Financial due diligence establishes what a business is really worth and whether reported earnings reflect underlying economics. Forensic investigation establishes what happened in relation to a specific concern, to an evidentiary standard. Risk assessment establishes what could still go wrong over the next twelve to thirty six months. The three exercises share subject matter. They do not share objectives, methodology, evidence standards or conclusions, and one report cannot substitute for another.
Boards, lenders and investors frequently treat these as variations of the same review. The assumption is understandable and it is expensive. A business can look financially healthy and still carry serious risk. It can pass a clean statutory audit and still be concealing a fraud. It can survive a forensic investigation with no adverse finding and still be one customer away from a liquidity crisis.
This article sets out what each exercise is designed to do, when each one is the correct response, and how they work together on a single situation.
1. Financial due diligence: what am I actually buying?
Financial due diligence is a transaction support discipline. It exists to inform a price, a structure, a covenant or a decision to walk away.
A financial due diligence exercise typically examines:
- Revenue quality, sustainability and recognition policy
- EBITDA normalisation and the adjustments a seller has proposed
- Working capital and its true normalised level
- Cash conversion against reported profit
- Debt and debt-like items, including off balance sheet obligations
- Customer, vendor and geographic concentration
- Related party transactions and their commercial substance
- One-off, non-recurring and owner-benefit items
- Overall quality of earnings
The objective is not to verify that the accounts add up. That is the statutory auditor's territory. The objective is to determine whether reported financial performance represents the underlying economics of the business, and what a buyer or lender is actually acquiring exposure to.
In the due diligence engagements handled by Northrop Management Private Limited, the findings that most often move a deal are not arithmetic errors. They are normalisation adjustments the seller had never previously been asked to justify.
The question it answers: what does the financial information really tell us about this business and this transaction?
2. Forensic investigation: what actually happened?
A forensic investigation begins from a different premise. Something has already triggered concern: a red flag, an allegation, an unexplained transaction, a whistleblower complaint, a lender directive, a regulatory query, or an auditor's reporting obligation under Section 143(12) of the Companies Act 2013.
The scope may cover fraud indicators, misappropriation of funds, fictitious or inflated transactions, revenue manipulation, undisclosed related party dealings, circular transactions and round tripping, suspicious payments, vendor and customer irregularities, diversion or end-use misuse of borrowed funds, document fabrication, and management override of controls.
The question is not whether the financial statements appear reasonable. The question is whether evidence exists that something occurred which should concern the board, the audit committee, the lender, the investor or the regulator.
Forensic work is evidence-led rather than analytical. It proceeds on the expectation that the output will be read by a credit committee, an audit committee, a regulator, counsel or a tribunal. That expectation changes the whole method: how documents and devices are preserved, how the chain of custody is maintained, how interviews are conducted and recorded, how conclusions are worded, and how much of the working file must survive external challenge. The ICAI Forensic Accounting and Investigation Standards set out the professional framework that applies.
In the Indian lending context the trigger is often procedural rather than discretionary. Where Early Warning Signals are present, an account may be classified as a Red Flagged Account, and a forensic examination follows under the applicable RBI framework and the lender's own directive, within defined timelines. Under the Insolvency and Bankruptcy Code 2016, a resolution professional's transaction review looks for preferential, undervalued, extortionate and fraudulent transactions under Sections 43, 45, 50 and 66, for application to the NCLT.
This is the discipline on which Northrop Management Private Limited was built. Our senior team's experience includes forensic audits conducted under public sector bank directives and mandates arising in insolvency and NCLT proceedings, where the operative question was rarely whether the accounts reconciled, but where the money went and whether it could be proved.
The question it answers: what happened, and is there evidence that will withstand scrutiny?
3. Risk assessment: what can still go wrong?
Risk assessment looks forward. It is the exercise boards defer most often, because nothing has gone wrong yet. That is precisely why it exists. A business may have no identified fraud. Its financial statements may be reasonably accurate. It can still carry material financial, operational, regulatory, credit and governance exposure.
A risk assessment may examine liquidity and cash flow risk, customer and revenue concentration, counterparty and supply chain exposure, debt servicing capacity and covenant headroom, internal financial control gaps, regulatory and compliance exposure, governance gaps at board and committee level, operational dependencies, key person and founder dependency, technology and cybersecurity risk, and disclosure risk.
Due diligence examines a period that has closed. Forensic investigation examines events that have already occurred. Risk assessment is the only one of the three that asks what the next twelve to thirty six months could do to the enterprise.
The question it answers: what could materially affect this business, and how prepared is it to respond?
4. The three exercises side by side
5. Where boards and CFOs go wrong
The most common and most costly error is expecting one review to answer all three questions.
A clean set of financial statements does not mean there is no fraud. A statutory audit provides reasonable assurance on the financial statements taken as a whole. It is not designed to detect a well concealed collusive fraud and does not claim to be. Sampling, materiality thresholds and reliance on management representations are inherent features of the assurance model, not deficiencies in it.
