<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-28-2162</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v28i1.2162</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Forensic data analytics as an information management capability for fraud detection</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-4871-1680</contrib-id>
<name>
<surname>Maruatle</surname>
<given-names>Letebele D.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-2323-2483</contrib-id>
<name>
<surname>Rama</surname>
<given-names>Pranisha</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>Department of Accounting, Faculty of Business and Economics, University of Johannesburg, Johannesburg, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Pranisha Rama, <email xlink:href="pranishar@uj.ac.za">pranishar@uj.ac.za</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>13</day><month>07</month><year>2026</year></pub-date>
<pub-date pub-type="collection"><year>2026</year></pub-date>
<volume>28</volume>
<issue>1</issue>
<elocation-id>2162</elocation-id>
<history>
<date date-type="received"><day>05</day><month>02</month><year>2026</year></date>
<date date-type="accepted"><day>29</day><month>04</month><year>2026</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026. The Authors</copyright-statement>
<copyright-year>2026</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>Fraudsters increasingly rely on electronic evidence to conceal their activities. As digital environments become more complex and organisations depend more heavily on electronic data, traditional audit methods are often insufficient for detecting fraud.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>This study investigates how technology-based audit tools, particularly generalised audit software and data analytics techniques, are applied to detect fraud in a petrochemical company.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>A qualitative design was employed, combining a literature review with a single-case study of 23 forensic audit engagements conducted between 2024 and 2025. The data were coded thematically and organised into analytical categories.</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>The findings highlighted that both proactive and reactive forensic data analytics (FDA) approaches are complementary in fraud detection, enhancing internal controls and providing assurance services.</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>Rapid advances in technology, data and telecommunications have enabled increasingly sophisticated forms of economic crime. In this context, forensic auditing supported by data analytics has become an essential fraud-detection technique.</p>
</sec>
<sec id="st6">
<title>Contribution</title>
<p>This study offers practitioners a structured and standardised approach for applying FDA to improve the effectiveness of organisational fraud detection.</p>
</sec>
</abstract>
<kwd-group>
<kwd>data analytics</kwd>
<kwd>forensic audit</kwd>
<kwd>fraud data analytics</kwd>
<kwd>fraud detection</kwd>
<kwd>information management</kwd>
</kwd-group>
<funding-group>
<funding-statement><bold>Funding information</bold> This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</funding-statement>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>In recent years, many organisations have invested in Information Technology to enhance service delivery, improve business processes and increase profitability (McKinsey <xref ref-type="bibr" rid="CIT0030">2020</xref>). This digital transformation has resulted in the exponential growth of electronic data, which, while enabling efficiency, has also introduced complexities that expose organisations to fraud and cybercrime (Putra et al. <xref ref-type="bibr" rid="CIT0040">2022</xref>; Vera-Baquero &#x0026; Colomo-Palacios <xref ref-type="bibr" rid="CIT0057">2013</xref>). As fraudsters exploit technological vulnerabilities, auditors are increasingly required to be proficient in advanced audit technologies to safeguard organisational data and integrity (Eulerich et al. <xref ref-type="bibr" rid="CIT0020">2023</xref>).</p>
<p>Computer-aided audit techniques and tools (CAATs) were developed to assist auditors in extracting, testing and interpreting computer-generated data. Common CAATs include generalised audit software, expert systems, utility software, test data and application tracing and mapping (Global Technology Audit Guide [GTAG] <xref ref-type="bibr" rid="CIT0021">2009</xref>; Lambrechts et al. <xref ref-type="bibr" rid="CIT0028">2011</xref>). More recently, data analytics has extended the functionality of CAATs by enabling auditors to design procedures that detect fraud, misstatements and errors in financial information (Suyts, Shadrin &#x0026; Leonov <xref ref-type="bibr" rid="CIT0053">2017</xref>). This development reflects the growing need for fraud-prevention mechanisms that protect not only profitability but also business continuity, economic stability and social responsibility (Isa &#x0026; Chakraborty <xref ref-type="bibr" rid="CIT0026">2022</xref>; Samagaio &#x0026; Diogo <xref ref-type="bibr" rid="CIT0047">2022</xref>).</p>
<p>The Association of Certified Fraud Examiners (ACFE) reported that in 2018, 63&#x0025; of fraud concealment involved manipulation of physical and electronic data, rising to 76&#x0025; in 2020 (ACFE <xref ref-type="bibr" rid="CIT0003">2018a</xref>, <xref ref-type="bibr" rid="CIT0004">2018b</xref>, <xref ref-type="bibr" rid="CIT0005">2020</xref>). By 2022, electronic evidence concealment had become the most common method used by fraudsters, often exploiting emerging technologies such as blockchain (ACFE <xref ref-type="bibr" rid="CIT0006">2022</xref>). Similarly, PricewaterhouseCoopers (PwC) found that 53&#x0025; of organisations reported financial losses resulting from fraud, primarily driven by external offenders exploiting weak internal processes (PwC <xref ref-type="bibr" rid="CIT0039">2022</xref>). Empirical evidence underscores the scale of the challenge posed by fraud and economic crime (EC).</p>
<p>Fraud detection remains inherently complex because perpetrators deliberately manipulate systems to conceal their actions, departing from expected behaviour (Pacini et al. <xref ref-type="bibr" rid="CIT0038">2019</xref>). Traditional audit methods often fail to detect such anomalies, particularly in organisations with complex structures and large volumes of data (Brahimi &#x0026; Elhussein <xref ref-type="bibr" rid="CIT0012">2023</xref>; Cybersource <xref ref-type="bibr" rid="CIT0017">2021</xref>). Scholars highlight challenges such as incomplete records, undersampling and evolving fraudulent patterns that complicate detection (Seify et al. <xref ref-type="bibr" rid="CIT0049">2022</xref>; West &#x0026; Bhattacharya <xref ref-type="bibr" rid="CIT0060">2016a</xref>). At the same time, data analytics has demonstrated its ability to uncover hidden patterns and anomalies, offering auditors a more reliable basis for fraud detection in computerised environments (Sawangarreerak &#x0026; Thanathamathee <xref ref-type="bibr" rid="CIT0048">2021</xref>).</p>
<sec id="s20002">
<title>Problem statement</title>
<p>Despite growing interest in audit technology, the literature offers limited evidence on how forensic auditors operationalise data analytics in actual fraud investigations, particularly within complex South African organisations. Many studies rely on models, surveys or sampled transactions rather than full case evidence, leaving a gap in understanding how data analytics functions as an information management capability in practice. This study addresses that gap by examining how forensic data analytics (FDA) is applied to support fraud detection and audit processes within a petrochemical company.</p>
</sec>
<sec id="s20003">
<title>Theoretical framework</title>
<p>This study uses fraud triangle theory as its theoretical lens because it explains the conditions under which fraud emerges and highlights the points at which data analytics can assist.</p>
</sec>
<sec id="s20004">
<title>Fraud triangle theory</title>
<p>The fraud triangle comprises opportunity, pressure and rationalisation (Tickner &#x0026; Button <xref ref-type="bibr" rid="CIT0054">2021</xref>). Opportunity refers to weaknesses in controls or oversight that allow misconduct to occur; pressure reflects the financial or organisational incentives that motivate wrongdoing and rationalisation explains how perpetrators justify their unethical behaviour. In this study, FDA is positioned primarily as a mechanism for reducing opportunity by identifying control breakdowns, anomalous transactions and patterns that warrant investigation while also providing evidence that may reveal indicators of pressure and rationalisation.</p>
</sec>
</sec>
<sec id="s0005">
<title>Literature review</title>
