FACF 372 Digital Forensics and Data Analytics for Accountants – Comprehensive Exam Study Guide (NWU BCom Forensic Accountancy)

This study guide provides integrated exam-oriented notes for FACF 372: Digital Forensics and Data Analytics for Accountants in the North-West University (NWU) BCom Forensic Accountancy stream. It is geared toward South African accounting and forensic students who also compare content with modules like UNISA DSC 1630, UNISA AUE 3761, and CUT AUDI 376: Computer Auditing and Data Analytics, but the primary focus is NWU. The emphasis is on digital evidence, fraud-related data analytics, and practical exam-style applications in a South African regulatory and business context.

1. Core Concepts of Digital Forensics for Accountants

1.1 What Is Digital Forensics in the Accounting Context?

Digital forensics is the systematic process of identifying, preserving, collecting, analyzing, and presenting digital evidence in a way that is legally admissible and forensically sound. For accountants and forensic accountants, the primary aim is to support fraud examinations, financial investigations, and litigation.

Key focus areas for FACF 372:

  • Uncovering manipulation in:
    • General ledgers
    • Sub-ledgers (debtors, creditors, inventory)
    • Payroll systems
    • Point-of-sale systems
  • Supporting investigations into:
    • Asset misappropriation
    • Financial statement fraud
    • Corruption and procurement irregularities
    • Money laundering and tax evasion

Digital forensics in this context is not limited to “IT” systems; it cuts across accounting software, emails, messaging platforms, and enterprise databases that contain accounting-relevant records.

1.2 Types of Digital Evidence Relevant to Accountants

Digital evidence is any information of probative value stored or transmitted in binary form. For FACF 372, you should be able to identify, describe, and classify evidence types commonly used in financial and fraud investigations.

Typical categories:

  1. Structured accounting data

    • ERP systems (e.g., SAP, Sage 300)
    • Standalone accounting packages (e.g., Sage Pastel, QuickBooks)
    • Payroll systems (e.g., VIP, Sage 300 People)
    • Bank statement exports (CSV, MT940, PDF with embedded text)
  2. Semi-structured and unstructured data

    • Emails (Exchange, Gmail, internal servers)
    • Instant messages (Teams, WhatsApp backups, Slack)
    • Spreadsheets used as “shadow systems”
    • PDF invoices and scanned documents (with/without OCR)
  3. System and application logs

    • User login/logout logs
    • Transaction logs from accounting software
    • Audit trails (e.g., who posted and who approved journal entries)
    • Network access logs (VPN activity, firewall logs)
  4. Device-level evidence

    • Hard drives, SSDs, and external drives
    • USB flash drives and SD cards
    • Mobile phones and tablets (e.g., reimbursement evidence via banking apps)
    • Cloud storage (OneDrive, Google Drive, Dropbox, SharePoint)
  5. Meta-data

    • File creation, modification, and access times
    • Document authorship (MS Office properties)
    • Email headers (IP addresses, routing path)
    • GPS/meta-data in photos of assets, invoices, or delivery notes

In exam questions, you are often asked to:

  1. Identify relevant evidence sources, and
  2. Explain why they are relevant to a specific fraud hypothesis.

1.3 Stages of the Digital Forensic Process

Most FACF 372-style questions test your understanding of the forensic process flow and how it supports chain of evidence and legal admissibility.

A widely accepted model includes:

  1. Identification

    • Determine potential sources of evidence.
    • Example: For suspected payroll ghost employees at a municipality, identify the payroll system, HR files, bank account details, biometric clocking data, and access control logs.
  2. Preservation

    • Prevent alteration or destruction of data.
    • Actions:
      • Isolate devices (e.g., disconnect from network).
      • Take forensic images (bit-by-bit copies) using write blockers.
      • Compute and document hash values (e.g., MD5, SHA-256).
    • Objective: Maintain integrity and chain of custody.
  3. Collection

    • Acquire data in a systematic, reproducible way.
    • Techniques:
      • Live acquisition (for volatile data like RAM, active sessions).
      • Static acquisition (offline imaging of disks, copying logs).
      • Logical vs. physical acquisition, depending on scope and tools.
  4. Examination

    • Filtering and identifying relevant items.
    • Steps:
      • Keyword searches (“bribe”, “backhander”, “cash payment”).
      • Timeline reconstruction (who did what, when).
      • Recovery of deleted files (if relevant and possible).
    • For accountants, this often includes:
      • Extracting transactional data from accounting databases.
      • Identifying unusual journal entries, overrides, or backdated postings.
  5. Analysis

    • Interpreting evidence in relation to the allegation.
    • Accounting focus:
      • Linking digital records to financial statements.
      • Reconstructing missing records.
      • Identifying schemes (fictitious vendors, kickbacks).
    • Methods:
      • Data analytics (Benford’s law, ratio analysis, outlier detection).
      • Cross-referencing internal and external records (e.g., bank vs. general ledger).
  6. Reporting & Presentation

    • Prepare clear, objective, well-structured reports.
    • Content:
      • Scope, methodology, limitations.
      • Evidence summary, findings, and conclusions.
      • Impact on financial statements and control weaknesses.
    • Must be understandable by:
      • Non-technical management
      • Legal professionals
      • Regulatory bodies (e.g., SARS, FSCA, SAPS’ DPCI)

Memorise the sequence and be able to apply it to a scenario, not just recite it.

