Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Macy’s initially estimated that erroneous delivery-expense accounting had misstated cumulative expenses by $132 million to $154 million. After an investigation, the company reported a figure of approximately $151 million. Its filings describe deliberate entries and falsified supporting records, along with a weakness in how controls were designed—not proof that a particular accounting, audit, or GRC system would have prevented the conduct. Macy’s later reported remediation and effective internal controls, while its auditor cautioned that controls provide reasonable, not absolute, assurance.
What Macy’s disclosed—and how the amount changed
In a Form 10-Q filed December 12, 2024, Macy’s reported that an independent investigation and forensic analysis found approximately $151 million in cumulative delivery expenses had been misstated. The company had first disclosed an estimate of approximately $132 million to $154 million on November 25, 2024; $154 million was the upper end of that range, not the final amount reported after the investigation.
According to the filing, a single employee responsible for small-package delivery-expense accounting intentionally made erroneous accrual entries and falsified supporting documentation. The activity covered the fourth quarter of 2021 through the third quarter of 2024. Macy’s said the affected financial statements should be revised. The filing also said a misstatement of approximately $9 million in the first half of fiscal 2024 was adjusted in total during the third quarter of 2024.
| Stage | What Macy’s reported |
|---|---|
| November 25, 2024 | Initial public estimate: approximately $132 million to $154 million in cumulative delivery expenses. |
| December 12, 2024 Form 10-Q | After investigation and forensic analysis: approximately $151 million, covering Q4 2021 through Q3 2024. |
| First half of fiscal 2024 | Approximately $9 million of misstatement, adjusted in total during Q3 2024. |
The discovery sequence matters. Macy’s said the issue was identified while the company was preparing its November 2, 2024 interim financial statements, after which management initiated an independent investigation. The filings do not say that the external audit detected the conduct.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The weakness was in control design, not simply in the accounting software
Macy’s described a material weakness in the design of controls over manual journal entries for delivery expenses and certain other non-merchandise expenses, as well as reconciliations of the related accrued liabilities. The filing said the design did not account for the possibility that an employee could circumvent controls. It also identified deficiencies in obtaining or generating and using relevant, quality information, including validating that information was reliable.
That distinction is important: a company can have accounting software, approval steps, and reconciliations on paper while still lacking controls that reliably challenge unusual entries or verify the evidence behind them. Macy’s filings identify the kinds of processes involved, but do not disclose every detail of how the employee made each entry. They also do not name an accounting platform or GRC product.
Rank #2
- Used Book in Good Condition
Controls that address different points in the process
| Control question | What it is meant to address |
|---|---|
| Who can initiate and approve an entry? | Separating responsibilities can make it harder for one person to create and authorize an adjustment without independent scrutiny. |
| Does the reconciliation test the underlying balance? | A reconciliation should do more than repeat or accept the same information used to record the accrual; it should challenge completeness and support. |
| Can the evidence be trusted? | Controls depend on the quality and reliability of source data and documents, not only on whether a review box is checked. |
| Would an exception be noticed in time? | Preventive approvals and timely, independent detection serve different purposes; a process needs to consider both. |
Why the case does not prove audits or GRC systems are ineffective
An audit opinion on internal control is an assessment of a company’s controls at a stated date under a defined framework. It is not a guarantee that every instance of misconduct will be prevented or found. In its report for the year ended January 31, 2026, KPMG said Macy’s maintained effective internal control over financial reporting as of that date using COSO’s Internal Control—Integrated Framework (2013). KPMG described risk-based testing and explained that internal controls have inherent limitations and may not prevent or detect misstatements.
The later effective-control opinion and the earlier material weakness describe different points in time. Macy’s fiscal 2024 annual report said management reassessed employee-circumvention risk, implemented and redesigned process-level controls over delivery and certain other non-merchandise expenses and related accrued liabilities, and validated the reliability of supporting information. Management concluded the weakness had been remediated as of February 1, 2025; KPMG issued an unqualified opinion on internal-control effectiveness as of that date.
Those disclosures support a lesson about the limits of assurance: controls and audits can reduce risk and provide reasonable assurance, but neither amounts to a promise of perfect detection. They do not show that an audit team discovered the conduct, nor that the same weakness remained open after Macy’s reported remediation.
Expert commentary offers context, not a finding about this incident. CIO quoted auditor and GRC specialist JR Kunkle describing accruals as an area that can be difficult to audit because estimates involve judgment. Robert Kramer of Moor Insights & Strategy said stronger internal controls can include multi-employee workflows. These views are consistent with the general value of independent review, but Macy’s filings do not establish that a particular workflow product—or any one technology—would have caught these entries.
Rank #4
Practical control lessons for finance teams
The disclosures point to questions that organizations can ask about their own close and expense processes. These are operational lessons from the weakness and remediation Macy’s described, not claims about undisclosed details of the employee’s conduct.
- Assess how one employee could bypass an approval, supporting-document, or reconciliation control, including through access rights and manual adjustments.
- Where practical, separate entry initiation, review, and reconciliation so that no single person controls the full chain.
- Test whether accruals are complete and supported, rather than treating a signed reconciliation as evidence that the balance is correct.
- Validate the source data and documents that reviewers rely on, including whether the information is reliable and independently traceable.
- Consider whether exception review can identify unusual entries soon enough to address errors before they accumulate across reporting periods.
For escalation, Macy’s governance page says concerns about accounting, internal accounting controls, or auditing matters are referred to the Audit Committee and may be submitted anonymously or confidentially. That describes a reporting channel; it is not evidence about whether such a channel was used in this incident.
What the filings establish—and what they leave unknown
The filings establish Macy’s reported amount, the period involved, the company’s description of the employee’s actions, the control-design weakness, the remediation it reported, and the later dates on which management and KPMG expressed effective-control conclusions. They do not identify the employee, state a motive, describe every entry’s mechanics, or identify a software system whose presence or absence caused the failure.
For readers evaluating what an audit or controls opinion means, the most defensible takeaway is specific: formal systems and an effective opinion can support reliable reporting, but their value depends on control design, independent challenge, and trustworthy evidence—and they cannot eliminate all risk of circumvention or undetected misstatement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




