Use this guide to connect accounting evidence with the wider work of fraud examination. Each concept explains a rule or distinction, applies it to an original example and identifies a mistake to avoid. The accounting emphasis sits within the CFE Exam’s three sections: Fraud Schemes and Financial Crimes, Fraud Investigations and Legal Issues, and Fraud Prevention and Deterrence.
Accounting and Financial Reporting Foundations
1. Balanced Entries Can Still Conceal Fraud
Double-entry accounting maintains the relationship assets equal liabilities plus equity. A balanced entry establishes arithmetic consistency, not whether a transaction occurred or was classified properly. Fraud examination must connect ledger entries to underlying events, supporting records and appropriate accounting treatment.
Worked example: An employee records a nonexistent $9,000 receivable and $9,000 sale. The entry balances, but customer confirmation and delivery records provide no support for the sale.
Mistake to avoid: Treating a balanced trial balance as evidence that recorded transactions are genuine.
Source reference: About the CFE Exam
2. Accrual Profit and Cash Movements
Accrual accounting recognizes economic activity in the relevant period rather than simply when money changes hands. Receivables, payables and prepayments explain legitimate differences between profit and cash flow. Investigate the underlying timing and balances before interpreting those differences as manipulation.
Worked example: A supported $15,000 credit sale increases revenue and receivables while leaving current cash unchanged. Collection next month increases cash and reduces receivables without creating another sale.
Mistake to avoid: Counting a receivable collection as new revenue or assuming every cash shortfall proves fraud.
Source reference: About the CFE Exam
3. Revenue Occurrence and Cutoff
Revenue testing addresses both whether a transaction qualifies for recognition and whether it belongs in the recorded period. Applicable accounting requirements and contract terms matter. Compare invoices with delivery, acceptance or service-performance evidence instead of relying on invoice dates alone.
Worked example: A December invoice covers consulting performed entirely in January. With no December performance supporting recognition, the invoice alone does not justify December service revenue.
Mistake to avoid: Assuming that issuing an invoice automatically establishes earned revenue.
Source reference: About the CFE Exam
4. Capitalization Versus Immediate Expense
Capitalization records qualifying expenditure as an asset; expensing recognizes the cost in current earnings. Improper capitalization can inflate both assets and profit. Assess the nature of the expenditure and applicable recognition requirements, then examine subsequent depreciation or amortization where relevant.
Worked example: A company places $24,000 of ordinary maintenance in an equipment account. If the expenditure does not qualify as an asset, correcting it to expense reduces current profit by $24,000 before tax.
Mistake to avoid: Accepting an asset classification merely because management expects some future benefit.
Source reference: About the CFE Exam
5. Estimates, Bias and Supporting Assumptions
Accounting estimates involve uncertainty, but uncertainty does not permit arbitrary numbers. Examine the method, data, assumptions and consistency of an estimate. A suspicious change becomes more meaningful when unsupported assumptions systematically improve reported results or contradict information available at the reporting date.
Worked example: Receivables total $100,000. Documented analysis supports an $8,000 allowance, but management records $2,000 without explanation. The $6,000 difference overstates net receivables and pretax profit.
Mistake to avoid: Calling every estimate change fraudulent without evaluating its supporting evidence.
Source reference: About the CFE Exam
6. Following Effects Across Financial Statements
A manipulation often affects several accounts and statements. Trace both sides of an entry and its later reversal or settlement. This helps distinguish a genuine economic change from an accounting adjustment that improves reported performance without producing corresponding resources.
Worked example: Omitting a $7,500 unpaid utility expense understates liabilities and overstates pretax profit by $7,500. Cash remains unchanged until payment, so the absence of a cash movement does not validate the omission.
Mistake to avoid: Examining the income statement alone when the corresponding liability or asset carries the evidence.
Source reference: About the CFE Exam
7. Interpreting Financial Ratios in Context
Ratios highlight relationships that absolute totals can hide. Compare consistent periods, accounting classifications and business conditions. An unusual ratio identifies a question to investigate; it does not establish intent. Changes in product mix, prices or operating conditions can produce legitimate movements.
Worked example: Revenue rises from $200,000 to $250,000 while gross profit rises from $60,000 to $100,000. Gross margin increases from 30% to 40%, prompting examination of pricing, inventory costs and cutoff.
