Study Guide

CFE Exam Study Guide: Accounting Focus

Explore 60 concepts covering accounting, fraud schemes, investigations, legal issues, prevention and ethics for the ACFE CFE Exam.

Updated October 202625 min readStudy GuideAcctPrep
Olivia Morgan

Olivia Morgan

AcctPrep Editorial Team

Use this guide to connect accounting evidence with the wider work of fraud examination. Each concept explains a rule or distinction, applies it to an original example and identifies a mistake to avoid. The accounting emphasis sits within the CFE Exam’s three sections: Fraud Schemes and Financial Crimes, Fraud Investigations and Legal Issues, and Fraud Prevention and Deterrence.

Accounting and Financial Reporting Foundations

1. Balanced Entries Can Still Conceal Fraud

Double-entry accounting maintains the relationship assets equal liabilities plus equity. A balanced entry establishes arithmetic consistency, not whether a transaction occurred or was classified properly. Fraud examination must connect ledger entries to underlying events, supporting records and appropriate accounting treatment.

Worked example: An employee records a nonexistent $9,000 receivable and $9,000 sale. The entry balances, but customer confirmation and delivery records provide no support for the sale.

Mistake to avoid: Treating a balanced trial balance as evidence that recorded transactions are genuine.

Source reference: About the CFE Exam

2. Accrual Profit and Cash Movements

Accrual accounting recognizes economic activity in the relevant period rather than simply when money changes hands. Receivables, payables and prepayments explain legitimate differences between profit and cash flow. Investigate the underlying timing and balances before interpreting those differences as manipulation.

Worked example: A supported $15,000 credit sale increases revenue and receivables while leaving current cash unchanged. Collection next month increases cash and reduces receivables without creating another sale.

Mistake to avoid: Counting a receivable collection as new revenue or assuming every cash shortfall proves fraud.

Source reference: About the CFE Exam

3. Revenue Occurrence and Cutoff

Revenue testing addresses both whether a transaction qualifies for recognition and whether it belongs in the recorded period. Applicable accounting requirements and contract terms matter. Compare invoices with delivery, acceptance or service-performance evidence instead of relying on invoice dates alone.

Worked example: A December invoice covers consulting performed entirely in January. With no December performance supporting recognition, the invoice alone does not justify December service revenue.

Mistake to avoid: Assuming that issuing an invoice automatically establishes earned revenue.

Source reference: About the CFE Exam

4. Capitalization Versus Immediate Expense

Capitalization records qualifying expenditure as an asset; expensing recognizes the cost in current earnings. Improper capitalization can inflate both assets and profit. Assess the nature of the expenditure and applicable recognition requirements, then examine subsequent depreciation or amortization where relevant.

Worked example: A company places $24,000 of ordinary maintenance in an equipment account. If the expenditure does not qualify as an asset, correcting it to expense reduces current profit by $24,000 before tax.

Mistake to avoid: Accepting an asset classification merely because management expects some future benefit.

Source reference: About the CFE Exam

5. Estimates, Bias and Supporting Assumptions

Accounting estimates involve uncertainty, but uncertainty does not permit arbitrary numbers. Examine the method, data, assumptions and consistency of an estimate. A suspicious change becomes more meaningful when unsupported assumptions systematically improve reported results or contradict information available at the reporting date.

Worked example: Receivables total $100,000. Documented analysis supports an $8,000 allowance, but management records $2,000 without explanation. The $6,000 difference overstates net receivables and pretax profit.

Mistake to avoid: Calling every estimate change fraudulent without evaluating its supporting evidence.

Source reference: About the CFE Exam

6. Following Effects Across Financial Statements

A manipulation often affects several accounts and statements. Trace both sides of an entry and its later reversal or settlement. This helps distinguish a genuine economic change from an accounting adjustment that improves reported performance without producing corresponding resources.

Worked example: Omitting a $7,500 unpaid utility expense understates liabilities and overstates pretax profit by $7,500. Cash remains unchanged until payment, so the absence of a cash movement does not validate the omission.

Mistake to avoid: Examining the income statement alone when the corresponding liability or asset carries the evidence.

Source reference: About the CFE Exam

7. Interpreting Financial Ratios in Context

Ratios highlight relationships that absolute totals can hide. Compare consistent periods, accounting classifications and business conditions. An unusual ratio identifies a question to investigate; it does not establish intent. Changes in product mix, prices or operating conditions can produce legitimate movements.