<p>The literature review moves from the respective roles of auditors in fraud detection to technology-enabled fraud, analytical tools and anomaly-detection challenges that motivate the use of FDA in practice. Internal, external and forensic auditors play complementary roles in fraud detection and prevention. Vanasco, Skousen and Verschoor (<xref ref-type="bibr" rid="CIT0056">1995</xref>) argue that external auditors provide an independent evaluation of financial statements to assure stakeholders of their accuracy and the absence of material misstatement. According to the Institute of Internal Auditors (IIA <xref ref-type="bibr" rid="CIT0025">2016</xref>), internal auditors focus on the effectiveness of internal controls and risk management through continuous monitoring. Forensic auditors intervene when fraud is suspected or detected, conducting investigations to determine the extent of activities and gather evidence for legal proceedings (Olaoye &#x0026; Olanipekun <xref ref-type="bibr" rid="CIT0037">2018</xref>).</p>
<p>Fraud is defined as intentional misrepresentation resulting in actual or potential prejudice (the Southern African Legal Information Institute [SAFLII] <xref ref-type="bibr" rid="CIT0045">2007</xref>; Snyman <xref ref-type="bibr" rid="CIT0051">2002</xref>). High-profile cases such as Steinhoff International and Venda Building Society (VBS) Mutual Bank illustrate the evolving and often systemic nature of fraud in South Africa (Van Wyk <xref ref-type="bibr" rid="CIT0055">2020</xref>). The fraud triangle opportunity, pressure and rationalisation offer a useful framework for understanding the motivations underlying fraudulent behaviour (Tickner &#x0026; Button <xref ref-type="bibr" rid="CIT0054">2021</xref>). As electronic data volumes continue to grow, traditional auditing methods based on sampling and manual review are increasingly inadequate for detecting complex and technology-enabled fraud (Rakipi, De Santis &#x0026; D&#x2019;Onza <xref ref-type="bibr" rid="CIT0041">2020</xref>; Zhu et al. <xref ref-type="bibr" rid="CIT0067">2021</xref>).</p>
<p>Ikhsan et al. (<xref ref-type="bibr" rid="CIT0023">2022</xref>) assert that, unlike traditional fraud, technology-enabled fraud can be perpetrated remotely and may be more difficult to trace to perpetrators. Generalised audit software plays a central role in modern auditing. Tools such as Audit Command Language and Interactive Data Extraction and Analysis enable auditors to import, consolidate and analyse large datasets from organisational systems and spreadsheets (Boritz &#x0026; Datardina <xref ref-type="bibr" rid="CIT0010">2007</xref>; Widuri, Handoko &#x0026; Riantono <xref ref-type="bibr" rid="CIT0062">2019</xref>). Other tools, including Microsoft Excel and Power BI, support data visualisation, dashboard development and the communication of findings (Doko &#x0026; Miskovski <xref ref-type="bibr" rid="CIT0018">2020</xref>; Nigrini <xref ref-type="bibr" rid="CIT0036">2020</xref>). This study does not seek to review all fraud theories or all CAATs; instead, it focuses on the applications and techniques through which data analytics supports fraud detection.</p>
<p>Runkler (<xref ref-type="bibr" rid="CIT0044">2012</xref>:2) defines data analytics as: &#x2018;the application of computer systems to the analysis of large data sets for the support of decisions&#x2019;. Auditors employ analytics to process entire data populations, identify anomalies and visualise suspicious patterns (Information Systems Audit and Control Association [ISACA] <xref ref-type="bibr" rid="CIT0024">2011</xref>; West &#x0026; Bhattacharya <xref ref-type="bibr" rid="CIT0061">2016b</xref>). Data analysis has emerged as a predominant activity in forensic auditing, enabling auditors to identify fraud within electronic data. However, its effectiveness can be undermined by technology-related risks, including changes in business processes, collusion, data breaches and cybercrimes. Despite being transaction based, the data analysis process contributes significant value by offering recommendations that enhance clients&#x2019; control effectiveness and highlight vulnerabilities to fraud and corruption (Smidt <xref ref-type="bibr" rid="CIT0050">2016</xref>).</p>
<p>The role of data analytics in detecting fraud and irregularities is indispensable. Data analytics provides the auditor with the ability to run automated procedures and analyse the full data population (Bierstaker, Janvrin &#x0026; Lowe <xref ref-type="bibr" rid="CIT0009">2013</xref>). Its role extends beyond fraud detection to include risk assessment, continuous monitoring and strengthening internal controls (GTAG <xref ref-type="bibr" rid="CIT0021">2009</xref>). The primary objective of data analytics is to uncover anomalies and patterns in datasets that may indicate misconduct, thereby identifying warning signs and suspicious markers that help prevent illicit activities (Nejad, Khan &#x0026; Othman <xref ref-type="bibr" rid="CIT0034">2024</xref>). The process encompasses data collection, cleansing and detailed examination to identify anomalies or behavioural patterns associated with fraud (Stripling et al. <xref ref-type="bibr" rid="CIT0052">2018</xref>). By applying analytical techniques, auditors can move from descriptive analysis of past events to predictive modelling of potential fraud risks (Rakipi et al. <xref ref-type="bibr" rid="CIT0041">2020</xref>).</p>
<p>While various tools exist, many do not provide straightforward rules for fraud detection and instead require specialised skills and knowledge to be applied effectively (Alexiou <xref ref-type="bibr" rid="CIT0001">2016</xref>). Data analytics in forensic auditing is inherently explorative and investigative, aiming to produce documented findings, conclusions and recommendations. Moreover, the process often involves the use of targeted analytic queries designed to generate purposeful audit reports based on identified anomalies and patterns (Lambrechts et al. <xref ref-type="bibr" rid="CIT0028">2011</xref>). Data analytics software supports functions such as sampling, stratification, Benford&#x2019;s Law analysis and the automation of repetitive tasks, thereby enhancing efficiency and precision in fraud detection (Motubatse et al. <xref ref-type="bibr" rid="CIT0032">2015</xref>).</p>
<p>Fraud detection can be understood as the application of forensic auditing tools and techniques to uncover fraudulent activities. Because fraudulent schemes are often concealed through collusion, process manipulation and control override, detection requires both technical expertise and a strong understanding of how fraud is perpetrated and concealed (Bakri, Mohamed &#x0026; Said <xref ref-type="bibr" rid="CIT0007">2017</xref>; Bello et al. <xref ref-type="bibr" rid="CIT0008">2023</xref>).</p>
<p>Kerler and Killough (<xref ref-type="bibr" rid="CIT0027">2009</xref>) emphasise that the complexity of fraud detection necessitates the exercise of professional scepticism when evaluating evidence during forensic audits. Such complexity often arises from collusion among employees, manipulation of operational processes and management&#x2019;s ability to override internal controls (ACFE <xref ref-type="bibr" rid="CIT0005">2020</xref>). These factors significantly hinder detection, as perpetrators may actively conceal their actions and destroy evidence to avoid exposure (Villaescusa &#x0026; Amat <xref ref-type="bibr" rid="CIT0058">2022</xref>).</p>
<p>The expansion of data analytics is linked to the growth of data volume and the increasing complexity of fraudulent schemes (Zhou et al. <xref ref-type="bibr" rid="CIT0066">2020</xref>). One key challenge is the detection of anomalies in large and heterogeneous datasets, as inconsistencies, missing values and deliberate manipulation can obscure fraudulent behaviour. Both structured and unstructured data can contain anomalies, rendering manual detection and traditional audit procedures inadequate in complex environments (West &#x0026; Bhattacharya <xref ref-type="bibr" rid="CIT0060">2016a</xref>).</p>
<p>Patterns of anomalies may change as business processes evolve and transaction volumes increase, which complicates fraud detection. Common manifestations include additions, removals and unauthorised changes in data and events (Motie &#x0026; Raahemi <xref ref-type="bibr" rid="CIT0033">2024</xref>; Saha et al. <xref ref-type="bibr" rid="CIT0046">2023</xref>). In response, scholars advocate combining supervised and unsupervised analytical methods to strengthen the identification of both known and previously undetected fraud patterns. The broader implication is that big-data environments require more advanced and adaptable analytical approaches.</p>
