,

The CFE for Internal Auditors: Is It Worth It, What the Exam Tests and How to Earn It

Internal auditors take the Certified Fraud Examiner credential for one of two reasons, and the reasons lead to different decisions. The first is that fraud keeps arriving on their desk: a hotline tip, a driver skimming cash, a vendor that turns out to belong to a depot manager, and the function has no protocol for what happens next. The second is that they want to move toward investigation, forensic accounting or financial-crime work and need the credential the market filters on. This guide serves both. It explains what the CFE certifies and what it does not, who gains from it inside internal audit, what the three-section exam actually tests and where you have already met the material, the points system, fees and timeline as the ACFE publishes them, a ten-week study plan, how the CFE compares with the CIA and the CISA for an internal auditor, how to use it at work without crossing the line from auditor to investigator, and a worked example from a small function that took it after a theft.

Facts about the credential come from the ACFE’s own certification and exam pages as they stood in September 2026; the fraud statistics come from the ACFE’s 2026 Report to the Nations. The ACFE restructured the exam from four sections to three, and a great deal of older advice, including some on the ACFE’s own community forums, still describes the four-section version. Where we give a view, it is labelled as one. For the fraud discipline itself rather than the credential, start with fraud risk management and internal audit; for the credential decision against the internal auditor’s own designation, see the CIA exam requirements.

In this guide

What the CFE certifies, and what it does not

The Certified Fraud Examiner is the credential of the Association of Certified Fraud Examiners, founded in 1988 and now, by its own count, a membership of more than 90,000 in most of the world’s countries. The body of knowledge behind it is the Fraud Examiners Manual, a reference that runs to thousands of pages across the same four areas the exam once mirrored: financial transactions and fraud schemes, law, investigation, and fraud prevention and deterrence. The credential certifies that you know how frauds are committed, how they are detected and investigated, what the law permits and requires of an investigator, and how organizations deter fraud. It is deliberately broad; a CFE is expected to be able to talk to an auditor, a lawyer, a data analyst and a police officer in each of their languages.

It does not certify that you are an investigator. Interviewing a suspect, preserving evidence to a standard a court will accept, and managing the legal exposure of an organization during an inquiry are skills learned by doing them under supervision, and the ACFE says as much in its own materials. Nor does it certify accounting or audit competence; a CFE without an accounting background may know the schemes cold and still be unable to trace them through a ledger. For an internal auditor the credential’s value is precise: it puts a structure around fraud risk that most audit functions lack, it makes the auditor credible with the people who run investigations, and it is what recruiters search for when a role has the word fraud in it.

The scale of the problem the credential addresses is well documented. The ACFE’s 2026 Report to the Nations analysed 2,402 cases from 143 countries with total losses above 3.4 billion dollars, a median loss of 104,000 dollars per case and a median duration of twelve months before detection. Tips were the initial detection method in 43 percent of cases, and organizations with proactive data monitoring saw median losses 53 percent lower than those without. Those figures are the reason fraud arrives on the internal auditor’s desk whether or not the function planned for it, and the reason the guide on fraud red flags is one of the most read on this site.

Who gains from it inside internal audit

The CFE is worth more to some internal auditors than others, and the difference is mostly about what the function is asked to do with fraud. A function with a formal investigations unit next door needs one or two CFEs for liaison and for the fraud risk assessment; a function that is the investigations unit, as most small and mid-sized ones are, needs the discipline in the room. The profiles below cover the cases that come up.

