"A forensic audit is just a deeper statutory audit": what Indian law actually says
Most business owners believe a forensic audit is simply a statutory audit done more carefully, over a longer period, by someone more suspicious. That belief is wrong on every count. The trigger is different, the standard of proof is different, the output is different, and the liability the Chartered Accountant carries is different. A statutory auditor forms an opinion on whether financial statements give a true and fair view; a forensic auditor builds a case file intended to survive cross-examination. This piece sets out the four separate legal regimes that actually mandate forensic audits in India — Sections 210, 212, 213 and 143(12) of the Companies Act 2013, the RBI Red Flagged Account framework, SEBI LODR disclosure obligations, and transaction audits under IBC 2016 — and then explains the part practitioners most often get wrong: what makes forensic evidence admissible. Since 1 July 2024 the Bharatiya Sakshya Adhiniyam 2023 governs electronic records, and Section 63 certification is not optional. Includes a nine-step engagement checklist and the three distinct heads of personal liability a signing CA carries.
Harun Raaj
Chartered Accountant · Harun Raaj & Associates
Ask most business owners what a forensic audit is and you get the same answer: it is a statutory audit done more carefully, by someone more suspicious, over a longer period. That belief is wrong on every count — the trigger is different, the standard of proof is different, the output is different, and the liability the professional carries is different. A statutory auditor forms an opinion on whether financial statements give a true and fair view. A forensic auditor builds a case file intended to survive cross-examination. Those are not the same job scaled up; they are different jobs.
The confusion costs money. Companies commission "a forensic review" from their existing auditor, receive a report that reads like an extended management letter, and then discover in front of a Tribunal or a bank's fraud committee that nothing in it is admissible, sourced, or defensible. This piece sets out who can order a forensic audit in India, what actually makes the evidence stand up, and where the Chartered Accountant's personal liability begins.
What the law actually says
There is no single "Forensic Audit Act" in India. The mandate comes from four separate regimes, and which one applies decides everything about scope and process.
Companies Act 2013. Section 210 empowers the Central Government to order an investigation into a company's affairs. Section 212 assigns serious cases to the Serious Fraud Investigation Office, a multi-disciplinary body whose staffing expressly includes forensic auditing expertise. Section 213 allows the National Company Law Tribunal to direct an investigation on application by members or on other grounds, including where the company's business is being conducted with intent to defraud creditors. Separately, Section 143(12) puts a positive duty on the statutory auditor: on reasonable belief that an offence of fraud is being or has been committed against the company by officers or employees, the auditor must report — to the Central Government where the amount involved is Rs.1 crore or above, and to the audit committee or board below that threshold. Fraud itself is defined and punished under Section 447, and false statements in any return, report or certificate attract Section 448.
RBI framework. For lenders, the driver is the RBI's Master Directions on fraud risk management and classification. Where an account is flagged as a Red Flagged Account on the appearance of early warning signals, banks are expected to complete a forensic examination within a defined window before the account can be classified as fraud or the borrower declared a wilful defaulter. This is the single largest source of forensic audit work in India, and the report is written for a bank's fraud identification committee, not for management.
SEBI LODR. Listed entities must disclose the initiation of a forensic audit — including the fact of it, the name of the auditor and the reason — as a material event, and must disclose the final report other than the investigation-sensitive portions. A listed company cannot quietly commission one and bury the outcome.
IBC 2016. Once a company is in insolvency, the resolution professional runs a transaction audit to identify preferential transactions under Section 43, undervalued transactions under Section 45, extortionate credit under Section 50, and fraudulent or wrongful trading under Section 66. These findings feed applications to the Adjudicating Authority to reverse transactions and fix personal liability on directors.
Standards. The ICAI's Forensic Accounting and Investigation Standards govern how the engagement is planned, how evidence is gathered and how the report is framed. A CA accepting a forensic engagement is expected to work to those standards, not to the audit standards used for a statutory audit.
What makes the evidence admissible
This is the part practitioners get wrong, and it is where reports collapse.
Since 1 July 2024, the Bharatiya Sakshya Adhiniyam 2023 has replaced the Indian Evidence Act 1872. The provision that matters most in forensic work is Section 63, which governs the admissibility of electronic records — the successor to the old Section 65B. Almost all forensic evidence today is electronic: tally backups, ERP extracts, email archives, WhatsApp exports, bank statement PDFs, server logs. None of it is automatically admissible.
Under Section 63, an electronic record produced as evidence must be accompanied by a certificate identifying the record, describing the manner in which it was produced, and giving particulars of the device or process involved — signed by the person in charge of the device and by an expert. Without that certificate, the printout is a piece of paper with numbers on it.
