Fraud risk explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Fraud is usually hidden, so the practical question is where to look first. The ICAI's forensic standards answer with fraud risk, the idea that work should be focused on the areas most open to fraud, and with hypotheses, the habit of turning a red flag into a theory that evidence can prove or disprove. SIA 11 gives the internal auditor's side.
This article is from the ICAI Compendium of Forensic Accounting and Investigation Standards (as on September 2025); mandatory for engagements conducted on or after 1 July 2023. SIA 11 is taken from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). ICAI may revise standards, so check the current texts on icai.org and internalaudit.icai.org.
FAIS 120 asks the Professional to make a preliminary fraud risk understanding and to prioritise the areas most vulnerable to fraud. FAIS 140 asks for flexible hypotheses that are tested neutrally, ending in a result of proved, disproved or not proved. SIA 11 says the primary responsibility for preventing and detecting fraud rests with management, while the internal auditor evaluates the controls and must tell management at once about actual or suspected fraud.
FAIS 120: what fraud risk means
Paragraph 1.2 uses a short definition of fraud: an intentional or deliberate act to deprive another of property or money through deception or other unfair means. Paragraph 1.3 notes the typical features: an incentive or pressure, a perceived opportunity and some rationalisation. Fraud risk applies the idea of risk to that setting, so that the work is focused on areas of importance and greater vulnerability (paragraph 1.4).
The requirements are three:
- A preliminary fraud risk understanding of the areas and processes relevant to the subject matter, to judge complexity and assign skills (paragraph 3.1).
- Prioritising work to identify fraud indicators, concentrating on the areas most vulnerable, in line with FAIS 330 (paragraph 3.2).
- Giving due consideration to matters indicating fraud risk when reporting, in line with FAIS 510 (paragraph 3.3).
Paragraph 4.1 observes that fraud is concealed and hard to detect, but conditions pointing to motive or opportunity can often be seen. Documentation consists of a note on the fraud risk understanding and notes on indicators observed, their relevance and how they were addressed (paragraphs 5.1 and 5.2).
FAIS 140: applying hypotheses
A hypothesis, in paragraph 1.2, is a provisional, unproven theory based on limited facts that must be established through further examination of evidence. In forensic accounting it is tested by checking transactions and balances for exceptions; in investigation it is developed from the facts of the case, tested and revised to support or reject a possible modus operandi (paragraphs 1.2(a) and (b)). The method balances scepticism with neutrality (paragraph 1.3).
- The Professional applies the concept, where applicable, to validate possible violations or exceptions that may or may not have occurred (paragraph 3.1).
- Methods are designed around the hypotheses while keeping neutrality (3.2).
- Hypotheses are flexible, evolving, and include alternates (3.3).
- At the end the Professional can prove, disprove or not prove the theory (3.4).
- All types of evidence are collected, whether it proves or disproves (paragraph 4.2).
- The file shows how each hypothesis was formed, tested, and accepted or rejected, and keeps a chain of custody (paragraphs 5.1, 5.2).
A hypothesis need not appear in the report, but applying it makes the evidence more reliable (paragraph 1.4).
From red flag to hypothesis to test
FAIS 330 (paragraph 4.2) describes a first phase in which fraud indicators are spotted and a second phase in which they are validated by detailed review. The table below is an illustrative working aid, not a list from any standard.
| Illustrative red flag | Possible hypothesis | Illustrative test |
|---|---|---|
| Vendor bank account matches an employee's account | Fictitious or conflicted vendor | Match vendor master to payroll and HR bank details |
| Round-sum invoices just under an approval limit | Splitting to avoid approval | Group invoices by vendor and date; compare to limits |
| Credit notes raised after quarter-end reversed next month | Revenue pulled forward | Trace credit notes and re-invoices around period-end |
| Employee on payroll with no attendance or leave record | Ghost employee | Compare payroll list to attendance and ID checks |
| Missing or altered vouchers in one department | Concealment of unauthorised payments | Compare voucher series to the payment register |
| Same person creates and approves entries | Weak segregation allowing override | Review user logs for creator-approver overlap |
Where such tests run on large data, see our article on data analysis and digital evidence. For a business owner, a systematic review of vendor, payroll and cash records is part of what our team offers under compliance advisory.
SIA 11: fraud in an internal audit
SIA 11 sits in the compendium's older group of standards (as on 1 July 2013). Its own front note says it was recommendatory in the initial period and becomes mandatory from a date the Council notifies, and its effective-date paragraph is printed with a blank date. Check the current status on the internal audit board's site before relying on it as mandatory.
Its main points:
- Paragraph 2: management and those charged with governance bear the primary responsibility for preventing and detecting fraud, by running effective internal controls.
- Paragraphs 3 and 4: the internal auditor need not have a fraud investigator's expertise, but should know the factors that raise the risk of fraud and use reasonable care and scepticism. Fraud usually involves incentive or pressure, opportunity and rationalisation.
- Paragraph 6: internal controls give only reasonable assurance and are limited by collusion and management override, among other things.
- Paragraphs 14 to 18: the internal auditor understands and evaluates the control environment, the entity's fraud risk assessment, the information and communication processes, the control activities and the monitoring, each for operating effectiveness.
- Paragraph 19: on coming across actual or suspected fraud or misappropriation, the internal auditor should immediately bring it to the management's attention.
- Paragraph 20: document the fraud risk factors identified and the response, including any extra procedures.
The handover is the important point: an internal audit that finds red flags does not turn itself into an investigation. As FAIS 110 (paragraph 4.1) says, audit work can identify red flags that become the starting point of a forensic engagement. Our article on internal controls under SIA 120 covers the control evaluation behind the SIA 11 steps.
The statutory auditor and the Companies Act
A statutory auditor deals with fraud under SA 240, not these standards; see our two-part guide, SA 240 part 1 and part 2. Reporting of fraud by an auditor under section 143(12) of the Companies Act, 2013 is covered in our guide to auditor fraud reporting, and the offence of fraud is in our section 447 guide. Neither is restated here.
Illustrative example
Illustrative: Harbor Light Foods Pvt Ltd's internal auditor notes that a plant supervisor's relative is a vendor for packaging, and that invoices cluster just under the supervisor's approval limit. Under SIA 11 paragraph 19, the auditor tells management without delay and records the red flags (paragraph 20). Management engages an accountant for an investigation. Using FAIS 140, the accountant sets two hypotheses: splitting of invoices, and an inflated rate. Rate comparison with three other vendors disproves the second; the first is proved on the invoice pattern and approval logs. A third hypothesis, kickbacks to the supervisor, cannot be proved because the bank records needed are with a closed account, and the report says so as not proved.
Common lapses
- Treating one red flag as proof.
- Testing only the evidence that supports the first theory.
- An internal auditor investigating alone and interviewing suspects before management is told.
- No record of the red flags that were examined and cleared.
Need help with a fraud risk review?
If you see unexplained payment patterns or vendor oddities and want a structured view of the risk before deciding on an investigation, our team can help through compliance advisory with a review of controls and records.
Key takeaways
- Start with a preliminary fraud risk understanding and focus on the most vulnerable areas (FAIS 120, paragraphs 3.1 and 3.2).
- Turn red flags into hypotheses, test neutrally and accept that some will end as "not proved" (FAIS 140, paragraph 3.4).
- Management carries the primary responsibility for preventing and detecting fraud (SIA 11, paragraph 2).
- An internal auditor reports actual or suspected fraud to management at once (SIA 11, paragraph 19).
- Statutory-audit fraud duties and section 143(12) are separate and are covered in the linked guides.
Read next
- Forensic Accounting and Investigation Standards: framework and basic principles
- Data analysis and digital evidence in forensic work
- SIA 120: internal controls and internal financial controls
- SA 240, part 1: fraud risk assessment
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