Worked example: Revenue rises from $200,000 to $250,000 while gross profit rises from $60,000 to $100,000. Gross margin increases from 30% to 40%, prompting examination of pricing, inventory costs and cutoff.

Mistake to avoid: Using a ratio change as a verdict without testing competing explanations.

Source reference: About the CFE Exam

8. Journal Entries and Management Override

Journal-entry analysis asks who posted an entry, why it was needed, what supports it and how it affected reporting. Manual adjustments, unusual users and entries outside normal workflows can merit review. Their significance depends on authorization, business purpose and corroborating records.

Worked example: A manager posts $18,000 to revenue with an offset to a suspense account, then reverses it after reporting. The unsupported purpose and temporary earnings effect warrant investigation.

Mistake to avoid: Assuming that every late or manual entry is fraudulent, or that senior approval makes it valid.

Source reference: About the CFE Exam

Fraud Schemes and Financial Crimes

9. Distinguishing Fraud, Error and Occupational Schemes

Fraud involves intentional deception; an error can produce the same accounting effect without that intent. Occupational schemes commonly involve asset misappropriation, corruption or financial statement fraud, and these categories can overlap. Classify the conduct and establish evidence of intent separately from calculating its financial effect.

Worked example: A clerk accidentally pays an invoice twice. Another clerk knowingly routes the second payment to an account they control. The duplicate-payment pattern alone does not distinguish their intent.

Mistake to avoid: Equating an accounting misstatement with proven fraud.

Source reference: About the CFE Exam

10. Skimming Versus Cash Larceny

Skimming takes receipts before they enter the accounting records. Cash larceny takes cash that has already been recorded. This distinction guides testing: skimming requires evidence outside the ledger, while recorded-cash theft may create shortages or concealment entries within the books.

Worked example: A cashier pockets an unrecorded $80 sale: skimming. If the sale is recorded and the cashier later removes $80 from the till, the conduct is cash larceny.

Mistake to avoid: Searching only recorded transactions for a scheme that deliberately avoids recording them.

Source reference: About the CFE Exam

11. Receivables Lapping

Lapping conceals a stolen customer payment by applying a later customer’s payment to the earlier account. The shortage moves between accounts rather than disappearing. Compare receipt dates, deposit records, customer remittances and the accounts credited to reconstruct the sequence.

Worked example: An employee steals Alder’s $600 payment and credits Birch’s subsequent $600 receipt to Alder. Alder appears settled, but Birch remains unpaid in the ledger despite having paid.

Mistake to avoid: Concluding that a customer balance is correct merely because it eventually reaches zero.

Source reference: About the CFE Exam

12. Fictitious Vendor Billing

A fictitious vendor scheme causes an organization to pay for nonexistent goods or services. Examine vendor legitimacy, ownership, receiving evidence and payment destinations together. A registered business or plausible invoice does not by itself establish that the invoiced work occurred.

Worked example: A department pays $4,200 for a supposed equipment inspection. No equipment list, site visit or inspection report exists, and the receiving employee cannot describe the service. The payment needs further investigation.

Mistake to avoid: Treating vendor registration or an invoice number as proof of delivery.

Source reference: About the CFE Exam

13. Ghost Employees and Payroll Manipulation

Payroll fraud can involve nonexistent employees or improper payments to real employees. Reconcile payroll with independently maintained personnel records, work evidence and authorized pay changes. Shared banking details or unusual overtime are leads requiring context, not automatic proof of wrongdoing.

Worked example: Payroll includes Rowan for 160 hours, but personnel records show no appointment and the supervisor confirms no work performed. A documented $3,200 payment becomes a specific transaction to investigate.

Mistake to avoid: Flagging shared addresses or bank accounts without considering legitimate household arrangements.

Source reference: About the CFE Exam

14. Expense Reimbursement Fraud

Expense schemes include fictitious purchases, inflated amounts, personal expenses and repeated reimbursement of one cost. Test business purpose, original transaction details and payment history. Compare reimbursements with corporate-card records so one legitimate purchase is not inadvertently treated as two separate expenses.

Worked example: An employee receives a $275 travel reimbursement for a hotel charge already paid by the company card. Unless an adjustment explains it, the employee has received $275 beyond the supported cost.

Mistake to avoid: Checking receipt authenticity while ignoring who originally paid the expense.

