Digital Forensic Investigations - Demystified for Accountants
An accountant’s knowledge is often put to test when it comes to addressing aspects related to fraud and more specifically related to frauds perpetrated using sophisticated digital techniques. Within the prevailing legal and regulatory framework, it is imperative to substantiate the occurrence of fraud with robust evidence before establishing the guilt of an accused perpetrator.
Background
At times, the sheer complexity of the fraud may need delving deep and resorting to reliance on corroborative (or often considered at times the most clinching!) evidence extracted from electronic data (Electronically Stored Information / ESI). Have you heard of the term ‘smoking gun’? While smoking is undoubtedly harmful for health, this ‘smoking gun’ does not come with those challenges. In the context of an investigation, a ‘smoking gun’ is often referred to as the singular piece of evidence that helps conclusively (or substantively) to prove the guilt of the fraudster. It is often that one email, one phone SMS or one document leads the fraudster to be proven guilty.
With the advancement in technologies, digital forensic (or digital investigations or electronic data review or electronically stored information review) have surfaced as a key element in any investigation.
Why is this necessary? What advantages does electronic evidence provide in a fraud investigation? Can one perform an investigation without considering electronic evidence? Will an investigation indeed be reliable and complete without performing digital forensic procedures? How complex and time consuming is it? And finally, is it worth the investment of time, effort, and money?
If thoughts like these have crossed your mind earlier and piqued your curiosity, this article will hopefully clarify a few of these pertinent questions and also encourage you to learn more.
It is difficult to comprehensively cover a field, as vast as this, in one article and hence, the article will not make an attempt to masquerade itself as a primer on digital forensics investigation. However, when encountered with any fraud investigation, in your capacity as either management or those charged with governance (TCWG), if any of the concepts discussed in this article will cause you to pause and pose a healthy challenge to your external consultants, have a better understanding of the forensics work and foster rethinking of the approach, then the purpose would have been met. It is also worthwhile to add that the Forensic Accounting Investigation Standards (FAIS) issued by the ICAI are an excellent source of material for accountants to understand the different methodologies deployed by Digital Forensic investigators (DFI). Some of the topics discussed here will also help you have a wider appreciation of FAIS. Welcome to the enigmatic and ever evolving world of ‘digital forensic investigations’!
Foundational Concepts: A Refresher
This article assumes that we as accountants are already familiar with the concepts of ‘fraud’, ‘investigation’ etc. and hence we will not labour too much on these areas. However, for the benefit of those who would prefer a short refresher, explanation to Section 447 of the Companies Act defines fraud as below:
‘Fraud’ in relation to affairs of a company or anybody corporate, includes any act, omission, concealment of any fact or abuse of position committed by any person or any other person with the connivance in any manner, with intent to deceive, to gain undue advantage from, or to injure the interests of, the company or its shareholders or its creditors or any other person, whether or not there is any wrongful gain or wrongful loss.
What is an Investigation?
There is no shying away from ensuring that all allegations of fraud are properly investigated and either confirmed or dispelled. An investigation is a fact-finding exercise performed by professionals that have adequate competence and experience in order to objectively and comprehensively perform suitable procedures to come to a conclusion whether the allegations have any merit.
What is Digital Forensic Investigation?
Digital forensic investigation has many synonyms such as digital forensics, electronic data review, electronic discovery review, forensic technology review etc.
Digital Evidence (DE) refers to data or information that is acquired, stored, accessed, examined, transmitted, and used in electronic form1. DE can be either in ‘structured data’ format or ‘unstructured data’ format. Structured data is the one that can be stored in financial/operational data systems such as ERPs, databases, spreadsheets, etc. Unstructured data is generally in the nature of emails, chat messages, images, videos, log files, etc.
For the purposes of this article, we will focus on DE in ‘unstructured data’ format as that is generally perceived to be more technically challenging to acquire and analyze and hence we will see how to demystify digital forensic investigation in the context of an investigation of ‘unstructured data’.
In simplistic terms, a focused review of digital evidence as part of any fraud investigation can be referred to as a digital forensic investigation.
One can draw various analogies between a digital forensic investigation and a non-digital investigation. In the physical world, the evidence is likely to be available at the crime scene, and in the digital world, this is available in the electronic device. In the physical world, there may be cabinets that may have relevant files and in a digital world, these will be stored on a hard drive. In the physical world, a thief may use burglar tools or weapons whereas, in the digital world a fraudster may use hacking tools etc.2
Given the proliferation of electronic devices, it is difficult nowadays to isolate one from the other and both are so intricately intertwined that it is difficult to draw a clear line. Gone are the days when one could be comfortable justifying that an investigation is completed in all aspects without performing some digital forensic investigation procedures.
Practical Case Illustration: Procurement Collusion
A whistleblower complaint was received by an organization that one of their employees in the procurement team was colluding with vendors, favoring them by approving higher rates, accepting kickbacks from the vendor in return, and in some cases approving fictitious vendors which were alleged to be owned by the employee himself. A digital forensic investigation assisted the organization in finding evidence from the employee’s computer hard drive that the employee had created fictitious quotations and invoices with fake vendor letterhead in a Word document. Analysis of the employee’s mobile phone data (to the extent permissible under law) also revealed that the employee had ‘negotiated’ kickbacks with a few alleged vendors. Analysis of the employee’s bank statements stored in his official laptop (to the extent permissible under law) also revealed unexplained sums of cash deposited to the employee’s personal bank account.
