The Supplier Is Genuine. So How Can the Payment Still Be Fraudulent?

 When a Genuine Invoice Leads to a Fraudulent Payment

A supplier may be completely genuine.

The invoice may be genuine.
The goods or services may have actually been received.
The purchase may have been properly approved.
And the payment amount may exactly match the invoice.

Yet, the payment can still be fraudulent.

How?

The risk is not always the supplier. It can be the bank account.

Consider a simple situation.

A company regularly purchases goods from a genuine supplier. The supplier’s name, GST details, invoices and transactions all appear legitimate.

At some point, the supplier’s bank account details are changed in the company’s records.

The new bank account may have been inserted or changed by someone within the accounts or finance process.

The payment is then made to the new account.

From the accounting records, everything may appear normal:

  • Genuine supplier
  • Genuine invoice
  • Genuine purchase
  • Correct invoice amount
  • Proper approval
  • Payment recorded against the supplier

But the money has gone to a different bank account.

In some cases, that account may belong to an employee, an employee’s relative, or another person connected with the fraud.

This is why verifying the supplier is not enough. The payment destination also needs to be verified.

Why can this be difficult to detect?

Most accounting controls focus on whether the transaction itself is genuine.

For example:

Purchase Order → Goods Received → Invoice → Approval → Payment

If all these documents match, the transaction may appear completely legitimate.

But there is another question that is often overlooked:

Who actually owns the bank account to which the payment was made?

If the supplier’s bank details were changed without independent verification, a genuine transaction can become a fraudulent payment.

A simple control that can reveal a serious problem

One practical review is to compare supplier bank-account information with employee-related bank-account information.

For example, take:

  1. The list of active supplier bank accounts.
  2. The list of employee salary bank accounts.
  3. Compare the bank account numbers.
  4. Where appropriate, also compare IFSC codes and account-holder names.
  5. Investigate any unusual matches.

Suppose a supplier’s bank account happens to be the same as an employee’s salary account.

That does not automatically prove fraud.

There could be a legitimate explanation. For example, the employee may have a genuine business relationship with the supplier or may have been authorised to receive payments in a particular arrangement.

However, such a match is certainly a red flag that deserves investigation.

The same principle can be extended to other unusual relationships, such as supplier bank details matching accounts associated with employees or their related parties.

The bigger control: independently verify changes in bank details

The most important control is not simply comparing account numbers.

It is having a proper process whenever supplier bank details are changed.

For example:

Supplier requests change in bank details

Change request is documented

Supporting bank details are obtained

Independent verification is performed using previously known contact details

Change is approved by an authorised person

Bank details are updated in the accounting system

Payment is released

The key word here is independent.

If the same person who receives the bank-change request can also update the master data and release the payment, the control is considerably weaker.

What businesses should consider implementing

A few simple controls can significantly reduce this risk:

1. Maker-checker control

The person who changes supplier bank details should not be the same person who approves the change.

2. Independent verification

Do not rely solely on the email or message requesting the change.

Verify the change through an independent communication channel, such as a previously registered supplier contact number.

3. Maintain an audit trail

Every change to supplier master data should leave a record showing:

  • Who requested the change
  • Who made the change
  • Who approved it
  • When it was changed
  • What the previous bank details were
  • What the new bank details are
4. Review unusual matches

Periodically compare supplier bank details with employee and other relevant master data to identify unusual overlaps.

5. Review recently changed bank accounts

Payments made shortly after a supplier’s bank details have been changed can receive additional scrutiny, particularly where the transaction is large or unusual.

What about the auditor?

This distinction is important.

The existence of a genuine supplier and genuine invoice does not, by itself, establish that the payment was made to the correct beneficiary.

At the same time, an auditor cannot be expected to detect every fraud simply because a fraud has occurred.

The nature and extent of audit procedures depend on the applicable auditing standards, the circumstances, the assessed risks and the controls in place.

For businesses, the practical lesson is therefore not to rely on the audit alone.

Fraud prevention starts with the company’s internal controls.

The question every finance team should ask

When a supplier’s bank details are changed, ask:

Does someone independent verify that the new bank account actually belongs to the genuine supplier before the payment is released?

If the answer is no, there may be a control gap worth addressing.

Because sometimes the supplier is genuine.

The invoice is genuine.

