Skip to content

Advanced Auditing, Assurance and Professional Ethics · Due Diligence, Investigation & Forensic Accounting

Fraud: Types, Red Flags and Fraud Triangle

Updated 5 October 2026 · Fact-checked

Fraud is an intentional act by one or more people, using deception, to gain an unjust or illegal advantage. The fraud triangle explains it through three conditions: incentive or pressure, opportunity and rationalisation. To answer questions, classify the fraud, map the triangle, list red flags from the facts, then assign responsibilities.

Understand Fraud: Types, Red Flags and Fraud Triangle

Fraud is an intentional act by management, those charged with governance, employees or third parties, involving deception to obtain an unjust or illegal advantage. Error is unintentional. Intent is the only difference, and it is hard to prove. That is why an auditor does not decide whether fraud has legally occurred. The auditor assesses whether a material misstatement exists and whether fraud is the likely cause.

For auditors, SA 240 deals with two types of intentional misstatement: fraudulent financial reporting (misstating or omitting amounts or disclosures to deceive users, for example fictitious sales, early revenue recognition, hidden liabilities) and misappropriation of assets (theft of cash, inventory or other assets, often hidden by false records). Other common classes you should know: corruption and bribery, cyber and payment fraud, and fraud by third parties such as vendors and customers.

The fraud triangle, from Donald Cressey, says fraud needs three things together. Incentive or pressure: debt, targets, covenant breach, personal greed. Opportunity: weak controls, management override, no supervision. Rationalisation: the person justifies it, such as 'I will repay it' or 'the company owes me'. Remove any one side and fraud becomes less likely. Opportunity is the side the organisation controls most directly.

Related theories extend this. The fraud diamond adds capability: the position, intelligence and confidence to carry out the fraud. The fraud scale (Albrecht) weighs situational pressures, opportunities and personal integrity. Be ready to name these and say how they differ from the triangle.

Red flags are warning signs, not proof. Examples: lifestyle far beyond income, reluctance to take leave, close relationship with a vendor, frequent unusual journal entries near period end, unexplained differences in reconciliations, missing documents, aggressive targets, high staff turnover in finance, and a dominant top manager. Responsibility is layered. Management and those charged with governance are primarily responsible for prevention and detection. The audit committee oversees financial reporting, internal controls and the whistle-blower mechanism. The auditor obtains reasonable assurance that financial statements are free from material misstatement, whether due to fraud or error, and maintains professional scepticism throughout.

Key rules to remember

Fraud triangle
Fraud = Incentive/Pressure + Opportunity + Rationalisation
All three conditions are present together. Removing one reduces the risk.
Fraud diamond
Fraud triangle + Capability
Capability covers position, skill and confidence to commit and conceal the fraud.
Fraud vs error
Fraud = intentional; Error = unintentional
Both cause misstatement. Intent separates them.
Two fraud types relevant to the auditor (SA 240)
Fraudulent financial reporting; Misappropriation of assets
Management fraud is usually the former; employee fraud is usually the latter.
Auditor's stance
Reasonable assurance + professional scepticism
Not absolute assurance. Unavoidable risk of undetected fraud remains, higher for fraud than error because of concealment.

How to solve Fraud: Types, Red Flags and Fraud Triangle questions

Use this sequence for any scenario or theory question on fraud. It keeps your answer in provision-facts-conclusion form.

  1. 1Read the facts and tag each as a pressure, an opportunity or a rationalisation, or as a red flag.
  2. 2Classify the fraud: financial reporting, misappropriation, corruption or other. Say who is involved: management, employee or third party.
  3. 3State the concept in one line, such as the fraud triangle or fraud diamond, then apply it to the facts under three clear labels.
  4. 4List the red flags found in the case, in a short bullet list, noting that they are indicators and not proof.
  5. 5Identify the responsible party: management and those charged with governance for prevention, the audit committee for oversight, the auditor for reasonable assurance.
  6. 6State the auditor's response: reassess the risk of material misstatement, perform substantive procedures such as surprise inventory counts and testing of suspicious adjustments to supporting documents, and enquire of management and those charged with governance. Mention written representations only as a supplementary step required by SA 240, never as a substitute for audit evidence.
  7. 7Recommend actions: strengthen controls, whistle-blower mechanism, segregation of duties, forensic review, extended audit procedures.
  8. 8Conclude in one sentence linked to the question asked.

Quickest way: P-O-R then flags then roles

When to use it: When time is short, or for a 4-5 mark theory answer or a case MCQ.

  1. Write P, O, R and fill each with a fact from the case.
  2. Name the fraud type in one phrase.
  3. Pick the two or three strongest red flags.
  4. Add one line on who is responsible and one preventive step.
  5. In MCQs, check whether the question asks for management, auditor or audit committee responsibility before choosing.

Common mistakes in Fraud: Types, Red Flags and Fraud Triangle

  • Treating red flags as proof of fraud.

    Case facts look damning, so students conclude fraud definitely occurred.