1.4 South African Legal and Regulatory Context

FACF 372 integrates digital forensics with South African law and professional guidance. While the module is not law-heavy like some UNISA LML or NWU law modules, you must understand key frameworks that shape forensic practice.

Relevant statutes and standards:

  • Criminal Procedure Act 51 of 1977

    • Regulates the admissibility of evidence in criminal courts.
    • Digital evidence must be collected and handled so that its integrity can be proven.
  • Electronic Communications and Transactions Act 25 of 2002 (ECTA)

    • Recognises admissibility of electronic evidence.
    • Section 15: Addresses data messages as evidence, requiring reliability of the manner of storage and communication.
  • Protection of Personal Information Act 4 of 2013 (POPIA)

    • Governs processing of personal data.
    • Important in forensic work:
      • Data minimisation
      • Purpose limitation
      • Security safeguards
    • In investigations, access must generally be tied to a legitimate purpose, supported by mandates.
  • Companies Act 71 of 2008

    • Requires accurate and fair recording of financial transactions.
    • Director duties include preventing and detecting fraud.
  • International Standards and Guidance

    • ACFE Fraud Examiners Manual (reference in many SA forensic courses)
    • ISACA’s IS Auditing and Digital Forensics Guidelines
    • SAICA and IRBA guidance on considering fraud (ISA 240, ISA 315, ISA 330) and use of IT.

You must be able to discuss how digital forensics findings are used in:

  • Criminal proceedings (SAPS and NPA-led)
  • Civil litigation (damages, contractual disputes)
  • Disciplinary hearings (corporate and public sector)
  • Regulatory investigations (FSCA, Prudential Authority, SARS, SIU)

1.5 Roles and Responsibilities: Accountant vs. Digital Forensic Specialist

In many smaller organisations, accountants may be called upon to perform basic digital forensic tasks. However, for high-stakes matters, specialised digital forensic experts are usually engaged.

Roles in an NWU BCom Forensic Accountancy environment:

  • Forensic Accountant

    • Designs and tests fraud hypotheses.
    • Interprets financial and transactional evidence.
    • Performs accounting-focused data analytics.
    • Works with digital forensic specialists on complex technical extractions.
  • Digital Forensic Specialist

    • Performs device imaging and recovery.
    • Handles complex log analysis and network traces.
    • Manages forensic tools and ensures technical integrity.
  • Internal/External Auditor

    • Evaluates controls relevant to fraud prevention and detection.
    • May perform continuous audit analytics.
    • Escalates to forensic team when red flags become serious.

In exam scenarios, clearly distinguish between what an accountant can do themselves (e.g., export general ledger data, perform ACL/IDEA analysis, review logs) and what requires specialist intervention (e.g., chip-off cellphone forensics, complex database carving).

2. Digital Evidence Management and Chain of Custody

2.1 Principles of Evidence Integrity

For NWU’s FACF 372, a recurring exam theme is evidence integrity: evidence must be authentic, reliable, complete, and tamper-evident.

Foundational principles:

  • Authenticity – Evidence is what it purports to be.
  • Integrity – Evidence has not been altered after collection.
  • Reliability – Evidence was collected and handled using sound, documented procedures.
  • Completeness – All relevant evidence has been considered; exculpatory evidence is not omitted.

In a digital environment, integrity is particularly fragile because:

  • Digital data is easily modified without visible traces.
  • System timestamps can be manipulated.
  • Deletion does not necessarily remove data, and recovery techniques can be questioned.

Examination elements:

  • Explain how hash values (e.g., MD5, SHA-256) confirm integrity.
  • Describe how write blockers prevent changes during imaging.
  • Discuss why screen captures without original logs may be weak evidence.

2.2 Chain of Custody: Concept and Documentation

Chain of custody is the chronological documentation showing the seizure, custody, control, transfer, analysis, and disposition of evidence. It bridges the gap between technical forensic work and legal admissibility.

