September 25, 2026

Spotting Fraud in Financial Due Diligence

Spotting Fraud in Financial Due Diligence

If I’m buying a company, I don’t trust summary financials by themselves. Fraud often shows up in the gap between reported profit and the source records that should support it.

Here’s the short version:

  • I look for intentional number changes, not simple errors
  • I compare revenue, cash flow, bank activity, and source documents
  • I test cutoff, reconciliations, manual journal entries, and user access
  • I treat month-end spikes, forced balancing entries, altered records, and missing support as warning signs
  • I separate control gaps from issues that can change price, escrow, or whether the deal should pause

A few facts stand out. The article notes that 43% of fraud cases come to light through tips. It also points out that fake revenue, hidden expenses, and inflated assets can sit inside clean-looking reports if I only review the top-line P&L and balance sheet.

What I’d do first is simple:

  1. Ask for the source package, not just summary statements
  2. Tie the GL, sub-ledgers, and bank statements together
  3. Trace selected sales to invoices, shipping, customer support, and cash receipts
  4. Review manual entries, cutoff periods, and vendor master file changes
  5. Escalate fast if management blocks access or records do not tie

This article is about one main idea: weak controls show me where fraud may be hiding, and transaction testing shows me whether the numbers are real.

2. Red Flags in Financial Records and How to Verify Them

Revenue and Cash Flow Do Not Match

Once you have the source records, the next step is simple: check whether reported revenue actually turns into cash.

A clear red flag shows up when revenue and net income go up, but operating cash flow stays flat or slips into negative territory. That gap can point to paper profits that never made it to the bank. When that happens, you need to trace sales back to cash receipts and the source documents behind them.

A good way to verify this is to trace a sample of sales through the full chain:

  • Invoices
  • Shipping records
  • Customer confirmations
  • Subsequent cash receipts

Also look closely at sales spikes at the end of the month or quarter. Those jumps can signal cutoff manipulation or revenue pulled forward from a later period. If you spot that pattern, test cutoff and trace the related transactions back to the underlying records.

Avoid Fraud: Key Financial Due Diligence Tips #shorts

3. Internal Controls That Help Expose Fraud

Weak controls give people room to hide fraud. In due diligence, they also show buyers where to look. Once you spot a red flag, the next step is simple: test whether weak controls could have concealed it.

Segregation of Duties, Approvals, and Reconciliations

Authorization, custody, recordkeeping, and reconciliation should sit with different people. When one person controls too much of the process, hiding fraud gets much easier.

A classic case is lapping. If the same employee opens incoming checks and updates accounts receivable, they can steal one customer's payment and cover the shortfall with the next customer's payment.

Purchases, payments, and journal entries should all need sign-off from someone outside the original transaction. Independent reconciliations can bring unsupported adjustments to the surface.

System Access and Management Review Controls

Accounting system permissions offer a direct look at fraud risk. Admin rights or shared accounts can let users delete audit trails, backdate revenue entries, or change vendor bank details without leaving a trace.

Buyers should ask for a User Access Matrix. This report shows each user's permissions. Pay close attention to anyone who can both change vendor details and release payments. That mix is a major red flag.

Manual journal entries (MJEs) also need close review. Each manual entry should include support and an independent review. Ask for a log of all MJEs posted during the close process.

Access risk often goes hand in hand with override risk. That's why review controls and reporting channels matter more when looked at together.

Whistleblower Reporting and Continuous Monitoring

Tips are still the most common way fraud comes to light, accounting for 43% of all cases. Companies with a whistleblower hotline tend to detect fraud sooner and suffer smaller losses. During due diligence, request the whistleblower policy and the incident log, including resolution status. Tip logs can reveal problems that routine reporting never shows.

Beyond hotlines, look for continuous monitoring controls. These can include automated scripts or exception reports that flag:

  • Duplicate vendors
  • Round-dollar transactions
  • Reversals
  • Entries posted on weekends and holidays

These patterns can slip past a periodic review but stand out fast in a well-set monitoring system.

The table below ties each control to the fraud risk it targets and the evidence buyers should request:

Control Fraud Risk Addressed Evidence to Request
Segregation of Duties Lapping, ghost employees, skimming Org charts, user access listings, payroll registers
Bank Reconciliations Skimming, unrecorded disbursements, kiting Monthly bank statements, GL detail, outstanding checks >90 days
Purchase Approvals Fictitious vendors, kickbacks, personal purchases Signed POs, three-way match documentation
System Audit Logs Deleted records, unauthorized master file changes Audit trail logs, vendor master file change history
Management Review of MJEs Financial statement manipulation, period-end window dressing Signed monthly financial reviews, manual journal entry logs with backup
Whistleblower Hotline Long-term collusion, management override of controls Whistleblower policy, incident log with resolution status

These controls connect straight to transaction testing.

4. A Step-by-Step Testing Sequence for Suspected Irregularities

Financial Due Diligence Fraud Detection: Step-by-Step Testing Sequence

Financial Due Diligence Fraud Detection: Step-by-Step Testing Sequence

Once a red flag shows up, the order of testing matters. If you jump ahead or test the wrong item first, you can damage the trail or alert the wrong people before you have enough proof to act.

Start with Reconciliations and Cutoff Testing

Begin with a three-way match. Reconcile the general ledger (GL) to bank statements and the sub-ledgers for accounts receivable and accounts payable. If the GL, bank statements, and sub-ledgers don't tie, move straight to forensic testing. Unexplained forced balancing entries - adjustments made only to make the numbers match - are a strong sign that something was hidden.

After that, move to cutoff testing. Look closely at the 15–30 days around each month-end, quarter-end, and year-end. This is where timing games tend to show up.

Watch for cases like:

  • "Bill-and-hold" arrangements, where revenue is recorded before goods ship
  • "Channel stuffing", where product is pushed onto distributors just to inflate reported sales

If shipping dates fall after the reporting period, that's a clear sign revenue was pulled forward.

Trace Transactions and Test Master File Changes

Once reconciliations are done, trace selected GL entries back to the original source documents and bank postings. Don't stop at exported spreadsheets. Ask for read-only ERP access so you can check transaction metadata and timestamps at the source. Seller-provided exports can be manipulated.

Then trace sales to actual third-party cash receipts. Fraud cases built on fabricated revenue show why direct trace-to-cash testing matters. The point here isn't just whether an entry exists. It's whether the cash came in, when it came in, and who had permission to post or change the record.

Next, review the vendor master files. Compare vendor addresses and bank account numbers to employee payroll data. If a vendor record matches an employee's personal details, that often points to ghost vendors or kickback arrangements. Also flag any vendor with only a P.O. box address or no tax ID.

If the trace breaks, move at once to interviews and evidence preservation.

Interview, Document, and Escalate

When transaction testing fails, the job changes. You're no longer just checking accuracy. You're trying to contain the issue.

Interview mid-level accounting staff separately from owners and senior management. AP clerks and warehouse managers often know how the process works in practice, not just how it's described on paper. If a supervisor tells one story and a clerk tells another, treat that gap as a primary fraud indicator - especially around segregation of duties, override, or altered records.

To avoid tipping people off too early, frame requests as routine QofE or pre-close integration work. At the same time, preserve system access logs, email archives, and original source data right away.

Escalate to a forensic accountant or legal counsel when findings show:

  • Backdated contracts
  • Altered invoices
  • Management override
  • Refusal to provide source data

Bringing in legal counsel early establishes attorney-client privilege over the investigation's findings. And if the issue points to possible violations of the FCPA, AML statutes, or material tax noncompliance, bring in specialized regulatory counsel before close so they can assess successor liability.

5. Transaction Decisions, Control Remediation, and Key Takeaways

How to Classify Findings and Respond

Once testing confirms an issue, the next step is to turn that finding into deal terms.

Not every issue found in diligence carries the same weight. A missing approval on a small expense report is usually a control deficiency. Backdated contracts, unsupported revenue entries, or unexplained working capital swings can point to fraud. The job is to sort findings by severity and likelihood, then decide what happens next.

Some gaps can wait and be fixed after close. More serious issues can change the purchase price or escrow terms. And if the signs of fraud look credible, the process should stop until the matter is resolved.

What a Remediation Plan Should Include

If a finding does not kill the deal, both sides need a written remediation plan. It should spell out the issue, the affected accounts, the estimated impact, the person responsible, and the evidence behind the assessment.

A solid plan should also cover a few control steps:

  • Name the control owner
  • Set approval thresholds
  • Restrict access where override risk exists
  • Schedule recurring independent reconciliations

After the issue is documented, assign a clear owner and deadline so the fix can be tracked. A plan without owners and deadlines is not a plan.

At this stage, the question is no longer just what happened. It’s what the issue means for the transaction.

Key Takeaways

Treat unusual financial patterns as signals to test, not as conclusions. Internal controls help surface both the risk and the proof. Weak controls are evidence of risk, not background noise.

Document testing steps and escalation decisions so the deal outcome has support behind it. Due diligence findings can also affect working capital targets and balance sheet adjustments, which can influence the final purchase price and post-close stability.

FAQs

What’s the biggest fraud red flag in due diligence?

The biggest red flag in financial due diligence is questionable accounting practices. They can make a company look healthier than it is on paper while hiding what’s going on underneath.

Watch for aggressive revenue recognition, inconsistent financial statements, and gaps between internal records and tax filings. Problems like these can hide liabilities or make earnings look higher than they are, which is why you need to verify the underlying financial data.

When should a buyer bring in a forensic accountant?

A buyer should bring in a forensic accountant or fraud expert when a standard financial review turns up red flags that point to manipulation or serious internal control gaps.

That usually means issues like inconsistent financial statements, aggressive revenue recognition, unexplained gaps in revenue or expenses, or signs of billing fraud. For example, you might spot duplicate charges or misuse of related-party transactions.

At that point, this goes beyond a normal review. You’re not just checking the numbers anymore - you’re trying to find out whether the numbers can be trusted at all.

How can weak internal controls affect the deal price?

Weak internal controls can be a red flag. They often point to poor financial management, can skew valuation, and can chip away at a company’s worth during negotiations.

They can also hide waste, let fraud slip through, and make financial reporting harder to trust.

When buyers spot these issues, they often protect themselves by:

  • lowering valuation multiples
  • renegotiating the purchase price
  • changing deal terms to cover possible liabilities and future financial instability

Related Blog Posts