By Thomas W. Raftery III
Raftery served 22 years as an FBI Special Agent and was the first appointed Inspector General for the Delaware River Port Authority. He is a Certified Fraud Examiner and holds an MBA with a concentration in accounting.
Internal audit and forensic accounting look similar on an org chart. In practice they answer different questions, follow different standards of proof, and often cannot be performed by the same team without compromising one or the other. Knowing which one a situation calls for, and when to escalate from one to the other, is the decision that determines whether a company preserves its options or loses them.
According to the ACFE's Occupational Fraud 2026: A Report to the Nations, the typical organization loses 5% of annual revenue to fraud, and the typical scheme runs for 12 months before anyone catches it. Schemes caught within six months carry a median loss of $40,000. Schemes that run five years or more carry a median loss above $1.1 million. The gap between those two numbers is, in large part, a story about which team was looking, and how.
What Is the Difference Between Internal Audit and Forensic Accounting?
Internal audit tests whether controls are operating as designed. Forensic accounting determines whether fraud occurred and builds a record that can withstand scrutiny outside the company. Both examine financial records. They start from different assumptions, apply different standards of proof, and produce work product built for different audiences.
That difference is not a matter of seniority or budget. It drives scope, methodology, documentation standards, and who is even permitted to know an engagement is underway.
What Internal Audit Is Built to Do
Internal audit exists to test whether controls are operating as designed. It is scheduled, cyclical, and disclosed in advance. The audit plan tells the business unit what is coming and roughly when. That transparency is a feature, not a flaw. It is what makes audit effective at catching control weaknesses, process drift, and unintentional errors before they compound.
The IIA's Global Internal Audit Standards, which took effect in January 2025, frame internal audit as an independent, objective assurance and consulting activity that evaluates and improves governance, risk management, and control processes. Assurance is the operative word. The function is designed to give the board and management a defensible answer to the question of whether the control environment is working.
Nothing in that mandate is oriented toward proving intent, preserving evidence, or preparing for an adversarial proceeding, because it was never meant to be.
What Forensic Accounting Is Built to Do
Forensic accounting exists to answer a narrower and more adversarial question: did someone commit fraud, and can it be proven? A forensic engagement assumes the possibility of concealment, deception, and an adversary who will actively work against discovery. It is built for a hearing, a regulator, or a courtroom from the first day of work, not just a management letter.
The practical consequence is that a forensic accountant works backward from the eventual audience. If a damages figure may end up in an expert report, it has to be built on a methodology that survives challenge under Federal Rule of Evidence 702. If an interview may be quoted in a deposition, it has to be conducted and documented accordingly. Those constraints shape the work from the first hour, and they cannot be applied retroactively.
Where the Two Overlap, and Why That Causes Problems
The two disciplines produce overlapping output even though they start from different intent. A forensic engagement will almost always turn up control weaknesses along the way: the approval that was never actually enforced, the reconciliation nobody reviewed. But that is a byproduct, not the objective. Internal audit sets out to test controls. Forensic accounting sets out to determine whether fraud occurred and prove it, and the control gaps it finds are simply how the scheme got room to operate.
Confusing the two leads a company to treat a forensic finding as a control remediation item and close it out with a policy update, when what it actually needed was an investigation. This is the same failure mode that shows up in regulated environments, where AML programs rarely fail on paper and routinely fail in execution. A documented remediation is not the same as a resolved question.
When Should You Call a Forensic Accountant?

Call a forensic accountant the moment the question shifts from whether a control failed to whether someone acted deliberately. Internal audit teams are good at identifying that something is wrong. They are frequently not equipped, by mandate, by training, or by proximity to the people involved, to determine who did it and whether the answer will hold up outside the building.
Three signals tend to mark that boundary. Any one of them is enough.
Signal One: The Findings Suggest Intent, Not Error
A control gap is an audit finding. A pattern of transactions structured to stay just under an approval threshold, or documentation that was altered after the fact, is not a control gap. It is evidence, and it needs to be handled like evidence from the moment it is found.
The distinction is behavioral rather than technical. Errors are usually random in direction and distributed across people and periods. Deliberate conduct tends to be directional, repetitive, and concentrated around a single actor or a single vendor relationship. When a finding starts to look designed rather than accidental, the correct next step is to stop testing and start preserving.
Signal Two: The Evidence Has to Survive Outside the Company
If a finding might end up in front of a regulator, an insurer, opposing counsel, or a jury, it needs a defensible chain of custody, contemporaneous documentation, and a methodology built to withstand cross examination. Most internal audit workpapers were never built for that purpose, and retrofitting them later is far harder than doing it right from the start.