<p>Forensic auditors rely on data as evidence, which means that relevant data must be accessible, available and preserved in a manner that protects its integrity (Renner-Micah, Effah &#x0026; Boateng <xref ref-type="bibr" rid="CIT0043">2023</xref>; Wiesm&#x00FC;ller &#x0026; Bauer <xref ref-type="bibr" rid="CIT0063">2023</xref>). In high-risk datasets, effective fraud detection often depends on reconstructing transactions, profiling patterns and applying analytical procedures that distinguish normal from abnormal behaviour (Gresoi et al. <xref ref-type="bibr" rid="CIT0022">2023</xref>). This reinforces the growing convergence between FDA and computer forensics in contemporary fraud investigations.</p>
</sec>
<sec id="s0006">
<title>Research methods and design</title>
<p>The study followed a systematic empirical research design, which provided a structured framework for uncovering insights into fraud detection through FDA. As Creswell (<xref ref-type="bibr" rid="CIT0016">2009</xref>) emphasises, research design offers control over variables that may affect validity, while empirical approaches remain grounded in direct observation and evidence (Wangrow, Schepker &#x0026; Barker <xref ref-type="bibr" rid="CIT0059">2015</xref>). This orientation ensured rigour and reliability, allowing the researcher to investigate fraud-detection practices in a real-world organisational context.</p>
<p>This study adopts an explanatory single-case study design to enable an in-depth examination of how data analytics are operationalised in fraud detection within a complex organisational environment. Consistent with prior methodological literature, single cases are particularly appropriate where the phenomenon is context dependent, access to fraud data is restricted, and the objective is theory development rather than statistical generalisation. The petroleum sector represents an information-rich context for examining fraud analytics because of its high transaction volumes, complex supply chains and elevated exposure to procurement and revenue-related fraud risks. The unit of analysis in this study is not the organisation itself, but the application of data analytics to specific fraud risk scenarios across key business cycles.</p>
<p>The study employed both primary and secondary data sources. Primary data comprised internal organisational documents relating to 23 forensic audit engagements in which data analytics had been applied. These documents included forensic audit reports, policies and procedures, file notes and working papers. Secondary sources comprised academic literature, journal articles and professional publications. Because the primary material was not publicly available, document analysis was used to examine how FDA tools were embedded in organisational processes and interpreted by practitioners (Wood <xref ref-type="bibr" rid="CIT0065">2020</xref>). The literature review complemented this analysis by establishing the theoretical foundation and informing the research questions, thereby supporting triangulation as reflected in <xref ref-type="table" rid="T0001">Table 1</xref>.</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Data collection followed a triangulated approach.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Data collected</th>
<th valign="top" align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Document analysis</td>
<td align="left">Company documents, including policies, procedures and forensic reports, were systematically reviewed to identify fraud detection practices.</td>
</tr>
<tr>
<td align="left">Case study evidence</td>
<td align="left">Contextual insights were drawn from the petrochemical company&#x2019;s fraud-detection lifecycle, offering micro-level perspectives on organisational responses. Case study evidence provided context-rich insights into organisational practices, illustrating how structured methodologies enhance fraud detection and risk identification.</td>
</tr>
<tr>
<td align="left">Literature review</td>
<td align="left">Academic and industry sources were used to validate findings and situate them within broader scholarly debates on fraud detection and forensic auditing.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Content analysis was used to examine the documentary evidence. It enabled the researcher to extract, organise and interpret meaning across documents of different types (Elo et al. <xref ref-type="bibr" rid="CIT0019">2014</xref>). Thematic analysis was then applied to identify patterns across the case material and to draw conclusions from the single-case study (Boyatzis <xref ref-type="bibr" rid="CIT0011">1998</xref>). This approach is flexible and valuable in making sense of rich qualitative data, particularly in case study contexts (Braun &#x0026; Clarke <xref ref-type="bibr" rid="CIT0013">2006</xref>).</p>
<p>According to Williams and Moser (<xref ref-type="bibr" rid="CIT0064">2019</xref>), thematic analysis allows researchers to explore experiences and perceptions, thereby providing deeper insights into how and why certain processes and decisions are made. Data were transformed from its raw form to coded segments, ensuring that meaning is preserved and patterns are revealed (Braun &#x0026; Clarke <xref ref-type="bibr" rid="CIT0014">2013</xref>). As outlined in the literature review, the researcher identified methods and standards utilised in data analytics. This provided predetermined deductions and inductive insights, including the identification of phases of data analytics. Consequently, the researcher was able to predetermine themes and codes derived both from existing literature and participant data.</p>
<p>Thematic analysis focused on understanding the processes, techniques, tools and conclusions evident in the case documents from the petrochemical company. These methods and standards were compared across proactive and reactive FDA engagements. Data extracted from the case documents were analysed to identify similarities and differences in the techniques and tools applied across varied scenarios. Each code contributed to the thematic analysis by linking specific methods, techniques and tools to individual cases. This coding process enabled the researcher to structure the analysis systematically and to interpret qualitative evidence from the documentary record. Importantly, thematic analysis reduced the likelihood of overlooking significant patterns or themes within the research data (Charmaz <xref ref-type="bibr" rid="CIT0015">2000</xref>).</p>
<p>Data analysis was qualitative, emphasising meaning and interpretation rather than reduction to variables (Ary et al. <xref ref-type="bibr" rid="CIT0002">2018</xref>). Following Mayer (<xref ref-type="bibr" rid="CIT0029">2015</xref>), the researcher described, classified and connected phenomena to research concepts. Data were organised into themes and subcodes, distinguishing proactive and reactive FDA approaches. Accuracy was enhanced through data-cleaning and verification checks, ensuring completeness and reliability (Morse &#x0026; Niehaus <xref ref-type="bibr" rid="CIT0031">2012</xref>). Two researchers independently reviewed the coding, discussed discrepancies after each round and refined the coding framework until consensus was reached. This process yielded 26 codes, which were consolidated into nine main themes.</p>
<sec id="s20007">
<title>Ethical considerations</title>
<p>The study was conducted with institutional permission and in accordance with ethical requirements. Ethical clearance to conduct this study was obtained from the School of Accounting Research Ethics Committee, University of Johannesburg (No. SAREC20241121/02). No interviews or direct contact with staff formed part of the data-collection process; the study relied exclusively on authorised documentary evidence.</p>
</sec>
</sec>
<sec id="s0008">
<title>Results</title>
<p>The findings from the petrochemical case study highlight how the FDA functions as both a proactive and reactive mechanism in fraud detection. Proactive FDA emphasises early identification of anomalies through risk-based assessments, trend analysis and red-flag detection, thereby strengthening internal controls and reducing exposure to EC. Reactive FDA, by contrast, is corrective in nature, initiated after allegations or whistleblower reports, and focuses on quantifying losses and reinforcing failed controls. Together, these approaches demonstrate the dual role of the FDA in enhancing both preventative and detective measures.</p>
<p>The thematic and content analysis further revealed a consistent reliance on direct system access, rigorous data-cleaning procedures and specialised tools such as Arbutus and Power BI. These practices underscore the importance of methodological rigour and technological capability in producing credible and reliable fraud-detection outcomes. The emphasis on hash totals and record counts (Nigrini <xref ref-type="bibr" rid="CIT0035">2011</xref>; Ramaswamy, Rastogi &#x0026; Shim <xref ref-type="bibr" rid="CIT0042">2000</xref>) confirms that data-integrity checks are indispensable in forensic auditing, while the preference for advanced visualisation platforms reflects the growing need to communicate complex findings to diverse stakeholders. <xref ref-type="table" rid="T0002">Table 2</xref> presents the themes and codes.</p>