Mistake to avoid: Using a ratio change as a verdict without testing competing explanations.
Source reference: About the CFE Exam
8. Journal Entries and Management Override
Journal-entry analysis asks who posted an entry, why it was needed, what supports it and how it affected reporting. Manual adjustments, unusual users and entries outside normal workflows can merit review. Their significance depends on authorization, business purpose and corroborating records.
Worked example: A manager posts $18,000 to revenue with an offset to a suspense account, then reverses it after reporting. The unsupported purpose and temporary earnings effect warrant investigation.
Mistake to avoid: Assuming that every late or manual entry is fraudulent, or that senior approval makes it valid.
Source reference: About the CFE Exam
Fraud Schemes and Financial Crimes
9. Distinguishing Fraud, Error and Occupational Schemes
Fraud involves intentional deception; an error can produce the same accounting effect without that intent. Occupational schemes commonly involve asset misappropriation, corruption or financial statement fraud, and these categories can overlap. Classify the conduct and establish evidence of intent separately from calculating its financial effect.
Worked example: A clerk accidentally pays an invoice twice. Another clerk knowingly routes the second payment to an account they control. The duplicate-payment pattern alone does not distinguish their intent.
Mistake to avoid: Equating an accounting misstatement with proven fraud.
Source reference: About the CFE Exam
10. Skimming Versus Cash Larceny
Skimming takes receipts before they enter the accounting records. Cash larceny takes cash that has already been recorded. This distinction guides testing: skimming requires evidence outside the ledger, while recorded-cash theft may create shortages or concealment entries within the books.
Worked example: A cashier pockets an unrecorded $80 sale: skimming. If the sale is recorded and the cashier later removes $80 from the till, the conduct is cash larceny.
Mistake to avoid: Searching only recorded transactions for a scheme that deliberately avoids recording them.
Source reference: About the CFE Exam
11. Receivables Lapping
Lapping conceals a stolen customer payment by applying a later customer’s payment to the earlier account. The shortage moves between accounts rather than disappearing. Compare receipt dates, deposit records, customer remittances and the accounts credited to reconstruct the sequence.
Worked example: An employee steals Alder’s $600 payment and credits Birch’s subsequent $600 receipt to Alder. Alder appears settled, but Birch remains unpaid in the ledger despite having paid.
Mistake to avoid: Concluding that a customer balance is correct merely because it eventually reaches zero.
Source reference: About the CFE Exam
12. Fictitious Vendor Billing
A fictitious vendor scheme causes an organization to pay for nonexistent goods or services. Examine vendor legitimacy, ownership, receiving evidence and payment destinations together. A registered business or plausible invoice does not by itself establish that the invoiced work occurred.
Worked example: A department pays $4,200 for a supposed equipment inspection. No equipment list, site visit or inspection report exists, and the receiving employee cannot describe the service. The payment needs further investigation.
Mistake to avoid: Treating vendor registration or an invoice number as proof of delivery.
Source reference: About the CFE Exam
13. Ghost Employees and Payroll Manipulation
Payroll fraud can involve nonexistent employees or improper payments to real employees. Reconcile payroll with independently maintained personnel records, work evidence and authorized pay changes. Shared banking details or unusual overtime are leads requiring context, not automatic proof of wrongdoing.
Worked example: Payroll includes Rowan for 160 hours, but personnel records show no appointment and the supervisor confirms no work performed. A documented $3,200 payment becomes a specific transaction to investigate.
Mistake to avoid: Flagging shared addresses or bank accounts without considering legitimate household arrangements.
Source reference: About the CFE Exam
14. Expense Reimbursement Fraud
Expense schemes include fictitious purchases, inflated amounts, personal expenses and repeated reimbursement of one cost. Test business purpose, original transaction details and payment history. Compare reimbursements with corporate-card records so one legitimate purchase is not inadvertently treated as two separate expenses.
Worked example: An employee receives a $275 travel reimbursement for a hotel charge already paid by the company card. Unless an adjustment explains it, the employee has received $275 beyond the supported cost.
Mistake to avoid: Checking receipt authenticity while ignoring who originally paid the expense.
