Forensic Audit, Fraud Reporting and Investigation
The statutory fraud reporting duty is unusual in Indian company law because it starts running from the moment an auditor has reason to believe a fraud has been committed, not from a year end or a filing date. It has a two-day step, a forty-five day step and a fifteen-day step, and a threshold that decides whether the report goes to the government as well as to the board or only to the board.
- The duty, the threshold and the timetable
- What a forensic engagement is, and what it is not
- The standards it is conducted under
- How this connects to fraud risk and whistle-blowing work
Two tiers and a clock
Section 143(12) of the Companies Act 2013 requires an auditor who has reason to believe that an offence of fraud is being or has been committed against the company by its officers or employees to report it. The reporting route depends on the amount.
| Amount involved | Report to | How |
|---|---|---|
| ₹1 crore or above, counted individually for each fraud. Exactly ₹1 crore is inside this tier | The Central Government, after the audit committee or board step below | In Form ADT-4. Filed electronically since 14 July 2025 under the Companies (Audit and Auditors) Amendment Rules 2025, which removed the sealed physical cover, the postal dispatch and the separate confirmatory email. The two-day, forty-five day and fifteen-day periods were not changed. |
| Below ₹1 crore | The audit committee, or the board where there is none | Reported, and disclosed in the board's report |
Reporting to the Central Government does not replace the internal step. Rule 13(2) requires the auditor to report the matter to the board or the audit committee immediately and in any event no later than two days after obtaining knowledge of the fraud, seeking its reply or observations within forty-five days. Where a reply comes, the auditor files Form ADT-4 electronically with the Central Government, together with the reply and the auditor's own comments, within fifteen days of receiving it.
The no-reply limb is the one commonly overstated, including by us before this was checked. Rule 13(2)(c) says that if no reply arrives within forty-five days the auditor shall forward the report with a note recording the earlier communication and the absence of a reply. Unlike clause (b), it does not state an express fifteen-day period running from the expiry of the forty-five days. Treating the outer limit as sixty days is a sensible compliance control and we use it, but it should not be described as wording the rule contains.
The same duty extends to cost auditors and secretarial auditors under section 143(14). And note that the auditor's report order separately requires reporting on whether a fraud report was in fact filed, so a decision not to report is itself visible.
What forensic work is, and is not
It is not a bigger audit
A statutory audit is designed to give reasonable assurance that financial statements are free from material misstatement. A forensic engagement is designed to establish what happened in a specific matter, to a standard that may have to survive a tribunal, a regulator or a court. Different objective, different evidence standard, different output.
It is not a disciplinary process
The engagement establishes facts. Decisions about individuals belong to the company, taken with employment law advice. Blurring these two is the most common way a well-conducted investigation becomes unusable.
It is not confidential from everyone
Where the statutory reporting duty is engaged, it is engaged. An investigation cannot be scoped so as to avoid a report that the law requires, and an adviser who agrees to that has a problem of their own.
It is evidence-led and preservation-first
The first hour matters more than the first week. Securing devices, logs, mailboxes and access records before anyone knows an investigation is underway determines what is available later. Most of what is lost is lost in the first day.
What the work is conducted under
The Institute released the revised Forensic Accounting and Investigation Standards on 1 July 2023 and made them mandatory for engagements conducted on or after that date.
It issued updated standards and an updated implementation guide as exposure drafts on 29 May 2025, with comments closing on 19 June 2025, aimed at making the set country-agnostic. No final issuance of those drafts had been identified as at 18 August 2026. So the standards released on 1 July 2023 remain the mandatory set for members, and the accompanying implementation guide remains recommendatory rather than mandatory. Neither set carries a version number that we would put on this page, and an engagement letter should not cite an exposure draft as though it were operative.
Where fraud risk is managed rather than investigated
An investigation is what happens when prevention did not. The preventive side, fraud risk assessment, the whistle-blower mechanism, and the controls that make misappropriation harder, sits on our governance, risk and internal control pages, which include a guide dedicated to fraud risk, forensic readiness and whistle-blowing.
The practical connection is that companies with a working whistle-blower mechanism find things earlier and smaller. The auditor's report order asks whether whistle-blower complaints were considered, which means the absence of a mechanism is visible in the audit file as well as in the loss.
Where to go next
Audit and Assurance Services
Back to the main page: the full range of engagements, how we work, and how to reach us.
Statutory Audit: Appointment, Rotation and What the Report Has to Say
Appointment and rotation, the eligibility bars, resignation, the auditor's report order and the reporting on internal financial controls, including the single most misquoted conjunction in Indian company law.
Tax Audit and the Move to the Income-tax Act 2025
The thresholds for FY 2025-26 under the old Act, what section 63 of the new Act does differently, the change of substance that widens who gets audited, and the consolidated form that replaces three.
Internal Audit, Risk-based Audit and Compliance Audit
When internal audit is a statutory obligation and when it is a management choice, who may hold the role, how a risk-based plan is actually built, and how this sits alongside our governance and internal control work.
Due Diligence, Information System Audit and ESG Assurance
Three assurance engagements that are not statutory audits: what a buyer's diligence should now cover after two years of legal change, where information system audit is mandated, and the sustainability assurance regime including the independence bar that decides who can do it.
Send an enquiry
If something has already surfaced, the useful call is an early one, before anyone is confronted and before any device is handed back. Preservation is the part that cannot be done retrospectively.
Position as at 15 September 2026. Reviewed every six months.
This page is general information, not professional advice. Audit obligations in India turn on thresholds that moved recently and on standards whose effective dates have been deferred more than once. The small company definition changed on 1 December 2025, the Income-tax Act 2025 replaced the 1961 Act on 1 April 2026, two quality management standards were deferred on 31 March 2026, and a revised group audit standard has been proposed but not notified. Whether a particular obligation applies to you depends on your own numbers at your own year end. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else's, without one.