<table-wrap id="T0002">
<label>TABLE 2</label>
<caption><p>Themes and codes.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Theme</th>
<th valign="top" align="left">Unique identifier</th>
<th valign="top" align="left">Codes</th>
<th valign="top" align="left">Definition</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="5" valign="top">Theme 1 &#x2013; Data identification (DI)</td>
<td align="left">DI 1</td>
<td align="left">Stakeholder Engagement</td>
<td align="left">Involving relevant stakeholders to define the scope and identify the relevant data sources and their location</td>
</tr>
<tr>
<td align="left" rowspan="2" valign="top">DI 2</td>
<td align="left" rowspan="2" valign="top">Direct Access</td>
<td align="left">Obtaining data directly from systems without intermediaries</td>
</tr>
<tr>
<td align="left">This is direct system-level access for data extraction.</td>
</tr>
<tr>
<td align="left">DI 3</td>
<td align="left">Third-Party Data</td>
<td align="left">Data acquired through external service providers, vendors, customers and system administrators</td>
</tr>
<tr>
<td align="left">DI 4</td>
<td align="left">Public Domain Data</td>
<td align="left">Data sourced from publicly available records</td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Theme 2 &#x2013; Data acquisition &#x0026; preservation (DAP)</td>
<td align="left">DAP 1</td>
<td align="left">IT Request</td>
<td align="left">Formal requests submitted to IT for data extraction and acquisition</td>
</tr>
<tr>
<td align="left">DAP 2</td>
<td align="left">Stakeholder Provision</td>
<td align="left">Data supplied by internal stakeholders manually or through access to systems</td>
</tr>
<tr>
<td align="left" rowspan="2" valign="top">DAP 3</td>
<td align="left" rowspan="2" valign="top">Direct Access</td>
<td align="left">Obtaining data directly from systems without intermediaries</td>
</tr>
<tr>
<td align="left">This is direct system-level access for data extraction.</td>
</tr>
<tr>
<td align="left" rowspan="5" valign="top">Theme 3 &#x2013; Data preparation &#x0026; validation (CD)</td>
<td align="left">CD 1</td>
<td align="left">Filters and Sanity Checks</td>
<td align="left">Applying filters and plausibility tests to validate data logic and remove noise and anomalies</td>
</tr>
<tr>
<td align="left">CD 2</td>
<td align="left">Hash Totals</td>
<td align="left">Using control totals to ensure data integrity before analysis</td>
</tr>
<tr>
<td align="left">CD 3</td>
<td align="left">Record Counts</td>
<td align="left">Verifying the number of records matches expectations to ensure completeness and consistency of datasets</td>
</tr>
<tr>
<td align="left">CD 4</td>
<td align="left">Follow-Ups</td>
<td align="left">Additional checks to clarify anomalies or inconsistencies in datasets with stakeholders</td>
</tr>
<tr>
<td align="left">CD 5</td>
<td align="left">Documentation in Working Papers</td>
<td align="left">Recording procedures and results for audit trail</td>
</tr>
<tr>
<td align="left" rowspan="6" valign="top">Theme 4 &#x2013; Technology-based audit tools (TL)</td>
<td align="left" rowspan="2" valign="top">TL 1</td>
<td align="left" rowspan="2" valign="top">Microsoft Excel</td>
<td align="left">Data analysis and visualisation using spreadsheets</td>
</tr>
<tr>
<td align="left">Used for basic data manipulation, tests and validation</td>
</tr>
<tr>
<td align="left" rowspan="2" valign="top">TL 2</td>
<td align="left" rowspan="2" valign="top">SQL Server</td>
<td align="left">Database querying and structured data analysis</td>
</tr>
<tr>
<td align="left">Supports structured queries and large-scale data handling</td>
</tr>
<tr>
<td align="left">TL 3</td>
<td align="left">Arbutus</td>
<td align="left">Specialised audit analytics software for fraud detection</td>
</tr>
<tr>
<td align="left">TL 4</td>
<td align="left">Power BI</td>
<td align="left">Advanced data visualisation, trend analysis and dashboarding</td>
</tr>
<tr>
<td align="left" rowspan="7" valign="top">Theme 5 &#x2013; Analytics procedures (DA)</td>
<td align="left">DA 1</td>
<td align="left">Benford&#x2019;s Law Analysis</td>
<td align="left">Tests on whether numerical and statistical data follows expected first-digit distribution</td>
</tr>
<tr>
<td align="left">DA 2</td>
<td align="left">Outlier and Anomaly-Detection</td>
<td align="left">Identifies unusual data points, patterns or deviations</td>
</tr>
<tr>
<td align="left">DA 3</td>
<td align="left">Duplicate and Gap Analysis</td>
<td align="left">Detects missing, duplicated or inconsistent entries</td>
</tr>
<tr>
<td align="left">DA 4</td>
<td align="left">Time-Series Analysis</td>
<td align="left">Examines trends, patterns and fluctuations over time</td>
</tr>
<tr>
<td align="left">DA 5</td>
<td align="left">Regression Analysis</td>
<td align="left">Tests and assesses relationships between dependent and independent variables</td>
</tr>
<tr>
<td align="left">DA 6</td>
<td align="left">Clustering and Association</td>
<td align="left">Groups data to reveal hidden relationships, correlations or similarities</td>
</tr>
<tr>
<td align="left">DA 7</td>
<td align="left">Log Analysis</td>
<td align="left">Examines logs to reconstruct activities, access times and system events and to detect suspicious activities</td>
</tr>
<tr>
<td align="left" rowspan="6" valign="top">Theme 6 &#x2013; External technical assistance (ET)</td>
<td align="left">ET 1</td>
<td align="left">In-House Data Analysts</td>
<td align="left">Support from internal analytics specialists</td>
</tr>
<tr>
<td align="left">ET 2</td>
<td align="left">In-House IT Specialists</td>
<td align="left">Technical support from organisational internal IT staff</td>
</tr>
<tr>
<td align="left">ET 3</td>
<td align="left">Insourced Data Analysts</td>
<td align="left">External analysts temporarily contracted in-house for specific assignments</td>
</tr>
<tr>
<td align="left">ET 4</td>
<td align="left">Internal Audit</td>
<td align="left">Support from the organisation&#x2019;s internal audit function, which is independently providing assurance</td>
</tr>
<tr>
<td align="left">ET 5</td>
<td align="left">Forensics Team</td>
<td align="left">Specialist dedicated forensic investigators</td>
</tr>
<tr>
<td align="left">ET 6</td>
<td align="left">Insourced IT Specialists</td>
<td align="left">External IT staff contracted for technical support</td>
</tr>
<tr>
<td align="left" rowspan="3" valign="top">Theme 7 &#x2013; Reporting (RP)</td>
<td align="left" rowspan="2" valign="top">RP 1</td>
<td align="left" rowspan="2" valign="top">Automated Reports or Dashboards</td>
<td align="left">Continuous reporting through automated tools</td>
</tr>
<tr>
<td align="left">Real-time visual outputs for monitoring and decision-making</td>
</tr>
<tr>
<td align="left">RP 2</td>
<td align="left">Forensic Reports</td>
<td align="left">Detailed investigation reports with contextual insights</td>
</tr>
<tr>
<td align="left" rowspan="3" valign="top">Theme 8 &#x2013; Economic crime conclusion (EC)</td>
<td align="left">EC 1</td>
<td align="left">Substantiated Exception</td>
<td align="left">Confirmed instance of EC</td>
</tr>
<tr>
<td align="left">EC 2</td>
<td align="left">No Substantiated Exception</td>
<td align="left">No evidence found to support allegations</td>
</tr>
<tr>
<td align="left">EC 3</td>
<td align="left">Possible Exception Indication</td>
<td align="left">Red flags identified but does not conclusively prove an EC</td>
</tr>
<tr>
<td align="left" rowspan="2" valign="top">Theme 9 &#x2013; Type of FDA approach (PA or RA)</td>
<td align="left">PA</td>
<td align="left">Proactive</td>
<td align="left">Engagements initiated to detect anomalies before incidents occur, anticipatory, risk-based analytics.</td>
</tr>
<tr>
<td align="left">RA</td>
<td align="left">Reactive</td>
<td align="left">Engagements triggered in response to reported or suspected incidents, response-driven analytics after events occur.</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>FDA, forensic data analytics; IT, Information Technology; EC, economic crime.</p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s0009">
<title>Discussion</title>
<p>In the discussion that follows, DA refers to the data analytics team or function operating within the forensic audit environment.</p>
<sec id="s20010">
<title>Theme 1 &#x2013; Data identification</title>
<p>The planning phase of FDA begins with data identification. In the case study, this phase relied heavily on Systems, Applications and Products, but the evidence also showed that relevant data may be dispersed across end-user repositories, SharePoint sites and other internal sources. Direct access (DI 2) was used across all 23 engagements, underscoring its central role in FDA practice. Direct access reduced dependence on intermediaries, supported timely retrieval of data and strengthened the integrity and efficiency of the acquisition process.</p>
