The moment an internal auditor realises that the anomaly on the screen is not an error is the most consequential moment in the engagement, and most functions have never rehearsed it. What happens in the following two days decides whether the evidence survives, whether the organisation can recover the money, whether a prosecution or a civil claim is possible, whether the person responsible walks out with the proof, whether the company keeps its insurance cover, whether it meets a regulatory clock it did not know was running, and whether the auditor who found it becomes a witness or a liability. The ACFE’s Occupational Fraud 2026 report says the median scheme runs for twelve months before detection; the first 48 hours after detection are shorter than that by a factor of a hundred and matter more than any of the twelve months did. The instincts that serve an auditor well in fieldwork, to ask the person, to gather more, to tell the manager, are exactly wrong here, and the protocol below exists to replace them with steps that were decided in advance, by people who were not in the room.
This guide is the first two days of a fraud response, written for the function that finds it: what “finding fraud” actually means and the threshold that triggers the protocol, the four rules that govern the first hour, the protocol hour by hour with owners, the roles and who decides what, the evidence-preservation checklist, the legal frame (privilege, preservation, employment, whistleblowers) in plain terms, the reporting clocks that may already be running (audit committee, regulators, insurers, prosecutors), the incident record template, and a worked comparison of two MidState Beverage cases, one handled badly and one handled well. It is the first-48-hours detail of the eight-step allegation protocol described in the CFE guide, and it assumes the program context of the fraud risk management guide.
In this guide
- What “finding fraud” means, and the threshold that triggers the protocol
- The four rules of the first hour
- The protocol, hour by hour
- Roles: who decides what
- The evidence-preservation checklist
- The legal frame in plain terms
- The reporting clocks that may already be running
- The incident record: a template for the first 48 hours
- Worked comparison: two MidState cases
- Concluding the engagement that found it
- Rehearsing the protocol: the annual tabletop
- The mistakes that turn a recoverable fraud into a loss
- Where to go next
What “finding fraud” means, and the threshold that triggers the protocol
Auditors find three different things and call all of them fraud. An indicator is an anomaly consistent with fraud but also with error: a duplicate payment, a vendor with a PO box, an adjustment nobody approved. An allegation is a statement by someone (a tip, a complaint, a colleague’s remark in a workshop) that fraud has occurred, with or without evidence. Predication, the term fraud examiners use, is the point at which the totality of circumstances would lead a reasonable, professionally trained person to believe fraud has occurred, is occurring, or will occur: an indicator plus corroboration, or an allegation plus a document, or a pattern that has no innocent explanation left. The protocol triggers at predication, not before and not after. Before it, the auditor is still auditing: the duplicate payment is dispositioned, the vendor is checked against the employee file, the adjustment is traced to its approver, all of which is ordinary fieldwork that leaves an ordinary trail. After it, the auditor stops auditing and starts preserving, because every further step taken as an auditor (asking the person, pulling more records under the person’s name, telling the person’s manager) is a step that may destroy evidence, tip off the subject, or compromise privilege. The single most useful sentence in the protocol is the definition of the trigger, agreed in advance with the general counsel, so that the auditor in the moment does not have to decide whether this is the moment.
The four rules of the first hour
Do not confront. The subject is the one person who must not learn, from you or from anyone you tell, that the matter is under review; confrontation ends the evidence (deleted mailboxes, wiped devices, vendors warned), ends the possibility of observing an ongoing scheme, and starts the employment clock in the wrong place. Do not tell the line. The subject’s manager, the manager’s manager and the head of the department are not the escalation path, because any of them may be involved, may be the subject’s friend, or may simply react; the escalation path is the protocol’s named people, usually the CAE and the general counsel, and nobody else until they say so. Do not gather more. The instinct to nail it down with three more documents before escalating is how privilege is lost, how logs are overwritten by the very queries that try to read them, and how an auditor becomes a fact witness with an unprotected working file; write down what you have, precisely, and stop. And write it down now. A contemporaneous note of what was seen, when, where, and what was done with it, made within the hour and never edited, is the most valuable document the eventual investigation will have, and the one most functions do not produce.