Key elements that must be documented:

  • Unique evidence ID
  • Description of the item (device type, serial number, capacity)
  • Date and time of collection
  • Exact location of seizure
  • Person who collected the item (name, position, signature)
  • Every transfer: from whom, to whom, why, date and time
  • Storage conditions and access controls
  • Final disposition (returned, destroyed, handed to court)

Typical chain of custody form fields:

Field Example Entry
Case Number NWU-FACF372-2025-01
Evidence ID E-001
Item Description Dell Laptop, S/N: DL-2025-01, 512 GB SSD
Collected By A. Naidoo, Forensic Accountant
Date/Time Seized 14 May 2025, 10:32 SAST
Location Seized Finance office, Bloemfontein branch
Transfer To B. Mokoena, Digital Forensic Analyst
Date/Time Transferred 14 May 2025, 14:05 SAST
Storage Location Forensic Lab Safe, Locker 4
Hash of Forensic Image SHA-256: 8A…F3 (full string recorded)

In exam questions, you may have to:

  • Identify weaknesses in a provided chain of custody.
  • Draft or complete a simple chain of custody record.
  • Explain the consequences if chain of custody is broken (e.g., evidence may be challenged and excluded or given less weight).

2.3 Forensic Imaging and Hashing

Forensic imaging is creating an exact bit-by-bit copy of a digital storage device. It allows analysis without modifying the original, which helps protect evidence integrity.

Main points:

  • Physical (bit-stream) image: Copies every sector, including slack space and unallocated space. Preferred in most forensic contexts.
  • Logical image: Copies files and folders as visible to the file system. Suitable when storage is large and time is limited, or legal scope is restricted.

Hashing:

  • A hash function (MD5, SHA-1, SHA-256) takes data and produces a unique “fingerprint.”
  • If even a single bit changes, the hash output changes dramatically.
  • Used to:
    • Validate that the forensic image is identical to the original.
    • Demonstrate that evidence was not altered during analysis.

Typical procedure:

  1. Connect device via write blocker.
  2. Calculate pre-imaging hash of the device (if appropriate).
  3. Create a forensic image (e.g., using FTK Imager, EnCase, or open-source tools).
  4. Calculate hash of the image.
  5. Confirm that:
    • If pre-imaging hash was calculated: pre-imaging hash = post-imaging hash.
    • If direct comparison is not possible, at least ensure multiple copies share the same hash.

Exam tip: Be able to justify why analysing directly on the live system without imaging is risky:

  • System activity can change logs and timestamps.
  • Malware or anti-forensic techniques might obscure evidence.
  • Defence can argue that the investigator contaminated the evidence.

2.4 Handling Live Systems vs. Dead Systems

Live forensics involves acquiring data from a running system, while dead forensics involves working on a powered-off, imaged copy.

Accounting-focused scenarios:

  • Live system:
    • When investigating a suspected fictitious vendor scheme in an ERP that is actively used.
    • Need to capture:
      • Logged-in users.
      • Running processes on the server.
      • Active network connections (e.g., exfiltration to external accounts).
      • Volatile memory containing decryption keys (for encrypted databases).
  • Dead system:
    • When a suspect’s laptop is seized outside working hours.
    • Appropriate to power down (if no risk of losing volatile data critical to the case) and image safely.

Weighing factors:

  • Volatility of evidence – If critical evidence is only in RAM, live capture may be necessary.
  • Risk of contamination – Interacting with a live system can alter logs and data.
  • Business impact – Shutting down a server can disrupt operations.

In FACF 372-style exam questions, evaluate the trade-offs and justify your chosen approach.

2.5 Secure Storage and Access Control

After acquisition, evidence must be stored securely to prevent tampering and unauthorised access.

Good practices:

  • Physical:

    • Locked evidence room with limited authorised personnel.
    • Environmental controls (e.g., temperature, humidity) to protect devices and media.
    • CCTV and access logs.
  • Logical:

    • Encrypted storage (e.g., BitLocker, VeraCrypt) for forensic images.
    • Role-based access control:
      • Only analysts assigned to the case access that case’s data.
    • Audit trails of who accessed which image, when, and for what purpose.

Forensic lab policies often include:

  • No internet-connected analysis workstations for sensitive cases.
  • Separate storage for working copies and archival copies.
  • Regular backups, with off-site redundancy.

Exam link: When asked to design an evidence management policy or “forensic lab controls” for a mid-sized firm in Johannesburg, include:

  • Physical and logical safeguards
  • Documentation and monitoring
  • Backup and disaster recovery
  • Alignment with POPIA (e.g., access only on a need-to-know basis)

2.6 Common Pitfalls and Anti-Forensics Tactics

Accountants must be alert to anti-forensic behaviour that may undermine evidence:

  • Deletion and wiping tools

    • Removing files and clearing recycle bins.
    • Using secure delete utilities (e.g., overwriting with random data).
  • Timestamp manipulation

    • Changing system clocks.
    • Using utilities that alter file-created/modified timestamps.
  • Encryption and steganography

    • Encrypted containers (e.g., VeraCrypt, BitLocker, password-protected archives).
    • Hiding data in images or other files.
  • Log tampering

    • Disabling audit trails.
    • Editing log files to remove incriminating actions.