The purchase is genuine.

The approval is genuine.

And yet the money still goes to the wrong person.

That is why supplier verification and payment verification should be treated as two separate controls.

Final takeaway

A genuine supplier does not automatically mean a genuine payment.

The risk can sit between the invoice and the bank transfer, particularly when supplier master data can be changed without adequate verification.

A simple, well-designed process for supplier bank-account changes, independent verification, maker-checker approval and periodic data analysis can help businesses identify and prevent potentially costly payment fraud.

The real question is not only, “Is this supplier genuine?”

It is also:

“Are we certain that the money is going to the genuine supplier?”

Disclaimer:

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.

The Role of Artificial Intelligence (AI) in Internal Auditing: Transforming Risk and Compliance

The Role of Artificial Intelligence (AI) in Internal Auditing: Transforming Risk and Compliance

Introduction

The rapid advancements in Artificial Intelligence (AI) are reshaping industries, and internal auditing is no exception. AI-powered tools are revolutionizing the way audits are conducted by automating repetitive tasks, improving risk assessment, and enhancing fraud detection. For Chartered Accountants (CAs) and internal auditors, AI offers significant opportunities to increase efficiency, accuracy, and compliance in auditing processes.

In this blog, we will explore how AI is transforming internal audits, its key benefits, and practical examples of AI applications in real-world auditing scenarios.

How AI Enhances Internal Audits

1. Automating Routine Audit Tasks

AI helps in automating repetitive and time-consuming audit tasks such as:

• Data extraction from invoices, receipts, and contracts

• Checking financial statements for compliance

• Performing reconciliations

» Practical Example: A multinational company implemented an AI-powered tool to automate bank reconciliations. The tool scanned thousands of transactions in seconds, flagged discrepancies, and reduced reconciliation time by 80%.

2. Advanced Data Analytics for Risk Assessment

AI can analyze vast amounts of financial and operational data to identify patterns and anomalies. It helps in:

• Detecting unusual transactions

• Predicting high-risk areas

• Improving audit sampling techniques

» Practical Example: An internal auditor at a financial institution used AI-driven analytics to assess loan default risks. The AI system analyzed past loan repayment behavior and identified high-risk borrowers, leading to improved credit assessment policies.

3. Fraud Detection and Prevention

AI algorithms can detect fraud by:

• Identifying suspicious transactions in real-time

• Analyzing employee expense claims

• Flagging duplicate invoices

» Practical Example: A retail chain used AI-based fraud detection software to monitor purchase transactions. The system detected irregular refund requests from specific store locations, leading to an internal investigation that uncovered employee fraud.

4. Compliance and Regulatory Monitoring

AI assists in ensuring compliance with regulations like GST, IFRS, and corporate tax laws by:

• Automating regulatory reporting

• Monitoring changes in tax and compliance rules

• Alerting auditors about non-compliance risks

» Practical Example: A CA firm integrated AI-powered compliance monitoring tools to track tax regulation changes. The tool automatically updated compliance checklists and flagged discrepancies in tax filings, reducing compliance errors.

5. Natural Language Processing (NLP) for Document Analysis

NLP enables AI to read and interpret contracts, policies, and legal documents to:

• Identify key terms and clauses

• Detect contract non-compliance

• Automate document reviews

» Practical Example: An internal audit team used AI to analyze vendor contracts. The AI tool scanned thousands of contracts, identified missing clauses, and highlighted high-risk agreements, reducing manual review efforts by 70%.

Challenges in Implementing AI in Internal Audit

While AI offers numerous benefits, some challenges include:

• High initial investment in AI tools

• Need for skilled auditors with AI expertise

• Data security concerns

• Dependence on accurate historical data for AI models

Conclusion: The Future of AI in Internal Auditing

AI is set to become an integral part of internal auditing, making audits faster, more accurate, and insightful. Chartered Accountants and internal auditors who embrace AI will be better equipped to detect risks, ensure compliance, and drive efficiency in auditing processes.

  • Are you ready to integrate AI into your internal audits? Let’s discuss how AI can revolutionize your audit approach!

Disclaimer:

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.

The Importance of Effective Audit Planning in Internal Audits

The Importance of Effective Audit Planning in Internal Audits

Introduction

Audit planning is a fundamental aspect of the internal audit function. A well-structured audit plan ensures that the internal audit aligns with an organization’s objectives, assesses risks efficiently, and allocates resources optimally. A lack of planning can lead to incomplete audits, overlooked risks, and ineffective compliance measures.