This is also where the eventual expert retention gets decided, whether anyone realizes it at the time. Counsel evaluating expert witness credibility in a white collar fraud case will look at how the underlying work was performed, not just at the credentials of the person presenting it. Weak field work cannot be rescued by a strong CV.
Signal Three: The Subject Has Access to the People or Files Doing the Review
If the person under suspicion supervises, works alongside, or has systems access to the audit team, that team's independence, real or perceived, is compromised the moment the engagement starts. This is less about competence and more about admissibility and optics later.
Systems access is the version most often overlooked. An internal auditor pulling records from an ERP the subject administers is generating evidence the subject can see being generated, and in some configurations can alter. The question a regulator will ask is not whether the auditor was honest. It is whether the record could have been influenced, and whether anyone can prove it was not.
How Is Occupational Fraud Actually Detected?
Tips detect 43% of occupational fraud, internal audit detects 15%, and management review detects 13%, according to the ACFE's 2026 Report to the Nations. Tips have been the leading detection method in every edition of the study since 1996, and they account for nearly three times as many cases as the second ranked method.
More than half of those tips come from employees. That finding, repeated across 14 editions and more than 20,000 cases, is the strongest available evidence that testing regimes are not the mechanism that surfaces deliberate misconduct. The teams built to find fraud through testing are, empirically, not the teams that usually find it.
None of this is an argument against internal audit. It is an argument about sequencing. Internal audit and management review together account for a substantial share of detections, and control testing narrows the space in which a scheme can operate. What the data does not support is the assumption that a functioning audit program makes a forensic capability unnecessary.
What Detection Delay Actually Costs
The ACFE's 2026 findings put a number on the delay. The median loss across 2,402 cases studied was $104,000, and the average loss exceeded $1.4 million. A typical case ran 12 months before detection, and 20% of cases produced losses over $1 million.
The duration curve is the part worth showing a board. Schemes caught within six months carry a median loss of $40,000. Schemes running five years or more carry a median loss above $1.1 million. Organizations with no reporting mechanism took roughly 17 months to detect the same conduct and absorbed materially higher losses than those with one.
Every month of delay has a price attached to it, and the delay that matters most is usually not the months before anyone noticed. It is the weeks after someone noticed and the matter sat with a team that was not equipped to resolve it.
What Does a Forensic Accounting Engagement Include?

A forensic accounting engagement is built around the possibility that the matter ends up outside the company, and every step reflects that. Four elements distinguish it from an audit procedure applied to the same records.
- Chain of custody for financial records, communications, and physical evidence, documented from first contact rather than reconstructed after the fact. That includes imaging rather than browsing, logged transfers, and a written record of who handled what and when.
- Interview protocols designed to preserve admissibility, generally led by someone independent of the reporting line in question. Sequence matters as much as content, and the order in which people are approached is itself an investigative decision.
- Quantification of loss built to survive challenge. The difference between a rough sense that roughly $400,000 walked out the door and a damages figure a CFE or CPA can defend under cross examination is methodology, documentation, and a stated basis for every assumption.
- Coordination with counsel from the outset, so the engagement can be structured under attorney client privilege where appropriate, rather than trying to retrofit privilege onto findings that already exist in an audit file. Work performed at the direction of counsel and work performed as routine business operations are treated very differently later.
None of this makes internal audit obsolete. It makes internal audit the mechanism that surfaces the anomaly, and forensic accounting the mechanism that determines what the anomaly actually means and what can be done about it.
Can Your Internal Audit Team Investigate Fraud Itself?
Sometimes, but the answer depends on mandate, training, and distance from the subject rather than on capability. Many internal audit functions include Certified Fraud Examiners and are entirely competent to run a fraud investigation on the technical merits.
The constraints are structural. Internal audit reports through a chain that may include the subject or the subject's supervisor. Its charter may not authorize investigative interviews. Its workpapers are ordinary business records and are generally discoverable. And its independence is judged after the fact by people who were not in the room.
The workable pattern for most organizations is a defined trigger, agreed in advance, that moves a matter from audit to investigation. The trigger should name who makes the call, who counsel is, and what happens to the work already performed. Building that pathway during a live matter is how good-faith teams create problems for themselves. It belongs in the same category as the financial controls discipline that runs through a functioning FCPA compliance program: decided in advance, documented, and consistently applied.
What Waiting Actually Costs
The cost of waiting is not primarily measured in additional fraud losses, though those accrue. It is measured in options that quietly close.
Privilege is the first. Findings generated as routine business operations before counsel is engaged generally cannot be swept under privilege afterward. Preservation is the second. Once a company reasonably anticipates litigation, the duty to preserve electronically stored information attaches, and Federal Rule of Civil Procedure 37(e) sets out what a court may do when that information is lost because reasonable steps were not taken. Routine deletion policies that were entirely defensible last quarter become a problem the moment they run past that line.