As a forensic accountant, you might:

  • Notice suspicious gaps in logs.
  • Observe abrupt changes in volume or patterns of transactions that might indicate data destruction.
  • Flag inconsistencies between system logs and business processes (e.g., approvals allegedly recorded outside any manager’s working hours).

In the exam, be prepared to identify red flags that point to anti-forensic tactics and suggest mitigation steps (e.g., retrieving logs from backup, using external logs such as bank transaction histories, ISP records, or third-party service providers).

3. Foundations of Data Analytics for Fraud and Forensic Accounting

3.1 Role of Data Analytics in NWU BCom Forensic Accountancy

In modern South African organisations, the volume of transactional data is too large for manual review. Data analytics is a core tool for:

  • Fraud detection and investigation
  • Control testing and continuous auditing
  • Risk assessment and monitoring

FACF 372 emphasises practical analytic techniques similar to those seen in:

  • UNISA’s DSC 1630: Introduction to Databases and Data Analysis
  • CUT’s AUDI 376: Computer Auditing and Data Analytics
  • UNISA’s AUE 3761: Computer Auditing

Accountants are expected to:

  • Define analytics objectives.
  • Extract and clean data from accounting systems.
  • Apply basic statistical and rule-based tests.
  • Interpret results, focusing on red flags and fraud schemes.

3.2 Data Life Cycle: From Raw Data to Evidence

Key stages:

  1. Data Identification and Scoping

    • Clarify the question:
      • Example: “Are there kickbacks or conflicts of interest in supplier payments from 2022–2024?”
    • Identify relevant data sources:
      • General ledger, AP sub-ledger
      • Supplier master file
      • Employee master file
      • Bank statements
  2. Data Extraction

    • Methods:
      • Direct exports from ERP (CSV, Excel, TXT).
      • Database queries (SQL).
      • Screen scraping or OCR for legacy systems.
    • Critical to document:
      • Who extracted the data.
      • Parameters and filters applied.
      • Extraction date and time.
  3. Data Cleaning and Preparation

    • Standardisation of:
      • Dates (e.g., YYYY-MM-DD)
      • Currency values (two decimals)
      • Vendor names (removing punctuation, normalising cases).
    • Handling missing values:
      • Decide whether to exclude, impute, or flag as anomalies.
    • Removing duplicate records and confirming record completeness.
  4. Data Integration

    • Combining data from multiple systems:
      • Matching supplier IDs from ERP to bank accounts in treasury system.
      • Linking employee data to vendor directors’ names for conflict-of-interest analysis.
  5. Analysis

    • Applying rules, statistics, and visualisation techniques.
    • Generating exception reports and anomaly lists.
  6. Interpretation and Follow‑up

    • Assess whether anomalies are:
      • Fraud indicators
      • Control weakness indicators
      • Benign operational issues
    • Plan follow-up steps:
      • Detailed testing
      • Document examination
      • Interviews
  7. Documentation and Reproducibility

    • Preserve scripts, queries, and intermediate results.
    • Rationale for parameter choices.
    • This supports both forensic rigor and potential court scrutiny.

3.3 Common Analytic Techniques for Fraud Detection

FACF 372 requires familiarity with a set of core analytic techniques. You must not only define them but also apply them in a South African business scenario.

3.3.1 Benford’s Law

  • Benford’s law predicts the frequency distribution of first digits in naturally occurring sets of numbers.
  • In many datasets (e.g., invoice amounts, expense claims), digit “1” should appear as the first digit around 30% of the time, and digit “9” around 4.6%.
  • Fraudsters who fabricate numbers often fail to mimic this distribution.

Application:

  • Use to test:
    • Expense reimbursements
    • Vendor invoices
    • Travel and entertainment claims
  • Limitations:
    • Works best on large datasets that span several orders of magnitude.
    • Not suitable for assigned numbers (e.g., invoice numbers) or capped values (e.g., per diem limits).

Exam expectation:

  • Explain conceptually.
  • Interpret a simple table of observed vs. expected frequencies.
  • Recognise that a significant deviation is a red flag, not proof of fraud.

3.3.2 Ratio and Trend Analysis

Using financial and operational ratios over time or between peers:

  • Examples:
    • Gross margin percentages by branch or product.
    • Expense-to-revenue ratios.
    • Receivable days vs. sector norms.