ProfileWhere the CFE helpsWhere it does notOur view
Auditor in a small or mid-sized function that handles its own allegationsA protocol for intake, triage, evidence, interviews and reporting; a credential the board will recognise when a matter escalatesDoes not remove the need for counsel and, for serious matters, an external forensic firmTake it. One CFE in the function changes how allegations are handled, and the study is the investigations training the function never had
Financial services auditor covering AML, sanctions or paymentsFraud schemes, financial crime typologies and the legal section overlap heavily with the work; regulators and second-line teams respect itThe compliance-specific credentials remain the ones those teams hold; the CFE is a complementTake it if fraud or financial crime is a recurring plan item; the guide on internal audit in financial services shows where it lands
Analytics-minded auditor building fraud testsScheme knowledge is what turns a generic test catalog into targeted detection; the exam’s scheme taxonomy is the best available index of what to look forThe exam is light on the technical side of analytics; the tooling comes from elsewhereTake it, and pair it with the test catalogs in procurement fraud analytics and journal entry analytics
Auditor who wants to move into investigations or forensic accountingThe filter credential for the field; the fastest way to be shortlisted for an investigator role from an audit backgroundEmployers will still want casework; a CFE with no interviews or evidence handling on the CV is a candidate, not a hireTake it early, then find casework: secondments, shadowing an external firm, the function’s own smaller matters
Senior or manager on the CAE trackBoard-level fluency on fraud governance, whistleblowing and the organization’s response capability; complements the CIAThe CIA and the stakeholder record carry the CAE decision; the CFE is a supporting lineOptional, unless the organization’s fraud exposure is high or the CAE owns the hotline. Consider it after the CIA, not instead

Two cautions. An auditor with no interest in fraud work should not take the CFE as a general-purpose signal; the CIA does that job better and cheaper in study time, and the comparison in CIA vs CISA applies just as well with the CFE in the third seat. And an auditor whose function has a real investigations unit should ask that unit what it would value before deciding; the answer is often a joint fraud risk assessment rather than another credential.

The three sections, and where you have already met them

The current CFE Exam has three sections, taken separately, each scored on its own and each passed on its own. All three must be completed within a 60-day window once the exam is issued, and the sections can be sat in any order. Delivery is by online remote proctoring, at Prometric test centers, or on paper at the end of an ACFE CFE Exam Review Course. The questions are multiple choice and true-or-false, drawn from the Fraud Examiners Manual, and the ACFE’s own prep course tracks the manual closely enough that most candidates never open the manual itself. The table gives the sections, their size and what an internal auditor will recognise in each.

SectionQuestions and timeWhat it coversWhere you have already met it
Fraud Schemes and Financial Crimes120 questions, 2.5 hoursThe scheme taxonomy: asset misappropriation (cash, inventory, billing, payroll, expense, check and register schemes), corruption (bribery, conflicts of interest, kickbacks), financial statement fraud, plus financial crimes such as money laundering, identity theft, insurance, healthcare, securities and cyber-enabled fraud; the accounting concepts needed to see them in the recordsEvery process audit you have run; the payables, payroll and expense work behind accounts payable analytics is scheme detection with the ACFE’s names attached
Fraud Investigations and Legal Issues120 questions, 2.5 hoursPlanning an investigation, evidence collection and preservation, digital forensics basics, interviewing and admission-seeking interviews, tracing illicit transactions, report writing, expert testimony; the legal elements of fraud, individual rights during investigations, criminal and civil procedure, the law of evidence, and the regulatory environmentOnly partly. Evidence standards are familiar from journal entry testing and similar work, but the legal and interviewing material is new to most auditors and is where study time goes
Fraud Prevention and Deterrence70 questions, 1.5 hoursWhy people commit fraud (the fraud triangle and its successors), white-collar crime theory, occupational fraud research, fraud risk assessment and management, corporate governance, ethics for fraud examiners, internal controls and the frameworks behind them, fraud prevention programs and hotlinesMost of it. Governance, control frameworks and risk assessment are the internal auditor’s home ground, and preventive, detective and corrective controls covers the control side in the auditor’s own terms

The ACFE’s legal content is written for a US audience first, with the international material presented alongside it. A candidate outside the United States should expect questions on US federal statutes, procedure and rights in the investigations section and should learn them as exam content rather than as law they will practise. Candidates from common-law jurisdictions find the material closer to home than those from civil-law systems, but nobody fails the section for lack of a law degree; they fail it for treating it as the section to skim.

Points, membership, fees and timeline

The ACFE uses a points system rather than a single experience rule, and the two thresholds it sets, to sit and to certify, are where candidates most often misread their position. The table gives the ACFE’s published requirements as of September 2026 and the errors we see.