Source reference: About the CFE Exam

15. Inventory Diversion and Concealment

Inventory theft removes goods; concealment may use false write-offs, transfers or quantity adjustments. Compare physical quantities with movement records and investigate the reasons for adjustments. Differentiate theft from damage, counting errors and timing differences before estimating the loss.

Worked example: Records show 240 units, but an authorized count finds 225. Fifteen unexplained units at a documented cost of $40 represent $600 of inventory discrepancy, pending investigation of its cause.

Mistake to avoid: Valuing every missing unit at selling price or labeling every count difference theft.

Source reference: About the CFE Exam

16. Payment Tampering and Destination Changes

Payment tampering diverts an otherwise intended payment through an altered instrument, beneficiary or payment instruction. Compare approved obligations with actual bank destinations. The supplier name in the ledger can remain correct even when the money reaches an unauthorized account.

Worked example: A genuine $11,000 supplier invoice is approved, but the payment file substitutes another beneficiary account. The ledger shows the supplier paid, while independent confirmation shows the supplier received nothing.

Mistake to avoid: Verifying only invoice approval and overlooking the actual payment recipient.

Source reference: About the CFE Exam

17. Procurement Collusion and Bid Manipulation

Procurement corruption can distort competition through coordinated bids, preferential information or manipulated specifications. Examine bidding patterns alongside communications, ownership and evaluation records. Similar prices or repeated winners can arise legitimately, so a conclusion requires evidence explaining how competition was compromised.

Worked example: Three bids contain the same unusual calculation error. That pattern supports checking their origins and communications; it does not alone prove the bidders coordinated.

Mistake to avoid: Treating a procurement anomaly as conclusive evidence of collusion.

Source reference: About the CFE Exam

18. Conflicts of Interest and Improper Benefits

A conflict of interest arises when personal interests can interfere with entrusted duties. Bribery involves an improper benefit intended to influence conduct; specific legal elements vary. An undisclosed relationship may require investigation even when no payment or financial loss has been established.

Worked example: A purchasing manager selects a business owned by their sibling without disclosure. The relationship creates a conflict requiring examination, but it does not by itself prove a bribe occurred.

Mistake to avoid: Using conflict of interest and bribery as interchangeable conclusions.

Source reference: About the CFE Exam

19. Ponzi and Pyramid Scheme Structures

A Ponzi scheme uses incoming investor money to fund apparent returns to earlier investors rather than genuine investment earnings. A pyramid scheme primarily rewards recruitment of additional participants. Trace the source of payouts and incentives; promotional labels do not establish the economic substance.

Worked example: A promoter receives $50,000 from new investors and uses $8,000 of it for existing investors’ supposed returns. With no supporting investment earnings, the payout fits a Ponzi funding pattern.

Mistake to avoid: Assuming that an early payout proves a venture earns legitimate returns.

Source reference: About the CFE Exam

20. Money Laundering and Economic Substance

Money laundering seeks to obscure the illicit origin or ownership of assets. Placement, layering and integration are useful analytical descriptions, but real cases need not follow a neat sequence. Examine ownership, funding sources and business purpose without treating complexity alone as criminal evidence.

Worked example: An inactive company receives funds, transfers nearly all of them through related entities and records unsupported consulting charges. The unexplained activity warrants tracing and corroboration, not an immediate laundering conclusion.

Mistake to avoid: Assuming that every cross-border transfer or complex company structure is unlawful.

Source reference: About the CFE Exam

Governance and Fraud Controls

21. Independent Governance Oversight

Governance establishes accountability for fraud risk and gives concerns an escalation route beyond the people involved. Oversight is more effective when those reviewing concerns can challenge management, access relevant information and track corrective action. Titles alone do not demonstrate independence or effective supervision.

Worked example: An allegation concerns the finance director. Routing it solely to that director creates a conflict; an appropriately independent oversight function should determine the authorized response.

Mistake to avoid: Assuming that a formal committee automatically provides independent oversight.

Source reference: About the CFE Exam

22. Segregation of Incompatible Duties

Separate authority to approve transactions, custody of assets, recordkeeping and reconciliation where practical. Concentrating these functions lets someone commit and conceal a scheme. When staffing prevents full separation, a genuinely independent review should address the specific combination of risks.

Worked example: One employee creates vendors, releases payments and reconciles the bank account. Assigning payment release and reconciliation to independent people reduces that employee’s ability to divert and conceal funds.

Mistake to avoid: Dividing job titles while leaving the same person with incompatible system permissions.