A satisfactory due diligence report does not mean there are no future business risks. A quality of earnings exercise can confirm that reported EBITDA is real and say nothing about whether the largest customer is about to leave.
A risk assessment does not establish that a transaction was fraudulent. Identifying a control weakness is not the same as proving that someone exploited it.
When a board asks one provider to compress all three exercises into a single report at a single fee, what it receives is a document that is defensible on none of the three. The cost of that compression is never visible at the time. It becomes visible eighteen months later, when a lender, a regulator or an acquirer asks a question the original scope never covered.
6. They work best connected, not merged
Consider a company reporting strong revenue growth.
Financial due diligence may establish that a large share of that revenue sits with a small number of customers, and that working capital deteriorated even as reported profit improved.
A forensic investigation may then be warranted where specific customer transactions, related parties or supporting documents show inconsistencies, particularly where receivables have aged well beyond commercial norms.
A risk assessment may then identify customer concentration, weak segregation of duties and aggressive revenue recognition as exposures that will outlive the transaction itself.
No single finding is sufficient on its own. Together they change the price, the structure and the post-closing governance plan.
That is how the practices at Northrop Management Private Limited are designed to operate: connected in perspective, deliberately separate in scope, methodology and conclusion.
7. What this means for the board
The question before a board is not whether the accounts are correct.
It is whether the board understands the financial quality, the integrity and the risk profile of the business well enough to make a decision it cannot reverse. Directors carry duties under the Companies Act 2013 that are not discharged by receiving a clean audit report. Where an audit committee has been put on notice of a credible red flag, the reasonable and defensible response is a scoped forensic review, not a second opinion on the accounts. The adequacy of the board's response, and the speed of it, is itself examined later.
8. What this means for the CFO
Know what the numbers say. Know what the evidence supports. Know where the risks sit. That distinction determines what a CFO can honestly represent to a board, a lender or an incoming investor, and it determines whether those representations hold up when tested.
Verdict
Financial due diligence tells you what you are buying. Forensic investigation tells you what happened. Risk assessment tells you what can still go wrong.
They are complementary. They are not interchangeable. A business can have good numbers, bad controls and significant risk, all at the same time.
Speak to Northrop Management
If you are approaching a transaction, responding to a red flag, or preparing a board for a decision it cannot reverse, the first conversation should be about scope, not price.
A scoping conversation with Northrop Management Private Limited covers four things:
- What triggered the question, and which of the three exercises actually answers it.
- What evidence exists today, and what must be preserved immediately.
- Who the eventual reader of the report will be: a board, a lender, an investor, a regulator or a tribunal.
- A defined scope, timeline and deliverable, agreed before an engagement letter is signed.
Northrop Management Private Limited is a forensic accounting, corporate governance and financial advisory firm advising boards, lenders, investors, promoters and regulators on forensic investigations, due diligence, risk advisory and corporate governance.
Request a scoping conversation: [email protected] | +91 92899 25657 | northropindia.com
Frequently Asked Questions
What is the difference between financial due diligence and a forensic audit?
Financial due diligence assesses earnings quality, working capital and value drivers to support a transaction decision, using analytical procedures. A forensic audit investigates a specific concern such as a suspected fraud or fund diversion, and is conducted to an evidentiary standard because the findings may be relied on by a lender, a regulator, counsel or a tribunal.
Does a clean audit report mean there is no fraud in the company?
No. A statutory audit gives reasonable assurance on the financial statements as a whole, based on sampling and materiality. It is not designed to detect a well concealed collusive fraud, particularly one involving management override of controls.
When should a board order a forensic investigation?
When a credible red flag arises: a whistleblower complaint, an unexplained transaction, an auditor's concern under Section 143(12) of the Companies Act 2013, a lender or regulatory directive, or a pattern that management cannot satisfactorily explain. The scope should be defined before the engagement begins.
Who can conduct a forensic audit in India?
Forensic examinations are typically conducted by chartered accountants and specialist forensic practitioners, working within the ICAI Forensic Accounting and Investigation Standards, and often alongside legal counsel and digital forensics specialists. Lenders and regulators may maintain their own panels for directed reviews.
What triggers a bank-mandated forensic audit?
Early Warning Signals in a borrower account can lead to classification as a Red Flagged Account under the applicable RBI framework, after which the lender directs a forensic examination within defined timelines to determine whether fraud has occurred.
How is risk assessment different from internal audit?
Internal audit tests whether existing controls are operating as designed. Risk assessment identifies which exposures could materially affect the enterprise, including those for which no control currently exists.
Can one firm perform all three exercises?
A firm can perform all three, and there is real value in a single team that understands the business. They should not be merged into one scope, one methodology or one report. Independence and conflict considerations also need to be assessed where the same firm advises on a transaction and later investigates it.
How long does a forensic investigation take?
It depends on the period under review, data availability and the number of entities involved. What matters more than duration is that evidence is preserved at the outset. Delay in preservation is the single most common reason an investigation cannot reach a conclusion.
