Skip to content

CMA Final · Cost and Management Audit

Forensic Audit: formula sheet

Full chapter guide

Key formulas

Core test of forensic audit
Suspicion or allegation → investigation → evidence → report usable in legal proceedings
Use this to explain why it differs from a statutory audit, which starts from a routine opinion on true and fair view.
Objectives checklist
Detect · Identify persons · Quantify loss · Preserve evidence · Support action · Prevent recurrence
Six-point recall list for a 'state the objectives' question.
Forensic vs statutory audit: key contrasts
Purpose · Trigger · Approach · Depth · Output · Users
Compare on these six headings and your answer is complete and well structured.
Fraud triangle
Fraud = Pressure + Opportunity + Rationalisation
All three elements are usually present. Removing any one reduces fraud risk. This is a conceptual model, not a numerical formula.
Fraud vs error test
Intentional act = fraud; unintentional act = error
Intent is the deciding factor. The effect on the financial statements may look the same.
Two main categories
Fraudulent financial reporting + Misappropriation of assets
Use these two headings first, then add corruption and cyber fraud as further types.
Stage sequence
Acceptance → Planning → Evidence collection → Analysis → Reporting → Follow-up
A memory aid for the flow. Textbooks may group or label stages differently, so explain each stage in your own words.
Loss quantification
Loss = Amount actually paid or diverted − Amount that was legitimately due
Use it to measure the financial impact of a proven fraud, for example an inflated purchase.
Typical report contents
Background + Scope + Procedures + Findings + Loss + Conclusion + Recommendations
Cover each item in a report answer. Facts are separated from opinion.
Benford's law: probability of first digit d
P(d) = log₁₀(1 + 1/d), for d = 1 to 9
Gives P(1) ≈ 30.1%, P(2) ≈ 17.6%, P(3) ≈ 12.5%, P(9) ≈ 4.6%. The nine probabilities add up to 100%.
Expected count under Benford's law
Expected count of digit d = P(d) × total number of items
Compare with the actual count. A large gap is a red flag needing follow-up, not proof.
Deviation for a digit
Deviation = Actual % − Expected %
Look at the biggest deviations first. Statistical tests such as chi-square or Z-test can judge if a gap is significant.
Order of an interview
Neutral witnesses → corroborative witnesses → suspect
Within each interview, go from open questions to closed questions, then to the key admission question.
Digital evidence lifecycle
Identify → Preserve → Collect → Examine → Analyse → Report
Use this sequence as the skeleton for any descriptive answer. Preservation comes before collection and analysis.
Integrity test
Hash(original) = Hash(forensic image) ⇒ copy is an exact duplicate
If the hash values differ, the copy cannot be treated as identical. Analysis is done on the copy, not the original.
Chain of custody record
What + Who + When + Where + How + Why (for every handling and transfer)
Any gap or undocumented transfer weakens the evidence.
Order of volatility
RAM / running processes → network connections → disk files → backups and archives
Capture the most perishable data first.
Core principle
Work on a copy, never on the original
Use write blockers so that the source device is not altered.
Elements of fraud under section 447
Act or omission or concealment or abuse of position + intent to deceive / gain undue advantage / injure interests
Wrongful gain or wrongful loss need not be proved. Intent is the key element.
Who may be affected
Company, its shareholders, creditors or any other person
Use this wording when applying the definition to a case.
SFIO route
Central Government assigns case → SFIO investigates → report to Central Government → prosecution in the Special Court
SFIO does not start on its own. Assignment by the Central Government is needed.
Admissibility of electronic record
Electronic record + statutory certificate + integrity shown = admissible as a document
Keep a hash value and a record of who handled the data (chain of custody).
Expert opinion
Expert opinion = relevant evidence, not conclusive
The court decides. Your reasoning must be explained and supported.
Fraud versus error
Fraud = intentional act involving deception; Error = unintentional mistake
Intent separates them. Both can cause a misstatement.
Auditor's responsibility under SA 240
Reasonable assurance of no material misstatement (fraud or error) + professional scepticism
It is not absolute assurance. Primary responsibility for prevention and detection lies with management and those charged with governance.
Presumed fraud risks
Revenue recognition (presumed) + management override of controls (always)
Revenue presumption can be rebutted with reasons. Management override cannot be rebutted.
Responses to management override
Test journal entries + review estimates for bias + evaluate significant unusual transactions
These procedures are performed in every audit.
Statutory audit versus forensic audit
Statutory: opinion on true and fair view, materiality, sampling. Forensic: specific suspicion, fact-finding, court-ready evidence
Use this contrast for comparison questions.
Core ethical principles
Integrity, objectivity, professional competence and due care, confidentiality, professional behaviour
Apply to the forensic auditor and expert witness.