Source reference: About the CFE Exam
15. Inventory Diversion and Concealment
Inventory theft removes goods; concealment may use false write-offs, transfers or quantity adjustments. Compare physical quantities with movement records and investigate the reasons for adjustments. Differentiate theft from damage, counting errors and timing differences before estimating the loss.
Worked example: Records show 240 units, but an authorized count finds 225. Fifteen unexplained units at a documented cost of $40 represent $600 of inventory discrepancy, pending investigation of its cause.
Mistake to avoid: Valuing every missing unit at selling price or labeling every count difference theft.
Source reference: About the CFE Exam
16. Payment Tampering and Destination Changes
Payment tampering diverts an otherwise intended payment through an altered instrument, beneficiary or payment instruction. Compare approved obligations with actual bank destinations. The supplier name in the ledger can remain correct even when the money reaches an unauthorized account.
Worked example: A genuine $11,000 supplier invoice is approved, but the payment file substitutes another beneficiary account. The ledger shows the supplier paid, while independent confirmation shows the supplier received nothing.
Mistake to avoid: Verifying only invoice approval and overlooking the actual payment recipient.
Source reference: About the CFE Exam
17. Procurement Collusion and Bid Manipulation
Procurement corruption can distort competition through coordinated bids, preferential information or manipulated specifications. Examine bidding patterns alongside communications, ownership and evaluation records. Similar prices or repeated winners can arise legitimately, so a conclusion requires evidence explaining how competition was compromised.
Worked example: Three bids contain the same unusual calculation error. That pattern supports checking their origins and communications; it does not alone prove the bidders coordinated.
Mistake to avoid: Treating a procurement anomaly as conclusive evidence of collusion.
Source reference: About the CFE Exam
18. Conflicts of Interest and Improper Benefits
A conflict of interest arises when personal interests can interfere with entrusted duties. Bribery involves an improper benefit intended to influence conduct; specific legal elements vary. An undisclosed relationship may require investigation even when no payment or financial loss has been established.
Worked example: A purchasing manager selects a business owned by their sibling without disclosure. The relationship creates a conflict requiring examination, but it does not by itself prove a bribe occurred.
Mistake to avoid: Using conflict of interest and bribery as interchangeable conclusions.
Source reference: About the CFE Exam
19. Ponzi and Pyramid Scheme Structures
A Ponzi scheme uses incoming investor money to fund apparent returns to earlier investors rather than genuine investment earnings. A pyramid scheme primarily rewards recruitment of additional participants. Trace the source of payouts and incentives; promotional labels do not establish the economic substance.
Worked example: A promoter receives $50,000 from new investors and uses $8,000 of it for existing investors’ supposed returns. With no supporting investment earnings, the payout fits a Ponzi funding pattern.
Mistake to avoid: Assuming that an early payout proves a venture earns legitimate returns.
Source reference: About the CFE Exam
20. Money Laundering and Economic Substance
Money laundering seeks to obscure the illicit origin or ownership of assets. Placement, layering and integration are useful analytical descriptions, but real cases need not follow a neat sequence. Examine ownership, funding sources and business purpose without treating complexity alone as criminal evidence.
Worked example: An inactive company receives funds, transfers nearly all of them through related entities and records unsupported consulting charges. The unexplained activity warrants tracing and corroboration, not an immediate laundering conclusion.
Mistake to avoid: Assuming that every cross-border transfer or complex company structure is unlawful.
Source reference: About the CFE Exam
Governance and Fraud Controls
21. Independent Governance Oversight
Governance establishes accountability for fraud risk and gives concerns an escalation route beyond the people involved. Oversight is more effective when those reviewing concerns can challenge management, access relevant information and track corrective action. Titles alone do not demonstrate independence or effective supervision.
Worked example: An allegation concerns the finance director. Routing it solely to that director creates a conflict; an appropriately independent oversight function should determine the authorized response.
Mistake to avoid: Assuming that a formal committee automatically provides independent oversight.
Source reference: About the CFE Exam
22. Segregation of Incompatible Duties
Separate authority to approve transactions, custody of assets, recordkeeping and reconciliation where practical. Concentrating these functions lets someone commit and conceal a scheme. When staffing prevents full separation, a genuinely independent review should address the specific combination of risks.
Worked example: One employee creates vendors, releases payments and reconciles the bank account. Assigning payment release and reconciliation to independent people reduces that employee’s ability to divert and conceal funds.