Fraud indicators:

  • Sudden, unexplained changes (e.g., cost of sales dropping relative to revenue may indicate premature revenue recognition).
  • Outliers relative to similar units (e.g., one branch with consistently higher discounts or write-offs).

Link to digital data:

  • Extract ratios directly from ERP reports or analytics tools.
  • Use visualisations (line graphs, dashboards) to detect anomalies.

3.3.3 Outlier and Exception Testing

Rule-based or statistical tests to find unusual items:

  • Rule-based:

    • Payments > R100 000 without secondary approval.
    • Weekend or public holiday postings.
    • Journal entries posted by users outside their normal departments.
    • Vendors with no tax number or physical address.
  • Statistical:

    • Z‑score analysis for unusual transaction amounts.
    • Boxplot-based outliers for expense categories.

In exam scenarios:

  • Propose at least 5–7 specific rules relevant to the scenario.
  • Explain why each rule is linked to potential fraud schemes (e.g., splitting invoices to avoid approval thresholds).

3.3.4 Duplicate and Fuzzy Matching

Duplicate analysis:

  • Identify identical:
    • Vendor names
    • Bank account numbers
    • Invoice numbers
    • Payment amounts and dates

Fuzzy matching:

  • Detect near-duplicates despite minor differences:
    • “ABC Trading cc” vs. “A.B.C. Trading CC”
    • Typos in names and addresses.

Fraud schemes detected:

  • Duplicate payments to same invoice.
  • Shell companies (e.g., employee-related vendors).
  • Intentional splitting or duplication to bypass controls.

Tools:

  • ACL/CaseWare IDEA.
  • Excel (with helper columns using functions like SOUNDEX-type logic or string similarity add-ins).
  • SQL Full-Text or LIKE-based matching.

3.4 Linking Analytics to Specific Fraud Schemes

Accountants must connect analytic methods to concrete fraud patterns:

  1. Fictitious Vendors

    • Tests:
      • Vendor created by same user who approves payments.
      • Vendor bank accounts matching employee accounts.
      • Vendors with PO Box only, no physical address, in high-risk locations.
    • Data sources:
      • AP master file, HR master data, bank details, user access logs.
  2. Kickbacks in Procurement

    • Tests:
      • Vendors linked to employees via surnames, IDs, or addresses.
      • Unusual price variances vs. market benchmarks.
      • Repeated use of the same supplier without tender.
    • Data sources:
      • Tender records, vendor database, employee data, comparative quotes.
  3. Payroll Ghost Employees

    • Tests:
      • Employees with no ID numbers or duplicated ID numbers.
      • Multiple employees sharing the same bank account or address.
      • Salaries paid to staff not recorded in HR records or access control system.
    • Data sources:
      • Payroll and HR master, time/attendance logs, access control records.
  4. Financial Statement Manipulation

    • Tests:
      • End-of-period large manual journal entries.
      • Reclassifications between expense and capital accounts.
      • Unusual revenue cut-off around year-end.

The exam often presents a short scenario and asks for:

  • The likely fraud scheme(s).
  • Specific data analytic tests.
  • The data fields and systems required.

3.5 Interpreting Results: False Positives and False Negatives

Anomalies are not necessarily fraud. Examine:

  • False positives – Legitimate transactions flagged as suspicious.
  • False negatives – Fraudulent transactions not flagged by the analytics.

Factors:

  • Poorly chosen thresholds (too low or too high).
  • Incomplete or poor-quality data.
  • Overreliance on a single test type (e.g., Benford only).

Good exam answers:

  • Acknowledge limitations of analytics.
  • Emphasise need for triangulation:
    • Combine multiple tests.
    • Use interviews and document inspections.
    • Review control design and context.

4. Tools, Techniques, and Exam-Style Application

4.1 Standard Tools in Digital Forensics and Data Analytics

While FACF 372 is not a pure tools course, you must understand categories and realistic examples that are also referenced in courses like UNISA ECS 2601 IT for Accountants and CUT AUDI 376.

4.1.1 Forensic Imaging and Analysis Tools

  • Commercial tools:

    • EnCase Forensic
    • FTK (Forensic Toolkit)
    • X-Ways Forensics
  • Open-source / Free:

    • Autopsy / Sleuth Kit
    • dd (Linux command-line imaging)
    • Magnet RAM Capture for memory capture

Functions:

  • Disk imaging
  • File carving (recovering deleted files)
  • Timeline analysis
  • Keyword search
  • Email extraction and reconstruction

Know what they do, not how to operate every function.

