Hands typing on a laptop showing a data spreadsheet

Traditional audit procedures examine a sample of transactions and extrapolate. That works for forming an opinion on financial statements, but fraud is rarely spread evenly across a population. It hides in a handful of entries among hundreds of thousands. Forensic data analytics tests every transaction, which changes the question from "is this sample clean?" to "where exactly are the exceptions?"

Start with the data, and prove it is complete

Every analysis is only as good as the data behind it. Before any testing, the extract should be reconciled to the trial balance and control totals, so that no ledger, period or location has been left out. For investigations, the extraction process should be documented and the files secured with hash values, so that it can be shown later that the data was not altered after it was obtained.

Tests that pay off most often

TestWhat it can reveal
Duplicate and near-duplicate paymentsInvoices paid twice, sometimes with a small change to the invoice number, date or amount
Vendor-to-employee matchingShared bank accounts, PAN, addresses or phone numbers between vendors and employees
Threshold analysisClusters of transactions just below approval limits, and orders split to avoid them
Sequence gaps and duplicatesMissing or reused document numbers in invoices, receipts or cheques
Round-sum amountsEstimates, manual entries or invented figures in populations that should contain irregular values
Timing analysisEntries posted on weekends, holidays, late at night or just before period-end
Journal entry testingManual entries to unusual account combinations, entries by unexpected users, or entries that reverse after the period closes
Trend and ratio analysisVendors, customers or cost centres whose behaviour departs sharply from their own history or their peers

Journal entries deserve particular attention. Management override of controls is one of the most serious fraud risks, and SA 240 specifically requires auditors to test the appropriateness of journal entries recorded in the general ledger. Full-population analytics makes that testing far more thorough.

Benford's Law: useful, but handle with care

In many naturally occurring sets of numbers, the leading digit is not evenly distributed. The digit 1 appears as the first digit about 30.1% of the time, 2 about 17.6%, and so on down to 9 at about 4.6%. This pattern, known as Benford's Law, follows the formula P(d) = log10(1 + 1/d).

When people invent numbers, they tend to spread digits more evenly than nature does, so a population that departs markedly from the expected distribution can point to fabricated or manipulated entries. The same analysis on the first two digits can highlight specific amounts that appear unusually often, such as figures repeated just under an approval limit.

But Benford's Law has clear limits. It does not apply to assigned numbers such as invoice or phone numbers, to amounts constrained by a minimum or maximum, or to small populations. A deviation is a signal to investigate, not evidence of fraud. Used alongside the other tests above, it is a valuable way to direct attention.

Exceptions are leads, not findings. Every exception needs to be followed up with documents and explanations before any conclusion is drawn. Good analytics reduces the number of transactions a reviewer must examine; it does not replace the review.

From one-off analysis to continuous monitoring

Tests that prove useful in an investigation can be turned into rules that run every week or month, with exceptions routed to an owner for review. Vendor master changes, duplicate payments and threshold splitting are good candidates to start with. Monitoring shortens the time between a fraud starting and its detection, which is the single biggest factor in limiting losses.

Tools

Purpose-built audit analytics tools such as ACL and IDEA remain popular because they keep a log of every step and protect the source data. SQL, Python and R handle very large volumes and complex matching, and Power BI and similar tools turn results into dashboards that management can use. The right choice depends on the volume of data, the questions being asked, and whether the organisation wants to run the tests itself afterwards.

This article is general information and not professional advice. It reflects the law and practice as understood on the date of publication. Please read our Disclaimer.