Fraud Reporting in Banks: Auditor Duties Under CAAP

CAAP By Ashish Jain · IIBF STORE Editorial · 27 August 2026 · Updated 10 Oct 2026 · 11 min read · 94 views
Fraud Reporting in Banks: Auditor Duties Under CAAP

Fraud reporting in banks runs on two separate tracks, and the fastest way to lose marks in the CAAP paper is to merge them. Track one is regulatory: the bank itself classifies an account as fraud and reports it to the Reserve Bank of India under the Master Directions on Fraud Risk Management. Track two is statutory: the auditor who has reason to believe that an offence involving fraud has been committed reports it under Section 143(12) of the Companies Act, 2013, read with Rule 13 of the Companies (Audit and Auditors) Rules, 2014.

Different triggers, different thresholds, different forms, different deadlines. Examiners almost always test the joint between the two tracks rather than either one on its own.

🚨 When a Red Flag Becomes a Reportable Fraud

A suspicion is not a fraud. Banks operate a graded funnel, and each stage has its own documentation trail that the auditor is expected to inspect.

It begins with Early Warning Signals (EWS) thrown up by the core banking system and by field observations: sudden routing of turnover away from the lending bank, frequent devolvement of letters of credit, disputes over stock statements, related-party transactions that appear only in the borrower's books. Where enough signals cluster, the account is tagged a Red Flagged Account (RFA) and put through a time-bound investigation, usually a forensic examination of the borrower's books.

Classification as fraud is a board-level act, not a branch-level one. Under the RBI's Master Directions on Fraud Risk Management, every bank must run a board-approved fraud risk management policy and route cases through the Special Committee of the Board for Monitoring and Follow-up of Cases of Frauds. Crucially, the borrower must first be issued a show cause notice setting out the material relied upon and given a reasonable opportunity to reply, following the Supreme Court's ruling in State Bank of India v. Rajesh Agarwal (2023). A reasoned, speaking order must then record the decision.

For candidates, the practical takeaway is that an auditor cannot demand that a branch treat a defaulting account as fraud simply because recovery looks doubtful. The chapter on bank audit and the various types of audits in banks sets out where each audit stream picks up these signals, and more worked examples sit in our Certified Accounting and Audit Professional topic hub.

📋 Section 143(12): The Auditor's Personal Obligation

This is the auditor's own duty, and it survives independently of what the bank decides to do. If, in the course of performing duties as auditor, you have reason to believe that an offence involving fraud is being or has been committed against the company by its officers or employees, you must report it.

The route depends on the amount involved:

  • Rs 1 crore or above — report to the Central Government, but only after first writing to the Board or Audit Committee.
  • Below Rs 1 crore — report to the Audit Committee or the Board, and the details are then disclosed in the Board's Report.

Rule 13 fixes the clock for the higher bracket. The auditor forwards the report to the Board or Audit Committee immediately, and in any case within two days of becoming aware, seeking their reply or observations within forty-five days. On receiving the reply, the auditor forwards the report, the reply and their own comments to the Central Government within fifteen days. If no reply arrives within forty-five days, the auditor forwards the report with a note recording the absence of a reply, again within fifteen days. The communication goes to the Secretary, Ministry of Corporate Affairs, in Form ADT-4, sent by registered post with acknowledgement due or by speed post followed by e-mail. The text of the section is available on India Code.

Section 143(13) protects a good-faith report: such disclosure is not treated as a breach of the auditor's duty of confidentiality.

💡 Exam Tip: The 2-45-15 sequence is the single most examined number set in this area. Remember the order — two days to write to the Board, forty-five days for their reply, fifteen days to file with the Central Government.
Key Concepts — Certified Accounting and Audit Professional
Key Concepts — Certified Accounting and Audit Professional

🗂️ Who Reports What, and to Whom

The table below separates the obligations candidates most often blur. Only the first two filings are made by the auditor personally; the rest belong to the bank, and the auditor merely verifies that they were made.

TriggerGoverning provisionWhere the report goesAuditor files it personally?
Suspected offence of fraud of Rs 1 crore or moreSection 143(12), Companies Act 2013 with Rule 13Board or Audit Committee first, then Form ADT-4 to the Central Government✅ Yes
Suspected offence of fraud below Rs 1 croreProviso to Section 143(12) with Rule 13Audit Committee or Board; disclosed in the Board's Report✅ Yes
Account classified as fraud after due processRBI Master Directions on Fraud Risk ManagementFraud Monitoring Return to RBI; Special Committee of the Board❌ No — the bank files; the auditor verifies

A fourth stream sits alongside these. Borrowers with an aggregate exposure of Rs 5 crore and above are reported by the bank to CRILC, and a red-flagged status travels with that reporting, so peer lenders see the signal early.

Staff accountability examination and the police or CBI complaint, where warranted, follow the bank's own policy and sit outside both tracks. The provisioning consequences of a fraud classification hit the profit and loss account directly, which is why risk-adjusted pricing matters here too — see our note on RAROC based loan pricing. Current Master Directions are published on the Reserve Bank of India website; always read the version in force on your audit date.

⚠️ Common Mistake: Candidates write that the auditor reports the fraud to RBI. The auditor does not. Reporting to RBI is the bank's obligation; the auditor's statutory filing under Section 143(12) goes to the Central Government through the Ministry of Corporate Affairs.

🔍 SA 240 in the Branch: Skepticism You Can Document

SA 240, the auditor's responsibilities relating to fraud in an audit of financial statements, supplies the working method behind the reporting rules. It distinguishes fraudulent financial reporting from misappropriation of assets, and it fixes responsibility for prevention and detection on those charged with governance and on management — the auditor obtains reasonable assurance, not a guarantee.