Source reference: About the CFE Exam

23. Meaningful Authorization Controls

Authorization controls require a reviewer with appropriate authority to assess the transaction’s purpose, supporting evidence and compliance with policy. A signature is useful only if the review is substantive. Examine whether transactions are divided or routed to circumvent the intended approval process.

Worked example: A policy requires additional review above $5,000. Two same-day $3,000 invoices for one purchase suggest possible approval avoidance and should be evaluated together.

Mistake to avoid: Treating approval as effective when reviewers lack the information needed to challenge a transaction.

Source reference: About the CFE Exam

24. Reconciliation and Unresolved Differences

A reconciliation compares independent records and explains differences between them. Its value comes from investigating discrepancies, not forcing totals to match. Review the age, support and subsequent resolution of reconciling items, especially items that recur without a clear business explanation.

Worked example: The ledger shows $38,400 in cash and the bank shows $37,900. A supported $500 deposit in transit explains the difference only if subsequent bank evidence confirms receipt.

Mistake to avoid: Accepting a recurring reconciling item without verifying what caused it.

Source reference: About the CFE Exam

25. Least Privilege and Access Review

Least privilege limits access to what a person needs for current duties. Periodic review should consider actual permissions, privileged accounts and incompatible capabilities. Access logs help investigate activity, but an account identifier alone may not establish who personally performed an action.

Worked example: A former payroll employee retains permission to alter bank details after moving to sales. Removing the unnecessary permission closes an avoidable payment-diversion opportunity.

Mistake to avoid: Assuming that a department transfer automatically updates system access.

Source reference: About the CFE Exam

26. Independent Verification of Master Data

Vendor and employee master data determine where payments go and how transactions are processed. Changes to sensitive fields need authorization and independent verification using trusted contact information. Verification should not rely entirely on the same message that requested the change.

Worked example: An email requests a supplier bank change. Contacting the supplier through an independently established channel reveals that no change was requested, preventing payment to the substituted account.

Mistake to avoid: Using the requester’s newly supplied telephone number to authenticate the requester.

Source reference: About the CFE Exam

27. Matching Orders, Receipts and Invoices

Matching a purchase order, receipt record and invoice tests authorization, delivery and billing consistency. Differences require explanation before payment under the organization’s procedures. Service purchases may need performance evidence rather than a warehouse receipt, and matching cannot defeat collusion among all participants.

Worked example: An order authorizes 70 units at $20, but receiving confirms 60. A $1,400 invoice exceeds the supported delivered quantity by $200 and needs resolution.

Mistake to avoid: Paying a fully matched invoice when the receiving evidence itself is unreliable.

Source reference: About the CFE Exam

28. Custody Controls and Independent Counts

Custody controls restrict access to assets and create accountability for transfers. Independent counts compare actual assets with records at a defined point in time. Document timing and movements during the count so ordinary transfers are not mistaken for shortages or counted twice.

Worked example: A cash record shows $1,250. An authorized independent count finds $1,170, and no supported movement explains the difference. The $80 shortage requires investigation.

Mistake to avoid: Allowing undocumented asset movements during a count and then treating the result as definitive.

Source reference: About the CFE Exam

29. Reporting Channels and Retaliation Risk

Effective reporting channels let people raise concerns through routes appropriate to the circumstances, including alternatives when a supervisor is implicated. Confidential handling, fair triage and protection against retaliation support useful reporting. Anonymous information still requires evaluation and corroboration.

Worked example: A warehouse worker reports unexplained write-offs through an independent channel because the supervisor approves them. Investigators assess the records without disclosing the worker’s identity unnecessarily.

Mistake to avoid: Dismissing an anonymous concern or promising absolute confidentiality that cannot be assured.

Source reference: About the CFE Exam

30. Management, Audit and Fraud Examination Roles

Management operates controls and manages fraud risk. Internal and external audit provide assurance within their respective mandates, while fraud examination investigates specific concerns. The scope and evidence requirements differ. An audit opinion does not establish that every transaction has been examined or that fraud is absent.

Worked example: A financial statement audit finds no material misstatement, but a later allegation identifies repeated small thefts. The allegation can justify a focused investigation despite the audit result.

Mistake to avoid: Treating a clean audit opinion as a guarantee against fraud.

Source reference: About the CFE Exam

Fraud Risk, Response and Professional Ethics

31. Pressure, Opportunity and Rationalization

The fraud triangle organizes possible contributing conditions: pressure, opportunity and rationalization. It helps identify risks and prevention options, but it is not a diagnostic test for guilt. People under financial pressure may act honestly, and investigators may never observe a person’s rationalization.

