Skip to content

Forensic accounting

Fraud-indicator review

Short answer

A fraud-indicator review from Finbryn screens a US business's books for patterns statistically associated with fraud: Benford's Law deviations, duplicate payments, round-dollar entries, and vendor data overlapping with employees. Each test produces its own ranked list of flagged items with the specific reason, reviewed by a senior reviewer before it reaches counsel.

Management report

Illustrative client ยท August 2026

USD

Reviewed before sending
Profit and loss
LineAugJul
Revenue142,380131,904
Cost of sales(51,260)(48,115)
Gross profit91,12083,789
Payroll(46,300)(45,900)
SoftwareNoted(6,480)(5,490)
Rent(8,000)(8,000)
Other operating(9,215)(9,870)
Net income21,12514,529

Reviewer's note

Software is up on last month after two seats were added mid-month. Revenue includes one milestone invoice that will not repeat next month.

Illustrative. An example of the document, not a client's figures.

Fraud rarely announces itself in a set of books. What it tends to leave behind are statistical fingerprints: a first-digit distribution across payment amounts that deviates from what Benford's Law predicts for naturally occurring numbers, the same invoice paid twice under slightly different reference numbers, a cluster of entries sitting suspiciously at round dollar amounts, or a vendor whose mailing address happens to match an employee's home address.

None of those patterns proves fraud on its own. Each one is a flag worth a closer look, and a review like this exists precisely because a business owner, a board, or an auditor scanning thousands of transactions by eye will miss most of them. We run a defined set of tests against the transaction population and hand back a ranked list, with the specific test and the specific reason each item surfaced, so the follow-up work starts from a short, prioritized list instead of a full ledger.

This is analytical screening, not an audit and not an accusation. We do not conclude that fraud occurred, and we are careful in how we phrase every flag, because a statistically unusual pattern very often has an entirely innocent explanation: a supplier who happens to price everything in round numbers, or a duplicate-looking payment that turns out to be a legitimate correction for an earlier underpayment. The value of the review is in surfacing the short list efficiently, not in rendering a verdict.

Engagements come from boards responding to a tip, owners who noticed something did not add up, insurers scoping a fidelity claim before it goes further, and attorneys running due diligence ahead of a transaction or a dispute. Whoever engages us, the review runs quietly against the records and produces a document, not a public accusation.

What is included

A fraud-indicator review runs four core tests against the transaction population for the period under review. A Benford's Law distribution test compares the actual first-digit frequency of payment amounts to the expected natural distribution and flags where the deviation is statistically significant. A duplicate-payment scan checks for the same vendor, amount, and near-matching date or invoice number appearing more than once. A round-dollar scan flags entries clustered at suspiciously even amounts relative to the business's normal transaction pattern. A vendor-master screen cross-references vendor names, addresses, and bank account details against employee records for any overlap.

Each test produces its own output, and we deliver a single ranked list combining all four, with the specific test and reasoning attached to every flagged item so a reviewer is never handed an opaque score with no explanation behind it.

How the process works

We start by pulling a full transaction-level export from the accounting system for the review period, using forensic data extraction methods that preserve the audit trail and do not alter the live file. That export becomes the working dataset for every test that follows.

The Benford's Law test runs against the full population of payment amounts; it works best with a larger dataset, so for a smaller business we still run it but weight the result accordingly and lean more heavily on the duplicate-payment and vendor tests, which hold up regardless of volume. Duplicate-payment and round-dollar scans run through CaseWare IDEA or ACL Analytics, which can compare tens of thousands of line items for near-matches far faster than manual review.

Vendor-master screening is largely a manual cross-reference exercise: we pull the vendor list and the employee list and check for overlapping addresses, phone numbers, or bank details, since this kind of match rarely shows up in a purely statistical test. Every flag from every test goes into one ranked list, reviewed by a senior reviewer for false positives and for language before it reaches the board or counsel.

Who this is for

Boards and audit committees responding to a whistleblower tip, owners of a business with a bookkeeper or controller who has broad, unsupervised access to payments, insurers scoping a fidelity or crime-policy claim before committing to a full investigation, and attorneys doing financial due diligence ahead of an acquisition or a dispute all engage this review for the same reason: they need a defensible, prioritized starting point rather than a full manual audit of every transaction.

