CMA Final · Cost and Management Audit
Forensic Audit: formula sheet
Key formulas
- Core test of forensic audit
- Suspicion or allegation → investigation → evidence → report usable in legal proceedings
- Use this to explain why it differs from a statutory audit, which starts from a routine opinion on true and fair view.
- Objectives checklist
- Detect · Identify persons · Quantify loss · Preserve evidence · Support action · Prevent recurrence
- Six-point recall list for a 'state the objectives' question.
- Forensic vs statutory audit: key contrasts
- Purpose · Trigger · Approach · Depth · Output · Users
- Compare on these six headings and your answer is complete and well structured.
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalisation
- All three elements are usually present. Removing any one reduces fraud risk. This is a conceptual model, not a numerical formula.
- Fraud vs error test
- Intentional act = fraud; unintentional act = error
- Intent is the deciding factor. The effect on the financial statements may look the same.
- Two main categories
- Fraudulent financial reporting + Misappropriation of assets
- Use these two headings first, then add corruption and cyber fraud as further types.
- Stage sequence
- Acceptance → Planning → Evidence collection → Analysis → Reporting → Follow-up
- A memory aid for the flow. Textbooks may group or label stages differently, so explain each stage in your own words.
- Loss quantification
- Loss = Amount actually paid or diverted − Amount that was legitimately due
- Use it to measure the financial impact of a proven fraud, for example an inflated purchase.
- Typical report contents
- Background + Scope + Procedures + Findings + Loss + Conclusion + Recommendations
- Cover each item in a report answer. Facts are separated from opinion.
- Benford's law: probability of first digit d
- P(d) = log₁₀(1 + 1/d), for d = 1 to 9
- Gives P(1) ≈ 30.1%, P(2) ≈ 17.6%, P(3) ≈ 12.5%, P(9) ≈ 4.6%. The nine probabilities add up to 100%.
- Expected count under Benford's law
- Expected count of digit d = P(d) × total number of items
- Compare with the actual count. A large gap is a red flag needing follow-up, not proof.
- Deviation for a digit
- Deviation = Actual % − Expected %
- Look at the biggest deviations first. Statistical tests such as chi-square or Z-test can judge if a gap is significant.
- Order of an interview
- Neutral witnesses → corroborative witnesses → suspect
- Within each interview, go from open questions to closed questions, then to the key admission question.
- Digital evidence lifecycle
- Identify → Preserve → Collect → Examine → Analyse → Report
- Use this sequence as the skeleton for any descriptive answer. Preservation comes before collection and analysis.
- Integrity test
- Hash(original) = Hash(forensic image) ⇒ copy is an exact duplicate
- If the hash values differ, the copy cannot be treated as identical. Analysis is done on the copy, not the original.
- Chain of custody record
- What + Who + When + Where + How + Why (for every handling and transfer)
- Any gap or undocumented transfer weakens the evidence.
- Order of volatility
- RAM / running processes → network connections → disk files → backups and archives
- Capture the most perishable data first.
- Core principle
- Work on a copy, never on the original
- Use write blockers so that the source device is not altered.
- Elements of fraud under section 447
- Act or omission or concealment or abuse of position + intent to deceive / gain undue advantage / injure interests
- Wrongful gain or wrongful loss need not be proved. Intent is the key element.
- Who may be affected
- Company, its shareholders, creditors or any other person
- Use this wording when applying the definition to a case.
- SFIO route
- Central Government assigns case → SFIO investigates → report to Central Government → prosecution in the Special Court
- SFIO does not start on its own. Assignment by the Central Government is needed.
- Admissibility of electronic record
- Electronic record + statutory certificate + integrity shown = admissible as a document
- Keep a hash value and a record of who handled the data (chain of custody).
- Expert opinion
- Expert opinion = relevant evidence, not conclusive
- The court decides. Your reasoning must be explained and supported.
- Fraud versus error
- Fraud = intentional act involving deception; Error = unintentional mistake
- Intent separates them. Both can cause a misstatement.
- Auditor's responsibility under SA 240
- Reasonable assurance of no material misstatement (fraud or error) + professional scepticism
- It is not absolute assurance. Primary responsibility for prevention and detection lies with management and those charged with governance.
- Presumed fraud risks
- Revenue recognition (presumed) + management override of controls (always)
- Revenue presumption can be rebutted with reasons. Management override cannot be rebutted.
- Responses to management override
- Test journal entries + review estimates for bias + evaluate significant unusual transactions
- These procedures are performed in every audit.
- Statutory audit versus forensic audit
- Statutory: opinion on true and fair view, materiality, sampling. Forensic: specific suspicion, fact-finding, court-ready evidence
- Use this contrast for comparison questions.
- Core ethical principles
- Integrity, objectivity, professional competence and due care, confidentiality, professional behaviour
- Apply to the forensic auditor and expert witness.
Quick revision
- Forensic audit aims to detect, investigate and document fraud so that findings can support legal action.
- A statutory audit gives an opinion on true and fair view; a forensic audit targets a specific suspicion or allegation.
- The fraud triangle has three elements: pressure (incentive), opportunity and rationalisation.
- Weak internal controls mainly create the opportunity side of the triangle.
- Common fraud groups include misappropriation of assets, fraudulent financial reporting and corruption.
- Red flags are warning signs, not proof of fraud.
- The process runs from acceptance and planning to evidence gathering, analysis and reporting.
- Data analytics can flag duplicates, gaps in sequence and unusual patterns across large volumes of records.
- In digital forensics, work on a copy of the data and protect the original.
- Maintain a chain of custody so the evidence can be shown to be untampered.
- Evidence must be relevant, reliable and admissible to be of use in a legal forum.
- The forensic auditor must stay objective, keep confidentiality and report facts without presuming guilt.
Common mistakes
- Saying forensic audit is just a more detailed statutory audit. Fix: State that the purpose, trigger and output differ. It is investigative, starts from suspicion and must produce court-ready evidence.
- Using forensic accounting and forensic auditing as exact synonyms. Fix: Say forensic accounting is the broader field including quantification and litigation support, while forensic auditing is the investigative examination of records.
- Calling every misstatement a fraud. Fix: Always test for intent. Unintentional misstatements are errors.
- Treating red flags as proof of fraud. Fix: Write that red flags call for further enquiry and evidence. They do not prove fraud.
- Treating a forensic audit like a statutory audit and giving an opinion on true and fair view. Fix: State that a forensic audit is allegation-driven, focuses on evidence and may support legal action.
- Skipping the acceptance stage and starting at evidence collection. Fix: Begin with acceptance: engagement terms, scope, independence, competence and confidentiality.
- Treating a Benford's law deviation as proof of fraud. Fix: Write that it is a red flag only. The next step is to examine the underlying documents and interview the people involved.
- Applying Benford's law to any data, such as cheque numbers or fixed price lists. Fix: State the conditions: large datasets, naturally occurring amounts, spanning several orders of magnitude, with no assigned numbers or caps.
- Suggesting that the auditor should examine the original computer directly. Fix: Say that analysis is done on a forensic image created with a write blocker, and the original is sealed and stored.
- Treating chain of custody as a one-time entry at the time of seizure. Fix: State that it is a continuous log of every handling, transfer and storage event until the evidence is produced.
Exam tips
- For 'distinguish' questions, use a two-column table-style list with at least five heads. Examiners reward structure.
- Include the words 'evidence', 'court' and 'fraud' in your definition. These are the keywords markers look for.
- In MCQs, watch for options that say forensic audit is compulsory annually or based only on sampling. Both are wrong.
- For case questions, name the red flag first, then the forensic response, then the evidence to preserve.
- Link need and scope to Indian context, such as bank frauds and money laundering, in a line or two.
- Always bring intent into the definition and the fraud versus error answer. Examiners look for it.
- In case questions, map facts to Pressure, Opportunity and Rationalisation explicitly. Use three labelled lines.
- For MCQs, remember opportunity is the side controlled by internal controls, and rationalisation lives in the person's mind.