Worked example: Aggressive sales targets create pressure, weak revenue review creates opportunity, and claims that adjustments are temporary suggest rationalization. Strengthening review addresses opportunity without accusing everyone facing targets.

Mistake to avoid: Inferring fraud from personal debt, stress or an assumed attitude.

Source reference: About the CFE Exam

32. Building Specific Fraud Risk Scenarios

A useful fraud risk assessment describes who could act, what they could do, how it could be concealed and which assets or reports would be affected. Specific scenarios connect risks to controls more effectively than broad labels such as payment fraud or dishonest employees.

Worked example: A payable clerk could redirect vendor payments by changing bank details and conceal the diversion through reconciliation access. This scenario identifies both master-data and independent-review controls.

Mistake to avoid: Listing generic risks without describing a plausible mechanism or concealment route.

Source reference: About the CFE Exam

33. Inherent Risk and Residual Risk

Inherent risk describes exposure before considering controls; residual risk describes exposure after considering their effectiveness. Assess likelihood and impact using a consistent organizational method. A control’s existence does not justify assuming it works, and qualitative risk ratings are not precise probabilities.

Worked example: Payment diversion has substantial inherent exposure. Independently verified bank changes reduce residual risk only if verification occurs consistently and exceptions receive appropriate review.

Mistake to avoid: Subtracting a fixed percentage from risk merely because a written policy exists.

Source reference: About the CFE Exam

34. Control Design Versus Operating Effectiveness

Design asks whether a control could address the identified risk if performed as intended. Operating effectiveness asks whether it actually worked during the period examined. A well-designed control can fail through inconsistent execution, insufficient evidence or an override that bypasses its purpose.

Worked example: Policy requires independent verification of bank changes, but eight sampled changes have no verification evidence. The design addresses diversion; the observed execution does not establish effectiveness.

Mistake to avoid: Using a policy document as proof that a control operated.

Source reference: About the CFE Exam

35. Preventive, Detective and Corrective Controls

Preventive controls seek to stop an event, detective controls identify events or warning signs, and corrective controls address consequences or weaknesses. A fraud program benefits from their combination because prevention can fail and detection has little value without an appropriate response.

Worked example: Restricted vendor editing is preventive, a bank-change exception report is detective, and removing unauthorized access after investigation is corrective. Each addresses a different stage of the risk.

Mistake to avoid: Assuming that a detective report prevents a payment unless someone acts on it in time.

Source reference: About the CFE Exam

36. Monitoring Indicators With Proper Denominators

Fraud monitoring should use measures that remain interpretable as business volume changes. Counts, rates, severity and unresolved exceptions provide different information. More reports may indicate greater willingness to speak up rather than more fraud; fewer alerts may reflect weaker detection.

Worked example: Duplicate-payment alerts rise from 10 among 1,000 payments to 15 among 3,000. The alert rate falls from 1% to 0.5%, despite the higher count.

Mistake to avoid: Comparing raw alert totals without considering transaction volume or changes in detection.

Source reference: About the CFE Exam

37. Proportionate Initial Fraud Response

An initial response should protect relevant records, assess ongoing exposure and assign an authorized, impartial investigation. Actions must respect applicable rights and procedures. Coordinate necessary specialist or legal input before steps that might destroy evidence, alert involved parties or exceed the organization’s authority.

Worked example: A payment-diversion allegation leads to authorized preservation of relevant records and review of pending payments. Investigators avoid unsupported public accusations while establishing facts.

Mistake to avoid: Deleting a suspicious account or broadly seizing personal information before assessing preservation and authority.

Source reference: About the CFE Exam

38. Root Causes and Remediation

Remediation should address the mechanism that enabled the event, not only its immediate outcome. Separate individual conduct from weaknesses in incentives, access, review and escalation. Assign responsibility for corrective actions and verify that the revised control works against the identified scenario.

Worked example: Recovering a diverted $6,000 payment does not fix unrestricted bank-detail changes. Independent verification and access changes address the mechanism; follow-up testing checks implementation.

Mistake to avoid: Closing an issue after recovery while leaving the same concealment opportunity available.

Source reference: About the CFE Exam

39. Objectivity and Conflicts in Examination

An examiner should evaluate evidence impartially, including facts that contradict the initial suspicion. Personal relationships, prior involvement and financial interests can impair objectivity or its appearance. Identify conflicts early and use disclosure, reassignment or other appropriate safeguards.