This blog provides an in-depth look at the key components of an internal audit plan, based on the internal audit checklist, covering aspects such as risk assessment, resource allocation, and governance.

Key Components of an Internal Audit Plan

1. Internal Audit Charter and Terms of Engagement

An internal audit charter outlines the scope, objectives, and authority of the internal audit function. It serves as the foundation of the audit process.

Risk: Without a well-defined audit charter, audits may not align with the organization’s overall objectives.

Control Measures: A documented audit process should be established, listing step-by-step procedures to develop an annual audit plan.

Testing Parameters: Ensure that the auditing plan covers all required areas and adheres to the annual audit planning process.

2. Business Knowledge Development

Understanding the business and regulatory environment is essential for auditors to identify key risks.

Risk: Lack of business knowledge can lead to oversight of crucial risk elements.

Control Measures: Internal audit teams should engage with internal and external stakeholders to stay updated on industry developments.

Testing Parameters: Verify interactions and research conducted by the audit team to ensure business knowledge is current.

3. Defining the Audit Universe

An audit universe includes all auditable entities, such as business units, processes, and legal entities.

Risk: Missing key risk areas in the internal audit plan can result in financial and operational setbacks.

Control Measures: Organizations must maintain an up-to-date audit universe and review it periodically.

Testing Parameters: Assess the availability, risk rating, and periodic updates of the audit universe.

4. Linkage with Enterprise Risk Management (ERM)

Integrating the audit plan with the ERM framework ensures that key business risks are effectively monitored.

Risk: If the audit planning process is not aligned with ERM, critical risks may not be addressed.

Control Measures: Input from the ERM team should be factored into the audit planning process.

Testing Parameters: Verify whether ERM inputs are utilized in formulating the overall audit plan.

5. Independent Risk Assessment for Auditable Units

Each business unit or process should undergo an independent risk assessment to prioritize high-risk areas.

Risk: Failure to conduct a risk assessment can result in inadequate audit coverage.

Control Measures: Conduct independent risk assessments of each unit and allocate resources accordingly.

Testing Parameters: Review methodologies used for risk assessments and verify coverage scope.

6. Resource and Time Allocation

Audit efficiency depends on proper allocation of skilled auditors and sufficient time for review.

Risk: Inadequate resource allocation can lead to ineffective audits.

Control Measures: Allocate resources based on the complexity and risk profile of each auditable unit.

Testing Parameters: Assess the adequacy of time and resource allocation in covering all high-risk areas.

7. Audit Plan Approval Process

The audit plan should be approved by the Audit Committee and the Board to ensure alignment with organizational priorities.

Risk: Lack of governance approval can lead to misalignment with business strategies.

Control Measures: Audit plans should be reviewed and approved at multiple levels.

Testing Parameters: Examine minutes of Audit Committee meetings to verify audit plan discussions and approvals.

8. Periodic Review of the Audit Plan

A periodic review of the audit plan ensures that it remains relevant and adaptable to emerging risks.

Risk: An outdated audit plan can derail audit objectives.

Control Measures: The Chief Audit Executive should conduct regular reviews to align the plan with business changes.

Testing Parameters: Evaluate periodic reviews to confirm alignment with the company’s strategic objectives.

Conclusion

A comprehensive audit planning process is vital for ensuring effective risk management, regulatory compliance, and operational efficiency. By incorporating structured risk assessment, stakeholder engagement, and robust governance measures, organizations can enhance their internal audit effectiveness.

For Chartered Accountants, following a detailed audit checklist and ensuring periodic reviews of the audit plan can significantly improve the quality and reliability of internal audits. By implementing these best practices, businesses can strengthen their financial and operational resilience while maintaining transparency and accountability.

Would you like additional insights on implementing this checklist in your organization? Share your thoughts in the comments! 🚀

Disclaimer:

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.

Internal Audit Decoded: Its Purpose & Vital Importance

Unlocking Business Excellence: The Value of Internal Audits

As a business owner or manager, ensuring the efficiency and effectiveness of your organization’s operations is paramount. One of the key strategies to achieving this goal is through conducting internal audits. In this blog, we explore the significance, benefits, and best practices of internal audits and how they contribute to long-term business success.