</sec>
<sec id="s20011">
<title>Theme 2 &#x2013; Data acquisition and preservation</title>
<p>Data were not always stored in a single location. In five engagements, two reactive and three proactive, the data analytics team did not have direct access to the required datasets. Where relevant information resided in end-user repositories, operational systems or SharePoint, the team relied on stakeholder requests and existing access channels to obtain the data. The findings indicate that direct access (DAP 3) remained the predominant acquisition and preservation method, appearing in 17 of the 23 cases. At the same time, the evidence highlights the importance of documenting how unstructured and sensitive data are converted, transferred and protected during acquisition.</p>
</sec>
<sec id="s20012">
<title>Theme 3 &#x2013; Data cleaning</title>
<p>According to Nigrini (<xref ref-type="bibr" rid="CIT0035">2011</xref>), data-cleaning and integrity checks ensure that data are complete, consistent and free from anomalies. In support of this view, Ramaswamy et al. (<xref ref-type="bibr" rid="CIT0042">2000</xref>) place emphasis on the fact that outlier detection is most reliable when the underlying data have been properly cleaned and normalised. This is evident from the results of the study, which show that the data-cleaning process is dominated by procedural checks for data integrity. These include hash totals (CD 2) and record counts (CD 3), both of which were used in all 23 cases (100&#x0025;), confirming their status as standard operating procedures. Other methods, such as filters and sanity checks (CD 1) and follow-ups (CD 4), were used less frequently. The emphasis on these methods confirms the completeness of data transfers and extraction and helps ensure that no data are lost during the acquisition phase.</p>
</sec>
<sec id="s20013">
<title>Theme 4 &#x2013; Technology-based audit tools</title>
<p>The choice of tools reflected a focused but flexible analytical environment. Arbutus (TL 3) and Power BI (TL 4) were the most frequently used tools, appearing in 21 and 17 of the 23 cases, respectively. These tools were selected for their ability to process large datasets and present complex findings in accessible formats. Microsoft Excel (TL 1) and SQL Server (TL 2) were used less frequently, in two and seven cases, respectively, and generally played supporting roles in extraction, validation and visualisation. Overall, the pattern suggests a preference for specialised forensic software complemented by general analytical tools.</p>
</sec>
<sec id="s20014">
<title>Theme 5 &#x2013; Analytical techniques and procedures</title>
<p>Outlier and anomaly-detection (DA 2) and time-series analysis (DA 4) were the most frequently used analytical procedures across the engagements, appearing 17 and 10 times, respectively. This pattern indicates a strong emphasis on identifying transactions that deviate from expected norms and on tracing behavioural patterns over time. The findings align with prior literature that positions anomaly-detection and time-based analysis as central to fraud detection in large and complex data environments.</p>
<p>By contrast, duplicate and gap analysis (DA 3), clustering and association (DA 6) and log analysis (DA 7) were used more selectively, especially in reactive engagements. These procedures were particularly useful where the objective was to reconstruct event sequences, identify relationships among transactions or trace potentially collusive behaviour. Although applied less frequently than anomaly detection, they proved effective in uncovering complex fraudulent patterns within large datasets.</p>
</sec>
<sec id="s20015">
<title>Theme 6 &#x2013; External technical assistance</title>
<p>External assistance was used sparingly. Only internal audit (ET 4) and insourced data analysts (ET 3) were engaged and then only in a small minority of cases. This suggests that the data analytics function operated with a high degree of internal capability and operational independence. Nevertheless, the limited use of external specialists also points to a potential constraint, as particularly complex fraud scenarios may benefit from additional technical expertise.</p>
</sec>
<sec id="s20016">
<title>Theme 7 &#x2013; Reporting</title>
<p>The data analytics team predominantly reported through formal forensic reports, which appeared in 22 of the 23 engagements. Automated dashboards were used less frequently, in six cases, and functioned mainly as supplementary reporting mechanisms. This pattern suggests that formal narrative reporting remains the principal vehicle through which findings are communicated to management, particularly where evidentiary detail and contextual interpretation are required.</p>
</sec>
<sec id="s20017">
<title>Theme 8 &#x2013; Economic crime conclusion</title>
<p>The outcome distribution shows that the most common result was the absence of substantiated EC, with 12 of the 23 engagements falling into this category. Nine engagements produced indications of possible EC and were referred for further investigation, while two reactive engagements substantiated fraud. These findings suggest that the FDA is not inherently accusatory; rather, it serves a confirmatory and screening role by distinguishing unsupported allegations from cases that warrant escalation. The review also revealed challenges in referrals to the Operating Model Entity, including incomplete disclosure, the risk of manipulated inputs and inconsistent follow-up on recommendations.</p>
</sec>
<sec id="s20018">
<title>Theme 9 &#x2013; Type of forensic data analytics and approach</title>
<p>Theme 9 synthesises Themes 1&#x2013;8 by showing how the techniques, tools and processes observed across the case material translated into distinct engagement types and outcomes. <xref ref-type="table" rid="T0003">Table 3</xref> provides a visual summary of the three outcome categories and their associated FDA approaches. For analytical clarity, the 23 engagements were grouped into three outcome categories: Category 1 (confirmed fraud), Category 2 (no substantiated evidence of wrongdoing) and Category 3 (possible EC indication). Categories 2 and 3 arose mainly from proactive engagements, whereas Category 1 was reactive in nature.</p>
<table-wrap id="T0003">
<label>TABLE 3</label>
<caption><p>Outcome categories across 23 forensic data analytics engagements.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Category number</th>
<th valign="top" align="left">Outcome</th>
<th valign="top" align="center">Number of cases</th>
<th valign="top" align="left">Description</th>
<th valign="top" align="left">FDA approach</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">1</td>
<td align="left">Confirmed fraud</td>
<td align="center">2</td>
<td align="left">Fraud was substantiated; the cases were reactive and required extensive analysis of large and complex datasets.</td>
<td align="left">Reactive</td>
</tr>
<tr>
<td align="left">2</td>
<td align="left">No substantiated evidence of wrongdoing</td>
<td align="center">12</td>
<td align="left">No evidence of fraud or economic crime was identified in these engagements.</td>
<td align="left">Proactive</td>
</tr>
<tr>
<td align="left">3</td>
<td align="left">Possible economic crime (EC)</td>
<td align="center">9</td>
<td align="left">Indicators of potential EC were identified and referred for further investigation.</td>
<td align="left">Proactive</td>
</tr>
<tr>
<td align="left" colspan="5"><hr/></td>
</tr>
<tr>
<td align="left">-</td>
<td align="left"><bold>Total</bold></td>
<td align="center"><bold>23</bold></td>
<td align="left">-</td>
<td align="left">-</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>FDA, forensic data analytics.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>In Category 1, the FDA substantiated fraud. In these cases, the data analytics team operated in a reactive mode and drew heavily on forensic investigators&#x2019; input to frame the analytical procedures and techniques. The analysis emphasised meticulous data preparation, duplicate filtering and targeted visualisation to reconstruct transactional behaviour and support the investigative process.</p>
<p>Category 2 engagements were predominantly proactive. The data analytics team leveraged direct access to information systems for data identification, extraction and validation through hash totals and record counts. The analytical phase was dominated by outlier detection and time-series analysis using Arbutus, Power BI and SQL Server. Although these engagements did not yield evidence of EC, they demonstrated the value of structured monitoring and technological integration in strengthening assurance.</p>
