Audit & Assurance
Forensic Audit & Fraud Detection
Forensic Audit
Frequently Asked Questions
What is the legal authority under which a forensic audit can be ordered in an Indian company, and who can appoint the forensic auditor?
A forensic audit can be ordered by the Board of Directors under Section 179 of the Companies Act 2013 in exercise of its general powers of management, or by the National Company Law Tribunal under Section 213 which empowers it to direct the Serious Fraud Investigation Office to investigate the affairs of a company on complaint. The Central Government may also order an investigation under Section 210 if it appears that the business of the company is being conducted fraudulently. For listed companies, SEBI may direct a forensic audit under Regulation 33 read with SEBI Circular SEBI/HO/CFD/CMD1/CIR/P/2021 as part of financial reporting oversight. The appointed forensic auditor typically a Chartered Accountant should have no prior engagement with the entity to preserve independence.
What types of fraud does a forensic audit typically investigate, and what standards govern the investigation?
A forensic audit typically covers misappropriation of assets, financial statement fraud (inflated revenues, understated liabilities), procurement fraud, payroll fraud, related-party siphoning, and cybercrime-related financial losses. The Institute of Chartered Accountants of India's Standard on Auditing 240 (The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements) sets out fraud risk factors and escalation duties for statutory auditors, while ICAI's Technical Guide on Forensic Accounting and Investigation Standards (2021) provides the methodology for dedicated forensic engagements. Digital evidence must be collected and preserved according to the Bharatiya Sakshya Adhiniyam 2023 (≡ Indian Evidence Act 1872, in force 1 Jul 2024) to ensure admissibility in court. A forensic report that does not follow chain-of-custody protocols may be challenged in NCLT or criminal proceedings.
If fraud is detected during a forensic audit, what are the mandatory reporting obligations of the CA?
Under Section 143(12) of the Companies Act 2013, if an auditor (including a forensic auditor engaged by the company) has reason to believe that an offence involving fraud is being or has been committed against the company by officers or employees, and the amount involved exceeds Rs 1 crore, the matter must be reported to the Central Government (Ministry of Corporate Affairs) within 60 days of knowledge. Below Rs 1 crore, the auditor must report to the Audit Committee or the Board within two days. Failure to report is an offence under Section 143(15) punishable with imprisonment up to one year and a fine between Rs 1 lakh and Rs 25 lakh. Additionally, Section 447 of the Companies Act 2013 defines fraud broadly and provides for imprisonment of 6 months to 10 years and fine for the perpetrators.
Can the forensic audit report be used as evidence in criminal proceedings against the accused employees?
A forensic audit report prepared by a Chartered Accountant can be submitted as documentary evidence in criminal proceedings, but its evidentiary weight depends on whether the data was collected in compliance with the Bharatiya Sakshya Adhiniyam 2023 (≡ Indian Evidence Act 1872, in force 1 Jul 2024), particularly Sections 61-65 governing electronic records and certificates for admissibility. The forensic auditor may be required to testify as an expert witness under Section 45 of the BSA 2023. For the report to be effective before the SFIO or CBI, the CA must be prepared to authenticate the methodology, tools used for data extraction (e.g. EnCase, FTK), and any hash values used to preserve data integrity. Reports based solely on management-provided data without independent verification carry limited evidentiary value.
What red flags in a company's books typically trigger a forensic audit referral?
Common red flags that trigger forensic audit referrals include unusual related-party transactions not at arm's length under Section 188 of the Companies Act 2013, round-tripping of funds through multiple layered entities, revenue recognition inconsistencies flagged under Ind AS 115, unexplained cash deposits or withdrawals in bank statements, and vendor payments to addresses matching employee residences. Auditors are required to assess fraud risk factors under SA 240 and escalate when journal entries are posted outside normal hours, when reconciling items persist beyond 90 days, or when management overrides internal controls consistently. SEBI's forensic audit guidelines for listed entities (SEBI circular dated March 19, 2021) also flag sudden changes in auditors, qualifications in audit reports, and pledging of promoter shares above 50% as triggers warranting investigation.
Ready to get Forensic Audit & Fraud Detection?
File a request in under 2 minutes. Our team contacts you within 24 hours.