The protocol, hour by hour
| Window | Actions | Owner | Output |
|---|---|---|---|
| Hour 0 to 1: detection | Auditor stops further inquiry; makes a contemporaneous note (what, when, source, amounts, people, what has already been done and who knows); secures the working file (copies to a restricted location, no edits); notifies the CAE only, by phone or in person, not by email that names the subject | Finding auditor; CAE | Detection note; restricted file |
| Hour 1 to 2: triage | CAE assesses predication against the agreed threshold; if met, notifies the general counsel; if the CAE or general counsel is implicated, the alternate route (audit committee chair) is used; decision recorded | CAE; general counsel | Triage decision; protocol formally opened; incident ID assigned |
| Hour 2 to 8: containment and preservation | Counsel directs the investigation from here (privilege); preservation instructions issued to IT security for mailboxes, devices, system logs, badge and VPN data, backups and the subject’s accounts, without alerting the subject; access decisions taken (monitor, restrict silently, or leave in place under observation); payment channels checked for in-flight transactions and, where funds have left, the bank recall or kill-chain request made immediately; insurer notice requirement checked | General counsel; IT security; CAE; treasury or the bank | Preservation confirmation; access decision; recall request time-stamped |
| Hour 8 to 24: scoping and notification | Counsel decides whether to engage external counsel and forensic support; scope of the initial fact-finding agreed (what, who, how far back); audit committee chair informed; HR briefed on the employment implications without the subject being told; a communications line agreed (who speaks, who does not); the fraud log entry opened | General counsel; CAE; HR; committee chair | Investigation scope; engagement of external support if needed; committee notification |
| Hour 24 to 48: first facts and decisions | Initial document review under counsel; preliminary quantification (order of magnitude, not precision); decision on the subject’s status (suspend on full pay with a neutral reason, remove access, or continue observation) taken with counsel and HR; regulatory and insurance clocks confirmed and diarised; recovery options listed (freezes, claims, restitution); the 48-hour summary written for the CAE and counsel | Counsel; investigation lead; HR; CAE | 48-hour summary; decisions log; clocks diarised |
Three features of the timeline are deliberate. The subject learns nothing until hour 24 at the earliest, and often much later, because observation of a live scheme is evidence that confrontation destroys. The recall request, where money has moved, is in the first eight hours and not the first two days, because the FBI’s Internet Crime Complaint Center froze 58 percent of the funds it was asked to chase in 2025 and the success rate depends almost entirely on speed; a request made on day four is a request made too late. And counsel takes direction at hour two, not hour twenty-four, because privilege attaches to work done at counsel’s direction for the purpose of legal advice, and it does not attach retrospectively to the auditor’s three extra documents.
Roles: who decides what
| Role | Decides | Does not decide | Notes |
|---|---|---|---|
| Finding auditor | Whether to stop and escalate (always yes at predication) | Anything else | Becomes a fact witness; keeps a contemporaneous note; is not the investigator |
| Chief audit executive | Whether the threshold is met; who is notified; whether internal audit supports the investigation or stands back to preserve independence for later validation | Employment action; regulatory reporting; whether to investigate | Reports to the audit committee chair under the charter; where the CAE is implicated, the alternate route applies |
| General counsel | Whether and how to investigate; privilege structure; external counsel and forensic engagement; preservation scope; regulatory and law-enforcement reporting; communications | The audit function’s independence | Directs the investigation from hour two; owns the clocks |
| IT security | How to preserve without alerting the subject; forensic imaging; log retention | What to preserve (counsel decides scope) | Acts on written instruction; documents chain of custody |
| Human resources | Employment process compliance: suspension, pay, notification timing, representation rights, policy alignment | Whether the person is guilty; the timing of any confrontation (counsel decides) | Terminating before counsel is briefed forfeits evidence and creates claims |
| Chief financial officer or treasurer | Recall and freeze requests; insurer notification; interim payment controls | Investigation scope | Unless implicated, in which case the alternate route applies |
| Audit committee chair | Whether the committee needs to meet; whether external resources are authorised; oversight of matters involving senior management | Operational steps | Informed within 24 hours for any matter involving management, material amounts or the financial statements |
| External counsel and forensic accountants | Investigation method, interviews, quantification, evidence handling | Business decisions | Engaged through counsel to preserve privilege; the auditor hands over the file, not the role |
The evidence-preservation checklist
| Source | Preservation action in the first eight hours | Who | Why it is urgent |
|---|---|---|---|
| The subject’s mailbox and messaging accounts | Litigation hold applied at the server; retention extended; no notification to the user; export to a forensic store | IT security on counsel’s instruction | Deletion is the first thing a subject does; server-side holds survive it, client-side deletion does not |
| Devices (laptop, phone, handheld, tokens) | Decide with counsel whether to image silently (remote imaging where possible) or secure on suspension; never wipe, reissue or “clean” a device | IT security | A wiped handheld destroyed the transaction history in one of the cases below |
