Fraud, as defined by the Association of Certified Fraud Examiners (ACFE), is an intentional act to deprive another party of money or property through deception or unfair means. Detecting it inside a business isn’t primarily about forensic investigation after the fact, it’s about the specific techniques built into the audit process itself, designed to surface irregularities before they escalate into something requiring a full investigation.
This guide covers the two main categories of accounting fraud, the audit techniques used to detect them, the red flags that should prompt closer scrutiny, and how journal entry testing actually targets suspicious transactions in practice.
What Is Fraud Auditing
Fraud auditing is the process an auditor uses to identify fraudulent activity within an organization’s financial records. It involves a thorough examination of financial records to uncover irregularities, gathering evidence through witness statements, supporting documentation, and any other proof of activity that doesn’t hold up under scrutiny. Businesses typically rely on an internal accountant to keep records straight day to day, but engage an external auditor, sometimes specifically for fraud auditing purposes, where there’s reason to look closer or as part of routine assurance.
Two Types of Accounting Fraud
1. Asset Misappropriation
The most common form of corporate fraud, generally falling into two categories:
- Skimming. Cash is stolen before it’s ever recorded in the books, which makes it particularly hard to detect since there’s no transaction trail to follow. Fake expense reimbursements, fraudulent billing schemes, and check manipulation are common examples.
- Misuse of company assets. Company resources, equipment, inventory, or other assets, are used improperly by individuals within the organization. This increases liability exposure and signals unauthorized use of company property.
2. Financial Statement Fraud
Less common than asset misappropriation but potentially far more damaging. It involves misrepresenting profits or assets, or concealing liabilities, to present a stronger financial position than actually exists. The financial statements are manipulated to show growth or profitability that doesn’t reflect reality.
Also check: Forensic Audit Services
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
Audit Techniques Used to Detect Fraud
1. Fraud Brainstorming
Every fraud audit should begin with a structured brainstorming session, where the audit team evaluates the ways a specific business could plausibly commit or fall victim to fraud, along with the preventative controls already in place. This session also draws on knowledge of past fraud schemes at comparable businesses in the same sector, since fraud patterns often repeat across similar industries and business models.
2. Journal Entry Testing
Journal entries are the foundation of every financial statement, and fraudulent activity almost always requires modifying them somewhere. This makes journal entry testing one of the most effective fraud detection techniques available. Auditors then request supporting documentation for each entry selected and assess whether it holds up.
3. Reviewing Historical Transactions
Past transactions are reviewed, and any changes to accounting processes over time are documented and examined. A shift in how a particular type of transaction is recorded, without a clear operational reason, is a meaningful indicator worth investigating. This typically extends to reviewing the company’s cash flow and working capital cycle for consistency with the transaction history.
4. Regular and Unexpected Management Reviews
Management should conduct periodic assessments of financial and operational statements, including unannounced reviews rather than only scheduled ones. Strong internal controls combined with genuine internal review activity are both a detection mechanism and a deterrent, since employees are less likely to attempt fraud where review is frequent and unpredictable.
Correcting a Common Misconception: How Journal Entry Testing Actually Targets Entries
Journal entry testing is sometimes described as selecting entries “at random,” but in practice, effective fraud-focused testing is risk-based first and random only as a supplement. Auditors specifically target entries that carry elevated fraud risk characteristics: round-number amounts, entries posted outside normal business hours, entries made by individuals with override authority over normal approval controls, entries to unusual account combinations, and entries near period-end that could be manipulating reported results. A purely random sample would need to be very large to have a realistic chance of catching a small number of fraudulent entries hidden among thousands of legitimate ones, which is why risk-based targeting, supplemented by some random sampling to guard against blind spots, is the approach that actually works in practice.
Red Flags That Should Trigger Closer Scrutiny
- An employee who never takes leave or resists having their duties covered. A classic fraud indicator, since ongoing schemes often require the perpetrator’s continuous presence to keep them concealed.
- Unusually close relationships with a single vendor or customer. Particularly where pricing, terms, or approval decisions consistently favor that party without clear business justification.
- Lifestyle inconsistent with known compensation. A visible standard of living that doesn’t match an employee’s role or salary is a long-recognized behavioral indicator.
- Resistance to segregation of duties. An employee who insists on personally handling multiple steps of a transaction that would normally be split between roles.
- Frequent, unexplained adjusting entries. Especially those made without clear supporting documentation or a consistent business rationale.
Must check: Internal Audit Services
Worked Example: Skimming Detected Through Reconciliation
A retail business’s monthly bank reconciliation shows deposits consistently running slightly below what daily sales reports would suggest, a small, easy-to-miss gap of roughly 2 to 3% most months. On its own, this looks like normal variance. But when an auditor applies historical transaction review across a full year, the pattern is consistent rather than random, deposits are short almost every month, never over. Combined with the fact that one employee has sole responsibility for both counting daily cash and making the bank deposit, a control weakness that should have been flagged earlier, this consistent shortfall is exactly the kind of pattern that separates ordinary variance from a likely skimming scheme, and it’s the kind of finding that historical transaction review is specifically designed to surface.
Frequently Asked Questions (FAQs)
What is the difference between fraud auditing and forensic accounting?
What are the two main types of accounting fraud?
Are journal entries selected for testing completely at random?
Why is skimming particularly hard to detect?
What behavioral red flags might indicate employee fraud?
How often should management review financial and operational statements?
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Farahat & Co.’s certified fraud examiners support businesses with fraud audit procedures, internal control review, and forensic investigation where fraud is suspected or confirmed.
Contact Farahat & Co. today to discuss your fraud detection and audit requirements.
