Getting Audit Fraud Inquiry Questions And Answers Right
Audit fraud inquiries don't follow a single script, but there are patterns that separate people who actually understand the work from those just going through the motions. Most firms still rely on templated question lists borrowed from textbooks, which tends to produce predictable evasive answers rather than useful information. The practical approach starts with understanding what the inquiry is trying to surface before writing a single question. Here's how this typically plays out on the ground. When I'm designing inquiry questions for a fraud audit, I don't start with questions like "Did you commit fraud?" That's never useful. Instead, I structure around behavioral anchors and control environment vulnerabilities. A typical first set of questions focuses on process exposure: "Can you walk me through who has the ability to initiate a vendor change in the system versus who approves it?" This reveals segregation of duties gaps without anyone feeling interrogated. The follow-up matters more than the initial question. If someone says "I don't know" or deflects to policy documents, you've already learned something about whether controls are actually observed or just written down.
Second round questions drill into exception handling. "Tell me about the last time a purchase order was modified after approval. What triggered the change and who signed off?" Real fraud investigations live in the exceptions, not the standard flow. People rarely volunteer information about edge cases until they feel the question is routine enough that they don't think they need to be careful. Third round addresses conflicting incentives. "How is your team's bonus or performance review tied to the accuracy of expense reports you process?" This surfaces pressure points directly. When someone hesitates here, that hesitation carries more weight than any answer they give. The answers part of this is where most auditors fumble. Recording and interpreting responses requires noting the exact wording, not paraphrasing into something cleaner. A subject saying "we usually don't really do that formally" means something completely different from "we don't do that." The qualifier carries evidentiary weight. I keep a separate column in my notes for hedging language, qualifications, and emotional tells. It sounds excessive until you're three months later trying to reconstruct what was actually said.
I remember running a vendor fraud inquiry at a mid-size manufacturing company where the procurement manager kept giving perfectly polished answers about dual-approval controls. Everything checked out on paper. Two weeks into the inquiry, I asked her casually what happened during the one time last quarter when the system blocked a duplicate vendor creation. She hadn't been asked about system blocks before. Her answer was vague, she corrected herself twice, and mentioned a workaround that wasn't documented anywhere in the policy manual. That undocumented workaround turned out to be the exact channel used to route payments to a shell vendor for eleven months. The question about system blocks wasn't in any template I'd ever seen. It came from reading the actual workflow logs before asking anyone anything.
Get the Full Details

Why Standard Question Banks Fail
The biggest mistake I see is auditing firms copying question sets from ISACA or ACFE materials without adapting them to the specific environment. Those frameworks are fine as starting points, but they assume a control maturity that doesn't exist in most organizations. A question about "independent reconciliations" means nothing if the person being asked doesn't actually know what an independent reconciliation looks like in their own system. Another counter-intuitive reality: asking about red flags directly often backfires. People who are aware of fraud detection indicators will consciously or unconsciously adjust their answers to avoid appearing suspicious. It's more productive to ask about normal operations and let the gaps appear organically. If you ask someone to describe their invoice processing workflow step by step, the places where they skip steps or say "that's handled by someone else" reveal more than any checklist of warning signs ever would. There's also the problem of confirmation bias in the answers you record. Auditors tend to note responses that align with their hypothesis and gloss over contradictions. I've started requiring that every inquiry session includes at least two questions that could contradict the initial theory, even if the auditor believes the theory is solid. This forces honest documentation and prevents the inquiry from becoming a self-fulfilling narrative.
Practical Execution Notes
The timing and setting of the inquiry matter more than the wording. People give less guarded answers in their own workspace than in a conference room with a recorder. I usually start with a brief informal conversation in the subject's office before moving to formal questioning. This establishes baseline behavior so deviations later are noticeable. Without a baseline, you can't tell if someone is nervous because they're guilty or because they're being asked personal questions by a stranger. Session length is another practical constraint. Cognitive fatigue sets in around 45 minutes for complex behavioral questions. After that, answers become generic and less reliable. I break longer inquiries into multiple shorter sessions rather than pushing through. It takes more calendar days but the quality difference is significant. Documentation should include the sequence of questions asked, not just the final answers. The order influences responses, and reconstructing the actual flow is necessary if the inquiry ever faces legal scrutiny. I've seen cases where the defense successfully challenged inquiry validity because the documented question sequence didn't match what actually happened. The auditor had rearranged questions during the session to follow a more natural conversational path, which changed how the subject interpreted earlier questions.
Limitations and When This Approach Breaks
This method isn't a substitute for data analytics. Inquiry-based questioning identifies behavioral and procedural issues but can't confirm financial fraud on its own. You need transaction testing, Benford's law analysis, and data matching to build a factual foundation. The best inquiries I've run were informed by three weeks of data work beforehand. Going in blind and relying solely on questions tends to produce inconclusive results. Similarly, this approach struggles with sophisticated collusive fraud where multiple people have rehearsed consistent stories. No amount of clever questioning will break a coordinated lie without external corroborating evidence. In those cases, the inquiry serves more as a control assessment than a detection tool. You're mapping the environment to understand where controls failed rather than expecting a confession. If you're looking for a structured template to adapt rather than build from scratch, the ACFE offers fraud examination frameworks that include inquiry question categories. Government agencies like the GAO also publish guidance on audit inquiry techniques. These resources give you a foundation, but adapting them to your specific engagement scope is where the actual work happens.

Common Pitfalls to Avoid
Asking compound questions is one of the most frequent errors. "Did you follow the approval process and verify the vendor was legitimate?" gives you no useful answer whether the subject says yes or no. Each component needs its own question. Split them apart and ask about process first, then about verification separately. Another pitfall is not accounting for cultural and hierarchical dynamics. In some organizational cultures, questioning a senior manager's process knowledge is inherently loaded and will produce either deferral or defensiveness. I've learned to frame questions about process ownership differently depending on whether the subject is mid-level management or C-suite. The content stays the same but the framing changes significantly. Perhaps the most overlooked issue is not documenting the subject's body language and environmental context during the inquiry. I once saw a lead auditor mark a response as "inconsistent" when it actually matched an earlier statement, just phrased differently. The real inconsistency was behavioral—the subject had shifted from engaged to withdrawn between two answers that were substantively identical. The written record alone wouldn't have caught that. The behavioral shift was the signal.
The intersection of well-structured inquiry questions with solid analytical work produces the most reliable fraud detection outcomes. Questions without data context are guessing. Data without behavioral context is noise. Both are necessary, neither is sufficient alone.