Worked example: An examiner previously approved the transactions under investigation. Assigning an independent examiner reduces the risk that the review becomes a defense of the earlier approval.

Mistake to avoid: Ignoring contradictory evidence because it weakens a favored explanation.

Source reference: About the CFE Exam

40. Confidentiality and Competence Boundaries

Sensitive information should be accessed and shared only for an authorized purpose with appropriate recipients. Examiners must also recognize the limits of their competence. Specialized accounting, legal or technical questions may require qualified assistance rather than unsupported conclusions presented with certainty.

Worked example: A ledger review uncovers potentially privileged communications and encrypted files. The examiner seeks appropriate legal and technical guidance instead of circulating the material or claiming unsupported technical findings.

Mistake to avoid: Treating access to information as permission to disclose it or as proof of specialist competence.

Source reference: About the CFE Exam

Evidence and Accounting Data Analysis

41. Turning Allegations Into Testable Hypotheses

An allegation is a starting claim, not an established fact. Convert it into testable propositions and identify competing explanations. For each proposition, specify records or observations that could support or weaken it, then revise the investigation as evidence develops.

Worked example: A tip alleges inflated overtime. Investigators compare approved hours, work schedules and access records, while considering whether legitimate off-site work explains apparent differences.

Mistake to avoid: Searching only for confirmation and treating the original allegation as the conclusion.

Source reference: About the CFE Exam

42. Defining an Investigation’s Scope and Authority

An investigation plan defines the issues, relevant periods, information needed, responsibilities and authorized access. Scope should expand when evidence justifies it rather than through indiscriminate collection. Document significant changes and consider employee rights, privacy and applicable legal restrictions throughout.

Worked example: A March expense concern initially requires March claims and payment records. Evidence of repeated January claims supports an authorized extension to earlier periods, rather than unrestricted collection of unrelated personal files.

Mistake to avoid: Assuming that a business concern authorizes access to every available account or device.

Source reference: About the CFE Exam

43. Relevance, Reliability and Evidence Sufficiency

Relevant evidence bears on the issue being examined; reliable evidence has a trustworthy origin and dependable content. Sufficiency concerns whether the body of evidence supports the conclusion. Numerous copies of one unverified claim do not provide the same support as independent corroboration.

Worked example: Five forwarded emails repeat one rumor about a vendor. A receiving record, payment confirmation and independently obtained supplier response provide different, potentially corroborating evidence.

Mistake to avoid: Counting documents without assessing their independence, source or connection to the issue.

Source reference: About the CFE Exam

44. Chain of Custody and Evidence Handling

Chain-of-custody records document evidence identification, possession, transfers and handling. Their purpose is to help explain what happened to an item and whether its integrity was maintained. Good documentation does not automatically establish authenticity or admissibility under every legal system.

Worked example: An authorized collector records a device identifier, collection time, storage location and each transfer. A later reviewer can reconstruct who handled the device and when.

Mistake to avoid: Leaving unexplained custody gaps or assuming a custody log guarantees legal admissibility.

Source reference: About the CFE Exam

45. Preserved Originals, Working Copies and Hashes

Where appropriate, preserve original evidence and analyze controlled copies using suitable procedures. A cryptographic hash helps detect whether digital content has changed between documented points. Matching hashes do not prove that a file was truthful, complete or authentic before collection.

Worked example: A preserved export and its working copy have matching hashes. This supports content consistency between them, but does not prove that the original system contained every relevant transaction.

Mistake to avoid: Describing a matching hash as proof that the underlying business records are accurate.

Source reference: About the CFE Exam

46. Metadata and Timestamp Interpretation

Metadata can describe file creation, modification, authorship or system activity, but its meaning depends on the application and environment. Time zones, copying, clock differences and editable fields can complicate interpretation. Corroborate a timeline with independent records before assigning actions to a person.

Worked example: An invoice file has a later creation timestamp than its printed date. The difference could reflect copying or regeneration, so investigators compare system logs and transaction history before concluding it was fabricated.

Mistake to avoid: Treating a timestamp or author field as conclusive evidence of personal authorship.

Source reference: About the CFE Exam

47. Authorized and Purposeful Data Collection

Collect data under appropriate authority and limit collection to what the investigation reasonably needs. Relevant financial records can include sensitive information about uninvolved people. Document the source and collection boundaries, and apply suitable access and retention controls without assuming universal legal permissions.