<p>Category 3 was also largely proactive. These engagements surfaced indicators of potential EC without reaching definitive conclusions. The analytical approach resembled that of Category 2, but the team more frequently extended its procedures to duplicate and gap analysis to investigate anomalies in greater detail. The presence of red flags prompted referral to investigative teams or business units, illustrating how FDA can function as a bridge between anomaly detection and organisational response.</p>
<p>Collectively, the three categories demonstrate that the FDA is both adaptive and decision useful. Its value lies not only in technical execution but also in its capacity to support escalation, inform managerial judgement foster institutional learning and strengthen governance frameworks.</p>
<p>From a broader perspective, the study illustrates how the FDA integrates into assurance services as a strategic model that enhances governance, accountability and financial oversight. By systematically coding and analysing case data, the research contributes to the knowledge base on fraud detection, offering insights that extend beyond the immediate organisational context. The findings reinforce the argument that forensic auditors must not only acquire technical skills in data analytics but also develop interpretive and communicative competencies to translate analytical results into actionable insights for decision-makers. <xref ref-type="fig" rid="F0001">Figure 1</xref> displays findings across the three categories.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Findings across three categories.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2162-g001.tif"/>
</fig>
</sec>
</sec>
<sec id="s0019">
<title>Conclusion</title>
<p>This study was undertaken to understand how auditors apply data analytics in fraud detection. Drawing on both a literature review and a single case study, the research provides insights into the processes, tools and techniques that underpin FDA engagements. The study confirms that the integration of technological solutions strengthens fraud-detection systems, reduces failures and enhances financial security. Effective fraud detection requires organisations to manage datasets across multiple platforms, with the FDA playing a central role in identifying and evaluating EC risk variables.</p>
<p>The literature review emphasised the growing importance of proactive monitoring techniques and the structured application of FDA across complex data environments. The case study similarly demonstrated the value of a clear FDA lifecycle, from data identification and acquisition to analysis, reporting and outcome evaluation. Nine core themes emerged from the empirical analysis, including data identification, acquisition, cleaning, analytics, external assistance, reporting and EC conclusion.</p>
<p>Outcomes across the 23 FDA engagements varied. Twelve engagements revealed no substantiated evidence of wrongdoing, nine indicated possible EC and were referred for further investigation, and two confirmed fraud. Notably, the confirmed fraud cases were reactive in nature and required extensive analysis of large and complex datasets. These findings highlight the critical role of the FDA in reactive engagements while also demonstrating its screening value in proactive assurance work.</p>
<p>The study demonstrates that FDA is not merely a technical exercise but a holistic process requiring planning, stakeholder engagement, legal compliance and quality assurance. It also highlights the challenges auditors face, including restricted access to sensitive data, the complexity of cleaning large datasets, the need for specialised tools and weaknesses in downstream referral processes. Addressing these challenges requires investment in training, infrastructure and collaborative frameworks that support forensic auditors in applying the FDA effectively.</p>
<p>Ultimately, the case study underscores that the FDA is a cornerstone of modern fraud detection. Its proactive and reactive dimensions provide organisations with both early warning systems and corrective mechanisms, thereby strengthening resilience against EC. The integration of the FDA into assurance services represents a forward-looking approach that aligns with broader trends in governance, accountability and compliance.</p>
<p>The study highlights that fraud-detection effectiveness depends heavily on the rigour of data analytics approaches. Analytical techniques, including duplicate and gap analysis, clustering, association analysis and log analysis, were particularly useful in detecting complex patterns of fraudulent activity. Forensic data analytics therefore play both a confirmatory and preventative role in modern fraud detection. This study is limited to a single internal forensic audit environment within a petrochemical company, which constrains analytical generalisation. Future research could compare the application of the FDA across industries and examine how artificial intelligence and machine learning can extend automated and predictive fraud-detection capabilities.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<p>This article is based on research originally conducted as part of Letebele D. Maruatle&#x2019;s master&#x2019;s thesis titled &#x2018;The application of data analytics in identifying fraud&#x2019;, submitted to the College of Business Economics, Department of Accounting, University of Johannesburg in 2025. The thesis is currently unpublished and not publicly available. The thesis was supervised by Pranisha Rama. The thesis was reworked, revised and adapted into a journal article for publication. The author confirms that the content has not been previously published or disseminated and complies with ethical standards for original publication.</p>
<sec id="s20020" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20021">
<title>CRediT authorship contribution</title>
<p>Letebele D. Maruatle: Conceptualisation, Data curation, Methodology, Writing &#x2013; original draft. Pranisha Rama: Supervision, Writing &#x2013; review &#x0026; editing. All authors reviewed the article, contributed to the discussion of results, approved the final version for submission and publication and take responsibility for the integrity of its findings.</p>
</sec>
<sec id="s20022">
<title>Funding information</title>
<p>This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</p>
</sec>
<sec id="s20023" sec-type="data-availability">
<title>Data availability</title>
<p>The data that support the findings of this study are available from the corresponding author, Pranisha Rama, upon reasonable request.</p>
</sec>
<sec id="s20024">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and are the product of professional research. They do not necessarily reflect the official policy or position of any affiliated institution, funder, agency or that of the publisher. The authors are responsible for this article&#x2019;s results, findings and content.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Alexiou</surname>, <given-names>S</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<chapter-title>Advanced data analytics for IT auditors</chapter-title>&#x2019;, <source><italic>ISACA Journal</italic></source>, vol. <volume>6</volume>, <publisher-name>Information Systems Audit and Control Association (ISACA)</publisher-name>, <comment>viewed 5 April 2026, from <ext-link ext-link-type="uri" xlink:href="https://www.isaca.org/-/media/files/isacadp/project/isaca/articles/journal/2016/volume-6/advanced-data-analytics-for-it-auditors_joa_eng_1116.pdf">https://www.isaca.org/-/media/files/isacadp/project/isaca/articles/journal/2016/volume-6/advanced-data-analytics-for-it-auditors_joa_eng_1116.pdf</ext-link></comment></mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ary</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Jacobs</surname>, <given-names>L.C</given-names></string-name>., <string-name><surname>Irvine</surname>, <given-names>C.K</given-names></string-name>. &#x0026; <string-name><surname>Walker</surname>, <given-names>D</given-names></string-name></person-group>., <year>2018</year>, <source><italic>Introduction to research in education</italic></source>, <publisher-name>Cengage Learning</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Association of Certified Fraud Examiners (ACFE)</collab></person-group>, <year>2018a</year>, <source><italic>Fraud examiners manual</italic></source>, <publisher-name>ACFE</publisher-name>, <publisher-loc>Austin, TX</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Association of Certified Fraud Examiners (ACFE)</collab></person-group>, <year>2018b</year>, <source><italic>Report to the nations. Global study on occupational fraud and abuse</italic></source>, <publisher-name>ACFE, ACFE</publisher-name>, <publisher-loc>Austin, TX</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Association