CS Professional · Internal and Forensic Audit
Fraud Detecting Techniques: formula sheet
Key formulas
- Fraud detection vs prevention
- Prevention = stop before it happens; Detection = find after or during it happens
- Use this one-line contrast whenever the question asks for the meaning or importance of detection.
- Red flag rule
- Red flag = indicator of possible fraud, not proof of fraud
- State this caveat in every answer. It shows you understand the auditor must corroborate with evidence.
- Fraud triangle link
- Pressure + Opportunity + Rationalisation → Fraud
- Map each red flag to one side of the triangle to add depth to your answer.
- Red flag groups
- Behavioural | Financial/transactional | Document | Control/organisational
- A four-group structure lets you organise any list of warning signs quickly.
- Stages of fraud detection
- Risk assessment → Red flag identification → Testing and analysis → Investigation → Reporting and follow-up
- Use this sequence as the skeleton of any process question.
- Proactive approach
- Detect before suspicion: fraud risk assessment + analytics + surprise checks + continuous monitoring
- Aims at both early detection and deterrence.
- Reactive approach
- Detect after a trigger: tip, complaint, loss, regulator query
- Starts with the trigger, then moves to investigation.
- Detection sources
- Internal controls + audit (internal/external) + analytics + whistleblowing + management review
- Name several sources; do not rely on one.
- Benford's law: probability of first digit d
- P(d) = log₁₀(1 + 1/d), for d = 1 to 9
- Gives about 30.1% for digit 1, 17.6% for 2, 12.5% for 3, 9.7% for 4, 7.9% for 5, 6.7% for 6, 5.8% for 7, 5.1% for 8 and 4.6% for 9.
- Expected count under Benford's law
- Expected count = P(d) × total number of items
- Compare with the actual count. A large gap is a red flag, not proof of fraud.
- Percentage variance (trend analysis)
- Variance % = (Current − Base) ÷ Base × 100
- Use it to compare year-on-year movements in expenses, sales or receivables.
- Days sales outstanding
- DSO = Average receivables ÷ Credit sales × Number of days
- A rising DSO with rising sales can indicate fictitious sales or weak collection.
- Vouching direction
- Ledger entry → voucher → supporting documents and approval
- Starts from the books and tests that each recorded entry is real and authorised. It tests for overstated or fictitious entries.
- Reverse (tracing) direction
- Source document → book entry
- Tests completeness: whether genuine transactions were recorded. Useful for suppressed income or unrecorded liabilities.
- Bank reconciliation
- Balance as per cash book ± timing differences = Balance as per bank statement
- Any difference not explained by timing items (cheques not presented, deposits in transit, charges not yet booked) needs investigation.
- Interview sequence
- Neutral witnesses → informed or involved persons → suspect
- A rule of practice, not a statutory rule. It lets you build facts before confronting the suspect.
- Analytical review ratio
- Gross profit margin = (Gross profit ÷ Sales) × 100
- Unexplained movement against past periods or industry may indicate manipulated sales, purchases or stock.
- Fraud risk rating
- Risk rating = Likelihood × Impact
- Use the scale your organisation sets, such as High/Medium/Low. Rate inherent risk first, then residual risk after controls.
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalisation
- A conceptual model, not a calculation. Risk assessment mainly targets opportunity.
- Residual risk
- Residual risk = Inherent risk after considering effectiveness of controls
- A conceptual relationship, not arithmetic. Strong controls lower residual risk; weak or overridden controls leave it high.
Quick revision
- A red flag is a warning sign that suggests fraud may exist. It is not proof of fraud.
- Red flags can be financial, behavioural or documentary. Give examples from each group in answers.
- Detection is risk-based: you direct more testing to areas with higher fraud risk.
- Data analytics tests entire populations, while traditional sampling tests only a part.
- CAATs use software to test data, for example to find duplicates, gaps in sequences and unusual entries.
- Typical analytic tests include duplicate payments, round-sum entries, entries after hours and unusual vendor patterns.
- Document examination looks for alterations, missing pages, photocopies in place of originals and inconsistencies.
- Interviews and inquiry should go from general to specific questions and be documented carefully.
- Fraud risk assessment: identify risks, rate likelihood and impact, link to controls and tests, then monitor.
- Always end a case answer with a conclusion and a recommendation, not just a list of techniques.
- Detection does not prove fraud. Proof needs a proper investigation with sound evidence.
Common mistakes
- Treating a red flag as proof of fraud Fix: Use words like 'may indicate' and state that further evidence is required before any conclusion.
- Confusing fraud detection with fraud prevention Fix: Remember timing: prevention acts before the event, detection acts during or after it.
- Treating detection and prevention as the same thing Fix: Say prevention reduces the chance of fraud; detection finds fraud that has occurred. Note that proactive detection also deters.
- Listing only reactive methods Fix: Always include proactive tools such as analytics, surprise audits and continuous monitoring.
- Saying a Benford's law deviation proves fraud. Fix: Call it an indicator. Natural causes such as small datasets or capped amounts can also cause deviation. Always follow up.
- Using Benford's law on data that is assigned or limited, like invoice numbers or fixed-price items. Fix: State that it suits large, naturally occurring numeric data across wide ranges.
- Treating vouching and tracing as the same thing. Fix: Vouching goes from book entry to document and tests for overstatement. Tracing goes from document to book and tests completeness.
- Interviewing the suspect first. Fix: Interview neutral witnesses first, gather documents, and meet the suspect last, when you can test the story against evidence.
- Treating a red flag as proof of fraud. Fix: Write that the flag calls for further examination. Conclude only after evidence supports it.
- Mixing up prevention and detection. Fix: Prevention reduces opportunity in advance, such as segregation of duties. Detection finds fraud that has already occurred, such as analytics or exception reports.
Exam tips
- Open with a crisp definition and the prevention versus detection contrast. It takes ten seconds and secures easy marks.
- Group red flags under headings. A structured answer reads better than a long mixed list.
- In case questions, quote the facts and name the flag next to each one.
- Always include the caveat that red flags are not proof, and end with the auditor's next steps.
- Link at least a few flags to the fraud triangle to show analysis rather than memory.
- Answer with the five-stage process first; examiners reward a clear sequence.
- Always name at least two proactive and two reactive methods.
- In case questions, link each fact to a red flag before suggesting a technique.