4.1.2 Data Analytics and Computer Auditing Tools

  • Audit-focused:
    • CaseWare IDEA
    • ACL Analytics
  • General-purpose:
    • Microsoft Excel (incl. Power Query, pivot tables)
    • SQL (MySQL, SQL Server, Oracle)
    • Python (pandas) and R (for advanced users, often in honours/masters)
  • BI and visualisation:
    • Power BI
    • Tableau

In FACF 372 exam context, clearly articulate:

  • Why using SQL is appropriate for querying large ERP databases.
  • How Excel might be sufficient for smaller datasets, but with higher risk of errors.
  • How ACL/IDEA streamline repetitive controls and fraud tests.

4.2 Designing an Analytics Plan (Exam-Style Framework)

You are often asked to design an analytics plan given a scenario. Use a structured approach:

  1. Objective

    • Example: “Identify unusual vendor payments that might indicate fictitious vendors or kickbacks for financial years 2023–2024.”
  2. Data Sources and Fields

    • AP transactions:
      • Invoice number, date, vendor ID, amount, GL account, user ID.
    • Vendor master:
      • Vendor name, bank account, registration number, VAT number, address.
    • HR master:
      • Employee name, ID number, bank account, physical address.
    • Logs:
      • System user access logs, changes to vendor master.
  3. Specific Analytics Tests

    • Duplicate invoice numbers and amounts.
    • Payments to vendors sharing bank accounts with employees.
    • Vendors created and first-paid within the same month.
    • Large payments just below approval thresholds.
  4. Tools

    • Data extraction via SQL from ERP.
    • Analysis in ACL or Excel.
  5. Expected Output

    • Exception list of high-risk transactions with key fields.
    • Summary statistics (counts, totals, percentages).
    • Visual dashboards for management presentation (optional).
  6. Follow-up Actions

    • Review supporting documents (contracts, invoices).
    • Conduct background checks on suspicious vendors.
    • Interview relevant staff.

4.3 Case Study 1: Municipal Procurement Fraud

Scenario (aligned with typical NWU case material):

  • A mid-sized municipality in the North West Province suspects inflated contracts with certain road maintenance suppliers.
  • The internal audit team includes a BCom Forensic Accountancy graduate trained in FACF 372.
  • Suspected schemes:
    • Collusion between officials and suppliers.
    • Kickbacks paid to municipal employees.
    • Overbilling through change orders.

Analytics Plan:

  1. Objective

    • Identify anomalous patterns in procurement and payments to road maintenance suppliers from 2022–2024.
  2. Data Sources

    • Procurement/tender records:
      • Tender number, description, winner, amount, competing bids.
    • AP vouchers:
      • Vendor, invoice number, date, amount, project code.
    • Supplier master file:
      • Registration number, directors, bank accounts, address.
    • Employee master:
      • Positions, responsibilities, related-party declarations.
    • Bank statements (if accessible via court order or voluntarily supplied by vendors).
  3. Tests

    • Bid rotation and pattern analysis:
      • Frequent awards to a small cluster of vendors.
      • Vendor A wins one contract, Vendor B wins the next, in repeated sequence.
    • Price comparison:
      • Compare contract rates per kilometre of road surfaced vs. neighbouring municipalities.
      • Identify above-market pricing without clear justification.
    • Change order analysis:
      • Contracts that significantly exceeded initial award value.
      • Many small changes pushing final cost above budget.
    • Conflict-of-interest analysis:
      • Vendor directors’ surnames or addresses matching employees.
      • Employee declarations missing suppliers later shown to be related parties.
  4. Interpretation

    • Transactions flagged must be investigated substantively:
      • Cross-check physical work performed (site visits, engineering reports).
      • Interview procurement and project managers.
      • Review email correspondence for collusive intent.

Exam answer expectations:

  • Provide at least 5–7 well-explained tests.
  • Integrate both quantitative analytics and qualitative follow-up.
  • Explicitly mention use of digital forensic retrieval of emails and logs to support analytics findings.

4.4 Case Study 2: Payroll Ghost Employees in a Manufacturing Company

Scenario:

  • A Gauteng-based manufacturer with 700 employees suspects ghost employees on the payroll.
  • The company uses a biometric time-and-attendance system and a separate payroll system.

