The phrase "forensic audit" is used loosely, sometimes to mean any detailed audit and sometimes to mean a full fraud investigation. For a board or finance leader deciding whether to commission one, the distinction matters. This article explains what a forensic audit is, how it differs from the audits an organisation already has, and the situations in which one is worth commissioning.
A different question from a statutory audit
A statutory audit answers one broad question: do the financial statements, taken as a whole, give a true and fair view? The auditor plans the work around materiality, relies substantially on sampling, and provides reasonable, not absolute, assurance. Under SA 240, the auditor is responsible for obtaining reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error. The auditor is not, however, engaged to investigate specific suspicions.
A forensic audit starts from a specific question. Were payments to a particular vendor genuine? Were loan funds used for the stated purpose? Did a group of transactions move money to related parties? The work is designed to answer that question with evidence, which usually means examining the relevant transactions in full rather than sampling them, tracing funds beyond the organisation's own books, and documenting findings to a standard that can be relied on in legal or regulatory proceedings.
The professional framework in India
Since 1 July 2023, members of the Institute of Chartered Accountants of India carrying out forensic accounting and investigation engagements have been required to follow ICAI's Forensic Accounting and Investigation Standards (FAIS). The standards are principle-based and cover the whole engagement: accepting the work and confirming independence, planning, gathering and documenting evidence, conducting interviews, working with digital evidence and reporting.
A central principle is that the forensic accountant reports facts and the evidence supporting them. Deciding whether someone is guilty or liable is for the court, regulator or other appropriate authority. A well-written forensic report is useful precisely because it separates what the evidence shows from what might be inferred.
When organisations commission a forensic audit
The triggers vary, but most fall into a few groups:
- An allegation or tip. A whistleblower complaint, an anonymous letter or a concern raised by an employee needs to be examined independently and quickly.
- An unexplained anomaly. Stock that does not reconcile, margins that have shifted without explanation, or a vendor whose spend has grown faster than the business.
- The statutory auditor's concerns. Under Section 143(12) of the Companies Act, 2013, an auditor who has reason to believe that a fraud is being or has been committed against the company by its officers or employees must report it. Rule 13 of the Companies (Audit and Auditors) Rules, 2014 requires frauds of ₹1 crore or more to be reported to the Central Government, and smaller amounts to the audit committee or board. CARO 2020 separately asks the auditor to report on frauds noticed during the year and on whistleblower complaints considered. A board facing such a report usually needs a forensic review to understand the facts.
- Lenders. Banks and financial institutions commission forensic audits when an account shows early warning signals or is under review for possible fraud, to establish how the borrowed funds were actually used.
- Insolvency. Resolution professionals and liquidators examine transactions that may be preferential, undervalued, extortionate or fraudulent under Sections 43, 45, 50 and 66 of the Insolvency and Bankruptcy Code, 2016. These transaction audits are forensic in nature.
- Disputes. Shareholder, partnership and commercial disputes often turn on how money was accounted for and where it went.
What the engagement looks like
Every engagement is different, but the stages are broadly consistent:
- Scoping. Agreeing the questions to be answered, the period and entities in scope, access to records and people, and reporting lines. Where litigation is possible, engaging through legal counsel is often sensible.
- Preserving evidence. Securing documents, emails and system data before they can be altered or lost, and recording a chain of custody.
- Analysis. Reconstructing transactions, tracing funds, testing data in full and comparing records against independent sources such as bank statements, tax filings and third-party confirmations.
- Interviews. Speaking with relevant people once the documentary picture is clear, so that questions are specific and responses can be tested against the evidence.
- Reporting. A report that sets out the scope, the procedures performed, the findings and the evidence for each one, and any limitations.
Getting the most from a forensic audit
A few decisions early on make a large difference. Act quickly to preserve evidence, since data is easiest to secure before anyone knows an inquiry is under way. Keep the circle small: tell only those who need to know. Be precise about the questions, because a clear scope produces a useful report on time and within budget. Finally, plan what happens next. A forensic audit often leads to recovery action, disciplinary proceedings, disclosures or control improvements, and the report is most valuable when it has been scoped with those uses in mind.
This article is general information and not professional advice. It reflects the law and practice as understood on the date of publication. Please read our Disclaimer.