Mistake to avoid: Dividing job titles while leaving the same person with incompatible system permissions.
Source reference: About the CFE Exam
23. Meaningful Authorization Controls
Authorization controls require a reviewer with appropriate authority to assess the transaction’s purpose, supporting evidence and compliance with policy. A signature is useful only if the review is substantive. Examine whether transactions are divided or routed to circumvent the intended approval process.
Worked example: A policy requires additional review above $5,000. Two same-day $3,000 invoices for one purchase suggest possible approval avoidance and should be evaluated together.
Mistake to avoid: Treating approval as effective when reviewers lack the information needed to challenge a transaction.
Source reference: About the CFE Exam
24. Reconciliation and Unresolved Differences
A reconciliation compares independent records and explains differences between them. Its value comes from investigating discrepancies, not forcing totals to match. Review the age, support and subsequent resolution of reconciling items, especially items that recur without a clear business explanation.
Worked example: The ledger shows $38,400 in cash and the bank shows $37,900. A supported $500 deposit in transit explains the difference only if subsequent bank evidence confirms receipt.
Mistake to avoid: Accepting a recurring reconciling item without verifying what caused it.
Source reference: About the CFE Exam
25. Least Privilege and Access Review
Least privilege limits access to what a person needs for current duties. Periodic review should consider actual permissions, privileged accounts and incompatible capabilities. Access logs help investigate activity, but an account identifier alone may not establish who personally performed an action.
Worked example: A former payroll employee retains permission to alter bank details after moving to sales. Removing the unnecessary permission closes an avoidable payment-diversion opportunity.
Mistake to avoid: Assuming that a department transfer automatically updates system access.
Source reference: About the CFE Exam
26. Independent Verification of Master Data
Vendor and employee master data determine where payments go and how transactions are processed. Changes to sensitive fields need authorization and independent verification using trusted contact information. Verification should not rely entirely on the same message that requested the change.
Worked example: An email requests a supplier bank change. Contacting the supplier through an independently established channel reveals that no change was requested, preventing payment to the substituted account.
Mistake to avoid: Using the requester’s newly supplied telephone number to authenticate the requester.
Source reference: About the CFE Exam
27. Matching Orders, Receipts and Invoices
Matching a purchase order, receipt record and invoice tests authorization, delivery and billing consistency. Differences require explanation before payment under the organization’s procedures. Service purchases may need performance evidence rather than a warehouse receipt, and matching cannot defeat collusion among all participants.
Worked example: An order authorizes 70 units at $20, but receiving confirms 60. A $1,400 invoice exceeds the supported delivered quantity by $200 and needs resolution.
Mistake to avoid: Paying a fully matched invoice when the receiving evidence itself is unreliable.
Source reference: About the CFE Exam
28. Custody Controls and Independent Counts
Custody controls restrict access to assets and create accountability for transfers. Independent counts compare actual assets with records at a defined point in time. Document timing and movements during the count so ordinary transfers are not mistaken for shortages or counted twice.
Worked example: A cash record shows $1,250. An authorized independent count finds $1,170, and no supported movement explains the difference. The $80 shortage requires investigation.
Mistake to avoid: Allowing undocumented asset movements during a count and then treating the result as definitive.
Source reference: About the CFE Exam
29. Reporting Channels and Retaliation Risk
Effective reporting channels let people raise concerns through routes appropriate to the circumstances, including alternatives when a supervisor is implicated. Confidential handling, fair triage and protection against retaliation support useful reporting. Anonymous information still requires evaluation and corroboration.
Worked example: A warehouse worker reports unexplained write-offs through an independent channel because the supervisor approves them. Investigators assess the records without disclosing the worker’s identity unnecessarily.
Mistake to avoid: Dismissing an anonymous concern or promising absolute confidentiality that cannot be assured.
Source reference: About the CFE Exam
30. Management, Audit and Fraud Examination Roles
Management operates controls and manages fraud risk. Internal and external audit provide assurance within their respective mandates, while fraud examination investigates specific concerns. The scope and evidence requirements differ. An audit opinion does not establish that every transaction has been examined or that fraud is absent.
