Skip to content

Cost and Management Audit · Forensic Audit

Forensic Audit Process and Planning: Stages Explained

Updated 11 October 2026 · Fact-checked

A forensic audit is an investigation of suspected fraud or financial misconduct, done so that findings can stand as evidence. The process runs in stages: acceptance, planning, evidence collection and analysis, reporting, and follow-up. To answer a question, name each stage and apply it to the facts given.

Understand Forensic Audit Process and Planning

A forensic audit is different from a statutory or cost audit. A statutory audit gives an opinion on whether statements show a true and fair view. A forensic audit starts with a suspicion or allegation. It asks what happened, who did it, how much was lost and whether the proof will hold up before a court or authority.

Because the work may end in legal action, the process must be disciplined. Every step is planned, every document is traced to its source, and every finding is recorded. A weak process can make good evidence unusable.

The engagement moves through stages. First is acceptance: you check who is asking, why, the scope, and whether you have the skills and independence for it. Next is planning: you understand the entity and the allegation, set objectives, choose methods, form the team and plan how to secure evidence.

Then comes investigation. You collect documents and electronic data, keep their chain of custody, run analytical tests, interview people and quantify the loss. After that you prepare the report and follow up on what the client does with it, which may include supporting legal proceedings.

The exact number of stages differs between textbooks. Do not worry about the labels. Marks come from showing the logical flow and tying each stage to the case in the question.

Key rules to remember

Stage sequence
Acceptance → Planning → Evidence collection → Analysis → Reporting → Follow-up
A memory aid for the flow. Textbooks may group or label stages differently, so explain each stage in your own words.
Loss quantification
Loss = Amount actually paid or diverted − Amount that was legitimately due
Use it to measure the financial impact of a proven fraud, for example an inflated purchase.
Typical report contents
Background + Scope + Procedures + Findings + Loss + Conclusion + Recommendations
Cover each item in a report answer. Facts are separated from opinion.

How to solve Forensic Audit Process and Planning questions

Most questions ask you to describe the process, plan an engagement for a scenario, or list the report contents. Use one method for all of them.

  1. 1Read the question and mark the keywords: allegation, entity, type of fraud, and what is being asked.
  2. 2Name the stages in order. Show that you know the full flow before going deep on any one.
  3. 3For the stage asked, give the actions: for planning, cover understanding the entity, objectives, scope, team, risks and evidence plan.
  4. 4Tie each action to the facts. For example, if the fraud is in purchases, mention vendor files and price comparisons.
  5. 5Stress evidence quality: chain of custody, original documents, confidentiality and legal admissibility.
  6. 6Close with reporting and follow-up, including recommendations on control weaknesses and support to legal action.

Quickest way: Stage-and-scenario method

When to use it: Use it for short descriptive questions when time is tight.

  1. Write the stages as one line of headings.
  2. Under each heading, write one or two points linked to the case.
  3. Add one line on evidence handling.
  4. End with the report and follow-up in one line each.

Common mistakes in Forensic Audit Process and Planning

  • Treating a forensic audit like a statutory audit and giving an opinion on true and fair view.

    Both are called audits, so students reuse the familiar framework.

    Fix: State that a forensic audit is allegation-driven, focuses on evidence and may support legal action.

  • Skipping the acceptance stage and starting at evidence collection.

    Students think the work begins when documents are examined.

    Fix: Begin with acceptance: engagement terms, scope, independence, competence and confidentiality.

  • Writing generic planning points that ignore the scenario.

    Students memorise a list without applying it.

    Fix: Link every planning point to the entity, the alleged fraud and the likely evidence in the question.

  • Ignoring chain of custody and preservation of evidence.

    Students focus on finding the fraud, not on proving it.

    Fix: Mention securing originals, making forensic copies of data, logging who handled what, and limiting access.

  • Mixing facts with opinion in the report, or giving legal conclusions of guilt.

    Students want to sound decisive.

    Fix: Report findings supported by evidence. Leave the determination of guilt to the courts or competent authority.

Worked examples

Example 1

A company suspects that its purchase manager has been paying inflated prices to a related vendor. You are asked to plan the forensic audit engagement. Outline your approach.

Show the solution
  1. Acceptance: confirm who is engaging you, written terms, scope limited to purchases, and your independence from the manager and vendor. Agree confidentiality.
  2. Planning: understand the purchasing process, approval limits and vendor onboarding. Set the objective: establish whether prices were inflated, by how much and who benefited.
  3. Team and resources: form a team with cost and data analytics skills. Plan access to ERP data.
  4. Evidence plan: secure purchase orders, invoices, vendor master, bank payments and emails. Take forensic copies of data and keep a custody log.
  5. Procedures: compare prices with market and other vendors, test for related-party links, check approvals and duplicate or split orders, and interview staff.
  6. Quantify loss as price paid less a fair price, for the quantity bought.
  7. Report facts, method, loss and control weaknesses. Follow up on recommendations and support any legal action.

Answer: Accept the engagement with clear terms, plan around the purchase cycle, secure evidence with chain of custody, test prices and related links, quantify the loss, then report factually and follow up.

Example 2

List the main contents of a forensic audit report and explain why facts must be kept separate from opinion.

Show the solution
  1. Contents: background and the allegation, scope and objectives, procedures performed and limitations, findings supported by evidence, quantified loss, conclusion, and recommendations.
  2. Annexures: include copies of key documents, schedules and analyses so each finding can be traced to its source.
  3. Reason for separation: the report may be used before a court or authority. Facts are verifiable, but opinion is open to challenge.
  4. Keeping them apart protects the credibility of the evidence and the auditor, and avoids stating legal guilt, which is for the competent authority to decide.

Answer: The report covers background, scope, procedures, evidence-backed findings, loss, conclusion, recommendations and annexures. Facts and opinion are separated so that the report stays credible and usable as evidence.

Exam tips

  • Always give the stages in order, then expand the one asked.
  • Apply planning points to the scenario. Generic lists score less.
  • Mention evidence handling in every answer: originals, forensic copies, custody log.
  • In report questions, state that findings are factual and legal guilt is not decided by the auditor.
  • In MCQs, remember that a forensic audit starts with an allegation or suspicion.

Practice questions from Forensic Audit

Forensic Audit Process and Planning in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Forensic Audit Process and Planning: frequently asked questions

What are the steps in a forensic audit?

The usual flow is acceptance, planning, evidence collection, analysis and investigation, reporting, and follow-up. Sources may label or group the stages differently. In the exam, show the logical sequence and link it to the case.

How is forensic audit planning different from normal audit planning?

It starts from a specific allegation, not a general opinion on the accounts. Planning focuses on objectives of the investigation, preserving evidence, secrecy and legal use of the findings.

What should a forensic audit report contain?

It should state the background, scope, procedures, findings backed by evidence, the quantified loss, a conclusion and recommendations. Key documents are attached as annexures. Keep facts separate from opinion.

Why is chain of custody important?

It records who held the evidence and when, which shows it was not altered. Without it, the evidence may be challenged and rejected in legal proceedings.