Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026in 2 days 11 OCTGSTR-1 · Outward supplies · Sep 2026in 6 days 15 OCTPF & ESI · Contributions · Sep 2026in 10 days 20 OCTGSTR-3B · Summary return · Sep 2026in 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 25 days 31 OCTITR filing · Audit cases · AY 2026-27in 26 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 55 days 15 DECAdvance Tax · 3rd (75%) instalment · FY 2026-27in 71 days
All due dates

Fraud risk, red flags and detection techniques: FAIS 120 on fraud risk, FAIS 140 on applying hypotheses and SIA 11 on fraud in an internal audit

FAIS 120 asks the Professional to make a preliminary fraud risk understanding and to prioritise the areas most vulnerable to fraud. FAIS 140 asks for flexible hypotheses that are...

Published
Updated
Reading time
8 min
Views
3
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 5, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Fraud is usually hidden, so the practical question is where to look first. The ICAI's forensic standards answer with fraud risk, the idea that work should be focused on the areas most open to fraud, and with hypotheses, the habit of turning a red flag into a theory that evidence can prove or disprove. SIA 11 gives the internal auditor's side.

This article is from the ICAI Compendium of Forensic Accounting and Investigation Standards (as on September 2025); mandatory for engagements conducted on or after 1 July 2023. SIA 11 is taken from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). ICAI may revise standards, so check the current texts on icai.org and internalaudit.icai.org.

FAIS 120: what fraud risk means

Paragraph 1.2 uses a short definition of fraud: an intentional or deliberate act to deprive another of property or money through deception or other unfair means. Paragraph 1.3 notes the typical features: an incentive or pressure, a perceived opportunity and some rationalisation. Fraud risk applies the idea of risk to that setting, so that the work is focused on areas of importance and greater vulnerability (paragraph 1.4).

The requirements are three:

  1. A preliminary fraud risk understanding of the areas and processes relevant to the subject matter, to judge complexity and assign skills (paragraph 3.1).
  2. Prioritising work to identify fraud indicators, concentrating on the areas most vulnerable, in line with FAIS 330 (paragraph 3.2).
  3. Giving due consideration to matters indicating fraud risk when reporting, in line with FAIS 510 (paragraph 3.3).

Paragraph 4.1 observes that fraud is concealed and hard to detect, but conditions pointing to motive or opportunity can often be seen. Documentation consists of a note on the fraud risk understanding and notes on indicators observed, their relevance and how they were addressed (paragraphs 5.1 and 5.2).

FAIS 140: applying hypotheses

A hypothesis, in paragraph 1.2, is a provisional, unproven theory based on limited facts that must be established through further examination of evidence. In forensic accounting it is tested by checking transactions and balances for exceptions; in investigation it is developed from the facts of the case, tested and revised to support or reject a possible modus operandi (paragraphs 1.2(a) and (b)). The method balances scepticism with neutrality (paragraph 1.3).

  • The Professional applies the concept, where applicable, to validate possible violations or exceptions that may or may not have occurred (paragraph 3.1).
  • Methods are designed around the hypotheses while keeping neutrality (3.2).
  • Hypotheses are flexible, evolving, and include alternates (3.3).
  • At the end the Professional can prove, disprove or not prove the theory (3.4).
  • All types of evidence are collected, whether it proves or disproves (paragraph 4.2).
  • The file shows how each hypothesis was formed, tested, and accepted or rejected, and keeps a chain of custody (paragraphs 5.1, 5.2).

A hypothesis need not appear in the report, but applying it makes the evidence more reliable (paragraph 1.4).

From red flag to hypothesis to test

FAIS 330 (paragraph 4.2) describes a first phase in which fraud indicators are spotted and a second phase in which they are validated by detailed review. The table below is an illustrative working aid, not a list from any standard.

Illustrative red flagPossible hypothesisIllustrative test
Vendor bank account matches an employee's accountFictitious or conflicted vendorMatch vendor master to payroll and HR bank details
Round-sum invoices just under an approval limitSplitting to avoid approvalGroup invoices by vendor and date; compare to limits
Credit notes raised after quarter-end reversed next monthRevenue pulled forwardTrace credit notes and re-invoices around period-end
Employee on payroll with no attendance or leave recordGhost employeeCompare payroll list to attendance and ID checks
Missing or altered vouchers in one departmentConcealment of unauthorised paymentsCompare voucher series to the payment register
Same person creates and approves entriesWeak segregation allowing overrideReview user logs for creator-approver overlap

Where such tests run on large data, see our article on data analysis and digital evidence. For a business owner, a systematic review of vendor, payroll and cash records is part of what our team offers under compliance advisory.

SIA 11: fraud in an internal audit

SIA 11 sits in the compendium's older group of standards (as on 1 July 2013). Its own front note says it was recommendatory in the initial period and becomes mandatory from a date the Council notifies, and its effective-date paragraph is printed with a blank date. Check the current status on the internal audit board's site before relying on it as mandatory.

Its main points:

  • Paragraph 2: management and those charged with governance bear the primary responsibility for preventing and detecting fraud, by running effective internal controls.
  • Paragraphs 3 and 4: the internal auditor need not have a fraud investigator's expertise, but should know the factors that raise the risk of fraud and use reasonable care and scepticism. Fraud usually involves incentive or pressure, opportunity and rationalisation.
  • Paragraph 6: internal controls give only reasonable assurance and are limited by collusion and management override, among other things.
  • Paragraphs 14 to 18: the internal auditor understands and evaluates the control environment, the entity's fraud risk assessment, the information and communication processes, the control activities and the monitoring, each for operating effectiveness.
  • Paragraph 19: on coming across actual or suspected fraud or misappropriation, the internal auditor should immediately bring it to the management's attention.
  • Paragraph 20: document the fraud risk factors identified and the response, including any extra procedures.

The handover is the important point: an internal audit that finds red flags does not turn itself into an investigation. As FAIS 110 (paragraph 4.1) says, audit work can identify red flags that become the starting point of a forensic engagement. Our article on internal controls under SIA 120 covers the control evaluation behind the SIA 11 steps.

The statutory auditor and the Companies Act

A statutory auditor deals with fraud under SA 240, not these standards; see our two-part guide, SA 240 part 1 and part 2. Reporting of fraud by an auditor under section 143(12) of the Companies Act, 2013 is covered in our guide to auditor fraud reporting, and the offence of fraud is in our section 447 guide. Neither is restated here.

Illustrative example

Illustrative: Harbor Light Foods Pvt Ltd's internal auditor notes that a plant supervisor's relative is a vendor for packaging, and that invoices cluster just under the supervisor's approval limit. Under SIA 11 paragraph 19, the auditor tells management without delay and records the red flags (paragraph 20). Management engages an accountant for an investigation. Using FAIS 140, the accountant sets two hypotheses: splitting of invoices, and an inflated rate. Rate comparison with three other vendors disproves the second; the first is proved on the invoice pattern and approval logs. A third hypothesis, kickbacks to the supervisor, cannot be proved because the bank records needed are with a closed account, and the report says so as not proved.

Common lapses

  • Treating one red flag as proof.
  • Testing only the evidence that supports the first theory.
  • An internal auditor investigating alone and interviewing suspects before management is told.
  • No record of the red flags that were examined and cleared.

Need help with a fraud risk review?

If you see unexplained payment patterns or vendor oddities and want a structured view of the risk before deciding on an investigation, our team can help through compliance advisory with a review of controls and records.

Key takeaways

  • Start with a preliminary fraud risk understanding and focus on the most vulnerable areas (FAIS 120, paragraphs 3.1 and 3.2).
  • Turn red flags into hypotheses, test neutrally and accept that some will end as "not proved" (FAIS 140, paragraph 3.4).
  • Management carries the primary responsibility for preventing and detecting fraud (SIA 11, paragraph 2).
  • An internal auditor reports actual or suspected fraud to management at once (SIA 11, paragraph 19).
  • Statutory-audit fraud duties and section 143(12) are separate and are covered in the linked guides.

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Fraud risk

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What are the three elements usually present in a fraud?

FAIS 120 paragraph 1.3 names an incentive or pressure, a perceived opportunity and some rationalisation of the act.

Is an internal auditor expected to detect all frauds?

No. SIA 11 paragraph 3 says the internal auditor cannot be expected to have the expertise of a fraud specialist, but should use knowledge and skills to identify indicators.

An entry without a voucher is a question waiting for an auditor.

— TaxClue Accounts & Audit Desk

Fraud risk: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,327 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

FAIS 120 paragraph 1.3 names an incentive or pressure, a perceived opportunity and some rationalisation of the act.

No. SIA 11 paragraph 3 says the internal auditor cannot be expected to have the expertise of a fraud specialist, but should use knowledge and skills to identify indicators.

A provisional, unproven theory based on limited facts that the evidence must establish or reject (FAIS 140, paragraph 1.2).

Not necessarily. FAIS 140 paragraph 1.4 says the hypothesis may not be referred to in the report, but applying it improves the quality of evidence.

The compendium prints it with a note that it was recommendatory in the initial period and becomes mandatory from a date the Council notifies, and its effective date is left blank. Check the current status on the internal audit board's site.

SIA 11 paragraph 19 requires bringing it to the attention of management. Reporting duties of statutory auditors are in the linked section 143(12) guide.