Worked example: A financial statement audit finds no material misstatement, but a later allegation identifies repeated small thefts. The allegation can justify a focused investigation despite the audit result.
Mistake to avoid: Treating a clean audit opinion as a guarantee against fraud.
Source reference: About the CFE Exam
Fraud Risk, Response and Professional Ethics
31. Pressure, Opportunity and Rationalization
The fraud triangle organizes possible contributing conditions: pressure, opportunity and rationalization. It helps identify risks and prevention options, but it is not a diagnostic test for guilt. People under financial pressure may act honestly, and investigators may never observe a person’s rationalization.
Worked example: Aggressive sales targets create pressure, weak revenue review creates opportunity, and claims that adjustments are temporary suggest rationalization. Strengthening review addresses opportunity without accusing everyone facing targets.
Mistake to avoid: Inferring fraud from personal debt, stress or an assumed attitude.
Source reference: About the CFE Exam
32. Building Specific Fraud Risk Scenarios
A useful fraud risk assessment describes who could act, what they could do, how it could be concealed and which assets or reports would be affected. Specific scenarios connect risks to controls more effectively than broad labels such as payment fraud or dishonest employees.
Worked example: A payable clerk could redirect vendor payments by changing bank details and conceal the diversion through reconciliation access. This scenario identifies both master-data and independent-review controls.
Mistake to avoid: Listing generic risks without describing a plausible mechanism or concealment route.
Source reference: About the CFE Exam
33. Inherent Risk and Residual Risk
Inherent risk describes exposure before considering controls; residual risk describes exposure after considering their effectiveness. Assess likelihood and impact using a consistent organizational method. A control’s existence does not justify assuming it works, and qualitative risk ratings are not precise probabilities.
Worked example: Payment diversion has substantial inherent exposure. Independently verified bank changes reduce residual risk only if verification occurs consistently and exceptions receive appropriate review.
Mistake to avoid: Subtracting a fixed percentage from risk merely because a written policy exists.
Source reference: About the CFE Exam
34. Control Design Versus Operating Effectiveness
Design asks whether a control could address the identified risk if performed as intended. Operating effectiveness asks whether it actually worked during the period examined. A well-designed control can fail through inconsistent execution, insufficient evidence or an override that bypasses its purpose.
Worked example: Policy requires independent verification of bank changes, but eight sampled changes have no verification evidence. The design addresses diversion; the observed execution does not establish effectiveness.
Mistake to avoid: Using a policy document as proof that a control operated.
Source reference: About the CFE Exam
35. Preventive, Detective and Corrective Controls
Preventive controls seek to stop an event, detective controls identify events or warning signs, and corrective controls address consequences or weaknesses. A fraud program benefits from their combination because prevention can fail and detection has little value without an appropriate response.
Worked example: Restricted vendor editing is preventive, a bank-change exception report is detective, and removing unauthorized access after investigation is corrective. Each addresses a different stage of the risk.
Mistake to avoid: Assuming that a detective report prevents a payment unless someone acts on it in time.
Source reference: About the CFE Exam
36. Monitoring Indicators With Proper Denominators
Fraud monitoring should use measures that remain interpretable as business volume changes. Counts, rates, severity and unresolved exceptions provide different information. More reports may indicate greater willingness to speak up rather than more fraud; fewer alerts may reflect weaker detection.
Worked example: Duplicate-payment alerts rise from 10 among 1,000 payments to 15 among 3,000. The alert rate falls from 1% to 0.5%, despite the higher count.
Mistake to avoid: Comparing raw alert totals without considering transaction volume or changes in detection.
Source reference: About the CFE Exam
37. Proportionate Initial Fraud Response
An initial response should protect relevant records, assess ongoing exposure and assign an authorized, impartial investigation. Actions must respect applicable rights and procedures. Coordinate necessary specialist or legal input before steps that might destroy evidence, alert involved parties or exceed the organization’s authority.
Worked example: A payment-diversion allegation leads to authorized preservation of relevant records and review of pending payments. Investigators avoid unsupported public accusations while establishing facts.
Mistake to avoid: Deleting a suspicious account or broadly seizing personal information before assessing preservation and authority.
Source reference: About the CFE Exam
38. Root Causes and Remediation
Remediation should address the mechanism that enabled the event, not only its immediate outcome. Separate individual conduct from weaknesses in incentives, access, review and escalation. Assign responsibility for corrective actions and verify that the revised control works against the identified scenario.
Worked example: Recovering a diverted $6,000 payment does not fix unrestricted bank-detail changes. Independent verification and access changes address the mechanism; follow-up testing checks implementation.
Mistake to avoid: Closing an issue after recovery while leaving the same concealment opportunity available.
Source reference: About the CFE Exam
39. Objectivity and Conflicts in Examination
An examiner should evaluate evidence impartially, including facts that contradict the initial suspicion. Personal relationships, prior involvement and financial interests can impair objectivity or its appearance. Identify conflicts early and use disclosure, reassignment or other appropriate safeguards.
Worked example: An examiner previously approved the transactions under investigation. Assigning an independent examiner reduces the risk that the review becomes a defense of the earlier approval.
Mistake to avoid: Ignoring contradictory evidence because it weakens a favored explanation.
Source reference: About the CFE Exam
40. Confidentiality and Competence Boundaries
Sensitive information should be accessed and shared only for an authorized purpose with appropriate recipients. Examiners must also recognize the limits of their competence. Specialized accounting, legal or technical questions may require qualified assistance rather than unsupported conclusions presented with certainty.
Worked example: A ledger review uncovers potentially privileged communications and encrypted files. The examiner seeks appropriate legal and technical guidance instead of circulating the material or claiming unsupported technical findings.
Mistake to avoid: Treating access to information as permission to disclose it or as proof of specialist competence.
Source reference: About the CFE Exam
Evidence and Accounting Data Analysis
41. Turning Allegations Into Testable Hypotheses
An allegation is a starting claim, not an established fact. Convert it into testable propositions and identify competing explanations. For each proposition, specify records or observations that could support or weaken it, then revise the investigation as evidence develops.
Worked example: A tip alleges inflated overtime. Investigators compare approved hours, work schedules and access records, while considering whether legitimate off-site work explains apparent differences.
Mistake to avoid: Searching only for confirmation and treating the original allegation as the conclusion.
Source reference: About the CFE Exam
42. Defining an Investigation’s Scope and Authority
An investigation plan defines the issues, relevant periods, information needed, responsibilities and authorized access. Scope should expand when evidence justifies it rather than through indiscriminate collection. Document significant changes and consider employee rights, privacy and applicable legal restrictions throughout.
Worked example: A March expense concern initially requires March claims and payment records. Evidence of repeated January claims supports an authorized extension to earlier periods, rather than unrestricted collection of unrelated personal files.
Mistake to avoid: Assuming that a business concern authorizes access to every available account or device.
Source reference: About the CFE Exam
43. Relevance, Reliability and Evidence Sufficiency
Relevant evidence bears on the issue being examined; reliable evidence has a trustworthy origin and dependable content. Sufficiency concerns whether the body of evidence supports the conclusion. Numerous copies of one unverified claim do not provide the same support as independent corroboration.
Worked example: Five forwarded emails repeat one rumor about a vendor. A receiving record, payment confirmation and independently obtained supplier response provide different, potentially corroborating evidence.
Mistake to avoid: Counting documents without assessing their independence, source or connection to the issue.
Source reference: About the CFE Exam
44. Chain of Custody and Evidence Handling
Chain-of-custody records document evidence identification, possession, transfers and handling. Their purpose is to help explain what happened to an item and whether its integrity was maintained. Good documentation does not automatically establish authenticity or admissibility under every legal system.
Worked example: An authorized collector records a device identifier, collection time, storage location and each transfer. A later reviewer can reconstruct who handled the device and when.
Mistake to avoid: Leaving unexplained custody gaps or assuming a custody log guarantees legal admissibility.
Source reference: About the CFE Exam
45. Preserved Originals, Working Copies and Hashes
Where appropriate, preserve original evidence and analyze controlled copies using suitable procedures. A cryptographic hash helps detect whether digital content has changed between documented points. Matching hashes do not prove that a file was truthful, complete or authentic before collection.
Worked example: A preserved export and its working copy have matching hashes. This supports content consistency between them, but does not prove that the original system contained every relevant transaction.
Mistake to avoid: Describing a matching hash as proof that the underlying business records are accurate.