Three practical consequences follow.
First, chain of custody must be documented from the moment of seizure. When a laptop or server image is taken, record who took it, when, in whose presence, and what hash value the image produced. If the hash of the working copy does not match the hash of the original at the time of production, the defence will say the data was altered, and they will be right to ask.
Second, work on images, never on originals. Opening a live accounting file changes access timestamps and, in some systems, writes to the database. Take a forensic image, verify the hash, seal the original, and analyse only the copy.
Third, the interview is evidence too. Statements recorded from employees must be voluntary, contemporaneously written, read back, and signed. A statement obtained under pressure — or reconstructed from memory three weeks later — is worse than no statement, because it hands the other side a credibility attack that taints the whole report.
The general rule to work by: if you cannot explain, on a single page, where a document came from, who handled it, and why the copy in the annexure is identical to what existed on the system, do not put it in the report.
Step-by-step: how to run or commission one properly
- Fix the mandate in writing before starting. The engagement letter must state the trigger (RBI RFA, NCLT direction, board resolution, audit committee instruction), the period under review, the entities and accounts in scope, the reporting line, and who owns the report. Ambiguity here is what later lets a client say the auditor exceeded the brief.
- Confirm independence, and confirm it separately. The existing statutory auditor should generally not conduct the forensic audit on the same period. Reviewing your own prior conclusions is a self-review threat, and where lenders or a regulator will read the report, that threat is fatal to its weight.
- Preserve before you analyse. Issue a litigation hold. Suspend auto-deletion on mailboxes. Image the relevant devices and record hash values. This step is first because evidence destroyed on day two cannot be recovered on day thirty.
- Build the data room and reconcile it to the books. Tie the extracted ledgers back to the signed financial statements for each year in scope. If the extract does not reconcile, every finding drawn from it is arguable.
- Run the tests, then look for the exceptions. Vendor master versus employee master on bank account and address fields. Round-sum payments. Payments just below approval thresholds. Journal entries posted outside working hours or by users with no business reason to post them. Credit notes issued near period end. Related-party flows not disclosed under Section 188.
- Corroborate every finding from at least two independent sources. A single ledger entry is a data point. A ledger entry, the underlying invoice, the bank narration and the approval email is a finding.
- Give the affected persons an opportunity to respond. Natural justice is not optional. A report that names individuals without putting the allegations to them will be challenged on that ground alone, and the challenge usually succeeds in delaying everything.
- Write the report in two layers. Findings of fact, each cross-referenced to an annexure. Then, separately, inferences. Never blend them. The forensic auditor's job is to establish what happened; the characterisation of it as an offence under Section 447 is for the authority, not the auditor.
- Report upward where the statute requires it. If the engagement surfaces fraud and you are also the statutory auditor, the Section 143(12) clock is running independently of the forensic timetable.
FAQ
Can my statutory auditor also do the forensic audit?
For the same period, no — not in any engagement where a bank, the NCLT or SEBI will read the report. The self-review threat destroys the report's credibility even where no rule expressly bars it. Appoint a separate firm, and document why.
Is a forensic audit report admissible in court on its own?
No. The report is an expert opinion; it is only as strong as the evidence annexed to it. The underlying electronic records must independently satisfy the certificate requirement under Section 63 of the Bharatiya Sakshya Adhiniyam 2023. Courts routinely accept the report while rejecting individual annexures that lack the certificate — and the findings resting on those annexures fall with them.
What is my personal exposure as the CA signing it?
Three distinct heads. Professional misconduct proceedings before the ICAI under the Chartered Accountants Act 1949 for negligence or failure to obtain sufficient information. Action by the National Financial Reporting Authority under Section 132 of the Companies Act 2013 where a listed or large unlisted company is involved, with monetary penalties and debarment. And, where the report itself contains a knowingly false statement, Section 448 and potentially Section 447. Carry professional indemnity cover sized to the engagement, and keep the working papers — they are the only defence that works.
How long should it take, and what does it cost?
A single-entity review of two to three years typically runs six to twelve weeks; multi-entity or cross-border matters run considerably longer. Fees are time-based, and any firm quoting a fixed low fee before scoping the data volume has not understood the engagement. Insist on a scoping phase priced separately, then a fee for the main work once the data volume is known.
For your specific situation, book a consultation at harunraaj.com
Harun Raaj & Associates | Chartered Accountants
---
See Also
Need help with this?
Our team handles the paperwork. You focus on your business.