ItemACFE’s positionWhat candidates get wrong
MembershipACFE Associate membership is required to sit the exam and to hold the credential; annual dues apply (check the current figure on the ACFE site before budgeting)Forgetting the dues in the all-in cost, and letting membership lapse after certifying, which lapses the credential
Points to sit40 points on the ACFE’s qualification scale; a bachelor’s degree alone is worth 40, and points also accrue for years of fraud-related professional experience and for certain professional credentialsAssuming a degree is mandatory. It is the easiest route to 40 points, not the only one; check the ACFE’s points calculator
Points to certify50 points plus at least two years of professional experience in a field directly or indirectly related to fraud, which the ACFE lists to include accounting and auditing, law, loss prevention, criminology and fraud investigation, among othersAssuming internal audit does not count. It does; the experience requirement is the one an auditor usually already meets
Exam fee475 dollars, covering the first attempt at each of the three sections; a section that is not passed can be retaken for 110 dollars per sectionBudgeting for retakes as if they were free, and missing the 60-day completion window
SchedulingRescheduling a section costs 35 dollars if done three to 29 days before the appointment and 50 dollars inside three daysBooking all three sections in one week and discovering that the investigations section needed another fortnight
Study materialThe ACFE’s CFE Exam Prep Course is sold in one-year packages: Silver at 899.20 dollars for members and 1,124 for non-members, Gold at 1,149.60 and 1,437, Platinum at 1,699.20 and 2,124; the course carries more than 500 lessons and roughly 1,400 practice questions, with the higher tiers adding material and services the ACFE listsBuying the top tier by default. Most auditors pass on the base course plus their own professional background
Certification applicationAfter passing, submit the application with the supporting documents the ACFE lists, including proof of education and experience and professional recommendationsLeaving it for months. The credential is not held until the application is approved, and the CV should not say CFE before then
Maintenance20 CPE hours each year, of which at least 10 must relate directly to fraud and at least two to ethics; continued membership; adherence to the ACFE Code of Professional EthicsReporting general audit CPE against the fraud-specific ten; keep fraud sessions clearly labelled in the log

All in, a member candidate who buys the base prep course and passes each section once spends roughly 1,400 dollars on the course and exam plus the annual dues, before any review course, and most employers reimburse it under the same policy that funds the CIA. The timeline is short by certification standards: ten to twelve weeks of study, the three sections spread across three or four weeks inside the 60-day window, and the application immediately after, since an internal auditor with two years of experience is usually eligible to certify on the day of the last pass. Compare that with the three-part structure and the fee schedule in the CIA exam cost guide, and the CFE is the quicker credential to complete and the cheaper one per year of study, though not per exam sitting.

A ten-week study plan around audit work

The plan assumes the ACFE prep course, eight hours a week, and an internal auditor with a few years of process audit behind them. It orders the sections by unfamiliarity rather than by exam order, gives the investigations and legal section the most time because that is where auditors lose marks, and schedules the three sittings inside the 60-day window so that a failed section can be retaken without breaching it. Book the first section before you start studying; the date is the discipline.

Weeks 1 to 4: Fraud Investigations and Legal Issues. Two weeks on investigation: planning, evidence handling and chain of custody, digital evidence, tracing transactions, interview types and the structure of an admission-seeking interview, report writing. Two weeks on law: the legal elements of the main fraud offences, individual rights during an internal investigation, criminal versus civil process, rules of evidence, the regulatory bodies. Build a one-page table of the US statutes and doctrines the course names; you will be asked about them by name. Practice questions after each week; a section-length practice test at the end of week four.

Weeks 5 to 7: Fraud Schemes and Financial Crimes. Learn the scheme taxonomy as a tree, not a list: asset misappropriation splits into cash and non-cash, cash into theft of cash on hand, theft of receipts and fraudulent disbursements, and so on down. For every scheme write one line on how it appears in the records and one on the control that stops it; that pairing is what the exam tests and what you will reuse at work. Week seven covers the financial crimes and the accounting concepts, with a section-length practice test.

Week 8: Fraud Prevention and Deterrence. One week is enough for a practising auditor: the theory of why people commit fraud, the occupational fraud research (the current Report to the Nations figures are fair game), fraud risk assessment, governance and ethics, control frameworks. Practice test at the end.

Week 9: Sit the first two sections. Prevention and Deterrence early in the week while it is fresh, Fraud Schemes later. Review every wrong practice answer in the investigations material in the gaps.

Week 10: Sit Fraud Investigations and Legal Issues. Two light days of review of the statutes table and the interview structure, then the section. If any section is not passed, the retake sits inside the remaining weeks of the 60-day window.