Three requirements do most of the work in a bank branch audit. First, professional skepticism is mandatory throughout; records and explanations are accepted only after testing, however cooperative the branch team is. Second, SA 240 creates a rebuttable presumption of fraud risk in revenue recognition, which in a branch translates into scrutiny of interest application, unapplied and memorandum interest on stressed accounts, and reversals near the cut-off date. Third, the risk of management override of controls is presumed to exist in every engagement, so testing of unusual journal entries, one-sided entries and estimates for bias is not optional.

Where fraud risk is identified, the response is documented at the assertion level: changing the nature, timing and extent of procedures, adding an element of unpredictability, and involving specialists where the evidence is technical. Findings that matter are communicated to those charged with governance under SA 260 and, where they reveal control weaknesses, under SA 265.

Fraud findings also feed the branch-level narrative reporting. The Long Form Audit Report carries specific questions on frauds detected and reported during the year, and a suspected fraud in a large exposure often triggers doubt over the borrower, which links directly to the going concern assumption in bank audit.

Process & Framework — Certified Accounting and Audit Professional
Process & Framework — Certified Accounting and Audit Professional

🖥️ Catching Fraud in a Computerised Environment

Every scheduled bank runs on core banking software, so fraud detection is now largely an exercise in interrogating data rather than turning ledger pages. The auditor's evidence comes from exception reports, audit trails and system-generated returns, and the reliability of that evidence depends on the general and application controls around the system.

The high-yield areas for examination questions are consistent. Override and force-post logs show where a maker-checker control was bypassed. Dormant and inoperative account activity, especially credits followed by immediate withdrawal, is a classic misappropriation route. Repeated manual interference with the system-driven asset classification date is a red flag for income recognition fraud. Gold loan and locker operations, cash retention limit breaches, and staff accounts operated by the same officer who authorises entries all deserve targeted testing.

Computer Assisted Audit Techniques (CAATs) let the auditor test the full population rather than a sample: re-computing interest across the loan portfolio, listing entries posted outside business hours, matching supplier and staff bank details, and identifying accounts with the same address, mobile number or PAN. Two study chapters build this skill directly — audit in a computerized environment and preparation of final accounts of banks, where these exceptions eventually surface as provisions and disclosures.

Banks increasingly automate this monitoring, which is why continuous controls monitoring in bank audit now appears in CAAP questions. If you are revising the wider audit syllabus alongside this, the structured plan in our CAIIB and certification course path keeps the sequence sensible.

In Practice — Certified Accounting and Audit Professional
In Practice — Certified Accounting and Audit Professional

🧠 Practice MCQs: Fraud Reporting in Banks

Q1. Under Rule 13 of the Companies (Audit and Auditors) Rules, 2014, the auditor seeks the reply or observations of the Board or Audit Committee within what period? (a) 15 days (b) 30 days (c) 45 days (d) 60 days

Answer: (c) — The auditor's report goes to the Board or Audit Committee within two days, seeking a reply within forty-five days.

Q2. A statutory auditor must report a suspected offence involving fraud to the Central Government when the amount involved is at least: (a) Rs 25 lakh (b) Rs 1 crore (c) Rs 5 crore (d) Rs 10 crore

Answer: (b) — At Rs 1 crore and above the report goes to the Central Government; below that it goes to the Audit Committee or Board.

Q3. Which Standard on Auditing deals with the auditor's responsibilities relating to fraud in an audit of financial statements? (a) SA 240 (b) SA 230 (c) SA 260 (d) SA 315

Answer: (a) — SA 230 covers documentation, SA 260 communication with governance and SA 315 risk assessment.

Q4. Before an account is classified as fraud, the bank must: (a) obtain prior approval of RBI (b) first lodge a police complaint (c) downgrade the account to loss asset (d) issue a show cause notice and give the borrower an opportunity to respond

Answer: (d) — Principles of natural justice require a show cause notice and a reasoned order before classification.

Q5. Banks report borrower-wise credit information to CRILC once aggregate exposure reaches: (a) Rs 1 crore (b) Rs 2 crore (c) Rs 5 crore (d) Rs 10 crore

Answer: (c) — CRILC reporting applies to borrowers with aggregate exposure of Rs 5 crore and above, including red-flagged status.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does the statutory auditor report a suspected fraud directly to RBI?

No. The auditor's statutory filing under Section 143(12) is made to the Central Government in Form ADT-4, after first writing to the Board or Audit Committee. Reporting a classified fraud to RBI is the bank's obligation under the Master Directions on Fraud Risk Management.

What happens if the Board does not reply within forty-five days?

The auditor forwards the original report to the Central Government along with a note stating that no reply or observations were received, within fifteen days of the expiry of the forty-five day period. Silence from the Board does not suspend the auditor's duty.

Is a fraud below Rs 1 crore simply ignored?

No. It is reported to the Audit Committee, or to the Board where no Audit Committee exists, and the nature of the fraud, the amount involved and the parties concerned are disclosed in the Board's Report. Only the Central Government filing is dispensed with.

Can the auditor be sued for reporting in good faith?

Section 143(13) provides that a disclosure made in good faith in compliance with the section is not treated as a breach of the duty of confidentiality. The protection depends on good faith and on following the prescribed procedure and timelines.

🎯 Before You Sit the Paper

Fix three things in memory: the two-track structure, the 2-45-15 timeline with Form ADT-4, and the fact that classification as fraud needs a hearing and a reasoned order. Everything else in this area is built on those. Then test yourself under time pressure — take a free chapter-wise mock test and check whether you can separate the auditor's duty from the bank's without hesitating.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading