Forensic audit and fraud prevention
When you have a signal that something is wrong, we establish what happened, who was involved and what it cost — so that the findings hold up in proceedings.
A forensic audit differs from an ordinary one in a single respect: from the outset we assume someone may have acted deliberately and may have covered their tracks. That changes how evidence is gathered, the order of steps, and who is told that work is under way.
We operate in two modes. Reactively — when an event has occurred and needs explaining. Preventively — building a system that detects fraud early, before it grows to a scale that threatens the organisation.
Discretion is part of the method. Work begins after a non-disclosure agreement is signed. In sensitive matters we limit the circle of people informed to the minimum agreed with the client — including inside the organisation.
Investigating a specific event
The matters we are typically engaged on.
Procurement fraud
Tenders shaped around a chosen supplier, orders split below thresholds, bid rigging, acceptance of benefits, invoices for work not performed or performed to a lesser extent.
Conflict of interest
Personal and capital links between decision-maker and counterparty, competing activity by an employee, employment of close relatives, personal benefit derived from decisions taken in an official capacity.
Diversion of funds and assets
Sham contracts and invoices, cost inflation, warehouse shrinkage, unauthorised asset disposal, abuse of expense claims, fuel and corporate cards.
Financial reporting manipulation
Shifting revenue and cost between periods, concealing liabilities, inflating project indicators, unreliable settlement of grants.
Information and data leaks
Establishing the scope of the leak, its source and how the data was obtained, analysis of logs and access traces, assessment of the impact and of obligations towards the supervisory authority.
Workplace investigations
Reports of bullying, discrimination and unwanted behaviour — conducted independently, preserving the dignity of both parties and to an evidentiary standard that will stand up before a labour court.
How we run a forensic audit
-
Initial assessment of the report
We establish whether the signal has a factual basis and how large the potential problem is. We identify what must be secured immediately, before anyone learns that an investigation has begun.
-
Securing the evidence
System data, correspondence, paper documentation, access logs. Secured in a documented manner with an unbroken chain of custody, so the evidence retains its value in any subsequent proceedings.
-
Data analysis and anomaly detection
Tests on the full population: duplicates, payments to accounts outside the register, transactions just below approval thresholds, activity outside working hours, matches between counterparty and employee data, unusual value distributions.
-
External register checks
Verification of counterparties in the commercial register, business register, ultimate beneficial owner register, VAT taxpayer list, case-law and insolvency databases. Reconstruction of personal and capital connections.
-
Investigative interviews
Conducted in a considered order — neutral witnesses first, then those involved. Every interview recorded, with the right to present one’s own position preserved.
-
Report with findings and loss valuation
The facts, based solely on evidence, with a clear separation of facts, circumstantial indications and hypotheses. Valuation of the loss, assessment of the control gaps exploited, and recommendations: legal, organisational and remedial.
-
Support afterwards
Preparing material for a notification to law enforcement or a civil claim, support in disciplinary proceedings, and closing the control gaps that made the event possible.
A fraud prevention system
Detecting fraud after the fact always costs more than making it impossible. We build arrangements that raise the probability of detection — because that, rather than the size of the sanction, is the strongest deterrent.
Fraud vulnerability assessment
A review of processes against the fraud triangle: where opportunity exists, where control is nominal, and where one person controls an entire operating cycle. The output is a map of high-risk areas with specific gaps.
Anti-fraud policy and reporting channel
Documentation, a procedure for handling reports, a whistleblowing channel meeting the requirements of the Polish whistleblower protection act, rules protecting the reporter, and a register of reports.
Continuous testing and red flags
A set of tests run periodically against transaction data, detecting typical fraud patterns. We implement them so your team can continue running them after we leave.
Have a signal you cannot verify?
The first conversation is free and confidential. We will tell you whether the matter can be handled internally or needs an independent audit — and what must be secured straight away.
Get in touch