Analytics Plan:

  1. Objective

    • Detect ghost employees and other payroll irregularities from January 2023 to December 2024.
  2. Data Sources

    • Payroll master:
      • Employee ID, name, ID number, bank account, salary, start/end dates.
    • HR records:
      • Contracts, physical files, address, emergency contacts.
    • Time-and-attendance (T&A):
      • Clock-in/clock-out logs, biometric IDs.
    • Physical access control logs.
    • Bank statement exports for payroll account.
  3. Tests

    • Master file integrity:
      • Employees with missing or invalid South African ID numbers.
      • Duplicate bank accounts across multiple employees.
      • Employees without physical addresses.
    • Attendance vs. payroll comparison:
      • Employees paid but with zero T&A records over several pay periods.
      • T&A logins outside typical working locations (where relevant).
    • Bank transaction analysis:
      • Compare payroll run totals to GL postings.
      • Check for multiple manual payments outside routine payroll cycles.
    • Hire/termination patterns:
      • Employees hired and terminated within a few months, with minimal T&A but full salaries.
  4. Techniques and Tools

    • Use SQL or Excel Power Query to join payroll and T&A data on employee IDs.
    • Pivot tables or summary reports to highlight employees with high salaries but minimal attendance.
    • Exception lists sorted by risk indicators (multiple issues per employee).
  5. Follow-up

    • Physical headcount verification.
    • HR file review for flagged employees.
    • Interviews with supervisors.

Exam angle:

  • Demonstrate understanding of how to reconcile digital traces across systems (payroll vs. T&A vs. bank).
  • Emphasise the importance of corroborating evidence, not accusing employees based solely on analytics.

4.5 Reporting and Communication of Digital Findings

A well-structured forensic report is vital. Elements:

  1. Background

    • Who engaged the investigation.
    • Purpose and scope.
  2. Methodology

    • Digital evidence acquisition:
      • Devices imaged, tools used, hash values.
    • Data analytics:
      • Data sources, tests performed, and tools used.
  3. Findings

    • Present key exceptions and patterns.
    • Use clear tables and, where appropriate, charts.
    • Use appendices for detailed exception lists.
  4. Conclusion

    • Summarise overall assessment of fraud risk or incident.
    • Quantify financial impact where possible.
  5. Recommendations

    • Control improvements.
    • Further investigation or disciplinary action.
    • System and log management enhancements.

In exams, you may be asked to outline a report or draft key findings paragraphs. Marks are awarded for:

  • Clarity and conciseness.
  • Proper linkage between evidence, findings, and conclusions.
  • Neutral, professional language without legal overreach (avoid declaring guilt—stick to evidence).

5. Exam Preparation Strategies and Integrated Revision Themes

5.1 How FACF 372 Fits within NWU BCom Forensic Accountancy

Within the NWU BCom Forensic Accountancy stream, FACF 372 connects with:

  • Financial Accounting modules (e.g., FACF 271/272):
    • Understanding accounting entries, controls, and financial statement assertions.
  • Auditing and Assurance modules:
    • ISA 240 (fraud considerations)
    • Risk assessment procedures
    • Internal control evaluations
  • Law and Ethics components:
    • Evidence law (for admissibility)
    • Professional ethics (IRBA, SAICA, ACFE)

Digital forensics and data analytics bring a technology lens to this foundation. Exam questions frequently expect you to:

  • Refer to accounting assertions (existence, completeness, valuation) and show how digital evidence supports or challenges them.
  • Relate analytics results to control weaknesses and risk assessment narratives.
  • Demonstrate awareness of ethical boundaries (e.g., POPlA compliance) when accessing employee data.

5.2 High-Yield Topics and Typical Question Patterns

Focus your revision on topics that historically carry significant weight:

  1. Digital Forensic Process

    • Sequence (identification, preservation, collection, examination, analysis, reporting).
    • Application in case scenarios.
  2. Chain of Custody and Evidence Integrity

    • Concepts of hash values and forensic imaging.
    • Drafting or critiquing chain of custody records.
  3. Data Analytics Techniques

    • Benford’s law, duplicate detection, trend analysis, outlier detection.
    • Scenario-based application.
  4. Fraud Schemes and Analytics

    • Fictitious vendors, payroll fraud, revenue manipulation, procurement collusion.
    • How to link patterns in data to these schemes.
  5. South African Context

    • Roles of ECTA, POPIA, Companies Act, and Criminal Procedure Act in digital evidence.
    • Use of digital evidence in disciplinary vs. criminal matters.
  6. Practical Application

    • Mini case studies similar to those in CUT’s AUDI 376 or UNISA’s AUE 3761.
    • Designing an analytics plan for a specific industry (e.g., retail, manufacturing, public sector).

Question types you might encounter:

  • Short theory questions:

    • Define and explain terms (e.g., chain of custody, forensic image).
    • List and briefly describe stages of the digital forensic process.
  • Application questions:

    • Given a scenario, propose data analytic tests.
    • Identify weaknesses in evidence handling.
  • Integrated case studies (long-form):

    • Up to 20–30 marks.
    • Require multi-step analysis:
      • Identify fraud risks.
      • Propose analytics.
      • Discuss digital forensic procedures.
      • Reflect on legal and ethical issues.

