Skip to content

CS Professional · Internal and Forensic Audit · Emerging Issues and Challenges

An internal auditor at Bharat Logistics Ltd uses data analytics on the vendor master and finds 14 vendors whose bank account numbers match those of employees, and all were created by one user outside normal approval workflow. Which conclusion and next step are most appropriate?

The findings are red flags of possible fraud, not proof. The auditor should preserve system logs as evidence, escalate to the audit committee and extend testing of payments to those vendors. Concluding guilt immediately, ignoring analytics, or quietly correcting the data would each be improper.

  1. AConclude fraud has been proven and recommend dismissal immediately
  2. BTreat as a red flag of possible fraudulent vendors; preserve the log evidence, escalate to the audit committee and extend testing of payments to these vendorsCorrect
  3. CIgnore it because analytics results are not reliable audit evidence
  4. DCorrect the vendor master quietly and not report it, as the amounts are unknown

Explanation

Matching bank accounts and bypassed approvals are strong indicators, not proof. The auditor should preserve evidence, report through the proper channel and extend substantive testing to quantify loss. Concluding guilt is premature, while ignoring or concealing the matter breaches audit duty.

Did you get it right without looking?

One question tells you little. A timed set on Emerging Issues and Challenges shows your real accuracy, how long you take and where you lose marks.

More Emerging Issues and Challenges questions