What is an Internal Audit?

An internal audit is a thorough evaluation of an organization’s internal controls, risk management processes, and governance framework. It plays a critical role in identifying potential risks, improving operational efficiency, and ensuring compliance with relevant regulations. In essence, internal audits are an essential part of an organization’s risk management strategy.

Why Are Internal Audits Important?

Internal audits provide a wide array of benefits, including:

  1. 1. Risk Management: Helps identify and mitigate potential risks that could impact the business.
  2. 2. Compliance: Ensures compliance with legal, regulatory, and industry standards.
  3. 3. Operational Efficiency: Streamlines workflows, reduces inefficiencies, and boosts productivity.
  4. 4. Financial Management: Safeguards assets and ensures accurate financial reporting.
  5. 5. Stakeholder Confidence: Strengthens trust by demonstrating a commitment to transparency, accountability, and sound governance.

Best Practices for Effective Internal Audits

To maximize the impact of internal audits, consider the following best practices:

  1. 1. Establish an Independent Audit Committee: Ensure the audit committee is independent, well-qualified, and empowered to lead the audit process.
  2. 2. Develop a Comprehensive Audit Plan: Clearly define audit objectives, scope, and key risks to ensure thorough evaluation.
  3. 3. Leverage Technology: Use audit software and tools to enhance efficiency, improve accuracy, and streamline reporting.
  4. 4. Foster a Culture of Transparency: Promote open communication and collaboration, and encourage learning from audit results.
  5. 5. Regular Monitoring and Evaluation: Continuously assess the effectiveness of internal controls and risk management strategies to maintain governance standards.

Conclusion

Internal audits are a critical element of a well-managed and well-governed organization. By embracing the significance and benefits of internal audits, businesses can not only identify areas for improvement but also mitigate risks and foster sustainable growth.

File on Time, Export with Confidence: RoDTEP Annual Return Essentials

In a recent development, the Directorate General of Foreign Trade (DGFT) has introduced the Annual RoDTEP Return (ARR) through Public Notice No. 27/2024-25, dated 23rd October 2024. This blog will break down the key aspects of the ARR, its implications, and how exporters can ensure compliance

(A) Key Highlights of Public Notice No. 27/2024-25:

 

  1. What is the Annual RoDTEP Return (ARR) 

    • The Annual RoDTEP Return (ARR) is a mandatory filing requirement for exporters who have claimed RoDTEP benefits exceeding Rs. 1 crore in a financial year. The ARR is designed to assess the nature of inputs used in export production and the actual taxes and duties incurred, as permitted under Paragraph 4.54 of the Foreign Trade Policy (FTP)
  2. Mandatory Filing of ARR

    • Who Needs to File?: Exporters (IECs) whose total RoDTEP claims exceed Rs. 1 crore in a financial year across all 8-digit HS codes. It is important note that if the total RoDTEP claim value exceeds Rs. 1 crore, the ARR must be filed, even if the actual claim received is less than Rs. 1 crore. For example – If the total RoDTEP claim value is Rs. 1,00,00,000, however, the actual claim received is Rs. 95,00,000, the exporter is required to file the Annual RoDTEP Return.
    • Deadline: The ARR for the financial year 2023-24 must be filed by 31st March 2025. Thereafter the Annual RoDTEP Return (ARR) for RoDTEP claims filed in a particular financial year shall be filed on DGFT Portal by 31st March of the next financial year.
    • Grace Period: A grace period of 3 months (until 30th June 2025) is provided for delayed filings, subject to a composition fee of Rs. 10,000. After 30th June, the fee increases to Rs. 20,000.
  3. Consequences of Non-Compliance

    • Denial of Benefits: Failure to file the ARR will result in the denial of RoDTEP benefits, and no further scroll-out of RoDTEP claims will be permitted at the Customs Port of Export after the grace period i.e. June 2025
    • Resumption of Scrolls: After paying the applicable composition fee, RoDTEP scrolls will resume within 45 days, covering Shipping Bills that were not scrolled out earlier due to non-compliance
  4. Record Keeping and Scrutiny

    • Exporters must maintain physical/digital records substantiating their duty remission claims for 5 years. These records may be required for scrutiny by the concerned authorities.
    • Certain ARR filings may be subject to IT-assisted risk-based scrutiny to assess the nature of inputs and the actual taxes/duties incurred. Exporters found to have claimed excess benefits will be required to refund or surrender the excess amount.