Source reference: About the CFE Exam
46. Metadata and Timestamp Interpretation
Metadata can describe file creation, modification, authorship or system activity, but its meaning depends on the application and environment. Time zones, copying, clock differences and editable fields can complicate interpretation. Corroborate a timeline with independent records before assigning actions to a person.
Worked example: An invoice file has a later creation timestamp than its printed date. The difference could reflect copying or regeneration, so investigators compare system logs and transaction history before concluding it was fabricated.
Mistake to avoid: Treating a timestamp or author field as conclusive evidence of personal authorship.
Source reference: About the CFE Exam
47. Authorized and Purposeful Data Collection
Collect data under appropriate authority and limit collection to what the investigation reasonably needs. Relevant financial records can include sensitive information about uninvolved people. Document the source and collection boundaries, and apply suitable access and retention controls without assuming universal legal permissions.
Worked example: To examine duplicate reimbursements, an authorized export includes claim identifiers, dates, amounts and payment references. Unrelated medical details are excluded because they do not answer the investigative question.
Mistake to avoid: Collecting all available personal data merely because storage is inexpensive.
Source reference: About the CFE Exam
48. Join Logic and Duplicate Amplification
Data joins must match the relationship between tables. Joining a payment to several invoice lines can repeat the payment amount and inflate totals. Check key uniqueness, unmatched records and row counts before interpreting combined data, especially when relationships are one-to-many.
Worked example: One $900 payment joins to three invoice lines. Summing the repeated payment field produces $2,700; summing each payment once gives the correct $900.
Mistake to avoid: Assuming a larger joined dataset contains more money rather than repeated representations of the same transaction.
Source reference: About the CFE Exam
49. Data Completeness and Control Totals
An analysis can be internally correct yet incomplete because records were omitted, filtered or truncated. Reconcile row counts and monetary totals to an appropriate independent source. Understand date fields, canceled entries and extraction criteria before concluding that an export represents the full population.
Worked example: The ledger records $420,000 of payments, but an export totals $405,000. Investigators identify an excluded payment batch of $15,000 before relying on the analysis.
Mistake to avoid: Treating a successfully opened file as proof that every relevant record was extracted.
Source reference: About the CFE Exam
50. Duplicate Detection and False Positives
Duplicate tests compare selected fields to identify transactions needing review. Exact matches can miss altered invoice references, while broad matches can flag legitimate recurring charges. Resolve alerts using underlying documents, payment status and transaction relationships rather than classifying matches automatically as losses.
Worked example: Two $480 invoices from one landlord have different monthly service periods. The matching supplier and amount generate an alert, but the documents resolve it as legitimate recurring rent.
Mistake to avoid: Adding every duplicate alert to the fraud-loss total.
Source reference: About the CFE Exam
51. Outliers, Trends and Appropriate Comparisons
Outlier analysis identifies observations unlike a suitable comparison group. The choice of group matters: job role, season, location and transaction type can explain variation. An unusual observation becomes an investigative lead; supporting evidence determines whether it reflects error, legitimate activity or fraud.
Worked example: A salesperson’s travel cost is twice the office average but consistent with other international sales staff. Comparing similar roles avoids an unsupported inference from the office-wide average.
Mistake to avoid: Using an arbitrary cutoff or an unsuitable peer group as proof of misconduct.
Source reference: About the CFE Exam
52. Loss Quantification Without Double Counting
Define what a loss figure measures and separate confirmed amounts, estimates and recoveries. Trace transactions so the same economic loss is not counted through both a payment and its related accounting entry. Any extrapolation requires a justified method and explicit limitations.
Worked example: Confirmed improper payments total $12,000, with $3,000 recovered. Report $12,000 gross confirmed loss and $9,000 unrecovered, rather than counting both figures as separate losses.
Mistake to avoid: Mixing gross loss, outstanding recovery and speculative exposure into one unexplained total.
Source reference: About the CFE Exam
Interviews, Reporting and Legal Understanding
53. Open Questions Followed by Focused Clarification
Open questions invite an interviewee to describe events in their own terms. Focused questions then clarify dates, responsibilities and documents. Neutral wording reduces the risk of supplying an answer. Interview methods must remain appropriate to the person’s rights and the investigation’s authorized purpose.
