How to Conduct a Forensic Audit in Corporate Fraud Cases Under Indian Law
- Kaustav Chowdhury

- 8 minutes ago
- 8 min read
Corporate fraud in India has grown in both scale and sophistication. From financial statement manipulation to fund diversion and related party abuse, fraudulent schemes demand rigorous investigation. A forensic audit is the cornerstone of such investigations, combining accounting expertise, legal knowledge, and investigative technique to uncover fraud, quantify losses, and produce evidence that stands up in court.
This guide provides a step-by-step framework for conducting forensic audits in corporate fraud cases under Indian law, outlining the legal basis, procedural requirements, and practical considerations that corporate lawyers, compliance officers, and forensic auditors need to know.
Understanding the Legal Framework
Before initiating a forensic audit, it is essential to understand the legal provisions that define corporate fraud and empower investigators.
Section 447 of the Companies Act, 2013: Defining Fraud
Section 447 of the Companies Act, 2013 is the primary provision defining fraud in the corporate context. It covers any act, omission, concealment of fact, or abuse of position committed by any person or with connivance, with the intent to deceive, gain undue advantage, or injure the interests of the company, its shareholders, creditors, or any other person.
The penalty is severe: fraud under Section 447 carries imprisonment ranging from six months to ten years, along with a fine that shall not be less than the amount involved in the fraud and may extend to three times that amount. Where the fraud involves public interest, the minimum imprisonment is three years.
SFIO Powers Under Sections 211 and 212
The Serious Fraud Investigation Office (SFIO) derives its statutory legitimacy from Sections 211 and 212 of the Companies Act, 2013. Section 211 establishes the SFIO as a multidisciplinary body comprising experts from banking, corporate affairs, taxation, capital markets, IT, forensic audit, and law. Section 212 grants SFIO extensive investigative powers, including the power to arrest individuals suspected of fraud under Section 447.
SFIO can prosecute fraud under Section 447 and initiate disgorgement under Section 212(14A), compelling fraudsters to return misappropriated funds. The Registrar of Companies (RoC) can also conduct enquiries into company affairs and report findings to the Central Government, which may then refer the matter to SFIO.
Twin Bail Conditions and PMLA Parallels
Section 212(6) of the Companies Act imposes twin bail conditions for offences investigated by SFIO, mirroring Section 45 of the Prevention of Money Laundering Act, 2002 (PMLA). Bail can only be granted if the Public Prosecutor has been given an opportunity to oppose the application and the court is satisfied that there are reasonable grounds to believe the accused is not guilty and is unlikely to commit any offence while on bail.
Where proceeds of corporate fraud are laundered, the PMLA provides additional teeth, allowing the Enforcement Directorate to attach and confiscate properties derived from scheduled offences.
Step 1: Appointment of Forensic Auditors
The process begins with appointing a qualified forensic auditor. The appointment may be initiated by the board of directors, the audit committee, a regulatory body, or a court order. Key considerations include the following.
Independence: The forensic auditor must have no conflict of interest with the company, its promoters, or key managerial personnel.
Qualifications: Forensic auditors are typically Chartered Accountants with specialised training in fraud examination and digital forensics. Firms with Certified Fraud Examiner (CFE) credentials are preferred.
Engagement Letter: A detailed engagement letter should define the scope, objectives, timelines, reporting obligations, confidentiality terms, and fee structure.
Board Resolution: Where the company itself initiates the audit, a board or audit committee resolution authorising the forensic audit should be passed, specifying the auditor and the scope of the investigation.
Step 2: Defining the Scope of the Forensic Audit
A well-defined scope is essential. It should be specific enough to guide the investigation but flexible enough to allow the auditor to follow the evidence where it leads. The scope definition should address the following elements.
Time Period: Specify the financial years or date range under investigation.
Transactions and Areas: Identify the specific transactions, accounts, departments, or business units to be examined.
Persons of Interest: List the individuals, related parties, or entities whose conduct is under scrutiny.
Fraud Hypothesis: Articulate the suspected fraud scheme based on available information, which will guide the audit procedures.
Reporting Obligations: Clarify whether findings will be reported to the board, regulators, law enforcement, or all of these.
Step 3: Evidence Collection and Preservation
Evidence collection is the most critical phase. The quality and integrity of evidence determine whether findings will be admissible in legal proceedings and persuasive before courts and regulators.
Types of Evidence
A forensic audit typically involves collecting three broad categories of evidence.
Financial Records: General ledgers, bank statements, invoices, purchase orders, vouchers, journal entries, trial balances, and financial statements.
Digital Evidence: Emails, chat messages, access logs, deleted files, forensic images of hard drives, server logs, and metadata. Digital evidence must be handled with forensic precision.
Operational Data: HR records, attendance logs, vendor master data, customer databases, internal audit reports, minutes of meetings, and correspondence files.
Chain of Custody
Maintaining a strict chain of custody is non-negotiable. Every piece of evidence must be documented from collection through storage, analysis, and presentation. The record should capture who collected the evidence, when and where it was collected, how it was stored, who had access, and what analyses were performed. Under the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced the Indian Evidence Act and came into force on July 1, 2024, electronic evidence must comply with the requirements for admissibility of electronic records. Any break in the chain of custody can render evidence inadmissible.
Step 4: Digital Forensics
In modern corporate fraud cases, digital forensics is almost always crucial. Financial manipulation, fund diversion, and asset siphoning invariably leave digital trails. The process follows five recognised stages.
Identification: Determine which digital devices, systems, and data repositories are relevant. This includes computers, mobile phones, servers, cloud storage, ERP systems, email servers, and backup media.
Preservation: Create forensic images (bit-for-bit copies) of all relevant digital media. Forensic imaging must be performed using validated tools, and hash values (MD5 or SHA-256) must be generated and recorded to verify data integrity. Original media should be sealed and stored securely.
Analysis: Examine forensic images for relevant evidence. Techniques include keyword searches across emails and documents, timeline analysis of file access and modifications, recovery of deleted files, and review of system and application logs.
Documentation: Maintain detailed logs of every step taken during the forensic process, including the tools used, the parameters applied, the findings at each stage, and the qualifications of the examiner. This documentation forms the basis of the expert report.
Presentation: Prepare digital evidence for presentation before courts, regulators, or internal stakeholders in a manner understandable to non-technical audiences while retaining forensic integrity.
Under the BSA, electronic records are admissible as evidence when accompanied by a certificate under Section 63 (which corresponds to the former Section 65B of the Indian Evidence Act). Forensic auditors must ensure that all electronic evidence is accompanied by the requisite certification.
Step 5: Analysis, Investigation, and Quantification
With evidence collected and preserved, the forensic auditor proceeds to analyse the data and reconstruct the fraud. This phase involves several key activities.
Transaction Testing: Trace suspicious transactions from origination to completion. Look for round-tripping, layering through shell entities, fictitious invoicing, and manipulation of approval workflows.
Fund Flow Analysis: Map the flow of funds from the company to the ultimate beneficiaries. This is particularly important in related party fraud and fund diversion cases.
Witness Interviews: Conduct structured interviews with employees, management, vendors, and other relevant persons. Interviews should be documented, and where possible, conducted in the presence of a witness or recorded with consent.
Loss Quantification: Calculate the financial loss caused by the fraud with precision. Courts and regulators will rely on this quantification for recovery orders, disgorgement under Section 212(14A), and sentencing under Section 447.
Step 6: Reporting Format and Documentation
The forensic audit report is the primary deliverable of the engagement. A well-structured report strengthens enforcement actions and supports litigation. The report should include the following sections.
Executive Summary: A concise overview of the engagement, key findings, and conclusions. This section is often read by board members and regulators who may not review the full report.
Scope and Methodology: A detailed description of the audit scope, the methodology followed, the documents and data reviewed, and any limitations encountered.
Detailed Findings: A transaction-by-transaction or issue-by-issue analysis, supported by documentary evidence, fund flow charts, and timeline reconstructions.
Loss Quantification: A clear calculation of the financial impact of the fraud, with supporting schedules and assumptions stated transparently.
Annexures: Supporting documents, forensic images, hash certificates, chain of custody logs, interview transcripts, and any other evidence relied upon.
The report should present findings objectively, distinguishing between established facts and inferences. Forensic auditors should avoid legal conclusions and instead present evidence that enables adjudicating authorities to draw their own conclusions.
