Skip to content

Internal and Forensic Audit · Basic Concepts of Forensic Audit

Legal Framework and Evidence in Forensic Audit

Updated 11 October 2026 · Fact-checked

Forensic audit has no single statute. It runs on many laws: the Companies Act, 2013 (fraud, SFIO), the Bharatiya Nyaya Sanhita (offences), the Bharatiya Sakshya Adhiniyam (evidence), PMLA (laundering), the SEBI Act and regulations (market fraud) and the IT Act (digital offences). Your findings must be admissible as evidence to be useful.

Understand Legal Framework and Evidence in Forensic Audit

A forensic audit is an examination done so that the findings can stand in a court, tribunal or regulatory proceeding. So the auditor needs two things: knowledge of which law the wrongdoing breaks, and evidence that the law will accept.

The laws fall into groups. Companies Act, 2013 defines fraud in the explanation to section 447, punishes it, requires auditors to report fraud, and lets the Central Government order investigation by the Serious Fraud Investigation Office (SFIO). Criminal law (the Bharatiya Nyaya Sanhita, 2023, which replaced the IPC) covers offences such as cheating, criminal breach of trust, forgery and falsification of accounts. PMLA, 2002 deals with hiding the proceeds of crime and places duties on reporting entities such as banks and intermediaries. SEBI law covers insider trading, market manipulation and misleading disclosures by listed companies.

Evidence law decides whether your work counts. Evidence law is now the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced the Indian Evidence Act, 1872. Questions may still use the old name, so know both. Evidence can be oral, documentary or electronic. Electronic records are treated as documents. Under BSA section 63 (earlier section 65B of the Evidence Act), a computer output such as a printout or copy is deemed a document and is admissible only if the certificate in the prescribed Schedule format is given. The certificate has two parts. Part A is signed by the party, that is, the person in charge of the computer or communication device or the person who manages the relevant activities. Part B is signed by an expert. The certificate describes the device, how the record was produced and that the device worked properly. The Schedule also requires the hash value of the electronic record to be stated.

For digital evidence, how you collect matters as much as what you find. You must preserve the original, work on a forensic copy, record a hash value, and keep a chain of custody showing who held the evidence and when. A break in the chain gives the other side a reason to challenge it.

The forensic auditor is usually not the judge. Your report is an input. It gives facts, analysis and the link to the provision breached. Conclusions of guilt are for the court or the authority.

Key rules to remember

Fraud under the Companies Act, 2013
Section 447 explanation: any act, omission, concealment or abuse of position, with intent to deceive, gain undue advantage or injure interests of the company, shareholders, creditors or any other person, whether or not there is wrongful gain or loss
Intent is essential. Wrongful gain or loss need not be proved.
Auditor's duty on fraud
Section 143(12): fraud by officers or employees found during audit. Involving less than ₹1 crore: report to the Audit Committee or Board within 2 days, and the Board discloses it in its report under section 134(3)(ca). Involving ₹1 crore or more: report to the Board or Audit Committee within 2 days → allow 45 days for reply → report to the Central Government within 15 days of the reply or of the end of the 45 days
Procedure is in Rule 13 of the Companies (Audit and Auditors) Rules, 2014. For ₹1 crore or more, reporting to the Central Government is the last step of a sequence, not the first.
SFIO investigation
Section 212(1): the Central Government may assign investigation into the affairs of a company to SFIO
Triggers: a report of the Registrar or inspector under section 208, intimation of a special resolution passed by the company that its affairs are to be investigated, public interest, or a request from a Central or State Government department.
Digital evidence admissibility
Electronic record = document; computer output is admissible as a document only with the certificate in the prescribed Schedule format (BSA, 2023 section 63; earlier Evidence Act section 65B)
The certificate has Part A, signed by the party (person in charge of the device or who manages the relevant activities), and Part B, signed by an expert. It covers device, process and proper functioning, and the Schedule requires the hash value of the electronic record.
PMLA core offence
Money-laundering = direct or indirect involvement in any process or activity connected with proceeds of crime and projecting it as untainted property
Proceeds of crime come from a scheduled offence.
Chain of custody
Collect → Seal and record hash → Store → Transfer with log → Produce
Every hand-over must be documented.

How to solve Legal Framework and Evidence in Forensic Audit questions

Use this method for any case-based or theory question on the legal framework or evidence.

  1. 1Read the facts and list what happened: act, person, amount, document or system involved.
  2. 2Name the wrong: fraud, cheating, misstatement, laundering, market abuse or cyber offence.
  3. 3Match each wrong to its law and, if you are sure, the section. Companies Act for company fraud, BNS for criminal offence, PMLA for proceeds, SEBI for securities, IT Act for cyber.
  4. 4Identify who acts: auditor reporting, Board, SFIO, police, Enforcement Directorate, SEBI or FIU-IND.
  5. 5Test the evidence: is it original or copy, document or electronic, is a certificate needed, is custody documented.
  6. 6Advise the practical step: preserve, report, document, escalate.
  7. 7Conclude in one or two lines with the provision and the likely consequence.

Quickest way: Wrong → Law → Authority → Evidence

When to use it: When time is short and the question asks you to identify applicable laws or comment on evidence.

  1. Write the wrong in one phrase.
  2. List the laws in a short bullet each, with one line on why it applies.
  3. Name the authority that acts.
  4. Add one bullet on evidence: certificate, hash, chain of custody.
  5. Close with a conclusion sentence.

