CA Helper
Audit & Assurance

Forensic Audit Basics: When It's Commissioned and How It Differs From a Regular Audit

A forensic audit asks a different question than a statutory audit: not whether the statements are fair overall, but whether something specific actually happened.

CA Helper Editorial Team7 min read
A forensic auditor examining financial records and transaction documents at a desk

Key takeaways

  • Forensic audits are triggered by a specific concern, fraud suspicion, a dispute, or a lender's requirement, not run as a routine annual exercise
  • Materiality works differently: a comparatively small amount can be entirely in scope if it establishes a pattern or identifies who was involved
  • The output is typically a report of findings and evidence rather than an opinion on the financial statements as a whole
  • Evidence has to be gathered and preserved to a standard that can survive litigation or regulatory scrutiny, not just an audit file review
  • The skillset draws on digital forensics, structured interviewing and legal grounding well beyond a standard financial statement audit

A statutory audit tells you whether the financial statements, taken as a whole, are fairly presented. A forensic audit asks a completely different kind of question: did a specific thing happen, who was involved, and how much did it cost? The two get confused because both involve a CA working through a company's books, but the objective, the depth, the standard of evidence and even the audience are different enough that treating forensic work as 'a more thorough version of a normal audit' leads to a badly scoped engagement. For a CA being pulled into forensic work for the first time, usually because a statutory audit uncovered something that needed a closer look, the shift in mindset matters more than any specific technique.

What Actually Triggers a Forensic Audit

Forensic audits rarely start from a clean slate, something specific has already raised suspicion. A whistleblower complaint, an unusual variance an internal or statutory auditor flagged but could not fully explain within the normal audit timeline, a sudden resignation by a CFO or an auditor citing unspecified concerns, or a related-party transaction without any commercial rationale anyone can articulate are all common starting points. Lenders are a significant source of forensic audit mandates in India, once an account shows signs of fraud or diversion of funds, particularly in consortium or multiple-banking arrangements, RBI's fraud risk management framework expects the lending banks to commission a forensic audit once exposure crosses a specified threshold, with the findings feeding directly into how the account gets classified and reported.

  • Suspected fraud or misappropriation flagged internally, by a whistleblower, or during a statutory or internal audit
  • Lender-driven mandates once an account shows fraud indicators or fund diversion, particularly above the exposure thresholds RBI's fraud risk framework sets for consortium and multiple-banking accounts
  • Shareholder, partner or joint-venture disputes where one side alleges siphoning or misrepresentation of financial position
  • Due diligence red flags surfacing during a merger, acquisition or investment round
  • Court or regulatory directions, including matters referred for investigation under the Companies Act's fraud provisions

How the Objective Differs From a Statutory Audit

A statutory audit is built around materiality and reasonable assurance across the financial statements as a whole, a misstatement too small to matter to a reader's decisions is, by design, not something the audit is obligated to chase down. Forensic audit inverts that logic. A diversion of a comparatively small amount can be entirely within scope if it establishes a pattern, implicates a specific individual, or matters to the party that commissioned the engagement, regardless of whether it would ever have moved the needle on the overall financial statements. Sampling gives way to a close, often complete, review of the specific transactions, period or individuals under suspicion. And where a statutory audit ends in an opinion on the financial statements, a forensic audit typically ends in a report of findings and observations, laying out what the evidence shows, how it was gathered, and its limitations, without necessarily reaching a definitive conclusion the way an audit opinion does, since that determination often belongs to a court, a regulator, or the board itself.

Evidence Has to Survive Outside the Audit File

The evidentiary bar is the biggest practical difference. A statutory audit's working papers are built to support an opinion and survive a peer review. Forensic evidence often has to survive cross-examination, arbitration, or a regulator's own investigation, which changes how it needs to be gathered and preserved from day one. Chain of custody matters, an email or accounting entry pulled without documenting who accessed it, when, and how the original was preserved can lose much of its value in a legal proceeding, however clear it looked in isolation. Digital evidence typically needs forensic imaging rather than a simple copy-paste export, interviews need to be documented contemporaneously rather than summarised from memory afterward, and original documents need to stay traceable rather than being annotated directly. Many forensic engagements are commissioned through external legal counsel specifically so the work can claim privilege, a structuring decision that has to be made before the engagement starts, not retrofitted once findings are already written up.

The Skillset Looks Different Too

Forensic work draws on capabilities a standard audit rarely calls for in depth, structured interviewing, data and digital forensics for recovering or tracing electronic records, tracing money flow through layered transactions and related entities, and enough familiarity with the relevant law, the Companies Act's fraud provisions, the criminal law provisions on cheating and criminal breach of trust, and anti-money laundering law where it is alleged, to frame findings in terms that hold up outside an accounting context. A forensic auditor is also more likely to end up giving expert testimony on their findings, a different discipline from writing an audit opinion that nobody expects the auditor to personally defend under cross-examination.

None of this makes forensic audit a more advanced version of statutory audit that any experienced auditor can simply scale up into. It is a different exercise with a different objective, a different tolerance for what counts as immaterial, and a much higher bar for how evidence is preserved. A CA moving into this work for the first time does better starting from that distinction than from assuming existing audit habits will transfer unchanged.

Frequently asked questions

Who typically commissions a forensic audit?

It varies. A company's own board or audit committee, a lender in a consortium or multiple-banking arrangement once fraud indicators appear, a court or regulator directing an investigation, or one side in a shareholder or partner dispute can all commission one. It is rarely commissioned by the same statutory auditor who first flagged the concern, since independence and scope both call for a distinct engagement.

Does a forensic audit replace the statutory audit for that year?

No. They serve different purposes and usually run alongside or after each other rather than one substituting for the other. The statutory audit still has to be completed and opined on separately, even while a forensic audit is investigating a specific concern.

Is materiality still relevant in a forensic audit?

Not in the same way. A statutory audit uses materiality to decide what is worth chasing across the financial statements as a whole. Forensic work can pursue a comparatively small amount if it establishes a pattern, identifies who was involved, or matters to whoever commissioned the engagement, regardless of its size relative to the overall financials.

What happens to the forensic audit report once it is finished?

That depends on who commissioned it. A lender-driven forensic audit typically feeds into the bank's internal fraud classification and its reporting to RBI. A board-commissioned one might go to the audit committee, be used in a disciplinary or legal process, or in some cases get referred to a regulator, depending on what it finds.

Can any practising CA take up forensic audit assignments?

Technically yes, there is no separate licence requirement, but the work leans heavily on skills a standard audit training does not fully cover, digital forensics, structured interviewing, and enough legal grounding to make findings hold up outside an accounting context. Most CAs build into this area through specific experience or specialised certification rather than picking it up incidentally.

This article is for general informational purposes only and does not constitute professional tax, legal, or financial advice. Rules and rates change, so consult a qualified Chartered Accountant for advice specific to your situation.

Related reading