Skip to content

CS Professional · Internal and Forensic Audit

Fraud Detecting Techniques: formula sheet

Full chapter guide

Key formulas

Fraud detection vs prevention
Prevention = stop before it happens; Detection = find after or during it happens
Use this one-line contrast whenever the question asks for the meaning or importance of detection.
Red flag rule
Red flag = indicator of possible fraud, not proof of fraud
State this caveat in every answer. It shows you understand the auditor must corroborate with evidence.
Fraud triangle link
Pressure + Opportunity + Rationalisation → Fraud
Map each red flag to one side of the triangle to add depth to your answer.
Red flag groups
Behavioural | Financial/transactional | Document | Control/organisational
A four-group structure lets you organise any list of warning signs quickly.
Stages of fraud detection
Risk assessment → Red flag identification → Testing and analysis → Investigation → Reporting and follow-up
Use this sequence as the skeleton of any process question.
Proactive approach
Detect before suspicion: fraud risk assessment + analytics + surprise checks + continuous monitoring
Aims at both early detection and deterrence.
Reactive approach
Detect after a trigger: tip, complaint, loss, regulator query
Starts with the trigger, then moves to investigation.
Detection sources
Internal controls + audit (internal/external) + analytics + whistleblowing + management review
Name several sources; do not rely on one.
Benford's law: probability of first digit d
P(d) = log₁₀(1 + 1/d), for d = 1 to 9
Gives about 30.1% for digit 1, 17.6% for 2, 12.5% for 3, 9.7% for 4, 7.9% for 5, 6.7% for 6, 5.8% for 7, 5.1% for 8 and 4.6% for 9.
Expected count under Benford's law
Expected count = P(d) × total number of items
Compare with the actual count. A large gap is a red flag, not proof of fraud.
Percentage variance (trend analysis)
Variance % = (Current − Base) ÷ Base × 100
Use it to compare year-on-year movements in expenses, sales or receivables.
Days sales outstanding
DSO = Average receivables ÷ Credit sales × Number of days
A rising DSO with rising sales can indicate fictitious sales or weak collection.
Vouching direction
Ledger entry → voucher → supporting documents and approval
Starts from the books and tests that each recorded entry is real and authorised. It tests for overstated or fictitious entries.
Reverse (tracing) direction
Source document → book entry
Tests completeness: whether genuine transactions were recorded. Useful for suppressed income or unrecorded liabilities.
Bank reconciliation
Balance as per cash book ± timing differences = Balance as per bank statement
Any difference not explained by timing items (cheques not presented, deposits in transit, charges not yet booked) needs investigation.
Interview sequence
Neutral witnesses → informed or involved persons → suspect
A rule of practice, not a statutory rule. It lets you build facts before confronting the suspect.
Analytical review ratio
Gross profit margin = (Gross profit ÷ Sales) × 100
Unexplained movement against past periods or industry may indicate manipulated sales, purchases or stock.
Fraud risk rating
Risk rating = Likelihood × Impact
Use the scale your organisation sets, such as High/Medium/Low. Rate inherent risk first, then residual risk after controls.
Fraud triangle
Fraud = Pressure + Opportunity + Rationalisation
A conceptual model, not a calculation. Risk assessment mainly targets opportunity.
Residual risk
Residual risk = Inherent risk after considering effectiveness of controls
A conceptual relationship, not arithmetic. Strong controls lower residual risk; weak or overridden controls leave it high.

Quick revision

  • A red flag is a warning sign that suggests fraud may exist. It is not proof of fraud.
  • Red flags can be financial, behavioural or documentary. Give examples from each group in answers.
  • Detection is risk-based: you direct more testing to areas with higher fraud risk.
  • Data analytics tests entire populations, while traditional sampling tests only a part.
  • CAATs use software to test data, for example to find duplicates, gaps in sequences and unusual entries.
  • Typical analytic tests include duplicate payments, round-sum entries, entries after hours and unusual vendor patterns.
  • Document examination looks for alterations, missing pages, photocopies in place of originals and inconsistencies.
  • Interviews and inquiry should go from general to specific questions and be documented carefully.
  • Fraud risk assessment: identify risks, rate likelihood and impact, link to controls and tests, then monitor.
  • Always end a case answer with a conclusion and a recommendation, not just a list of techniques.
  • Detection does not prove fraud. Proof needs a proper investigation with sound evidence.

Common mistakes

  • Treating a red flag as proof of fraud Fix: Use words like 'may indicate' and state that further evidence is required before any conclusion.
  • Confusing fraud detection with fraud prevention Fix: Remember timing: prevention acts before the event, detection acts during or after it.
  • Treating detection and prevention as the same thing Fix: Say prevention reduces the chance of fraud; detection finds fraud that has occurred. Note that proactive detection also deters.
  • Listing only reactive methods Fix: Always include proactive tools such as analytics, surprise audits and continuous monitoring.
  • Saying a Benford's law deviation proves fraud. Fix: Call it an indicator. Natural causes such as small datasets or capped amounts can also cause deviation. Always follow up.
  • Using Benford's law on data that is assigned or limited, like invoice numbers or fixed-price items. Fix: State that it suits large, naturally occurring numeric data across wide ranges.
  • Treating vouching and tracing as the same thing. Fix: Vouching goes from book entry to document and tests for overstatement. Tracing goes from document to book and tests completeness.
  • Interviewing the suspect first. Fix: Interview neutral witnesses first, gather documents, and meet the suspect last, when you can test the story against evidence.
  • Treating a red flag as proof of fraud. Fix: Write that the flag calls for further examination. Conclude only after evidence supports it.
  • Mixing up prevention and detection. Fix: Prevention reduces opportunity in advance, such as segregation of duties. Detection finds fraud that has already occurred, such as analytics or exception reports.

Exam tips

  • Open with a crisp definition and the prevention versus detection contrast. It takes ten seconds and secures easy marks.
  • Group red flags under headings. A structured answer reads better than a long mixed list.
  • In case questions, quote the facts and name the flag next to each one.
  • Always include the caveat that red flags are not proof, and end with the auditor's next steps.
  • Link at least a few flags to the fraud triangle to show analysis rather than memory.
  • Answer with the five-stage process first; examiners reward a clear sequence.
  • Always name at least two proactive and two reactive methods.
  • In case questions, link each fact to a red flag before suggesting a technique.