Quick revision

  • Forensic audit aims to detect, investigate and document fraud so that findings can support legal action.
  • A statutory audit gives an opinion on true and fair view; a forensic audit targets a specific suspicion or allegation.
  • The fraud triangle has three elements: pressure (incentive), opportunity and rationalisation.
  • Weak internal controls mainly create the opportunity side of the triangle.
  • Common fraud groups include misappropriation of assets, fraudulent financial reporting and corruption.
  • Red flags are warning signs, not proof of fraud.
  • The process runs from acceptance and planning to evidence gathering, analysis and reporting.
  • Data analytics can flag duplicates, gaps in sequence and unusual patterns across large volumes of records.
  • In digital forensics, work on a copy of the data and protect the original.
  • Maintain a chain of custody so the evidence can be shown to be untampered.
  • Evidence must be relevant, reliable and admissible to be of use in a legal forum.
  • The forensic auditor must stay objective, keep confidentiality and report facts without presuming guilt.

Common mistakes

  • Saying forensic audit is just a more detailed statutory audit. Fix: State that the purpose, trigger and output differ. It is investigative, starts from suspicion and must produce court-ready evidence.
  • Using forensic accounting and forensic auditing as exact synonyms. Fix: Say forensic accounting is the broader field including quantification and litigation support, while forensic auditing is the investigative examination of records.
  • Calling every misstatement a fraud. Fix: Always test for intent. Unintentional misstatements are errors.
  • Treating red flags as proof of fraud. Fix: Write that red flags call for further enquiry and evidence. They do not prove fraud.
  • Treating a forensic audit like a statutory audit and giving an opinion on true and fair view. Fix: State that a forensic audit is allegation-driven, focuses on evidence and may support legal action.
  • Skipping the acceptance stage and starting at evidence collection. Fix: Begin with acceptance: engagement terms, scope, independence, competence and confidentiality.
  • Treating a Benford's law deviation as proof of fraud. Fix: Write that it is a red flag only. The next step is to examine the underlying documents and interview the people involved.
  • Applying Benford's law to any data, such as cheque numbers or fixed price lists. Fix: State the conditions: large datasets, naturally occurring amounts, spanning several orders of magnitude, with no assigned numbers or caps.
  • Suggesting that the auditor should examine the original computer directly. Fix: Say that analysis is done on a forensic image created with a write blocker, and the original is sealed and stored.
  • Treating chain of custody as a one-time entry at the time of seizure. Fix: State that it is a continuous log of every handling, transfer and storage event until the evidence is produced.

Exam tips

  • For 'distinguish' questions, use a two-column table-style list with at least five heads. Examiners reward structure.
  • Include the words 'evidence', 'court' and 'fraud' in your definition. These are the keywords markers look for.
  • In MCQs, watch for options that say forensic audit is compulsory annually or based only on sampling. Both are wrong.
  • For case questions, name the red flag first, then the forensic response, then the evidence to preserve.
  • Link need and scope to Indian context, such as bank frauds and money laundering, in a line or two.
  • Always bring intent into the definition and the fraud versus error answer. Examiners look for it.
  • In case questions, map facts to Pressure, Opportunity and Rationalisation explicitly. Use three labelled lines.
  • For MCQs, remember opportunity is the side controlled by internal controls, and rationalisation lives in the person's mind.