| System logs and audit trails | Extend retention on the relevant systems immediately; export the subject’s activity logs (ERP, payment, HR, access) to a restricted location; note that reading logs can itself write logs | IT security; application owners on instruction | Rolling retention windows overwrite logs in days or weeks |
| Financial records | Snapshot the relevant tables (transactions, master data, approvals, adjustments) as of now; restrict the subject’s ability to post or change without alerting them (monitor rather than block where observation is the plan) | Finance systems; CAE | Master-data changes can rewrite the story (a vendor’s bank account changed back) |
| Physical evidence | Secure documents, cheque stock, keys, cash counts; photograph and log; chain-of-custody form from the first item | Investigation lead | Physical evidence is easiest to remove and hardest to prove existed |
| Badge, VPN and CCTV data | Retention extended; exports requested for the period in question | Facilities and IT security | Usually the shortest retention of any source |
| Third-party records | Bank statements and payment details requested directly from the bank; vendor and customer records through counsel; recall or freeze requests made now | Treasury; counsel | Money moves; the recall window is hours |
| The auditor’s own working file | Copied unchanged to a restricted location with a hash; the original left untouched; the contemporaneous note attached | Finding auditor; CAE | The working file will be discoverable and is the first exhibit |
The legal frame in plain terms
Four legal concepts shape the first two days, and the auditor needs to understand them well enough to avoid damaging them, not well enough to practise law. Privilege: communications with counsel for the purpose of legal advice, and work done at counsel’s direction in anticipation of litigation, are generally protected from disclosure; an investigation run by internal audit for its own purposes generally is not, which is why counsel directs from hour two and why forensic accountants are engaged through counsel; in the United States the Upjohn warning, given to employees interviewed under a counsel-directed investigation, tells them the privilege belongs to the company and not to them. Preservation: once litigation or a regulatory inquiry is reasonably anticipated, the organisation has a duty to preserve relevant evidence, and the deletion or overwriting of records after that point, even by routine retention, can be sanctioned as spoliation; the litigation hold is the mechanism, and the duty starts earlier than most managers think. Employment: suspension on full pay with a neutral explanation preserves the position; termination before the facts are established forfeits the ability to interview, may breach contractual and statutory process, and in some jurisdictions converts a fraud investigation into a wrongful-dismissal claim; the timing of any confrontation is counsel’s and HR’s decision, taken together. Whistleblowers: where the matter arrived as a tip, the reporter may be protected by statute (Section 806 of the Sarbanes-Oxley Act and the Dodd-Frank Act in the United States, the EU Whistleblower Directive as transposed in member states, and equivalents elsewhere), which constrains what can be said about them and to whom, and prohibits retaliation; the protocol treats the reporter’s identity as restricted information from the first hour. The general counsel owns all four; the auditor’s job is to not have already spent them.
The reporting clocks that may already be running
Several external clocks can start at detection, and the protocol’s second day exists partly to find out which ones have. Insurance first, because it is the one companies forget: commercial crime and fidelity policies typically require notice of a loss or of circumstances that may give rise to a claim as soon as practicable after discovery, define discovery in terms of when a designated person first became aware, and can exclude losses notified late; the CFO or risk manager reads the policy on day one and notifies through the broker within the period, before the amount is known. Regulators: banks in the United States file a Suspicious Activity Report within 30 days of the initial detection of facts that may constitute a basis for filing (with a further 30 days permitted to identify a suspect), and regulated firms in most sectors have notification duties for material frauds, data incidents and control failures whose clocks run from awareness; listed companies assess materiality for disclosure and, for financial statement matters, whether prior periods can still be relied on. Prosecutors: the Department of Justice’s Corporate Enforcement and Voluntary Self-Disclosure Policy, revised on 12 May 2025, offers a declination to companies that voluntarily self-disclose misconduct before an imminent threat of disclosure or investigation, cooperate fully and remediate, and specifies that a company that receives a whistleblower’s internal report still qualifies if it self-reports within 120 days; whether the matter is one the policy covers is counsel’s call, but the window is measured from awareness, and the first 48 hours are inside it. The audit committee: under the charter and, for US listed companies, the Sarbanes-Oxley Section 301 procedures for complaints about accounting matters, the committee chair is informed of any matter involving management, material amounts or the financial statements, and the CAE’s independent reporting line exists for exactly this. The table in the next section records which clocks apply, because the question “did anyone tell the insurer” should never be asked for the first time in month three.
The incident record: a template for the first 48 hours
Incident record [ID] — first 48 hours. Opened by [CAE] at [date and time]; general counsel notified at [time]; alternate route used: [yes / no and why]. Restricted distribution: [names].