Common mistakes in Legal Framework and Evidence in Forensic Audit

  • Writing IPC and Indian Evidence Act only, without mentioning BNS and BSA.

    Older books and habits still use the old names.

    Fix: Write the new law first and mention the old one in brackets, for example BNS (earlier IPC).

  • Treating forensic audit as governed by one Act.

    Students look for a single provision like in statutory audit.

    Fix: Present it as a set of laws and show which one fits each fact.

  • Saying wrongful gain must be proved for fraud under the Companies Act.

    Confusing it with the criminal idea of cheating.

    Fix: State that the definition applies whether or not there is wrongful gain or wrongful loss, but intent to deceive is needed.

  • Ignoring the certificate for electronic records.

    Students assume a printout or email is enough.

    Fix: Mention the certificate, hash value and chain of custody every time digital evidence appears.

  • Mixing up who investigates: giving SFIO power to the auditor or the police.

    Several agencies overlap.

    Fix: Auditor reports, Central Government assigns SFIO, ED handles PMLA, SEBI handles securities cases.

  • Quoting section numbers from memory when unsure.

    Wanting to look precise.

    Fix: Use the Act name and the idea when unsure. Quote only sections you know well, such as 143(12), 212 and 447.

Worked examples

Example 1

During the audit of Sundaram Textiles Ltd, the auditor finds that the purchase manager created fake vendor invoices worth ₹2,40,00,000 and diverted the payments to a relative's account. Which laws apply and what must the auditor do?

Show the solution
  1. The wrong is fraud by an employee against the company: fake invoices and diversion of funds.
  2. Companies Act, 2013: the act falls within the definition of fraud in the explanation to section 447.
  3. Auditor's duty under section 143(12): the amount of ₹2.4 crore is ₹1 crore or more. Under Rule 13 of the Companies (Audit and Auditors) Rules, 2014, the auditor first reports to the Board or Audit Committee within 2 days of knowing of the fraud and asks for a reply within 45 days.
  4. After the reply is received, or the 45 days end, the auditor reports to the Central Government within 15 days. If the amount were below ₹1 crore, the auditor would report only to the Audit Committee or Board within 2 days, and the Board would disclose it in its report under section 134(3)(ca).
  5. Criminal law: the BNS provisions on cheating, forgery and criminal breach of trust may apply, and the company can file a complaint.
  6. PMLA: if the fraud is a scheduled offence and the funds were layered through accounts, laundering provisions can also be attracted.
  7. Evidence: preserve invoices, bank statements and system logs. For ERP records, take a forensic copy, record hash values and obtain a certificate for the electronic records.

Answer: Section 447 (fraud) and section 143(12) apply. Since the amount is ₹1 crore or more, the auditor reports to the Board or Audit Committee within 2 days, allows 45 days for reply, and then reports to the Central Government within 15 days. BNS offences of cheating, forgery and breach of trust, and possibly PMLA, may also apply. Electronic records must be supported by a certificate and a clean chain of custody.

Example 2

A forensic auditor extracts emails from a laptop and submits printouts as evidence. The opposing party objects. Is the objection valid, and how should the auditor have proceeded?

Show the solution
  1. Emails are electronic records, treated as documents under the Bharatiya Sakshya Adhiniyam, 2023.
  2. A printout is a computer output. Under BSA section 63 (earlier section 65B of the Evidence Act), it is admissible as a document only if the certificate in the prescribed Schedule format accompanies it.
  3. The certificate identifies the record, describes how it was produced, the device used, states the device was working properly, and gives the hash value of the record. Part A is signed by the person in charge of the device or the party, and Part B is signed by an expert.
  4. The auditor should have imaged the laptop, recorded a hash value to prove no change, and kept a chain of custody log.
  5. Without these, the other side can argue tampering or doubt authenticity.

Answer: The objection is valid if no certificate was produced. The auditor should have used a forensic image with a hash value, a documented chain of custody and the required certificate, so the printouts could be admitted.

Exam tips

  • Write BNS and BSA first, with IPC and the Evidence Act in brackets, since the question may use either name.
  • In case questions, structure the answer as law, application, conclusion. List each law as a separate bullet with its role.
  • For digital evidence always include certificate, hash value and chain of custody. These are the points markers look for.
  • Do not quote a section number unless sure. A correct Act name with the right idea earns marks.
  • Link the auditor's role to the authority: report fraud, support SFIO, file suspicious transaction information where PMLA applies.

Practice questions from Basic Concepts of Forensic Audit

Legal Framework and Evidence in Forensic Audit in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Legal Framework and Evidence in Forensic Audit: frequently asked questions

Which laws govern forensic audit in India?

There is no single law. The main ones are the Companies Act, 2013, BNS, BSA, PMLA, the SEBI Act and regulations, and the IT Act, 2000. You pick the law based on the type of wrongdoing.

What is the role of SFIO in forensic audit?

SFIO investigates complex corporate frauds when the Central Government assigns a case under the Companies Act, 2013. Forensic findings and reports can support or feed into such an investigation.

Is digital evidence admissible in Indian courts?

Yes. Electronic records are treated as documents. Copies need a certificate as required by the Bharatiya Sakshya Adhiniyam, 2023, which replaced the Evidence Act, 1872. Proper collection and chain of custody strengthen the evidence.

How does PMLA relate to forensic audit?

A forensic audit often traces the flow of funds from a crime. If those funds are proceeds of crime and are being disguised as legitimate, PMLA applies, and the findings can help authorities such as the Enforcement Directorate.