It is a poor fit if you already know specifically what happened and need the loss quantified rather than found; that work is better scoped as embezzlement investigation support. It is also not the right tool if what you actually need is an opinion on financial statements, since that requires a licensed audit, which is outside our scope entirely.

Common problems we fix

The most common problem is a board that wants a yes-or-no answer on whether fraud occurred, when what a screening review can actually deliver is a ranked list of items worth investigating further. We set that expectation at intake, because a review presented as a verdict when it is really a starting point creates more risk than it resolves.

A second problem is a small business with a modest transaction count expecting Benford's Law to carry the whole review. We explain upfront that the test is more reliable with volume, and for a smaller dataset we shift the weight toward duplicate-payment and vendor-overlap testing, which do not depend on a large sample to be meaningful.

A third problem is a vendor list that has never been cleaned, full of stale entries, inconsistent formatting, and duplicate vendors under slightly different names, which makes the vendor-overlap test noisier than it needs to be. We normalize the vendor master as part of the review itself rather than treating a messy list as a reason to skip the test.

Software and integrations

CaseWare IDEA and ACL Analytics run the bulk of the pattern-detection work: Benford's Law distribution testing, duplicate and near-duplicate payment matching, and round-dollar frequency analysis across the full transaction population exported from the client's accounting system. Both tools are built for exactly this kind of forensic data-analysis work rather than general bookkeeping.

The transaction export itself comes from QuickBooks Online or Xero, pulled at the transaction level rather than from summary reports, so voided and deleted entries the platform retained are included in the population being tested. Microsoft Excel organizes the final ranked output and the reasoning behind each flag into a document a non-technical board member or attorney can follow without needing to open the underlying analytics software.

What it costs

A fraud-indicator review is quoted per engagement based on transaction volume, the number of accounting systems and entities involved, and whether vendor and employee master data needs to be gathered from more than one source. A single-entity business on one accounting platform with a clean vendor list is a materially smaller engagement than a multi-entity group with several disconnected systems.

We provide a written estimate after a short scoping call covering the accounting system, the approximate transaction volume, and the period under review, and we flag early if the vendor or employee data needed for the overlap test is not readily available, since gathering it can add meaningfully to the timeline.

How we measure quality

Every flagged item on the ranked list carries the specific test that surfaced it and the specific reason, never a bare score with no explanation. Before delivery, a senior reviewer reviews the full list for obvious false positives, such as a supplier who legitimately prices in round numbers, and removes or annotates them rather than letting noise dilute the list a board or attorney has to work through.

The senior reviewer then reviews the finished list specifically for language: every flag is phrased as a pattern worth investigating, never as a conclusion about fraud having occurred, since a review that overstates its own findings creates real legal exposure for the client who acts on it.

How we work

The process

  1. 1

    Scoping call

    We confirm the accounting system, approximate transaction volume, review period, and whether vendor and employee master data is readily available.

  2. 2

    Data extraction

    A full transaction-level export is pulled from the accounting system using forensic extraction methods that preserve the audit trail without altering the live file.

  3. 3

    Benford's Law test

    The first-digit distribution of payment amounts is compared against the expected natural distribution, with results weighted for dataset size.

  4. 4

    Duplicate and round-dollar scans

    CaseWare IDEA or ACL Analytics scans the population for near-duplicate payments and clusters of suspiciously round-dollar entries.

  5. 5

    Vendor-master screening

    Vendor names, addresses, and bank details are cross-referenced against employee records for any overlap suggesting a conflict.

  6. 6

    Ranking and review

    All flags are combined into one ranked list; a senior reviewer removes obvious false positives, then reviews the language and conclusions.

  7. 7

    Delivery

    The ranked list is delivered to the board, owner, insurer, or counsel who engaged the review, with the reasoning behind each flag included.

Fraud-indicator review

Common problems we fix

  • A board wants a yes-or-no verdict on whether fraud occurred
    We set expectations at intake that a screening review produces a ranked list of items worth investigating, not a verdict, and explain what a definitive answer would actually require.
  • A small business's transaction count is too low for Benford's Law alone
    We run the test but weight the result accordingly and lean more heavily on duplicate-payment and vendor-overlap testing, which do not depend on a large sample.
  • A messy, duplicated vendor master makes the overlap test noisy
    We normalize the vendor list as part of the review itself rather than treating messy data as a reason to skip the test.
  • A legitimate supplier's round-number pricing triggers false flags
    A senior reviewer reviews flagged items for an obvious innocent explanation and annotates or removes them before the list is delivered.
  • The review risks being read as an accusation rather than a lead
    The senior reviewer reviews the final language specifically to keep every flag phrased as a pattern worth investigating, not a conclusion about fraud.

By the numbers

2,402

real occupational fraud cases the ACFE analyzed in its most recent global study, the population these detection methods are validated against

Source: acfe.com/report-to-the-nations, September 2026

143

countries and territories represented in the ACFE's most recent occupational fraud dataset

Source: acfe.com/report-to-the-nations, September 2026

46%

share of fraud tips in the ACFE's most recent study submitted through a web-based reporting mechanism, the largest single channel

Source: acfe.com/report-to-the-nations, September 2026

Pricing

A fraud-indicator review is quoted per engagement based on transaction volume, system count, and whether vendor and employee data needs to be gathered from more than one source, rather than sold as a flat monthly package. See /us/pricing for how our standard bookkeeping tiers are priced; a screening review of this kind is scoped and quoted separately once we understand the accounting system and data involved.

See pricing

Fraud-indicator review

Glossary

Benford's Law
A mathematical pattern describing how often each digit appears as the first digit in naturally occurring datasets, used to flag amounts that deviate from the expected distribution.
Duplicate payment
The same or a near-identical payment, by vendor, amount, and date or invoice number, appearing more than once in the transaction record.
Vendor-master screening
Cross-referencing vendor names, addresses, and banking details against employee records to identify any overlap that could indicate a conflict.
False positive
A transaction or vendor flagged by a test that, on closer review, has an innocent explanation and does not warrant further investigation.
Fraud triangle
A framework describing the three conditions commonly present when occupational fraud occurs: pressure, opportunity, and rationalization.

Questions

Frequently asked questions: Fraud-indicator review

Does a fraud-indicator review prove fraud occurred?

No. It surfaces patterns statistically associated with fraud so a human reviewer knows where to look next; it does not itself conclude that fraud happened.

Can this run on a small business with limited transaction volume?

Yes, though some tests, like Benford's Law, are more reliable with a larger transaction population, and we say so upfront and weight the review toward the other tests.

What software do you use for a fraud-indicator review?

We run Benford's Law and duplicate-payment tests through CaseWare IDEA or ACL Analytics against data exported from QuickBooks Online, Xero, or another accounting system, with results organized in Microsoft Excel.

Can this review run without anyone at the business knowing?

Yes, where the engaging party has lawful access to the records and wants the review kept quiet while other steps are considered before anyone involved is made aware.

What happens after something gets flagged?

The flag moves to whoever engaged the review, usually a board, owner, or attorney, who decides whether it warrants a deeper look, often through embezzlement investigation support or internal investigation bookkeeping.

Do you check for fake or shell vendors?

Yes, the vendor-master screen specifically checks for vendor addresses, phone numbers, or bank details that overlap with an employee, which is a common pattern behind a fictitious or shell vendor.

How long does a fraud-indicator review take?

It depends on transaction volume and how many systems and entities are involved. A single-entity business on one accounting platform typically turns around faster than a multi-entity group with several disconnected systems.

Will we know which specific test flagged an item?

Yes. Every item on the ranked list carries the specific test and the specific reason it was flagged, never an unexplained score, so the follow-up work can start from a clear basis.

Related services

Industries

Related guides

All services in Forensic accounting support

Sources

  1. [1]ACFE Report to the Nations, September 2026
  2. [2]CaseWare IDEA data analysis software, September 2026
  3. [3]QuickBooks Online, September 2026
  4. [4]IRS: Instructions for Forms 1099-MISC and 1099-NEC, September 2026

Next step

Talk to the team that would run your books

A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.

Need this in writing? Download a one to two page scope sheet for Fraud-indicator review: what is included, the process, and where pricing lives.

Download the scope sheet