5.3 Study Techniques and Practice Approaches

To prepare effectively:

  1. Concept Mapping

    • Draw links between:
      • Fraud schemes ↔ Data analytic tests ↔ Digital evidence types ↔ Legal/ethical constraints.
    • Example: “Ghost employees → Payroll and T&A analytics → Device logs and audit trails → POPIA constraints on personal information.”
  2. Case Study Practice

    • Create your own mini scenarios based on:
      • Municipal corruption
      • Retail stock shrinkage
      • Online banking fraud
    • For each, outline:
      • Data sources
      • Tests
      • Expected red flags
      • Follow-up procedures
  3. Tool Familiarity

    • Even if you do not use all tools in depth:
      • Practise in Excel: pivot tables, filters, conditional formatting, basic formulas for exception tests.
      • If possible, experiment with ACL/IDEA or open-source alternatives for hands-on understanding.
  4. Law and Standards Integration

    • Summarise how:
      • ECTA recognises electronic evidence.
      • POPIA constrains indiscriminate access to personal data.
      • ISA 240 and 315 tie into digital fraud detection responsibilities.
  5. Past Paper Review

    • If previous FACF 372 papers or sample questions are available:
      • Time yourself.
      • Analyse the marking guidelines.
      • Note recurring themes and favourite topics.

5.4 Common Exam Mistakes to Avoid

  1. Over-Technical Answers

    • Spending too much time describing specific software commands or low-level IT details.
    • The exam expects conceptual understanding and application, not system admin manuals.
  2. Missing the Accounting/Fraud Link

    • Describing analytics techniques but not tying them to fraud schemes or financial impacts.
    • Always show why the test matters from a forensic/accounting perspective.
  3. Ignoring Legal and Ethical Constraints

    • Proposing access to private devices or social media without any legal basis.
    • Not mentioning POPIA when handling employee personal data.
  4. Weak Structure in Case Study Answers

    • Jumping between ideas without logical flow.
    • Instead, structure answers:
      • Background/context
      • Risks identified
      • Analytics planned
      • Evidence management and legal aspects
      • Conclusion/recommendations
  5. Assuming Anomalies Equal Fraud

    • Failing to acknowledge the possibility of legitimate explanations.
    • Good answers mention:
      • Need for corroboration.
      • Role of interviews and document inspection.

5.5 Integrating Knowledge with Other South African University Modules

While the core of this guide focuses on NWU’s FACF 372, many students benchmark content against modules such as:

  • UNISA DSC 1630 – For query design, data handling, and database concept foundations.
  • UNISA AUE 3761 – For computer auditing, IT controls, and data-driven audit procedures.
  • CUT AUDI 376 – For computer auditing and data analytics in a more applied environment.

Cross-institution themes that reinforce FACF 372 content:

  • IT General Controls (ITGCs) and their relevance to digital evidence integrity:
    • Change management, access controls, backup and recovery.
  • Application Controls in accounting systems:
    • Input validation, processing controls, output controls.
  • Continuous Auditing and Continuous Monitoring:
    • Embedding analytics to run periodically or in real time.
  • Governance and Risk Frameworks:
    • King IV’s emphasis on technology and information governance.
    • How boards of South African companies are expected to oversee IT and data-related risks.

Using those comparisons can help deepen understanding but in the FACF 372 exam, keep your references anchored in NWU’s curriculum and terminology.

5.6 Final Checklists for the Exam

Use the following condensed checklists in your final revision days.

Digital Forensics Process Checklist:

  • Can I define digital forensics for accountants?
  • Do I remember and understand each step: identify → preserve → collect → examine → analyse → report?
  • Can I explain hashing, forensic imaging, and their purpose?
  • Do I understand chain of custody requirements?
  • Can I articulate at least three key South African legal frameworks affecting digital evidence?

Data Analytics Checklist:

  • Can I describe the full data life cycle from extraction to reporting?
  • Do I know at least 5–7 core analytic techniques and corresponding fraud risks?
  • Can I design a simple analytics plan given a scenario (e.g., fictitious vendors, ghost employees)?
  • Do I know typical data fields and sources for common fraud schemes?

Case Study & Reporting Checklist:

  • Can I structure a long-form answer with:
    • Background
    • Risks
    • Analytics
    • Digital forensic procedures
    • Legal/ethical considerations
    • Conclusions?
  • Can I outline a forensic report (sections and content)?
  • Do I know how to tie analytics findings to financial impact and control weaknesses?

A solid grasp of digital evidence handling, forensic process discipline, and targeted data analytics will allow NWU BCom Forensic Accountancy students to approach the FACF 372 Digital Forensics and Data Analytics for Accountants examination with confidence. Consistently practise scenario-based reasoning, emphasising both technical correctness and accounting relevance, and align your answers with South African legal and professional standards.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare