mid-size manufacturers tracking raw materials, work in process and finished goods inventory.
Related guides
- BookkeepingHow to Design a Chart of Accounts (With SaaS and Ecommerce Examples)How to number and structure a chart of accounts, with worked SaaS and ecommerce examples and the mistakes that force a costly rebuild later.
- BookkeepingCatch-Up Bookkeeping: How to Fix Months or Years of Neglected BooksHow to triage neglected books, the documents you need, how reconstruction works, what to prioritize before a deadline, and what drives the cost.
Sources
- [1]How long should I keep records, September 2026
- [2]FTC Safeguards Rule: What Your Business Needs to Know, September 2026
- [3]QuickBooks Online, September 2026
- [4]Xero, September 2026
Next step
Talk to the team that would run your books
A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.
Need this in writing? Download a one to two page scope sheet for Forensic data extraction from accounting systems: what is included, the process, and where pricing lives.
Download the scope sheet