What Forensic Auditors Actually Do

A forensic auditor investigates financial records to determine whether discrepancies reflect error, control failure, misconduct, or some combination of those possibilities. The work is different from a conventional financial-statement audit: a normal audit tests whether financial statements are fairly presented in material respects, while a forensic examination focuses on reconstructing transactions, tracing money, testing internal controls, identifying anomalies, and preserving evidence. A forensic audit may examine invoices, bank records, contracts, payroll, general-ledger entries, related-party transactions, and system-access logs. It can also interview employees and compare records held by third parties. The objective is not simply to find a mathematical difference, but to explain its cause, estimate its financial effect, and identify who was involved or which controls failed. The examiner should clearly define whether the assignment is a fraud examination, a reconciliation, a control review, or a broader financial investigation. This distinction matters because a discrepancy does not by itself prove fraud.

Also worth reading: How Should Organizations Investigate an Audit Discrepancy Before It Becomes a Financial Investigation? · What Is Forensic Financial Investigation and When Do You Need One? · What are the forensic accounting investigation best practices in 2026?

Forensic auditors must combine accounting knowledge with investigative technique. They should know how to trace electronic payments, identify duplicate invoices, test journal entries, analyze unusual year-end activity, and document every conclusion. A qualified professional may hold a CPA, CFE, CIA, CISA, or other relevant credential, although the title alone does not guarantee investigative competence. The right team should also understand the organization’s industry, accounting system, funding restrictions, and legal environment. For example, reviewing a nonprofit requires attention to donor restrictions and grant reporting, while tracing a municipal discrepancy may require knowledge of public-bidding rules, segregation of duties, and state audit requirements.

How to Define the Scope Before Hiring

Many organizations make the mistake of requesting a “forensic audit” without specifying what they want tested. Before soliciting proposals, the client should identify the discrepancy, the period involved, the records available, and the decisions the investigation must support. A bank reconciliation difference of $322,000 may require only a limited transaction trace, while repeated unexplained cash shortages over five years may justify a broader examination of purchasing, payroll, and journal entries. The scope should state whether the auditor will calculate the potential loss, interview management, review legal compliance, test anti-fraud controls, or provide testimony in litigation. It should also establish whether the engagement covers only the suspected period or several prior fiscal years.

The written scope protects both sides. It prevents the expectation that every unexplained balance is necessarily fraud and reduces the risk of an investigation that is too narrow to identify the underlying control weakness. The client should identify the systems and custodians involved, including the accounting platform, bank portals, payroll provider, purchasing system, and cloud storage. It should also state who has authority to approve access and who will receive interim findings. A practical threshold might be to escalate an issue when a single transaction exceeds $10,000, when repeated entries exceed $25,000 in aggregate, or when any discrepancy involves possible misappropriation, regulatory reporting, or management override. Those figures are starting points rather than universal rules; the organization must set thresholds proportionate to its size and risk.

The Questions to Ask Every Candidate

The most useful interview question is not “How many forensic audits have you done?” but “Show us how you would investigate this specific issue.” A capable candidate should explain how they would obtain source documents, establish a complete population of relevant transactions, reconcile records, and preserve a chain of custody. They should distinguish between corroborating evidence and assumption, identify records that could independently confirm a transaction, and describe how they would handle contradictory evidence. Ask who will perform the work, whether the engagement partner will remain involved, and whether the team has experience with the client’s industry and investigative method.

References should be checked carefully. A client can request two or three engagements that are similar in scale, then speak with the referenced clients about communication, responsiveness, evidence quality, and whether the final findings were useful in a board meeting, regulatory response, or court proceeding. It is also important to ask about conflicts of interest. A firm that performs the client’s annual audit may have useful institutional knowledge, but independence can be questioned if it also designs the controls being tested or has a financial relationship with the suspected person. For a regulated or publicly funded entity, procurement rules and independence requirements should be reviewed before selecting the firm.

FeatureAccounting-firm forensic teamIndependent forensic specialistInternal audit teamLaw-firm-led investigation
Best useComplex financial tracing and accounting analysisFocused testing or technical evidence reviewPreventive control assessment and internal follow-upLitigation, preservation, interviews, and legal strategy
Typical strengthAudit methodology, financial systems, and reportingDirect specialist attention and flexibilityInstitutional knowledge and ongoing control ownershipLegal privilege and formal evidence procedures
Main limitationMay have conflicts or limited field-investigation capacityMay lack broad organizational resourcesCan lack independence if internal reporting lines are weakOften does not provide the same depth of financial reconstruction unless supplemented
Cost profileCommonly higher for large or multi-year workModerate for a defined scopeLower marginal cost, but consumes internal capacityHighest when litigation and extensive interviews are required
DeliverableReconciliations, tracing schedules, quantified findings, and control recommendationsNarrow technical report or testing resultsControl findings and remediation planPrivileged legal analysis supported by financial evidence
The table is a starting framework, not a ranking. The correct alternative depends on whether the immediate need is an accounting reconstruction, an internal-control assessment, technical testing, or litigation support. A hybrid team can be efficient: for example, a law firm may lead interviews and evidence preservation while an accounting firm traces the funds and quantifies the loss.

Comparing Proposals Without Comparing Only Prices

Forensic-audit prices vary because the amount of work depends on data volume, record quality, number of locations, interview requirements, and the expected reporting audience. The supplied research includes a reported municipal range of approximately $6,500 to $65,000 for forensic-audit proposals in Mt. Morris Township, which illustrates how widely scope and pricing can differ. That range should not be treated as a market standard. A small reconciliation may cost less, while a multi-year examination of a public agency or a company with millions of transactions can require a substantially larger budget. The client should ask whether the quote includes data extraction, travel, interviews, expert analysis, report preparation, presentations, and follow-up testing.

A proposal should identify deliverables and assumptions. A weak proposal may simply say the firm will “investigate irregularities” and provide a broad estimate. A stronger proposal names the records to be reviewed, explains the transaction-tracing method, identifies testing populations, states the expected number of interviews, and specifies what will happen if records are missing. The client should also establish a process for change orders. If the initial population reveals a second issue, the auditor should not silently expand the work without written authorization, although the client should recognize that refusing necessary evidence can undermine the conclusion.

Cost can be controlled by first conducting a limited scoping phase. Many firms can review a bank reconciliation, account listing, and sample documents for a fixed preliminary fee, then provide a written estimate for the full investigation. This is useful when management is unsure whether the issue is an accounting error or a broader control failure. It is also safer than choosing a low fixed bid that ignores the volume of records. The client should compare total expected cost, not merely the hourly rate or headline engagement price.

Methods, Systems, and Evidence Quality

The best method depends on the type of discrepancy. For cash tracing, the auditor may follow funds from their origin through bank statements, ledgers, invoices, approvals, and recipient records. For revenue, the examiner may test whether recorded receipts agree with point-of-sale data, payment-processor reports, contracts, and remittance records. For payroll, the auditor may compare employee rosters, time records, tax filings, bank deposits, and terminated employees. For suspected procurement fraud, the review may test bid thresholds, split purchases, duplicate vendors, conflicts of interest, and invoice-to-receipt matching. Computerized analytics can identify duplicate payments, round-dollar transactions, weekend entries, users with unusual access, and vendors sharing addresses or tax information, but a flag is only an investigative lead, not proof of misconduct.

Evidence quality must be evaluated carefully. Bank statements and system audit logs are generally more useful than editable spreadsheets, especially when originals can be obtained directly from the bank or software provider. A missing invoice does not automatically mean the expense was fictitious; it may reflect poor archiving, a lost receipt, or an undocumented transaction. Conversely, a complete file can still conceal falsification if the same person created the underlying source data. The auditor should document chain of custody, preserve original files with metadata, record the date and source of each download, and use working papers that permit another examiner to repeat the tests. Digital evidence should not be altered merely because a spreadsheet appears disorganized.

The investigator should also use sampling strategically. A statistical sample can estimate error rates when a population is large and fairly structured, but a targeted sample is more appropriate when the risk is concentrated in specific vendors, users, dates, or transaction types. The client should ask how sampling decisions will be made and whether exceptions will expand the review. In a high-risk investigation, random sampling alone may miss a carefully concealed pattern.

Common Mistakes in Selecting a Forensic Audit Firm

One common mistake is hiring based on reputation, credentials, or a low price without testing the firm’s investigative approach. Large accounting firms may have strong technical resources but may assign junior staff after the sales interview. Small specialists may provide more direct attention but may have less capacity for a large data extraction. A firm’s marketing language should not substitute for a demonstrated understanding of the client’s records and risks. Another mistake is assuming that an outside audit guarantees fraud detection. Conventional audits are not designed to investigate every possible misconduct, and even reputable audits can miss fraud involving collusion, forged documents, or management override.

A second error is giving the auditor incomplete records or asking for a guaranteed answer. If a client withholds relevant emails, destroys responsive documents, or limits interviews because they are inconvenient, the final report may be qualified and the result may not satisfy a board, regulator, insurer, or court. The client should preserve records, suspend unnecessary deletion processes, and assign a knowledgeable project lead who can obtain information. Management should not edit a report before release, because doing so can undermine credibility and create an appearance of interference.

A third error is confusing a control review with a fraud conclusion. A finding that invoices were approved by the same person who paid them is serious, but it does not establish that money was stolen. The report should separate observed facts, possible explanations, control deficiencies, and unresolved questions. It should quantify what can be supported by evidence and clearly mark estimates as estimates. When the evidence is inconclusive, a qualified conclusion is more defensible than a confident accusation.

When to Act and How to Structure the Engagement

The organization should act promptly when a discrepancy could involve ongoing losses, destroyed evidence, legal deadlines, regulatory reporting, or an officer or employee with authority to alter records. Immediate steps may include restricting system access, preserving bank and accounting data, documenting the missing amount, and engaging counsel if a regulatory or criminal process is possible. The organization should avoid confronting a suspected individual before the evidence and interview strategy are considered, because an unplanned conversation can trigger document destruction, witness coaching, or unnecessary public disclosure.

An engagement letter should state the authority of the forensic team, access to records, interview protocols, confidentiality, privilege expectations where applicable, reporting recipients, and the distinction between findings and legal conclusions. The board or audit committee may need a separate channel for significant findings. Many organizations use a three-phase structure: an immediate triage of the reported discrepancy, a deeper forensic examination of the relevant transaction population, and a post-engagement review of control remediation. Each phase should have a written objective and acceptance criteria.

The client should also decide whether remediation is part of the project. A report that identifies a weak approval process but leaves the process unchanged may not prevent recurrence. Ask the firm to test redesigned controls after implementation, establish responsibility for each corrective action, and report whether the new control operates consistently for a defined period. A 90-day follow-up can be useful for a straightforward control change, while a transaction-heavy remediation may require six or twelve months of observation. Timing depends on transaction volume and the frequency with which the control is used.

What a Final Report Should Contain

A useful forensic-audit report should allow a reader who did not conduct the work to understand what happened and why. It normally includes the scope, limitations, source records, procedures performed, factual findings, financial calculations, control deficiencies, recommended actions, and unresolved questions. The report should not bury the amount or nature of a significant finding in vague language. It should identify the affected accounts, periods, transactions, and systems, while avoiding unsupported conclusions about intent.

The financial schedule should reconcile the beginning balance, identified transactions, adjustments, and ending discrepancy. If a loss is estimated, the report should explain the sample, assumptions, treatment of incomplete records, and degree of uncertainty. It should also distinguish confirmed amounts from possible exposure. A table showing confirmed receipts of $40,000, a questioned $12,500, and an unresolved $3,000 is more informative than a single statement that the investigation found “problems.”

The control recommendations should be practical. Separating purchase approval from payment is more useful than simply telling management to “improve controls.” Other recommendations may include requiring two vendor-master approvers, reconciling bank accounts monthly, reviewing duplicate-payment reports, prohibiting one person from edit and payment authority, and requiring independent confirmation for large wire transfers. The client should assign owners and deadlines, then verify operation. A forensic examination is valuable not only because it explains the past but also because it gives management a defensible basis for preventing the same failure from recurring.

Choosing a forensic auditor is therefore a process of matching investigative capability to a defined problem, not selecting the most impressive name or the cheapest proposal. Obtain competing proposals, test the proposed method, verify independence, define evidence requirements, and require a report that separates facts from inference. The organization should involve legal, compliance, and technical advisers when the issue reaches beyond ordinary accounting. Used carefully, a forensic audit can identify discrepancies, quantify exposure, and correct the control environment; used poorly, it can produce a report that is expensive, inconclusive, or disconnected from the decision the organization needs to make.