of Certified Fraud Examiners (ACFE)</collab></person-group>, <year>2020</year>, <source><italic>CFE code of professional standards</italic></source>, <publisher-name>ACFE</publisher-name>, <publisher-loc>Austin, TX</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Association of Certified Fraud Examiners (ACFE)</collab></person-group>, <year>2022</year>, <source>Occupational fraud 2022: A report to the nations</source>, <publisher-name>ACFE</publisher-name>, <publisher-loc>Austin, TX</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bakri</surname>, <given-names>H.H</given-names></string-name>., <string-name><surname>Mohamed</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Said</surname>, <given-names>J</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Mitigating asset misappropriation through integrity and fraud risk elements: Evidence emerging economies</article-title>&#x2019;, <source><italic>Journal of Financial Crime</italic></source> <volume>24</volume>(<issue>2</issue>), <fpage>242</fpage>&#x2013;<lpage>255</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/JFC-04-2016-0024">https://doi.org/10.1108/JFC-04-2016-0024</ext-link></comment></mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bello</surname>, <given-names>O.A</given-names></string-name>., <string-name><surname>Folorunso</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Onwuchekwa</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Ejiofor</surname>, <given-names>O.E</given-names></string-name>., <string-name><surname>Budale</surname>, <given-names>F.Z</given-names></string-name>. &#x0026; <string-name><surname>Egwuonwu</surname>, <given-names>M.N</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Analysing the impact of advanced analytics on fraud detection: A machine learning perspective</article-title>&#x2019;, <source><italic>European Journal of Computer Science and Information Technology</italic></source> <volume>11</volume>(<issue>6</issue>), <fpage>103</fpage>&#x2013;<lpage>126</lpage>.</mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bierstaker</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Janvrin</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Lowe</surname>, <given-names>J.D</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>What factors influence auditors&#x2019; use of computer-assisted audit techniques</article-title>&#x2019;, <source><italic>Advances in Accounting</italic></source> <volume>30</volume>(<issue>1</issue>), <fpage>67</fpage>&#x2013;<lpage>74</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.adiac.2013.12.005">https://doi.org/10.1016/j.adiac.2013.12.005</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Boritz</surname>, <given-names>J.E</given-names></string-name>. &#x0026; <string-name><surname>Datardina</surname>, <given-names>M</given-names></string-name></person-group>., <year>2007</year>, <source><italic>CAATs in the classroom</italic></source>, <publisher-name>University of Waterloo Center for Information System Assurance</publisher-name>, <publisher-loc>Waterloo, ON</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Boyatzis</surname>, <given-names>R</given-names></string-name></person-group>., <year>1998</year>, <source><italic>Transforming qualitative information: Thematic analysis and code development</italic></source>, <publisher-name>Sage</publisher-name>, <publisher-loc>Thousand Oaks, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Brahimi</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Elhussein</surname>, <given-names>M</given-names></string-name></person-group>., <year>2023</year>, <source><italic>Measuring the effect of fraud on data-quality dimensions</italic></source>, <comment>Department of Computer Information Systems, College of Computer Science and Information Technology</comment>, <publisher-name>Imam Abdulrahman Bin Faisal University</publisher-name>, <publisher-loc>Dammam</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Braun</surname>, <given-names>V</given-names></string-name>. &#x0026; <string-name><surname>Clarke</surname>, <given-names>V</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Using thematic analysis in psychology</article-title>&#x2019;, <source><italic>Qualitative Research in Psychology</italic></source> <volume>3</volume>(<issue>2</issue>), <fpage>77</fpage>&#x2013;<lpage>101</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1191/1478088706qp063oa">https://doi.org/10.1191/1478088706qp063oa</ext-link></comment></mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Braun</surname>, <given-names>V</given-names></string-name>. &#x0026; <string-name><surname>Clarke</surname>, <given-names>V</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>Teaching thematic analysis: Overcoming challenges and developing strategies for effective learning</article-title>&#x2019;, <source><italic>Psychologist</italic></source> <volume>26</volume>(<issue>2</issue>), <fpage>120</fpage>&#x2013;<lpage>123</lpage>.</mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Charmaz</surname>, <given-names>K</given-names></string-name></person-group>., <year>2000</year>, &#x2018;<chapter-title>Constructivist grounded theory: A qualitative research approach</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>N.K.</given-names> <surname>Denzin</surname></string-name> &#x0026; <string-name><given-names>Y.S.</given-names> <surname>Lincoln</surname></string-name> (eds.)</person-group>, <source><italic>Handbook of qualitative research</italic></source>, <edition>2nd edn.</edition>, pp. <fpage>509</fpage>&#x2013;<lpage>535</lpage>, <publisher-name>Sage</publisher-name>, <publisher-loc>Thousand Oaks, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Creswell</surname>, <given-names>J.W</given-names></string-name></person-group>., <year>2009</year>, <source><italic>Research design: Qualitative and mixed methods approaches</italic></source>, <publisher-name>Sage</publisher-name>, <publisher-loc>London</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Cybersource</collab></person-group>, <year>2021</year>, <source><italic>2021 global fraud report</italic></source>, <publisher-name>Cybersource</publisher-name>, <publisher-loc>Foster City, CA</publisher-loc>, <comment>viewed 12 June 2026, from <ext-link ext-link-type="uri" xlink:href="https://www.cybersource.com/content/dam/documents/campaign/global-fraud-report-2021.pdf">https://www.cybersource.com/content/dam/documents/campaign/global-fraud-report-2021.pdf</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Doko</surname>, <given-names>F</given-names></string-name>. &#x0026; <string-name><surname>Miskovski</surname>, <given-names>I</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Advanced analytics of big data using Power BI: Credit registry use case</article-title>&#x2019;, in <conf-name>17th international conference on informatics and information technologies</conf-name>, <conf-loc>North Macedonia</conf-loc>, <conf-date>May 8&#x2013;9, 2020</conf-date>, pp. <fpage>116</fpage>&#x2013;<lpage>119</lpage>.</mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Elo</surname>, <given-names>S</given-names></string-name>., <string-name><surname>K&#x00E4;&#x00E4;ri&#x00E4;inen</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Kanste</surname>, <given-names>O</given-names></string-name>., <string-name><surname>P&#x00F6;lkki</surname>, <given-names>T</given-names></string-name>., <string-name><surname>Utriainen</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Kyng&#x00E4;s</surname>, <given-names>H</given-names></string-name></person-group>., <year>2014</year>, <source><italic>The trustworthiness of content analysis</italic></source>, <publisher-name>SAGE Openm</publisher-name>, <publisher-loc>Waterloo, ON</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Eulerich</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Masli</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Pickerd</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Wood</surname>, <given-names>D.A</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>The impact of audit technology on audit task outcomes: Evidence for technology-based audit techniques</article-title>&#x2019;, <source><italic>Contemporary Accounting Research</italic></source> <volume>40</volume>(<issue>2</issue>), <fpage>981</fpage>&#x2013;<lpage>1012</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/1911-3846.12847">https://doi.org/10.1111/1911-3846.12847</ext-link></comment></mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Global Technology Audit Guide (GTAG)</collab></person-group>, <year>2009</year>, <source><italic>Fraud prevention and detection in an automated world</italic></source>, <comment>Global Technology Audit Guide (GTAG) 13</comment>, <publisher-name>The Institute of Internal Auditors Inc.