Harun Raaj & AssociatesHarun Raaj & Associates
🔍 Forensic Audit

Fraud Risk Assessment

Systematic assessment of fraud risks in financial processes and internal controls.

Start — upload documents, pay when ready →Talk to a CAWhatsApp us
SCOPEConfirmed in writing
TYPICAL TIMELINE14 days
APPLICABLE TOCompany

Regulatory Framework

Fraud risk assessment engagements at HRG are structured around the statutory fraud-reporting duty placed on company auditors under Section 143(12) of the Companies Act, 2013, read with Rule 13 of the Companies (Audit and Auditors) Rules, 2014.

Section 143(12) requires an auditor who, in the course of performing statutory audit duties, has reason to believe that an offence involving fraud is being or has been committed against the company by its officers or employees, to report the matter in the manner prescribed. Rule 13 sets out a threshold-based, two-track reporting process:

  • Fraud of ₹1 crore or above (involving or expected to involve): the auditor must first inform the Board or Audit Committee in writing within 2 days of becoming aware of the suspected fraud, seeking their reply or observations within 45 days. On receipt of that reply (or on expiry of the 45-day window), the auditor must forward the report, together with the Board/Audit Committee's observations and the auditor's own comments, to the Central Government (Ministry of Corporate Affairs) in Form ADT-4 within 15 days — a total statutory window of roughly 60 days from the date of knowledge.

  • Fraud below ₹1 crore: reported only to the Audit Committee (or Board, where no Audit Committee is constituted) within 2 days of knowledge; no Central Government filing is triggered at this tier.

Because the ₹1 crore threshold determines whether a suspected irregularity escalates to a Central Government filing (with attendant regulatory and reputational consequences), an independent, methodical fraud risk assessment — covering revenue recognition, related-party transactions, vendor/procurement controls, and journal-entry testing — is the practical mechanism by which companies and their auditors quantify exposure before this reporting clock starts running. Our assessments are scoped to surface and value red flags against this exact ₹1 crore threshold, so that Boards and Audit Committees can respond within the Rule 13 timelines with a documented, defensible position.

Overview

Fraud risk assessment is the systematic identification of where a business is vulnerable to fraud — the processes, the people and the controls where money can leak. The assessment maps the fraud risks across the business: the vendor master that nobody reviews, the payments approved by one person, the inventory counted by the same people who control it, the cash that never reconciles, the related-party transactions that circle back. For each risk, the assessment evaluates the likelihood, the impact and the controls in place. It is the preventive sibling of the forensic audit.

The value of the assessment is that it finds the fraud before the fraud finds the business. The classic frauds are all control failures — segregation of duties, authorization, reconciliation — and each is discoverable in a structured review. The assessment scores the business against the fraud triangle: the pressure, the opportunity and the rationalisation. Where the opportunity exists, the fraud will eventually be attempted; the assessment finds the opportunities.

The cost of skipping the assessment is the fraud itself: the leak that runs for years because nobody looked, the controls that existed on paper but never operated, the single point of failure that a determined employee exploits. The assessment is cheap relative to the fraud it prevents — the prevention is the point.

This service is for companies that want their fraud exposure known and reduced. We map the processes and the risks, test the controls, score the exposure and the controls, and deliver the risk register with the prioritized fixes — the segregation, the authorizations and the reconciliations that close the opportunities.

How It Works

  1. 1

    Process & Risk Mapping

    We map the key financial processes and the fraud risks within each.

    Harun Raaj & Associates does this1 week
  2. 2

    Control Testing

    We test the controls — segregation, authorization, reconciliation — for each risk area.

    Harun Raaj & Associates does this1-2 weeks
  3. 3

    Risk Scoring

    We score the likelihood and impact of each risk and the adequacy of the controls.

    Harun Raaj & Associates does this3-5 days
  4. 4

    Risk Register & Fixes

    We deliver the risk register with the prioritized remediation plan.

    Harun Raaj & Associates does this1 week
  5. 5

    Remediation Support

    We support the implementation of the fixes and the re-testing.

    Harun Raaj & Associates does this2-4 weeks

Ready to get Fraud Risk Assessment?

File a request in under 2 minutes. Our team contacts you within 24 hours.

Start — upload documents, pay when ready →