Forensic audit: what it is, what investigators examine, and how to prepare
A forensic audit is an examination of financial records, contracts, and communications to find, quantify, and evidence fraud or misconduct in a way that will hold up in an inspection, a disciplinary proceeding, or litigation. This guide covers how it differs from a statutory audit, what triggers one, what investigators look at, how fraud schemes are detected, and how evidence is preserved.
What is a forensic audit?
A forensic audit is a targeted investigation, not a periodic assurance exercise. A statutory audit gives an opinion on whether the financial statements are true and fair, works to a materiality threshold, and relies on sampling. A forensic audit starts from a specific allegation, tests the full population of relevant transactions, and produces findings that each point back to a source document.
The output is different too. A statutory audit produces an opinion; a forensic audit produces a report that states what was tested, what was found, the amount involved, and the evidence behind each finding — written so a regulator, a disciplinary panel, or a court can follow it.
What triggers a forensic audit?
An investigation is usually set off by one of the following:
- A whistleblower complaint through a hotline or to the audit committee
- A regulator's letter or a sector-specific reporting obligation
- A lender's demand following a covenant breach or a suspicious drawdown
- A red flag surfaced during transaction due diligence
- The statutory auditor's escalation of a suspected fraud under SA 240
- A board or audit-committee directive after an internal concern
- An insurance claim requiring quantification of a loss
Whatever the trigger, the first days matter most: preserve evidence, involve legal so privilege is protected, issue a legal hold, and avoid alerting the people involved before records are secured.
What do forensic auditors examine?
Forensic auditors work from the complete population of relevant records rather than a sample. A typical engagement pulls:
- The general ledger and every journal entry, with user, timestamp, and source
- Accounts payable, payment files, and the vendor master with its change history
- Bank statements for all accounts, in native form
- Procurement, tender, and contract files
- Payroll and HR data, including joiners and leavers
- Expense claims and corporate-card data
- Email and chat for the named custodians
- External data: company-registry and director filings, GST data, sanctions and PEP lists, litigation and property records
The point of collecting change logs, not just current values, is that concealment often lives in the history — a vendor bank account switched for one payment run and switched back.
How is fraud detected?
Each scheme has known red flags and specific data-driven tests, run across the entire population because a deliberate, concealed, low-frequency scheme is likely to fall outside any sample.
- Procurement and vendor fraud: match vendor bank accounts, addresses, and tax IDs against the employee master; detect purchase orders split to sit just under an approval limit; reconstruct the tender timeline for single-bid awards.
- Payments fraud: duplicate-payment detection including near-duplicates; trace circular and round-tripping flows; flag vendor bank-detail changes just before a payment.
- Payroll fraud: join payroll to the leaver register for payments after termination; group by bank account to find one account paying several employees.
- Revenue manipulation: profile manual and top-side journal entries near period end for round numbers, rare account pairings, and unusual users.
- Related-party fraud: build an entity graph from registry data and compare the transacting parties to the declared related-party register.
How is evidence preserved so findings hold up?
Findings are only as strong as the trail behind them. A legal hold suspends routine deletion across every system in scope. Key mailboxes and devices are forensically preserved before anyone searches them, because reviewing a live mailbox changes metadata. Every acquired file and dataset is hashed at the point of collection and recorded in a custody log with its source, time, and custodian.
In India, the certificate for electronic records under Section 63 of the Bharatiya Sakshya Adhiniyam 2023 (the successor to Section 65B of the Indian Evidence Act) is prepared at collection, not months later. Alignment to ISO/IEC 27037 covers the identification, collection, and preservation of digital evidence. Every analysis is reproducible from the source data and the exact test that produced it.
How long does a forensic audit take?
A focused engagement typically runs four to six weeks once data access is in place. The analysis configures quickly. The longest step is almost always securing complete, clean extracts from the ERP, bank, and communication systems, and preserving the evidence properly before review begins — which is why scoping and data access come before fieldwork.
Get the full Forensic Audit Readiness Guide
A 12-page PDF: the first 72 hours, an evidence source map covering 13 systems, chain-of-custody standards, a fraud-scheme detection-test matrix across eight scheme types, and a printable pre-engagement checklist.
This guide is general information for professionals, not legal advice. Investigations raise legal and regulatory questions that depend on your facts and jurisdiction.