Responding to Financial Irregularities Without Prejudging the Outcome

A disciplined response protects evidence, preserves objectivity, and supports proportionate action.

Crowe AHFAD | Audit Department
5/1/2026
Responding to Financial Red Flags

Warning signs require prompt examination, but conclusions must remain grounded in evidence.

An unexplained payment, unusual journal entry, inventory shortage, unsupported supplier, or unexplained variance may justify further examination. It does not, by itself, establish that fraud or misconduct has occurred.

Organizations must respond to warning signs promptly, but also objectively. Premature conclusions may damage individuals, compromise evidence, expose the organization to legal risk, and weaken the credibility of any subsequent examination.

Secure the Evidence First

5 top healthcare risks for higher education institutions in 2023

The immediate priority should be to preserve relevant information and prevent further loss or alteration.

Depending on the matter, this may include accounting records, emails, system logs, contracts, approvals, procurement documents, payment evidence, access histories, physical records, and relevant devices.

Access to the information should be controlled, and the steps taken to secure it should be documented. Where appropriate, management should consider whether individuals connected to the matter retain the ability to amend records or destroy evidence.

The response should also observe applicable legal, employment, confidentiality, and data protection requirements.

Define the Concern, Not the Conclusion

A specialized audit or investigation should begin with a clearly stated concern rather than an assumption of guilt.

The scope may focus on identified transactions, particular accounts, a defined period, specific suppliers, procurement activity, payroll records, inventory differences, unauthorized payments, or possible management override.

The terms of reference should identify the purpose, intended users, reporting line, confidentiality arrangements, access rights, and whether legal, technology, valuation, or other specialists may be required.

Scope discipline is essential. An engagement that expands without documented authorization can create uncertainty over responsibilities, cost, evidence, and reporting.

Understand the Auditor’s Role

Management and those charged with governance are responsible for preventing and detecting fraud through ethical culture, risk management, internal control, and appropriate oversight.

In a financial statement audit, the auditor seeks reasonable assurance that the financial statements as a whole are free from material misstatement due to fraud or error. This does not constitute a guarantee that every instance of fraud will be detected.

ISA 240 (Revised), issued by the IAASB in 2025 and effective for periods beginning on or after 15 December 2026, strengthens auditor responsibilities and transparency concerning fraud in financial statement audits.

Address the Control Environment

Even where misconduct is not established, the examination may identify conditions that made the concern possible.

These may include unrestricted access, weak supplier onboarding, inadequate segregation of duties, missing reconciliations, informal approvals, ineffective inventory controls, or management override without review.

Corrective action should therefore address both the specific matter and the underlying control weakness.

Report Only What the Evidence Supports

Reporting should distinguish among confirmed facts, inconsistencies, unsupported items, explanations received, evidence limitations, and matters requiring further action.

Terms such as fraud, theft, or misappropriation should not be used as legal conclusions unless their use is sufficiently supported and professionally appropriate.

A disciplined response protects the organization by establishing facts, preserving objectivity, and enabling management and governance bodies to act on reliable information rather than assumption.