Candidates from law, law enforcement or compliance reverse the order and give the schemes and the accounting concepts the four weeks, since debits and credits are the unfamiliar part for them. Whatever the order, keep the study log; the fraud-specific CPE requirement that follows certification is easier to meet when the habit of labelling hours by topic already exists, and the same log serves the CIA if you hold both, as the CIA CPE requirements guide describes.

CFE, CIA or CISA: the comparison for an internal auditor

The three credentials internal auditors weigh most often are not competitors so much as answers to different questions. The CIA certifies the internal audit discipline itself; the CISA certifies information systems audit; the CFE certifies fraud examination. The table compares them on the dimensions that decide the order in which to take them, using the figures each body published as of September 2026 and our own reading of what each is best for.

DimensionCFE (ACFE)CIA (IIA)CISA (ISACA)
What it certifiesFraud schemes, investigation and law, prevention and deterrenceThe internal audit profession: standards, practice, business knowledgeInformation systems auditing, governance, development, operations and security
Exam structureThree sections (120, 120 and 70 questions; 2.5, 2.5 and 1.5 hours) within a 60-day windowThree parts sat separately, each with its own feeOne exam of 150 questions in four hours, scaled 200 to 800, pass at 450
Exam fees at publication475 dollars covering a first attempt at each section; 110 per section to retakeApplication plus three part fees; see the cost guide for the current schedule575 dollars for members, 760 for non-members, per attempt
Experience to certify50 points and two years of fraud-related experience, which includes auditing; ACFE membershipVaries by education, generally one to five years of internal audit or equivalent experienceFive years of IS audit, control or security experience, with up to three years of waivers
Maintenance20 CPE hours a year including 10 fraud-related and two ethics; membership dues40 hours a year for practising CIAs, with an ethics component; see the CPE guide20 hours a year and 120 per three-year cycle; annual maintenance fee
Typical time to completeTen to twelve weeks of study, three sittings in a monthSix to eighteen months across three partsThree to four months of study, one sitting
Best first credential forAn auditor already handling allegations, or heading toward investigationsAlmost every internal auditor; the profession’s own designationAn auditor whose plan is mostly technology, or a career changer from IT
Best as a second credential forCIAs in fraud-exposed industries, financial services, analytics rolesCFEs and CISAs who want to lead a function rather than a specialismCIAs who keep inheriting the ITGC work; see the CISA guide for internal auditors

Our view on order, for an auditor who intends to stay in internal audit: CIA first, because it is the profession’s own designation and the one a CAE search will assume; then whichever of the CFE or CISA matches the larger share of the function’s plan. For an auditor who intends to leave for investigations, the order reverses, and the CFE comes first. For an auditor undecided between fraud and technology, the honest answer is that the CISA is the safer bet in most organizations, because technology risk is in every audit universe and fraud risk is in every audit universe only after something has gone wrong; the comparison with a fourth credential in CIA vs CFA makes the same point about choosing by destination rather than by prestige.

Using it at work without becoming the investigator

The first thing a newly certified internal auditor should do with the CFE is decide what the function will not do. Internal audit’s independence, its reporting line to the audit committee and its access rights make it the natural home for fraud risk assessment, for analytics-led detection and for the initial handling of allegations. They make it a poor home for the parts of an investigation that create legal exposure: interviewing a suspect without counsel’s direction, seizing devices, making findings of individual culpability, or dealing with law enforcement. A CFE in the function knows where those lines are, which is the credential’s most valuable single contribution, and the protocol below is the form that knowledge should take. It is written to be adopted as a function-level document, approved by the CAE and shared with the general counsel, and adapted to the organization’s own hotline, HR and legal arrangements.

Fraud allegation handling protocol: outline

1. Intake. Every allegation, from any channel (hotline, management, auditor observation, external party), is logged within one business day with date, source, subject matter, business unit and the name of the person who received it. Anonymous reports are logged with the channel as the source. The log is held by internal audit and visible to the general counsel.

2. Triage within five business days. The CAE (or the designated CFE) and the general counsel classify the allegation: (a) not a fraud matter, referred to HR, compliance or the business with a note; (b) a matter internal audit will assess; (c) a matter requiring an investigation under counsel’s direction, with or without external forensic support. Classification and the reasons are recorded.