Step 7: Privilege Considerations
Privilege is a critical but often overlooked aspect of forensic audits in India. Practitioners must carefully navigate the following issues.
Legal Professional Privilege: Where the forensic audit is commissioned through external legal counsel and the auditor operates under counsel's direction, the work product may attract legal professional privilege. To preserve this, the engagement should be structured so that the auditor reports to the law firm, not directly to the company.
Self-Incrimination: During witness interviews, individuals may invoke the right against self-incrimination under Article 20(3) of the Constitution. The auditor must ensure no individual is compelled to make statements that may incriminate them.
Data Privacy: The Digital Personal Data Protection Act, 2023 (DPDPA) imposes obligations on entities processing personal data. Forensic auditors must ensure that personal data accessed during the investigation is processed lawfully and not used beyond the investigation's scope.
Document Preservation Notices: Once a forensic audit is initiated, the company should issue litigation hold or document preservation notices to all relevant custodians, directing them to preserve all potentially relevant documents and data. Destruction of evidence can attract penalties under the Bharatiya Nyaya Sanhita, 2023 (BNS) for destruction of evidence and obstruction of justice.
Step 8: Coordination with Regulators and Law Enforcement
Corporate fraud investigations rarely exist in isolation. Coordination with regulators and law enforcement is often necessary and sometimes mandatory.
SFIO: If the Central Government has assigned the investigation to SFIO, the company and its officers must cooperate fully. SFIO can summon and examine any person on oath, require production of documents, and access books and records.
Enforcement Directorate: Where proceeds of fraud have been laundered, the Enforcement Directorate may initiate proceedings under the PMLA. Forensic audit findings can serve as the basis for PMLA complaints and attachment of assets.
Police and Economic Offences Wing: For filing criminal complaints, the company may approach the police or the Economic Offences Wing. Offences are now registered under the Bharatiya Nyaya Sanhita, 2023 (BNS), which replaced the Indian Penal Code, and investigated under the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), which replaced the Code of Criminal Procedure. Both statutes have been in force since July 1, 2024.
SEBI: For listed companies, fraud involving manipulation of financial statements or market manipulation may also trigger obligations under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015. Timely disclosure to stock exchanges and cooperation with SEBI investigations are mandatory.
Registrar of Companies: The RoC can conduct enquiries into the affairs of any company and report findings to the Central Government. Where a forensic audit reveals fraud, the company or its auditors may be obligated to report to the RoC under the statutory reporting framework.
Practical Tips for Effective Forensic Audits
Act swiftly. Delay in commencing the forensic audit gives potential wrongdoers time to destroy evidence, tamper with records, or flee the jurisdiction.
Secure digital evidence early. Issue preservation notices and create forensic images before suspects become aware of the investigation.
Use multidisciplinary teams. The best forensic audits combine the skills of forensic accountants, IT specialists, data analysts, and legal advisors working in coordination.
Maintain strict confidentiality throughout the investigation. Information leaks can compromise the investigation and expose the company to defamation claims.
Document everything. From the first board resolution to the final report, every decision and procedural step should be recorded.
Prepare for cross-examination. The forensic auditor may be called as an expert witness, and the report must withstand rigorous scrutiny.
Conclusion
Forensic audits are indispensable in the fight against corporate fraud in India. The Companies Act, 2013 provides robust enforcement through Section 447 and SFIO powers under Sections 211 and 212, while the PMLA adds a further layer of accountability. However, the effectiveness of any forensic audit depends on how it is conducted.
By following a structured approach (appointing independent auditors, defining a clear scope, preserving evidence meticulously, conducting rigorous digital forensics, producing comprehensive reports, managing privilege, and coordinating with regulators), companies and their advisors can ensure that forensic audits achieve their purpose: uncovering the truth, quantifying the damage, and building a case that can withstand legal challenge.
With the BNS, BNSS, and BSA now replacing the legacy criminal statutes, and the DPDPA introducing new data privacy obligations, forensic auditors and corporate lawyers must stay current with the legal landscape. A forensic audit conducted with precision, integrity, and legal awareness is the foundation upon which justice in corporate fraud cases is built.

Comments