1. Detection. [Who found what, when, from which source (engagement, analytic, tip, complaint); the contemporaneous note attached; what had already been done and who knew before escalation.]
2. Predication assessment. [The facts that meet the agreed threshold; the innocent explanations considered and why they were rejected; the decision to open the protocol and by whom.]
3. Subject and scope. [Role and access of the person or persons; processes, entities and period potentially affected; preliminary order of magnitude; whether funds are still moving.]
4. Preservation. [Each source from the checklist, the instruction given, to whom, at what time, and confirmation received; chain-of-custody log reference.]
5. Containment. [Access decisions and their rationale (monitor, restrict, suspend); payment controls applied; recall or freeze requests with time stamps and responses.]
6. Notifications. [Audit committee chair; HR; CFO; insurer or broker; regulator; law enforcement; external counsel and forensic support: each with the time, the person, and the decision not to notify where that was the decision.]
7. Clocks. [Every reporting or notice deadline identified, its trigger date, its due date, and the owner.]
8. Decisions log. [Every decision in the 48 hours, who took it, when, and on what basis; including decisions to wait.]
9. Internal audit’s position. [Whether the function is supporting the investigation or standing back; who in the function is a witness; how the engagement that found the matter will be concluded and reported without prejudicing the investigation.]
10. 48-hour summary. [One page for the CAE and counsel: what is known, what is not, what happens next, and by when.]
Worked comparison: two MidState cases
MidState Beverage, the three-state drinks distributor used across this site, provides the comparison because it had one fraud before its protocol existed and one after. In FY26 a driver at the Dayton depot diverted 18,400 dollars of route collections over five months and was exposed by a customer’s complaint about a balance; the response was improvised, and its failures are why the audit manager took the CFE and wrote the eight-step protocol in the CFE guide. The following year the function’s first accounts payable analytics run, in the AP analytics catalog, matched a vendor’s bank account to a depot manager’s payroll account: an undisclosed trucking vendor owned by the manager, paid through the depot he ran. The second case went through the protocol. The table sets the two side by side against the timeline above.
| Stage | Dayton driver (FY26, before the protocol) | Depot manager’s trucking vendor (FY27, under the protocol) |
|---|---|---|
| Detection | A customer complained to the depot about a balance that did not reflect cash paid; the depot manager looked at the driver’s route records himself | The analytics auditor’s vendor-employee bank match returned the hit; she stopped, wrote a contemporaneous note, and telephoned the CAE within the hour |
| Triage | None; the depot manager decided it was theft and decided what to do | The CAE assessed predication (a bank match plus payments approved by the manager himself) and notified the general counsel the same morning; incident record opened |
| Confrontation | The depot manager confronted the driver alone in the yard the same afternoon; the driver denied it, then admitted “some of it” | The manager was not told; his approvals continued under observation for eleven days while records were gathered |
| Preservation | The driver’s handheld was wiped and reissued to another driver two days later, as depot practice; the route transaction history for five months was lost with it | Counsel instructed IT security to hold the manager’s mailbox and export his ERP approval log the same day; vendor payments and master-data history snapshotted; the vendor’s registration obtained through counsel |
| Employment action | HR terminated the driver on the depot manager’s account before the general counsel had been told the matter existed | HR briefed at hour twelve; the manager suspended on full pay on day twelve, after the interview plan was agreed with external counsel |
| Recovery and reporting | No recall was possible (cash); the amount was established from the customer’s evidence and the reconciliations, not from the device; no claim under the crime policy because notice went out after the amount was known, six weeks later | Payments of about 61,000 dollars in the period confirmed from bank records; the insurer notified through the broker on day two; the audit committee chair informed on day one; the matter handed to HR and legal with a full evidence file |
| What it cost | The method was never fully established, the loss figure remained an estimate, the handling created an employment dispute, and the protocol had to be written afterwards | The investigation had every record it needed, the engagement report was worded so that it did not depend on the referred matter, and the function’s independence for the later validation was intact |
The difference between the two cases is not competence; the depot manager in the first case did what almost anyone does when they discover a theft, and the analytics auditor in the second did what she had been told to do in a protocol she had read twice and never used. That is the argument for writing the protocol before it is needed, rehearsing it once a year with the general counsel in the room, and defining the trigger so precisely that the person who finds the next one has nothing to decide except who to call.