3. Preservation. For any (b) or (c) matter, a preservation request is issued through counsel before any inquiry begins: relevant systems, mailboxes, devices and physical records are identified and held. Internal audit does not image devices or collect original evidence; it identifies what should be preserved.

4. Assessment (category b). Internal audit examines records and data, with the scope, the people informed and the reason documented; it does not interview the subject. The output is a memorandum of facts established from records, delivered to counsel and the CAE, with a recommendation on whether the matter should move to category (c).

5. Investigation (category c). Counsel directs; internal audit supports with records analysis, transaction tracing and data work under counsel’s instruction, so that privilege can be asserted where the organization chooses to. Interviews of subjects are conducted by trained investigators, with a second person present, on counsel’s plan.

6. Escalation. The audit committee chair is informed of any matter involving senior management, any matter above a stated monetary threshold, and any matter with regulatory or public disclosure implications, within the timeframe the charter sets. The CAE informs the chair directly, not through management.

7. Control response. Whatever the outcome for individuals, internal audit issues a report on the control failures the matter exposed, with owners and dates, tracked like any other finding and reported to the committee until closed.

8. Closure and learning. Every matter is closed in the log with the outcome category, the control actions and, for category (c), counsel’s confirmation of closure. The fraud risk assessment is updated for the scheme involved, and the analytics catalog gains a test if one would have detected the matter earlier.

Beyond the protocol, the credential earns its keep in three places. The fraud risk assessment, done properly, is a scheme-by-scheme exercise: which of the ACFE’s schemes could occur here, through which process, with which controls in the way, and that is a CFE’s native structure; the guide on fraud risk covers the assessment end to end. Detection analytics get sharper when the person writing the tests knows what a shell vendor, a ghost employee or a lapping scheme looks like in the data, which is why the test catalogs on this site are organized by scheme. And the lessons in what internal audit can learn from the big scandals read differently once the reader knows the schemes by name and the red flags by pattern.

Worked example: a function takes the CFE after a theft

MidState Beverage’s six-person internal audit function found out what it lacked when a customer complaint exposed a Dayton depot driver who had diverted 18,400 dollars of route cash over five months. The loss was small against 31 million dollars a year collected by drivers, and the handling was the problem: the depot manager confronted the driver alone, the driver’s handheld was wiped by the depot before anyone thought to preserve it, HR terminated him before counsel was told, and the audit manager, asked by the chief audit executive to “look into it”, spent two weeks reconstructing a case that a court would never have accepted and that the company, in the end, did not pursue. The audit committee chair’s question was short: what would we have done if it had been 1.8 million?

The CAE’s answer was a protocol and a credential. The audit manager, a CIA with nine years in internal audit and a bachelor’s degree, took the CFE over one quarter, following the ten-week plan above with the investigations section first because that was the section the Dayton matter had exposed. He passed all three sections inside the window, with one anxious week between the schemes section and the legal one, and certified immediately: 40 points from the degree, further points from his years of audit experience, and two years of fraud-related experience satisfied many times over by process audit work. The function paid the member prep course, the exam fee and the dues from its development budget, and the CAE reported the certification to the committee alongside the protocol, which the general counsel co-signed.

The protocol was tested within the year. The first accounts payable analytics run flagged a trucking vendor that turned out to be owned by a depot manager and had never been disclosed; under the protocol it was logged, triaged as a category (c) matter with counsel within four days, a preservation request went to IT before anyone spoke to the depot, and internal audit’s contribution was a fourteen-page memorandum tracing 14 months of invoices rather than an interview. The payroll analytics run surfaced an overtime approval loop at two depots that was referred under the protocol, and an HR administrator’s seventeen self-approved rate changes became a category (b) assessment, closed as a control failure with findings rather than as an accusation. The route cash audit that same year reported a design deficiency in reconciliation at nine of twelve depots and 1,412 self-approved overrides, and the fraud risk assessment that fed the audit plan was rebuilt scheme by scheme, with the driver skimming route now a named scheme with named controls rather than an incident.

What the credential changed was not the audit manager’s ability to find fraud; the analytics found it. It changed what happened in the four days after something was found, and it gave a six-person function a document the board could point to when it asked what would happen next time. That is the deal: for roughly the cost of one conference, a small function bought a protocol, a credential and a colleague who knows where the line is.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading