top of page
Search

What Is Frauditing? How Auditors Combine Fraud Examination and Traditional Auditing

16 hours ago
7 min read

Why Traditional Auditing Alone May Not Identify Fraud


Financial statement auditing, internal auditing, and fraud examination share important objectives, but they are not identical disciplines.


Traditional auditing evaluates financial information, controls, compliance, and organizational processes according to the objectives of the engagement.


Fraud examination focuses more directly on identifying, investigating, and understanding intentional deception.


Frauditing combines elements of both disciplines by applying a fraud-focused perspective to audit planning, testing, evidence evaluation, and reporting.


The term frauditing is commonly associated with fraud-focused auditing approaches that integrate accounting, auditing, investigative techniques, and an understanding of how fraud is committed and concealed.


It is not a separate set of professional auditing standards or a substitute for the requirements of the PCAOB, AICPA, Government Accountability Office, or Institute of Internal Auditors.


Instead, frauditing describes an approach that helps auditors think more critically about fraud risks and develop procedures responsive to those risks.


For internal auditors, external auditors, compliance professionals, and Audit Committee members, understanding frauditing can improve fraud risk awareness and strengthen organizational controls.


1. What Is Frauditing?

Frauditing is the application of fraud examination concepts and techniques within an auditing process.


The approach combines traditional audit methods with a more deliberate focus on how individuals might intentionally circumvent controls, manipulate records, misappropriate assets, or conceal misconduct.


A fraud-focused auditor asks questions such as:

  • How could someone commit fraud within this process?

  • What incentives or opportunities could motivate misconduct?

  • Which controls could be overridden or bypassed?

  • What records could be manipulated to conceal a transaction?

  • Which unusual relationships or transactions deserve further examination?

  • What evidence would support or contradict a suspected fraud scenario?


The objective is to move beyond routine transaction verification and evaluate whether the organization's processes create opportunities for intentional wrongdoing.



Frauditing changes the auditor's perspective from simply asking whether transactions were processed correctly to also asking how fraudulent transactions could be processed and concealed.


2. Frauditing vs. Traditional Auditing

The distinction is primarily one of emphasis, objectives, and procedures.

Characteristic

Traditional auditing

Frauditing

Primary focus

Engagement objectives, financial reporting, controls, and compliance

Fraud risks, schemes, concealment, and control circumvention

Risk assessment

Risks relevant to the audit objectives

Specific fraud scenarios and opportunities

Testing

Procedures responsive to assessed risks

Targeted procedures designed to identify fraud indicators

Evidence

Sufficient appropriate evidence for audit conclusions

Evidence relevant to potential intentional misconduct

Interviews

Inquiry about processes, controls, and transactions

Fraud-focused inquiry and investigative interviewing when appropriate

Analytics

Identify errors, trends, and anomalies

Identify suspicious patterns, relationships, and transactions

Reporting

Audit findings and conclusions

Fraud indicators, control vulnerabilities, and matters requiring investigation


This comparison does not mean traditional auditors ignore fraud.


External auditors have explicit fraud-related responsibilities under applicable auditing standards, and internal auditors must evaluate fraud risks relevant to their work.


Frauditing emphasizes applying these responsibilities through a more investigative lens.


3. Understanding the Fraud Triangle

One useful framework for fraud risk assessment is the Fraud Triangle.


The model identifies three conditions commonly associated with fraud.


Pressure or incentive: An individual experiences financial, personal, or organizational pressure.


Opportunity: Weak controls or access privileges make misconduct possible.


Rationalization: The individual develops a justification for the behavior.


Consider an employee responsible for maintaining vendor banking information.


The employee may face financial pressure, have unrestricted access to vendor master records, and rationalize unauthorized payments as temporary borrowing.


A fraud-focused auditor would examine the combination of access, authorization, payment processing, and monitoring controls.


The Fraud Triangle is a useful analytical framework, but it does not establish that fraud has occurred.


4. Identify How Fraud Could Occur

An important frauditing technique is developing specific fraud risk scenarios.


Instead of identifying a broad risk such as vendor fraud, the auditor describes how the fraud could occur.


For example:

Scenario: An employee changes a legitimate vendor's bank account to an account controlled by the employee or an accomplice.


The auditor then considers:

  • Who can change vendor banking information?

  • What documentation is required?

  • Is the change independently authenticated?

  • Who approves the change?

  • Can the same employee update the vendor record and release payments?

  • Are changes logged and independently reviewed?

  • Are unusual changes detected before payment?


This approach links fraud risks to specific internal controls and audit procedures.


5. Use Data Analytics to Identify Fraud Indicators

Data analytics can be particularly useful in fraud-focused auditing.


Examples include identifying:

  • Duplicate vendor payments.

  • Payments just below approval thresholds.

  • Multiple vendors sharing bank accounts.

  • Vendors sharing addresses with employees.

  • Unusual weekend or after-hours transactions.

  • Repeated round-dollar payments.

  • Transactions involving dormant vendors.

  • Sequential invoice numbers from supposedly unrelated suppliers.

  • Unusual journal entries near reporting deadlines.

  • Transactions involving employees with excessive system privileges.


These patterns do not prove fraud.


They identify transactions that may warrant additional examination.


The auditor must evaluate legitimate business explanations and obtain corroborating evidence before reaching conclusions.


6. Evaluate Management Override of Controls

Management override is a significant fraud risk because senior personnel may possess the authority to bypass otherwise effective controls.


Frauditing emphasizes examining how management could manipulate financial information or authorize improper transactions.


Relevant procedures may include:

  • Testing journal entries and other adjustments.

  • Evaluating accounting estimates for potential bias.

  • Examining significant unusual transactions.

  • Reviewing transactions involving related parties.

  • Evaluating unusual changes to accounting policies.

  • Investigating inconsistencies between supporting records and management explanations.


For external auditors, PCAOB AS 2401 establishes specific requirements concerning management override.


For internal auditors, the nature and extent of procedures depend on the engagement's objectives and assessed risks.


7. Examine Occupational Fraud Schemes

Frauditing is particularly relevant to occupational fraud.


Common categories include:


Asset misappropriation

Examples include:

  • Theft of cash.

  • Fraudulent expense reimbursements.

  • Payroll fraud.

  • Billing schemes.

  • Inventory theft.

  • Unauthorized electronic payments.


Corruption

Examples include:

  • Bribery.

  • Kickbacks.

  • Conflicts of interest.

  • Improper influence over procurement.

  • Undisclosed relationships with vendors.


Financial statement fraud

Examples include:

  • Premature revenue recognition.

  • Improper capitalization of expenses.

  • Concealment of liabilities.

  • Manipulation of accounting estimates.

  • Misleading financial disclosures.


The auditor should consider the organization's business model, control environment, and opportunities for concealment.


8. Apply Professional Skepticism

Professional skepticism is central to fraud-focused auditing.


Auditors should maintain a questioning mindset and critically evaluate evidence.


For example, management may explain that a large payment to a new vendor was an urgent operational necessity.


A fraud-focused auditor would consider whether:

  • The vendor was properly approved.

  • The transaction had a legitimate business purpose.

  • Supporting documentation was authentic.

  • The payment received appropriate authorization.

  • The goods or services were actually delivered.

  • The transaction involved an undisclosed related party.


Professional skepticism does not mean assuming that management or employees are dishonest.


It means avoiding unsupported assumptions that explanations and documents are reliable.


9. Strengthen Internal Controls to Prevent and Detect Fraud

Frauditing should help organizations identify control weaknesses that create fraud opportunities.


Important preventive controls include:

  • Segregation of duties.

  • Independent approval of significant transactions.

  • Vendor identity verification.

  • Authentication of banking changes.

  • Role-based system access.

  • Conflict-of-interest disclosures.

  • Mandatory vacation and job rotation where appropriate.


Important detective controls include:

  • Exception reporting.

  • Duplicate payment analysis.

  • Journal entry monitoring.

  • Independent reconciliations.

  • Vendor master file reviews.

  • Whistleblower reporting mechanisms.

  • Review of unusual transactions.


Corrective controls include investigation, remediation, disciplinary processes where appropriate, and improvements to the control environment.


The strongest fraud prevention programs combine preventive, detective, and corrective measures.


10. Understand the Difference Between Fraud Indicators and Fraud Evidence

A critical distinction is that an unusual transaction is not necessarily fraudulent.


Consider an employee who approves several payments just below an authorization threshold.


This pattern could indicate deliberate circumvention of approval controls.


It could also reflect legitimate recurring transactions.