    Fix: Say red flags are indicators that raise risk and call for further procedures. The auditor does not make legal determinations.

  • Saying the auditor is responsible for preventing fraud.

    Students confuse audit duty with management duty.

    Fix: Prevention and detection rest primarily with management and those charged with governance. The auditor gets reasonable assurance on the financial statements.

  • Mixing up fraud and error.

    Both create misstatements and the numbers look the same.

    Fix: Anchor on intent. Intentional with deception means fraud. Unintentional means error.

  • Naming the triangle elements but not applying them to the facts.

    Students memorise the labels and skip the case.

    Fix: Quote the fact next to each element, such as 'targets linked to bonus' under pressure.

  • Forgetting the audit committee and whistle-blower mechanism in prevention questions.

    Focus stays on the auditor.

    Fix: Add a line on audit committee oversight of controls and a vigil mechanism.

  • Confusing the fraud diamond's extra element.

    Similar names and diagrams.

    Fix: Diamond adds capability only. Rationalisation, pressure and opportunity are already in the triangle.

Worked examples

Example 1

Case: The finance head of a listed company is under pressure to meet profit targets that drive his bonus. He alone approves and posts year-end journal entries. Revenue of ₹4,50,00,000 for April was booked in March with no delivery proof. He tells a colleague, 'The sales will happen anyway.' Identify the fraud type and map the fraud triangle.

Show the solution
  1. Fraud type: fraudulent financial reporting, because revenue is recognised early with intent to deceive users.
  2. Pressure: profit targets linked to his bonus.
  3. Opportunity: he alone approves and posts journal entries, so there is no segregation of duties and management override is possible.
  4. Rationalisation: 'The sales will happen anyway' justifies the act as only a timing issue.
  5. Red flags: revenue booked at period end without delivery proof, a single person controlling journals, and a target-driven bonus.

Answer: This is fraudulent financial reporting by management. Pressure is the bonus-linked target, opportunity is unchecked journal posting, and rationalisation is the belief that the sales will occur. The auditor should treat the risk as significant and test cut-off and journal entries.

Example 2

Case: In a manufacturing company, the stores clerk has worked for eight years without taking leave. Inventory records show repeated adjustments for 'scrap', and the physical count is short by ₹6,20,000. The audit committee has never reviewed the whistle-blower log. As auditor, state the nature of the fraud risk, the red flags and who is responsible for what.

Show the solution
  1. Nature: misappropriation of assets, as inventory is likely stolen and concealed through false scrap adjustments.
  2. Red flags: employee never takes leave, repeated unexplained scrap adjustments, count shortage of ₹6,20,000, and no audit committee review of the whistle-blower log.
  3. Responsibility: management and those charged with governance design and run controls such as segregation of duties, mandatory leave and custody checks. The audit committee oversees controls and the vigil mechanism.
  4. Auditor: maintain professional scepticism and reassess the risk of material misstatement. Perform surprise inventory counts, test the scrap adjustments to supporting documents, and enquire of management and those charged with governance. Obtain written representations only as a supplementary step required by SA 240, not as a substitute for evidence.
  5. Communicate findings to management and those charged with governance as appropriate.

Answer: The risk is misappropriation of assets. The red flags are the clerk's no-leave pattern, scrap adjustments and the ₹6,20,000 shortage. Management and the audit committee are primarily responsible for prevention and detection. The auditor reassesses risk, performs surprise counts and tests scrap adjustments to documents, enquires of management and those charged with governance, and communicates, but gives reasonable, not absolute, assurance.

Exam tips

  • In case MCQs, match each fact to pressure, opportunity or rationalisation before reading the options.
  • For 'distinguish' questions, such as fraud vs error or triangle vs diamond, use a two-column style in bullet form with intent or capability as the key point.
  • Always add a one-line caveat that red flags are not proof and that audit gives reasonable assurance.
  • In forensic questions, link the red flags to the next step, such as a forensic audit, data analytics or investigation, to show application.

Practice questions from Due Diligence, Investigation & Forensic Accounting

Fraud: Types, Red Flags and Fraud Triangle in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Fraud: Types, Red Flags and Fraud Triangle: frequently asked questions

What is the fraud triangle in simple words?

It says people commit fraud when three things come together: a pressure or incentive, an opportunity to act, and a way to justify it to themselves. Controls mainly aim to remove opportunity.

What are the two types of fraud relevant to an auditor?

They are fraudulent financial reporting and misappropriation of assets. The first misstates the financial statements to deceive users. The second is theft of assets, usually hidden through false records.

Is the auditor responsible for detecting all fraud?

No. Management and those charged with governance are primarily responsible for prevention and detection. The auditor gets reasonable assurance that the financial statements are free from material misstatement, and a risk of undetected fraud remains.

How is the fraud diamond different from the fraud triangle?

The diamond adds capability: the person's position, skills and confidence to carry out and hide the fraud. The other three elements stay the same.