 

(B) Complete Guide for Filing RoDTEP Return

 

  1. Who Needs to File the Annual RoDTEP Return

    • Threshold of Rs. 1 Crore: If the total RoDTEP claim for an Importer-Exporter Code (IEC) holder exceeds Rs. 1 crore in a financial year, filing an ARR is compulsory.
    • If No Individual ITC-HS Code Crosses Rs. 50 Lakh then file the ARR only for the 8 digit HS code with the highest claim.
      •  Example:
        • HS1: Rs. 20 lakh
        • HS2: Rs. 30 lakh
        • HS3: Rs. 40 lakh
        • HS4: Rs. 30 lakh
      • ARR required only for HS3
    • If Any Individual ITC-HS Code Exceeds Rs. 50 Lakh then seperate ARR must be filed for each such HS codes.
      •  Example:
        • HS1: Rs. 60 lakh
        • HS2: Rs. 51 lakh
        • HS3: Rs. 3 lakh
        • HS4: Rs. 6 lakh
      • ARR required for HS1 and HS2.
  1. Seperate filings

    • It is important to note that seperate returns are required for exports under Domestic Tariff Area (DTA) and Special Economic Zones (SEZ)/Export-Oriented Units (EoU)/Advance Authorization (AA).
    • Example – if company is exporting 4 different HS codes through both Advance Authorization and without Advance Authorization and company has also claimed RoDTEP exceeding Rs. 50 lacs for each of the 4 HS codes then total 8 ARR (Annual RoDTEP Return) are required to be filed.
    • Details of the tax/duties/levies need to be provided in the return on pro-rata basis for export products on which the return is being filed.
  2. Step-by-Step Process to File RoDTEP Return

    • Basic Details like Name of Exporter, Type of Unit, PAN/IEC, Complete address and contact details and period of export i.e. Financial year
    • Export Product Details like 8 digit HS code, Unit Quantity Code (UQC), description of product as per shipping bill, export quantity and FOB Value.
    • Cost Component Details
      • (i) VAT and Excise duty on Inbound transportation (Road/Rail) of raw materials, suplies or part needed to make your export product.
      • (ii) VAT and Excise duty on Outbound transportation (Road/Rail) of export product from factory to the gateway port.
      • (iii) Electricity duty paid on the electricity consumed during the period.
      • (iv) Stamp duty on export documentation
      • (v) VAT and Excise paid on Fuel cost for captive power generation.
      • (vi) Embedded GST in purchases made from the unregistered dealers.
    • Details fo Incidence of tax borne by the export product on account of prior stage cumulative taxes on raw materials/inputs consumed in the manufacturing of export product like
      • (i) HS code of Input product
      • (ii) Value of Input used in the manufactur of per unit of Export product
      • (iii) Qty of input used in the manufacture of per unit of Export product
      • (iv) UQC/ Unit of measurement
      • (v) Total taxes/duties/levies paid on raw materials/input consumed
    • Total Tax/duties paid
      • Total taxes/duties paid on export product (based on above details provided)
      • Applicable RoDTEP rate as per governement policy (As mentioned in Annexure  4R and Annexure 4RE)
      • Final RoDTEP claim for the period.
  3. Common Queries and Clarifications

    • Q1. Do merchant exporters need to file ARR?
      • Yes, merchant exporters who have availed RoDTEP benefits exceeding Rs. 1 crore in a financial year are required to file the ARR. They must collaborate with the manufacturer to obtain the necessary details.
    • Q2. How to calculate taxes on fuel used for transportation?
      • If exact fuel consumption details are unavailable, exporters can use an approximation method based on a survey with transporters. This approximation should be justified and kept ready for verification

Conclusions

The RoDTEP scheme is a significant step towards making Indian exports more competitive in the global market. By understanding the intricacies of the scheme, especially the ARR filing process, exporters can ensure compliance and maximize their benefits.

For further details, refer to the RoDTEP User Guide and the relevant appendices (4R and 4RE). Stay updated with the latest notifications from the Directorate General of Foreign Trade (DGFT) to avoid any last-minute hassles.