The auditor should examine the underlying facts before drawing conclusions.


Potential fraud indicators may justify additional procedures, but allegations of fraud require careful handling, appropriate evidence, and established investigation protocols.


Frauditing should improve the quality of risk identification—not encourage unsupported accusations.


11. The Role of Internal Audit

Internal auditors can incorporate frauditing techniques into risk assessments and engagements.


Under the IIA's Global Internal Audit Standards, internal auditors must consider relevant fraud risks when evaluating governance, risk management, and internal controls.


Internal Audit can help by:

  • Evaluating fraud risk assessments.

  • Testing fraud prevention controls.

  • Reviewing whistleblower processes.

  • Identifying suspicious transaction patterns.

  • Evaluating management override risks.

  • Recommending control improvements.

  • Communicating significant concerns to the Board or Audit Committee.


However, Internal Audit should not automatically assume responsibility for every fraud investigation.


The organization should establish appropriate investigative authority, competence, independence, confidentiality, and legal oversight.


12. The Role of the Audit Committee

Audit Committees should understand how management identifies, assesses, and responds to fraud risks.


Important questions include:

  1. Has management performed a documented fraud risk assessment?

  2. Are significant fraud scenarios reflected in the internal control framework?

  3. Does Internal Audit evaluate fraud-related controls?

  4. Are significant allegations independently investigated?

  5. Are whistleblowers protected against retaliation?

  6. Does the committee receive timely reports about significant fraud risks?

  7. Are corrective actions tracked and verified?

  8. Are management override risks adequately addressed?


The Audit Committee should also ensure that sensitive allegations involving senior management can be escalated without inappropriate interference.


13. A Practical Frauditing Example: Vendor Payment Fraud

Consider an organization with 4,000 active vendors.


Its accounts payable department processes thousands of payments each month.


A traditional audit may test selected payments for invoices, approvals, and accounting accuracy.


A fraud-focused audit would also evaluate specific fraud scenarios.


For example, an employee could create a fictitious vendor, submit fraudulent invoices, and approve payments.


The auditor might perform the following procedures:

Fraud risk

Fraud-focused audit procedure

Fictitious vendors

Compare vendor records with employee information and verify selected vendors

Duplicate payments

Analyze invoice numbers, amounts, dates, and bank accounts

Unauthorized banking changes

Examine change logs, independent authentication, and approvals

Split transactions

Identify multiple payments near authorization thresholds

Conflicts of interest

Review vendor relationships and relevant disclosures

Dormant vendor abuse

Analyze payments following vendor reactivation

The auditor would investigate anomalies, evaluate supporting evidence, and determine whether control deficiencies or potential misconduct require escalation.


This approach integrates fraud risk assessment, data analytics, internal control testing, and professional skepticism.


14. Common Mistakes in Fraud-Focused Auditing

Common weaknesses include:

  • Treating every unusual transaction as evidence of fraud.

  • Using generic fraud checklists without identifying specific schemes.

  • Relying entirely on management representations.

  • Failing to evaluate system access and segregation of duties.

  • Ignoring potential management override.

  • Failing to validate the completeness and accuracy of data used in analytics.

  • Conducting investigative interviews without appropriate training.

  • Failing to preserve relevant evidence.

  • Making accusations before sufficient facts are established.

  • Failing to communicate significant concerns through authorized channels.


Frauditing requires professional judgment, technical competence, and disciplined evidence evaluation.


The Bottom Line

Frauditing combines the systematic discipline of auditing with the investigative perspective of fraud examination.


It encourages auditors to think about how fraud could occur, how controls could be circumvented, and what evidence would help identify or evaluate suspicious activity.


The approach can strengthen risk assessment, audit planning, transaction testing, and internal control evaluation.


But frauditing does not replace professional auditing standards or convert every audit into a fraud investigation.


The objective is to make auditors more effective at identifying fraud risks, recognizing warning signs, and evaluating the controls intended to prevent and detect intentional misconduct.


Organizations that incorporate fraud-focused thinking into their audit and internal control programs are better positioned to identify vulnerabilities before they result in significant financial losses or reputational damage.

 
 
 

Recent Posts

See All
Audit Committee Charter: What Should Be Included?

A Practical Guide to Building an Effective Audit Committee Charter An Audit Committee Charter is one of the most important documents in an organization's corporate governance framework. It establishes

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page