Third is the record itself. Workpapers, emails, and interview notes generated in good faith by a well-meaning internal team become documents the company later has to explain, or defend, to a judge, a regulator, or a board. None of them were written with that reader in mind.
A Practical Rule of Thumb
If the question is whether controls are working, that is internal audit's job, on its normal cycle. If the question becomes whether someone did this on purpose and what happens now, the moment that question is asked out loud is the moment to bring in a forensic accountant. Not after the internal team has already spent three weeks trying to answer it themselves.
A useful test for the person who has to make the call: if this matter were described in a deposition two years from now, would the first three weeks of work look like a careful investigation or like a company deciding what it wanted to find? The honest answer is usually available immediately.
What is the difference between a forensic accountant and an internal auditor?
An internal auditor tests whether controls are operating as designed, works on a disclosed schedule, and reports to management and the audit committee. A forensic accountant determines whether fraud occurred, assumes active concealment, and builds a documented record intended to withstand review by a regulator, an insurer, opposing counsel, or a court. Both examine financial records. Only one is built for an adversarial audience.
Can internal audit investigate fraud?
It can, and many internal audit teams include Certified Fraud Examiners. The limits are usually structural rather than technical: the reporting line may include the subject, the audit charter may not authorize investigative interviews, workpapers are ordinary business records, and independence is judged after the fact. Where any of those apply, a forensic engagement independent of the reporting line is the safer route.
When should a company call a forensic accountant?
When findings suggest intent rather than error, when evidence may have to survive outside the company, or when the subject of the review has access to the people or files conducting it. Any one of the three is sufficient. The trigger is the nature of the question, not the size of the suspected loss.
What does a forensic accounting engagement cost compared with an internal audit?
A forensic engagement costs more per hour and more in total, because chain of custody, independent interviews, defensible loss quantification, and coordination with counsel all take time that audit procedures do not. The comparison that matters is not forensic accounting against internal audit. It is the cost of the engagement against the cost of a scheme that keeps running and a record that cannot be defended later.
How is most occupational fraud detected?
By tips. The ACFE 2026 Report to the Nations found that 43% of cases were first detected by a tip, compared with 15% by internal audit and 13% by management review. More than half of tips came from employees, and tips have led every edition of the study since 1996.
Does calling a forensic accountant mean the company is admitting fraud occurred?
No. A forensic engagement is a fact-finding exercise, and a substantial share of them conclude that no fraud occurred. Documenting that conclusion through an independent process is itself valuable, particularly where an accusation has been made internally or an insurer, lender, or regulator may later ask what the company did about it.
The Bottom Line
The decision between internal audit and forensic accounting is not about which team is better. It is about which question is on the table.
Controls testing answers whether the system is working. Forensic accounting answers whether someone worked the system, and produces an answer that holds up when someone outside the company asks how it was reached. Companies that keep those two straight preserve their options. Companies that blur them usually discover the difference at the worst possible moment.
Key Takeaways

- The handoff point is intent. Once findings look designed rather than accidental, stop testing and start preserving.
- Independence is assessed after the fact by people who were not in the room. If the subject supervises, works alongside, or administers systems used by the reviewers, the engagement is already compromised.
- Tips detect 43% of occupational fraud and internal audit detects 15%. A functioning audit program does not substitute for a forensic capability.
- Detection speed is the single largest driver of loss. Six months carries a median loss of $40,000; five years or more carries a median above $1.1 million.
- Privilege and preservation obligations attach on their own timeline. Neither can be applied retroactively to work already sitting in an audit file.
- Define the escalation trigger before a live matter arrives. Who makes the call, who counsel is, and what happens to the work already performed.
Talk to Falcon Consulting Group
Falcon Consulting Group conducts forensic accounting engagements, internal fraud investigations, and loss quantification for organizations that need findings to hold up outside the building.
Our investigative and advisory services are delivered by former federal and state law enforcement personnel, certified fraud examiners, and accountants who have worked these matters from both the investigative and the corporate side. Where a matter is likely to reach litigation, we structure the engagement with counsel from the outset rather than after the fact.
If you are weighing whether a finding has crossed the line from control gap to investigation, contact us before your internal team spends another three weeks on it.
About the Author
Thomas W. Raftery III served 22 years as a Special Agent with the Federal Bureau of Investigation and was the first appointed Inspector General for the Delaware River Port Authority. He deployed to Afghanistan with the Special Inspector General for Afghanistan Reconstruction. He is a Certified Fraud Examiner and holds an MBA from Drexel University with a concentration in accounting. Learn more about the Falcon team.
