Bank Statement Red Flags: 12 Patterns Every CA Should Catch in Ledger Scrutiny (2026)
A working list of twelve red-flag patterns to hunt for in every client bank statement: what each looks like in a raw date-wise export, why a party-wise rollup is what exposes it, and the first action to take.
By the time a client's bank statement reaches you at finalisation, it has already been sorted the least useful way possible: by date. A date-wise export answers one small question, what happened on 14 March. Ledger scrutiny asks a bigger one: who is this counterparty, how much moved between them and the client across the whole year, and does that pattern hold up.
The red flags that matter almost never live on a single row. They surface only when you collapse a year of narration variants back onto the party behind them. That collapse, from date-wise to party-wise, is the entire craft of scrutiny. A row is an event. A party is a story, and stories are where the audit risk hides.
What follows is a working list of twelve patterns worth hunting for in every statement you touch. For each: what it looks like in the raw export, why a party-wise view is what actually exposes it, and what to do once you have caught it. None of these is proof of anything on its own. Each is a trigger for a question.
Why date-wise reading hides the pattern
The same counterparty rarely appears twice under the same string. A single customer might show up as a UPI reference one week, an IMPS transfer with a beneficiary code the next, an NEFT with the trading name in caps after that, and a cheque number with no name at all at quarter-end. Every bank writes narration its own way: an HDFC statement, an ICICI one, an SBI export and an Axis file describe the same payment in four different layouts.
No one scrolling two thousand rows can hold a running total per party in their head across all those variants. So the eye slides over the pattern. A party-wise rollup does the one thing manual reading cannot: it resolves every narration variant to a single counterparty and shows the net position for the year. Once each party carries its own subtotal, the outliers announce themselves. Everything below is a specific shape those subtotals take. For the mechanics of turning raw narration into named, categorised transactions, the linked guide goes deeper.
Pro tip
Ask for the statement as .xls, .xlsx, or .csv, not as a PDF. A machine-readable export is what lets you roll narration up by party in the first place.
The 12 red flags at a glance
Use this as a scan sheet. The columns are deliberately in the order you would work them: recognise the pattern, understand why the raw export hides it, see what the rollup surfaces, then act.
| # | Red flag | Why it hides date-wise | What a party-wise rollup reveals | First action |
|---|---|---|---|---|
| 1 | Party concentration | Credits spread across many dates | One name dominates the credit side | Confirm arm's length, consider disclosure |
| 2 | Undisclosed related-party flows | Reads as ordinary vendor payments | Aggregate ties back to a director or group entity | Test against related-party list; 40A(2)(b), 2(22)(e) |
| 3 | Out-and-back loans | Outflow and inflow are months apart | Same party shows a debit and a matching later credit | Confirm; check 269SS/269T and interest/TDS |
| 4 | Round-tripping | Debit and credit a few days apart | Money leaves and returns with no trade between | Trace both legs, test year-end cut-off |
| 5 | Circular transfers | Each leg in a different account and week | Funds loop back to origin with no substance | Map the loop, question substance |
| 6 | Round-sum transfers | A clean round figure looks tidy | A party billed only in exact round sums | Reclassify to loan or capital; check TDS |
| 7 | Large cash deposits and withdrawals | Cash entries scattered all year | Yearly cash-in and cash-out totals stand alone | Reconcile to cash book; check SFT and 269ST |
| 8 | Structuring below thresholds | Small amounts look unremarkable | Repeated receipts just under a statutory line | Document, question in writing, weigh reporting |
| 9 | Dormant-then-active spikes | Year-end burst is easy to scroll past | Large flows concentrate in the closing weeks | Intensify cut-off testing; confirm |
| 10 | Reference-number-as-party junk | Narration is all machine reference | Rows refuse to resolve and fill the suspense bucket | Chase the party behind every material row |
| 11 | Suspense-heavy narrations | Cannot be measured without reading all rows | Share of value left unattributed is quotable | Work suspense by value, largest first |
| 12 | Mismatched interest vs AIS | Interest credits blend into the noise | Total bank interest sits next to the AIS figure | Reconcile to AIS and 26AS; carry to ITR |
Concentration and hidden relationships (flags 1 to 3)
Concentration is about who dominates the statement, and whether that dominance is being disclosed.
1. Party concentration. A single counterparty accounts for the bulk of the year's credits.
- Date-wise: receipts are spread across dozens of dates, so nothing looks unusual on any one day.
- Party-wise: one name sits at the top of the credit side by a wide margin. That is a revenue-concentration and going-concern signal, and sometimes the sign that the client's many customers are really one.
- What to do: confirm the party is genuinely third-party and at arm's length, corroborate with invoices and agreements, and consider whether concentration disclosure is warranted.
2. Undisclosed related-party flows. Money moving to or from directors, partners, relatives, or sister concerns that never made the related-party list.
- Date-wise: a transfer to a plausible-looking trading name reads as an ordinary vendor payment.
- Party-wise: the aggregate to a party whose name, address, or UPI handle ties back to a director or a group entity rises to the surface, as do directors' current-account swings.
- What to do: test the rollup against the related-party list you were given, and the one you were not. Keep 40A(2)(b), deemed dividend under 2(22)(e) for closely held companies, and AS 18 / Ind AS 24 disclosure in view.
3. Out-and-back loans. Money leaves to a party and a near-equal amount returns from the same party months later.
- Date-wise: the outflow in April and the inflow in November are hundreds of rows apart and never connected.
- Party-wise: the same counterparty carries both a large debit and a matching later credit, the signature of a loan given and repaid, or an advance that round-tripped.
- What to do: obtain confirmation, check whether any leg touched cash against the 269SS and 269T limit of Rs 20,000, and verify whether interest and TDS were handled.
Circularity and layering (flags 4 to 6)
These three are about movement that exists to create an impression rather than to settle a real trade.
4. Round-tripping. Funds go out and come back, often to inflate turnover or dress up a year-end balance.
- Date-wise: a debit and a similar-sized credit a few days apart look like two unrelated transactions.
- Party-wise: money that leaves to one party and returns from the same or a linked party, with no goods or service in between, forms a visible there-and-back.
- What to do: trace both legs, test the cut-off around year-end, and ask what underlying transaction the movement supposedly represents.
5. Circular transfers. A loop across group or associated accounts, A to B to C and back to A.
- Date-wise: each leg sits in a different account and a different week, so the loop is invisible.
- Party-wise, read across the group: funds that return to their origin with no economic substance close the circle.
- What to do: map the full loop, question the substance of every leg, and consider disclosure and disallowance.
6. Round-sum transfers. Exact round figures, Rs 5,00,000 or Rs 2,00,000, with none of the odd-rupee texture of real invoices.
- Date-wise: a clean round amount looks tidier than a messy one, not more suspicious.
- Party-wise: a counterparty whose entire relationship is round numbers is almost never a trade debtor or creditor. It is financing, a loan, or capital, frequently misfiled as sales or an expense.
- What to do: reclassify to loan or capital, and check documentation, interest, and TDS accordingly.
Cash and threshold behaviour (flags 7 to 9)
Cash is where the statutory thresholds bite, so this cluster is as much about the law as about the pattern.
7. Large cash deposits and withdrawals. Aggregate cash movement that the client's books may not fully explain.
- Date-wise: CDM and branch cash entries are scattered through the year, individually unremarkable.
- Party-wise, treating cash as its own bucket: the yearly cash-in and cash-out totals stand on their own. Watch the reporting triggers: aggregate cash deposits of Rs 10,00,000 in savings or Rs 50,00,000 in a current account are SFT-reportable, and any single cash receipt of Rs 2,00,000 or more engages 269ST.
- What to do: reconcile the bank cash to the cash book, establish the source, and tie the totals to AIS and SFT.
8. Structuring and splitting below thresholds. Amounts parked deliberately just under a statutory line.
- Date-wise: Rs 19,000 on Monday and Rs 19,500 on Wednesday read as two small deposits.
- Party-wise, clustered by amount: repeated receipts just under Rs 20,000, or under the Rs 2,00,000 of 269ST, or under the Rs 10,000 of 40A(3), point to splitting rather than coincidence.
- What to do: this is a hard flag. Document the pattern, put the question to the client in writing, and weigh reporting and disallowance. The cash-transaction guide sets out the sections in full.
9. Dormant-then-active spikes. A quiet account that erupts near year-end.
- Date-wise: months of small activity, then a burst in February and March that you only notice if you happen to scroll there.
- Party-wise with a timeline: a sudden concentration of large flows, often from a new party, clustered in the closing weeks.
- What to do: raise the intensity of your cut-off testing on those weeks and confirm the closing transactions directly.
Worth knowing
A threshold breach or a structured pattern is a trigger for enquiry, never proof of wrongdoing on its own. Record the client's explanation before you conclude.
Data quality and reconciliation (flags 10 to 12)
The last three are about the quality of the data itself, and the honesty of what you do with the rows you cannot place.
10. Reference-number-as-party junk. Narrations that are all machine reference and no name.
- Date-wise: rows read as `UPI/2247xxxx` or `NEFT-SBINxxxx` with nothing human in them, by the hundred.
- Party-wise: these refuse to resolve to a counterparty and collect in Suspense or Unknown, taking real parties down with them.
- What to do: do not wave the bucket through. For every material row in it, chase the underlying party from the client or the bank. Clean categorisation is what keeps this bucket small.
11. Suspense-heavy narrations. The size of the unattributable pile is itself a finding.
- Date-wise: you cannot even measure it without reading every row.
- Party-wise: the share of total value sitting in Suspense is a number you can quote. A statement where a large slice of value is unattributed has been skimmed, not scrutinised. An honest suspense bucket is a feature: it tells you precisely what still needs answers.
- What to do: work the suspense by value, not by row count, and resolve the largest items first.
12. Mismatched interest versus AIS. Bank interest that does not agree with what the department already knows.
- Date-wise: interest credits land quarterly and blend into the noise.
- Party-wise: the year's total bank interest, rolled up as one figure, sits next to the AIS interest entry and the Form 26AS TDS. A gap means under-reported income or mis-deducted tax.
- What to do: reconcile bank interest to AIS and carry the reconciled figure through to the ITR summary.
Turning red flags into a working scrutiny routine
A red flag is only useful if it ends in a documented question and answer. A working routine looks like this:
- Rollup first, read second. Convert the date-wise export to a party-wise ledger before you form any view. Judge parties, not rows.
- Sort by value. Scrutiny time is finite. Rank counterparties and the suspense bucket by rupee value and start at the top.
- Run the threshold sweep. Pass the whole statement against the Rs 20,000, Rs 2,00,000, Rs 10,000, and SFT lines in one go, rather than spotting them by eye.
- Reconcile outward. Tie interest, TDS, and cash totals to AIS, 26AS, and the books, then carry the numbers into the ITR summary.
- Write the suspense down. Whatever will not resolve stays in an honest Unknown bucket with a note, so next year's file, or a reviewer, can see exactly what was open.
Most of this is mechanical, and mechanical work is where a person loses hours and misses the one row that mattered. The tedious middle, resolving narration variants to one counterparty and rolling a year of movement into a party-wise ledger, is exactly what Greenote automates from an Excel or CSV statement, so the judgement, which is yours alone, is what you spend your time on. If you are weighing whether to keep doing the rollup by hand, the comparison of manual Excel versus an automated pass and the wider software round-up for 2026 are worth a read.
Pro tip
Keep a one-line note against every counterparty you cleared, not just the ones you flagged. The clean parties are the ones a reviewer will ask you to justify.
Conclusion
None of these twelve patterns is a verdict. Each is a trigger for a question you put to the client and document the answer to. What they share is that they are patterns, not events, and a date-wise statement is built to hide patterns. The moment you collapse the year onto the party behind each row, concentration, circularity, structuring, and the fat suspense bucket all stop being invisible.
So the practical takeaway is small and stubborn: never scrutinise a statement in the order the bank printed it. Roll it up party-wise, sort by value, sweep the thresholds, reconcile to AIS, and be honest about what you could not place. Do that on every file, whether you resolve the rollup by hand or let Greenote do the mechanical part, and the red flags that matter will find their way to the top of the page instead of hiding on row 1,847.
Frequently asked questions
What is the single most useful way to review a bank statement for red flags?
Convert it from date-wise to party-wise first. Almost every meaningful red flag is a pattern across a counterparty's transactions for the year, not something visible on a single dated row. Once each party carries its own subtotal, concentration, out-and-back loans, and round-tripping become obvious.
Which cash thresholds should I keep in view during scrutiny?
The recurring ones are Rs 20,000 for accepting or repaying a loan or deposit in cash (269SS and 269T), Rs 2,00,000 for receiving cash (269ST), and Rs 10,000 for cash expenditure disallowance (40A(3)). For SFT, aggregate cash deposits of Rs 10,00,000 in savings or Rs 50,00,000 in a current account are reportable.
What should I do with rows I cannot attribute to any party?
Keep them in an honest Suspense or Unknown bucket rather than forcing a guess, then work that bucket by rupee value and resolve the largest items first. The size of the unattributed pile is itself a finding: a statement with a large share of value in suspense has been skimmed, not scrutinised.
Does a red flag mean the client has done something wrong?
No. Every pattern here is a trigger for a question, not a conclusion. Round sums, threshold-adjacent amounts, or a year-end spike each warrant an enquiry and a documented explanation, and many turn out to be perfectly legitimate once explained.
See it on your own statement
Upload an Excel or CSV bank statement and get back a party ledger, categorised transactions and an ITR-ready summary. First statement free. Files are processed and deleted, never stored.
Keep reading
Ledger Scrutiny Checklist for Finalisation (2026): What to Verify Before You Sign
A stage-by-stage checklist a practising CA can print and run before signing a finalisation or tax audit, from statement completeness and the party-wise rollup to the Section 269 cash-law tests, AIS and SFT tie-out, and suspense clearance.
How to Analyse a 10,000-Row Bank Statement Without Excel Falling Over (2026)
Ten thousand rows will not crash Excel, but the pivots, TEXTSPLIT formulas, and party-wise rollup you stack on top will. Here is where large bank statements actually break, and how to get a clean, audit-ready read.
How to Prepare Bank Statement Working Papers for a Section 44AB Tax Audit (2026)
A defensible bank-statement working-paper file is the spine of a 44AB audit. Here is what it contains, how it feeds Form 3CD clauses 31, 21 and 34, and the documentation discipline that lets it survive a scrutiny notice three years later.