Worked example: To examine duplicate reimbursements, an authorized export includes claim identifiers, dates, amounts and payment references. Unrelated medical details are excluded because they do not answer the investigative question.

Mistake to avoid: Collecting all available personal data merely because storage is inexpensive.

Source reference: About the CFE Exam

48. Join Logic and Duplicate Amplification

Data joins must match the relationship between tables. Joining a payment to several invoice lines can repeat the payment amount and inflate totals. Check key uniqueness, unmatched records and row counts before interpreting combined data, especially when relationships are one-to-many.

Worked example: One $900 payment joins to three invoice lines. Summing the repeated payment field produces $2,700; summing each payment once gives the correct $900.

Mistake to avoid: Assuming a larger joined dataset contains more money rather than repeated representations of the same transaction.

Source reference: About the CFE Exam

49. Data Completeness and Control Totals

An analysis can be internally correct yet incomplete because records were omitted, filtered or truncated. Reconcile row counts and monetary totals to an appropriate independent source. Understand date fields, canceled entries and extraction criteria before concluding that an export represents the full population.

Worked example: The ledger records $420,000 of payments, but an export totals $405,000. Investigators identify an excluded payment batch of $15,000 before relying on the analysis.

Mistake to avoid: Treating a successfully opened file as proof that every relevant record was extracted.

Source reference: About the CFE Exam

50. Duplicate Detection and False Positives

Duplicate tests compare selected fields to identify transactions needing review. Exact matches can miss altered invoice references, while broad matches can flag legitimate recurring charges. Resolve alerts using underlying documents, payment status and transaction relationships rather than classifying matches automatically as losses.

Worked example: Two $480 invoices from one landlord have different monthly service periods. The matching supplier and amount generate an alert, but the documents resolve it as legitimate recurring rent.

Mistake to avoid: Adding every duplicate alert to the fraud-loss total.

Source reference: About the CFE Exam

51. Outliers, Trends and Appropriate Comparisons

Outlier analysis identifies observations unlike a suitable comparison group. The choice of group matters: job role, season, location and transaction type can explain variation. An unusual observation becomes an investigative lead; supporting evidence determines whether it reflects error, legitimate activity or fraud.

Worked example: A salesperson’s travel cost is twice the office average but consistent with other international sales staff. Comparing similar roles avoids an unsupported inference from the office-wide average.

Mistake to avoid: Using an arbitrary cutoff or an unsuitable peer group as proof of misconduct.

Source reference: About the CFE Exam

52. Loss Quantification Without Double Counting

Define what a loss figure measures and separate confirmed amounts, estimates and recoveries. Trace transactions so the same economic loss is not counted through both a payment and its related accounting entry. Any extrapolation requires a justified method and explicit limitations.

Worked example: Confirmed improper payments total $12,000, with $3,000 recovered. Report $12,000 gross confirmed loss and $9,000 unrecovered, rather than counting both figures as separate losses.

Mistake to avoid: Mixing gross loss, outstanding recovery and speculative exposure into one unexplained total.

Source reference: About the CFE Exam

Interviews, Reporting and Legal Understanding

53. Open Questions Followed by Focused Clarification

Open questions invite an interviewee to describe events in their own terms. Focused questions then clarify dates, responsibilities and documents. Neutral wording reduces the risk of supplying an answer. Interview methods must remain appropriate to the person’s rights and the investigation’s authorized purpose.

Worked example: The interviewer asks, “How were vendor changes processed?” before asking who approved a particular change. The sequence establishes the usual process before exploring the exception.

Mistake to avoid: Beginning with a leading accusation that embeds unverified facts in the question.

Source reference: About the CFE Exam

54. Personal Knowledge, Hearsay and Chronology

Distinguish what a person directly observed from what they inferred or learned from someone else. Build a chronology with identifiable events and records, allowing uncertainty where memory is incomplete. A witness’s confidence does not automatically establish the accuracy or source of their recollection.

Worked example: A clerk says a manager altered an invoice, then explains that a colleague told them. The statement identifies another lead; it is not the clerk’s direct observation.

Mistake to avoid: Recording secondhand information as though the interviewee personally witnessed the event.

Source reference: About the CFE Exam

55. Resolving Inconsistencies Through Corroboration

An inconsistency warrants clarification and comparison with independent evidence. Memory errors, ambiguous questions and differing perspectives can produce conflicting accounts. Document the discrepancy fairly, seek an explanation and distinguish unresolved differences from demonstrated false statements.

Worked example: An employee recalls approval on Tuesday, while an email records Wednesday. The interviewer asks about the sequence and checks whether Tuesday involved an oral discussion before written approval.

Mistake to avoid: Inferring deception from nervousness, poor eye contact or one inconsistent detail.

Source reference: About the CFE Exam

56. Reports That Separate Facts and Inferences

An investigation report should connect findings to evidence and explain material limitations. Separate documented facts, witness statements, analytical inferences and unresolved issues. Describe methods and amounts clearly enough that a reader can understand the basis of the conclusion without overstating what was established.

Worked example: A report states that $2,400 reached an account, that a witness attributed it to an employee, and that ownership remains unverified. These are distinct evidential positions.

Mistake to avoid: Presenting a suspected explanation as an established fact or omitting contrary evidence.

Source reference: About the CFE Exam

57. Common Law and Civil Law Traditions

Common law and civil law describe broad legal traditions, with different emphases on precedent and codified rules. Actual jurisdictions can combine features, and procedures vary. Use the distinction as orientation rather than a substitute for checking the applicable law and obtaining appropriate legal guidance.

Worked example: An examiner receives a cross-border assignment. Familiarity with one country’s precedent-based procedures does not establish how evidence collection is authorized in the other country.

Mistake to avoid: Assuming that one legal tradition creates identical investigation rules across all its jurisdictions.

Source reference: About the CFE Exam

58. Criminal, Civil and Administrative Proceedings

Criminal proceedings address alleged offenses; civil proceedings generally address private claims and remedies; administrative proceedings concern regulatory or organizational authority. The same conduct may generate several processes. Applicable elements, evidential standards and available remedies depend on the jurisdiction and proceeding.

Worked example: A diverted payment may prompt an internal disciplinary process, a civil recovery claim and a criminal referral. Evidence supporting one process does not automatically satisfy the requirements of another.

Mistake to avoid: Applying one proceeding’s evidential standard or outcome to every related process.

Source reference: About the CFE Exam

59. Employee Rights, Recording and Privilege

Interviewing, recording, searching devices and handling potentially privileged material require attention to applicable rights and law. Consent, employment policies and investigative authority have limits that vary by setting. Identify these issues before acting and seek appropriate legal advice where requirements are uncertain.

Worked example: Before recording an employee interview, the team confirms the applicable authorization and consent requirements. It also establishes a process for referring potentially privileged material for legal assessment.

Mistake to avoid: Assuming that employer ownership of equipment permits every search, recording or disclosure.

Source reference: About the CFE Exam

60. Fact Testimony and Expert Opinion

Fact testimony concerns observations and actions; expert opinion applies specialized knowledge within an appropriate scope. An examiner should explain the data, methods, assumptions and limitations behind an opinion. Qualification and admissibility requirements vary, and expertise does not authorize unsupported conclusions about legal guilt.

Worked example: An examiner describes tracing $14,000 through payment records, then explains a loss calculation. Whether the conduct satisfies a criminal offense remains a separate legal determination.

Mistake to avoid: Presenting professional confidence as a substitute for a transparent method and supporting evidence.

Source reference: About the CFE Exam

Sources

Credential identity and exam scope:

Browse all study guides

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for CFE Exam (Certified Forensic Examiner) - Accounting focus Free Practice Test.

How does the accounting focus fit the CFE Exam?
Accounting helps explain transaction flows, financial statement manipulation and loss calculations. The ACFE CFE Exam also covers other fraud schemes, investigations, legal issues, prevention and ethics. This guide connects accounting foundations with all three exam sections.
Does an unusual transaction or ratio establish fraud?
No. An anomaly identifies something to examine. Establish what occurred, assess legitimate explanations, corroborate evidence and distinguish an error from intentional deception. Several alerts can also refer to the same transaction, so avoid counting them as separate losses.
Which legal rules should I apply to an investigation scenario?
Identify the jurisdiction, proceeding, source of authority and rights involved before applying a rule. Evidence collection, recording, privilege and testimony requirements can differ. The exam’s broad legal coverage does not confer investigative powers; confirm applicable requirements and obtain appropriate legal guidance for actual work.
How should I distinguish a control weakness from a proven loss?
A weakness describes exposure, such as unrestricted payment access. A proven loss requires supported transactions and a defensible calculation. Report weaknesses, suspicious transactions, confirmed losses and recoveries separately so the evidence does not appear stronger than it is.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.