Steps to Perform a Digital Forensic Investigation
In any field of work, the existence of a standard methodology or guidance always helps practitioners to ensure consistency. To cite an example closer to home, Indian Accounting Standards or Standards on Auditing are professional standards familiar to accountants. When it comes to digital forensics, the framework released by the National Institute of Standards and Technology, USA (‘NIST’) suggests four primary stages:
- Data gathering and collection: Accumulation of relevant data and preserving it for investigation purposes.
- Examination: Using specialized tools to process the data so that it is fit for investigation.
- Analysis: Bringing together the context of the investigation and using digital tools to uncover information from the processed data.
- Reporting: Presenting factual findings in a comprehensive, defensible manner.
Following this framework ensures that: (i) original data is protected from unintended modification; (ii) a pristine forensic copy is created; (iii) attempts are made to recover deleted data; (iv) specialized tools are deployed; and (v) all findings are compiled into an objective report.
Data Gathering & Collection Methodology
When embarking on an investigation, it is prudent to strike a balance between expected costs and potential benefits. An organization must consult with its DFI to arrive at an optimum combination of ‘likely suspects’ and ‘good to have data’.
Data Retention vs. Preservation: Many organizations enforce stringent data retention policies where emails and electronic logs are purged after a few months or years. When faced with an investigation spanning prolonged periods, constrained retention policies often become the ‘Achilles heel’. Preservation serves as a risk mitigation exercise against the efflux of time, ensuring critical evidence is not overwritten by incoming data.
Custodians and Legal Hold
A custodian is an individual within the span of the investigation whose data is targeted for acquisition. Scoping of custodians is carried out iteratively as new leads emerge.
A legal hold is a formal notice issued to individuals prohibiting the deletion of data, accompanied by administrative locks in backend IT systems to preserve electronically stored information (ESI).
Evidential Integrity and Continuity
Evidential Integrity: Mandates that the original evidence must never be tampered with. Under Locard’s Exchange Principle (‘every contact leaves a trace’), any collection activity can leave an imprint. DFIs utilize hardware and software write-blockers to access source media in ‘read-only’ mode. Furthermore, MD5/SHA cryptographic hash matching is employed to mathematically prove that the forensic clone is an exact match to the source evidence.
Evidential Continuity & Chain of Custody: Establishes a documented, unbroken trail demonstrating how evidence moved through various custody hands, capturing device details, dates, times, handlers, and operating states to withstand court scrutiny.
Examination, Analysis & Investigation Funnel
Forensic examination is not a simple ‘copy-paste’ or an MS Excel exercise. Specialized tools enable the recovery of deleted records and parsing of operating system artefacts (e.g., LNK shortcut files, prefetch files, USB connection logs, browser histories, internet cache, and social media communication).
The Digital Investigation Funnel
Anti-Forensics: Detecting Concealment and Deception
Anti-forensics refers to deliberate techniques used by fraudsters to erase traces, obfuscate trails, or wipe digital footprints. Specialized DFIs analyze artifacts to establish that an accused knowingly attempted to destroy evidence.
Practical Case Illustration: Anti-Forensic Tracking
In one investigation, the DFI created a forensic image of a custodian’s laptop and recovered deleted data. Analysis of internet search histories revealed queries for ‘file wiping software’. The download history confirmed the software was downloaded, shortcut analysis verified the tool was executed, and uninstalled software logs showed the utility was deleted immediately thereafter. This established clear corroborative evidence of intentional concealment.
Governance Checklist for Accountants and Auditors
Although DFIs execute the technical steps, the organization and those charged with governance (TCWG) remain accountable for ensuring that the investigation is conducted robustly and is legally defensible in court. The following checklist outlines key oversight questions:
1. DFI Team Competence & Credentials
- Does the investigation team have proven experience and credentials in conducting digital forensic examinations?
- Is the team deploying an appropriate combination of industry-standard hardware and software tools?
- Are open-source digital tools verified, peer-reviewed, and capable of withstanding the ‘court test’?
- Do examiners hold certifications from recognized professional authorities or software developers?
- Does the firm maintain an accredited digital forensic lab with secure physical and digital custody?
2. Legal Considerations & Scoping
- Has the organization consulted legal counsel regarding personal data protection and employee privacy rights?
- What methodology was adopted to define and refine the list of custodians?
- Have inputs been gathered from investigation sponsors to identify operational nuances?
- Is there a documented rationale for excluding potentially relevant individuals from the scope?
3. Information Technology Assets
- What sources of Electronically Stored Information (ESI) have been evaluated?
- Is there an up-to-date IT asset inventory (laptops, mobile phones, tablets, external storage)?
- What is the corporate policy regarding Bring Your Own Device (BYOD) and its permissible scope of review?
- Has server-level and cloud backup data been captured to prevent loss from local machine deletions?
4. Safe Custody of Assets
- Is an unbroken Chain of Custody maintained, with original devices returned safely after cloning?
- Is a designated central coordinator tracking original media custody within the organization?
- Has post-handover verification confirmed that returned devices operate without data corruption?
5. Robustness of Search & Analytical Procedures
- Does the plan include recovering deleted files and analyzing system-level artefacts?
- Have search keywords been formulated with domain experts to avoid missing critical slang or syntax?
- Are search strings appropriately calibrated to minimize unproductive false positives?
6. Closing and Evidence Handover
- What protocol governs the retention or disposal of forensic clones between the company and consultants?
- Is the investigation team conversant with the ICAI Forensic Accounting and Investigation Standards (FAIS)?
- FAIS 420: Evidence Gathering in Digital Domain, Institute of Chartered Accountants of India.
- NIST Special Publication: Digital Investigation Techniques (November 2022).
- Locard’s Exchange Principle in Forensic Science.
- NIST Framework on Digital Artefact Identification & Analysis.