How Forensic Audits Investigate Suspected Embezzlement

Share This Post

Share on facebook
Share on linkedin
Share on twitter
Share on email

A forensic audit can help establish what happened when an organ­i­sation suspects embez­zlement, but it does not automat­i­cally prove a crime. The work must convert an allegation into testable questions, preserve reliable evidence, trace assets and distin­guish accounting errors, control failures and autho­rised trans­ac­tions from delib­erate misap­pro­pri­ation.

Define the allegation before analysing data

Record who raised the concern, what asset or process is affected, the relevant period, possible actors and the known facts. Avoid announcing guilt. A focused allegation matrix prevents the inves­ti­gation from expanding into an unfocused review of every trans­action.

Question Evidence to test it
Was money or property entrusted to a person? Role descrip­tions, mandates, approvals and custody records
Was it diverted or concealed? Ledgers, bank records, invoices, access logs and commu­ni­ca­tions
Who autho­rised and benefited? Approval trails, ownership records, payment desti­na­tions and inter­views
Was there an innocent expla­nation? Contracts, delivery evidence, recon­cil­i­a­tions and contra­dictory records

Preserve evidence before alerting potential subjects

Coordinate with legal counsel and autho­rised IT personnel. Secure relevant email, accounting data, bank records, expense systems, devices and paper files using a documented process. Retain originals, record collection dates and custo­dians, use working copies and maintain a chain of custody where litigation or referral is possible.

This is where a forensic engagement differs from a routine audit. A financial-statement audit is designed to provide assurance on financial reporting; it is not a guarantee that every fraud will be found. A financial-forensics inves­ti­gation follows specific allega­tions and evidence trails.

Reconcile the full transaction cycle

Start with complete popula­tions rather than only suspi­cious samples. Reconcile the general ledger to bank state­ments, payroll, vendor files, expense claims, inventory and supporting documents. Trace selected entries from initi­ation to approval, payment, delivery and accounting treatment.

Useful tests include duplicate invoices, split purchases, payments to changed bank details, ghost employees, round-sum journals, manual entries outside normal hours, dormant suppliers, refunds to unrelated accounts and trans­ac­tions approved by the benefi­ciary. In procurement cases, the same records can be tested using the procure-to-pay inves­ti­gation workflow.

Map people, entities and money

Compare supplier ownership, directors, contact details, bank accounts, addresses, devices and employee relation­ships. Then construct a dated flow-of-funds schedule showing each source, inter­me­diary and desti­nation. Cross-border work may require lawful disclosure routes and local expertise; tracing misconduct across borders adds ownership and juris­dic­tional compli­ca­tions.

Interview from documents, not assumptions

Interview neutral witnesses first to under­stand the process, then people respon­sible for controls, and subjects only after the important records have been analysed. Use open questions, show documents carefully, record exact answers and test them against other evidence. Behaviour, wealth or reluc­tance to take leave may justify a question, but none estab­lishes embez­zlement.

Report facts, limitations and control failures

The final report should separate verified facts, reasonable infer­ences, disputed points and unresolved gaps. Quantify loss only where the method and supporting records justify it. The US Department of Justice notes that circum­stantial evidence can be relevant in embez­zlement cases, while criminal intent still has to be proved; its discussion of proof issues is juris­diction-specific but illus­trates the distinction.

The GAO Fraud Risk Framework also places inves­ti­gation within a wider cycle of prevention, detection, response and adaptation. Remedi­ation may include segre­gating duties, independent bank-detail verifi­cation, tighter access rights, exception reporting and management review.

For real-world context, Malta News Online reported on a forensic audit connected with allega­tions involving former Lebanese central-bank governor Riad Salameh. That report should be read as reporting on allega­tions and proceedings—not as a substitute for judgments, primary audit material or the presumption of innocence.

Related Posts