Concluding the engagement that found it, without prejudicing the investigation
The audit that surfaced the matter still has to be finished, and finishing it badly can compromise the investigation as surely as confronting the subject. Four rules. Report the control, not the person: the engagement report describes the condition that allowed the matter (a vendor master not screened against the employee file; a reconciliation prepared by the depositor) with the evidence the audit obtained through its normal procedures, and it does not describe the referred matter, name the subject, or speculate about intent; MidState’s accounts payable report in the accounts payable guide was worded so that the vendor-master finding stood on its own and did not depend on the referral. Separate the referral: the referral memorandum goes to the general counsel under the protocol, is not attached to the audit report, and is not in the audit file’s general section; the working file that contains the detection evidence is restricted and hashed. Mind the timing: if issuing the report would alert the subject before counsel is ready, counsel decides whether the report waits, is issued without the relevant section, or is issued with the section held in a restricted annex to the audit committee; the function does not decide this alone. And keep the function’s later role open: if internal audit runs or heavily supports the investigation, it cannot independently validate the remediation later, so the CAE decides at the outset whether the function investigates (common in organisations with no forensic capability) or stands back and validates (preferable where external forensic support is available), and records the decision. The Global Internal Audit Standards frame the communication duty plainly: significant matters go to senior management and the board under Standard 11.3, and the engagement’s final communication under Standard 15.1 must still be accurate and complete about the controls, whatever the investigation’s status.
Rehearsing the protocol: the annual tabletop
A protocol that has never been rehearsed is a document, and the people named in it will improvise on the day exactly as they would have without it. Once a year, in ninety minutes, walk one scenario with everyone named in the protocol in the room: the CAE, the general counsel, HR, IT security, the CFO or treasurer, and the audit committee chair or a delegate. Use a scenario drawn from the fraud risk register (a payment-redirection hit, a vendor-employee match, an allegation against a senior manager, an executive-level financial reporting concern), inject a complication at hour eight (the subject is on leave abroad; the finding auditor has already emailed the manager; the amount turns out to be ten times larger; the subject is the CFO), and time each decision against the protocol. Three things always come out of it: a name in the protocol that no longer works there, a preservation step IT security cannot actually perform silently, and a clock nobody had diarised. Fix them, re-issue the protocol, and note the exercise in the audit committee’s annual fraud briefing, which is also where the function reports the year’s referrals, the hotline statistics and the register’s red scenarios under one heading.
The mistakes that turn a recoverable fraud into a loss
Confronting the subject before preservation, which ends the evidence and the observation at once. Telling the line manager, who is the wrong person a surprising share of the time and an unreliable one the rest. Gathering three more documents before escalating, which spends privilege and overwrites logs. Emailing the matter with the subject’s name in the subject line to a distribution list, which is discoverable, forwardable and occasionally reaches the subject. Terminating before counsel is briefed, which forfeits the interview and creates the claim. Wiping or reissuing devices under normal practice. Making the bank recall on day four. Reading the insurance policy after the amount is known. Assuming no regulatory clock applies because the amount is small, when the clock runs from awareness rather than amount. Letting the function that found the fraud run the investigation, so that it cannot later validate the remediation independently. And, the mistake behind all the others, not having a protocol: an organisation that decides the steps in the moment decides them under pressure, from instinct, with the subject still in the building.
Where to go next
Write the protocol now, with the general counsel, HR, IT security, the CFO and the audit committee chair named in it; define the trigger; rehearse it; and keep the incident record template where the person who needs it at four o’clock on a Friday can find it. The full eight-step protocol and the certification that teaches the method are in the CFE guide; the program the protocol belongs to is in the fraud risk management guide; the assessment that predicts where the next one comes from is in the fraud risk assessment guide; and the schemes themselves are organised in the fraud tree guide. For the bank recall, the kill-chain figures and the payment-side controls, see how to audit payment operations and wire transfers.
Related guides
- The CFE for internal auditors — including the full eight-step allegation protocol
- Fraud risk management and internal audit — prevention, detection and response as a program
- How to run a fraud risk assessment — predicting where the next case comes from
- The ACFE fraud tree explained — classifying what was found
- Fraud red flags — the signals that precede detection
- Incident response audit — the cyber-incident equivalent of this protocol
- How to audit payment operations and wire transfers — the recall clock and the kill chain
- The accounts payable analytics catalog — the run that found the second case
- Test of design vs operating effectiveness — the route cash audit that followed the first
- Issue validation in internal audit — why the function stands back from the investigation
- Audit committee presentation template — reporting the matter upward
- Audit issue log template — where the control findings go afterwards
- Auditing corporate culture and ethics — the environment the protocol operates in
- All fraud risk guides and all CAE and audit leadership guides
Leave a Reply