Worked example: The interviewer asks, “How were vendor changes processed?” before asking who approved a particular change. The sequence establishes the usual process before exploring the exception.
Mistake to avoid: Beginning with a leading accusation that embeds unverified facts in the question.
Source reference: About the CFE Exam
54. Personal Knowledge, Hearsay and Chronology
Distinguish what a person directly observed from what they inferred or learned from someone else. Build a chronology with identifiable events and records, allowing uncertainty where memory is incomplete. A witness’s confidence does not automatically establish the accuracy or source of their recollection.
Worked example: A clerk says a manager altered an invoice, then explains that a colleague told them. The statement identifies another lead; it is not the clerk’s direct observation.
Mistake to avoid: Recording secondhand information as though the interviewee personally witnessed the event.
Source reference: About the CFE Exam
55. Resolving Inconsistencies Through Corroboration
An inconsistency warrants clarification and comparison with independent evidence. Memory errors, ambiguous questions and differing perspectives can produce conflicting accounts. Document the discrepancy fairly, seek an explanation and distinguish unresolved differences from demonstrated false statements.
Worked example: An employee recalls approval on Tuesday, while an email records Wednesday. The interviewer asks about the sequence and checks whether Tuesday involved an oral discussion before written approval.
Mistake to avoid: Inferring deception from nervousness, poor eye contact or one inconsistent detail.
Source reference: About the CFE Exam
56. Reports That Separate Facts and Inferences
An investigation report should connect findings to evidence and explain material limitations. Separate documented facts, witness statements, analytical inferences and unresolved issues. Describe methods and amounts clearly enough that a reader can understand the basis of the conclusion without overstating what was established.
Worked example: A report states that $2,400 reached an account, that a witness attributed it to an employee, and that ownership remains unverified. These are distinct evidential positions.
Mistake to avoid: Presenting a suspected explanation as an established fact or omitting contrary evidence.
Source reference: About the CFE Exam
57. Common Law and Civil Law Traditions
Common law and civil law describe broad legal traditions, with different emphases on precedent and codified rules. Actual jurisdictions can combine features, and procedures vary. Use the distinction as orientation rather than a substitute for checking the applicable law and obtaining appropriate legal guidance.
Worked example: An examiner receives a cross-border assignment. Familiarity with one country’s precedent-based procedures does not establish how evidence collection is authorized in the other country.
Mistake to avoid: Assuming that one legal tradition creates identical investigation rules across all its jurisdictions.
Source reference: About the CFE Exam
58. Criminal, Civil and Administrative Proceedings
Criminal proceedings address alleged offenses; civil proceedings generally address private claims and remedies; administrative proceedings concern regulatory or organizational authority. The same conduct may generate several processes. Applicable elements, evidential standards and available remedies depend on the jurisdiction and proceeding.
Worked example: A diverted payment may prompt an internal disciplinary process, a civil recovery claim and a criminal referral. Evidence supporting one process does not automatically satisfy the requirements of another.
Mistake to avoid: Applying one proceeding’s evidential standard or outcome to every related process.
Source reference: About the CFE Exam
59. Employee Rights, Recording and Privilege
Interviewing, recording, searching devices and handling potentially privileged material require attention to applicable rights and law. Consent, employment policies and investigative authority have limits that vary by setting. Identify these issues before acting and seek appropriate legal advice where requirements are uncertain.
Worked example: Before recording an employee interview, the team confirms the applicable authorization and consent requirements. It also establishes a process for referring potentially privileged material for legal assessment.
Mistake to avoid: Assuming that employer ownership of equipment permits every search, recording or disclosure.
Source reference: About the CFE Exam
60. Fact Testimony and Expert Opinion
Fact testimony concerns observations and actions; expert opinion applies specialized knowledge within an appropriate scope. An examiner should explain the data, methods, assumptions and limitations behind an opinion. Qualification and admissibility requirements vary, and expertise does not authorize unsupported conclusions about legal guilt.
Worked example: An examiner describes tracing $14,000 through payment records, then explains a loss calculation. Whether the conduct satisfies a criminal offense remains a separate legal determination.
Mistake to avoid: Presenting professional confidence as a substitute for a transparent method and supporting evidence.
Source reference: About the CFE Exam
Sources
Credential identity and exam scope:
Browse all study guides