</publisher-name>, <publisher-loc>Altamonte Springs, FL</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Gresoi</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Mocanu</surname>, <given-names>S</given-names></string-name>., <string-name><surname>F&#x01CE;g&#x01CE;r&#x01CE;an</surname>, <given-names>L</given-names></string-name>. &#x0026; <string-name><surname>Stamatescu</surname>, <given-names>G</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Enhancing the detection of fraudulent activities in the distribution of energy through data mining algorithms</article-title>&#x2019;, in <conf-name>24th international conference on control systems and computer science (CSCS)</conf-name>, <conf-loc>Bucharest, Romania</conf-loc>, <conf-date>May 24&#x2013;26, 2023</conf-date>, pp. <fpage>288</fpage>&#x2013;<lpage>294</lpage>.</mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ikhsan</surname>, <given-names>W.M</given-names></string-name>., <string-name><surname>Ednoer</surname>, <given-names>E.H</given-names></string-name>., <string-name><surname>Kridantika</surname>, <given-names>W.S</given-names></string-name>. &#x0026; <string-name><surname>Firmansyah</surname>, <given-names>A</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>Fraud detection automation through data analytics and artificial intelligence</article-title>&#x2019;, <source><italic>Riset: Jurnal Aplikasi Ekonomi, Akuntansi dan Bisnis</italic></source> <volume>4</volume>(<issue>2</issue>), <fpage>103</fpage>&#x2013;<lpage>119</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.37641/riset.v4i2.166">https://doi.org/10.37641/riset.v4i2.166</ext-link></comment></mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Information Systems Audit and Control Association (ISACA)</collab></person-group>, <year>2011</year>, <source><italic>Data analytics approach</italic></source>, <publisher-name>ISACA/Information Systems Audit and Control Association</publisher-name>, <publisher-loc>Rolling Meadows, IL</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Institute of Internal Auditors (IIA)</collab></person-group>, <year>2016</year>, <source><italic>2016 North American pulse of internal audit: Time to move out of the comfort zone</italic></source>, <publisher-name>IIA</publisher-name>, <publisher-loc>Altamonte Springs, FL</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Isa</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Chakraborty</surname>, <given-names>A</given-names></string-name></person-group>., <year>2022</year>, <source><italic>DFA standards on forensic auditing: Forensic accounting &#x0026; investigation standards</italic></source>, <publisher-name>The Institute of Cost Accountants of India</publisher-name>, <publisher-loc>Kolkata</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kerler</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Killough</surname>, <given-names>L</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>The effects of satisfaction with a client&#x2019;s management during a prior audit engagement, trust, and moral reasoning on auditors&#x2019; perceived risk of management fraud</article-title>&#x2019;, <source><italic>Journal of Business Ethics</italic></source> <volume>85</volume>, <fpage>109</fpage>&#x2013;<lpage>136</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10551-008-9752-x">https://doi.org/10.1007/s10551-008-9752-x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Lambrechts</surname>, <given-names>A.J</given-names></string-name>., <string-name><surname>Lourens</surname>, <given-names>J.E</given-names></string-name>., <string-name><surname>Millar</surname>, <given-names>P.B</given-names></string-name>. &#x0026; <string-name><surname>Sparks</surname>, <given-names>D.E</given-names></string-name></person-group>., <year>2011</year>, <source><italic>Data analysis technologies. IPPF: Recommended guidance &#x2013; Supplemental guidance: Global Technology Audit Guide (GTAG) 16</italic></source>, <publisher-name>Institute of Internal Auditors</publisher-name>, <publisher-loc>Altamonte Springs, FL</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mayer</surname>, <given-names>I</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Qualitative research with a focus on qualitative data analysis</article-title>&#x2019;, <source><italic>International Journal of Sales, Retailing and Marketing</italic></source> <volume>4</volume>(<issue>9</issue>), <fpage>57</fpage>&#x2013;<lpage>67</lpage>.</mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>McKinsey</collab></person-group>, <year>2020</year>, <source><italic>How COVID-19 has pushed companies over the technology tipping point &#x2013; And transformed business forever</italic></source>, <publisher-name>McKinsey &#x0026; Company</publisher-name>, <publisher-loc>New York, NY</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Morse</surname>, <given-names>J.M</given-names></string-name>. &#x0026; <string-name><surname>Niehaus</surname>, <given-names>L</given-names></string-name></person-group>., <year>2012</year>, <source><italic>Mixed method design: Principles and procedures</italic></source>, <publisher-name>Left Coast Press</publisher-name>, <publisher-loc>Walnut Creek, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Motubatse</surname>, <given-names>K.N</given-names></string-name>., <string-name><surname>Van Staden</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Steyn</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>Erasmus</surname>, <given-names>L</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Audit tools and techniques: Crucial dimensions of internal audit engagements in South Africa</article-title>&#x2019;, <source><italic>Journal of Economics</italic></source> <volume>6</volume>(<issue>3</issue>), <fpage>269</fpage>&#x2013;<lpage>279</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/09765239.2015.11917616">https://doi.org/10.1080/09765239.2015.11917616</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Motie</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Raahemi</surname>, <given-names>B</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Financial fraud detection using graph neural networks: A systematic review</article-title>&#x2019;, <source><italic>Expert Systems with Applications</italic></source> <volume>240</volume>, <fpage>122156</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.eswa.2023.122156">https://doi.org/10.1016/j.eswa.2023.122156</ext-link></comment></mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nejad</surname>, <given-names>M.Y</given-names></string-name>., <string-name><surname>Khan</surname>, <given-names>A.S</given-names></string-name>. &#x0026; <string-name><surname>Othman</surname>, <given-names>J</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>A panel data analysis of the effect of audit quality on financial statement fraud</article-title>&#x2019;, <source><italic>Asian Journal of Accounting Research</italic></source> <volume>9</volume>(<issue>4</issue>), <fpage>422</fpage>&#x2013;<lpage>445</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/AJAR-04-2023-0112">https://doi.org/10.1108/AJAR-04-2023-0112</ext-link></comment></mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Nigrini</surname>, <given-names>M.J</given-names></string-name></person-group>., <year>2011</year>, <source><italic>Forensic analytics: Methods and techniques for forensic accounting investigations</italic></source>, <publisher-name>Wiley</publisher-name>, <publisher-loc>Hoboken, NJ</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Nigrini</surname>, <given-names>M.J</given-names></string-name></person-group>., <year>2020</year>, <source><italic>Forensic analytics: Methods and techniques for forensic accounting investigations</italic></source>, <publisher-name>John Wiley &#x0026; Sons, Incorporated</publisher-name>, <publisher-loc>Hoboken, NJ</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Olaoye</surname>, <given-names>C.O</given-names></string-name>. &#x0026; <string-name><surname>Olanipekun</surname>, <given-names>C.T</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Impact of forensic accounting and investigation on corporate governance in Ekiti State</article-title>&#x2019;, <source><italic>Journal of Accounting, Business and Finance Research</italic></source> <volume>4</volume>(<issue>1</issue>), <fpage>28</fpage>&#x2013;<lpage>36</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.20448/2002.41.28.36">https://doi.org/10.20448/2002.41.28.36</ext-link></comment></mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pacini</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Hopwood</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Young</surname>, <given-names>G</given-names></string-name>. &#x0026; <string-name><surname>Crain</surname>, <given-names>J</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The role of shell entities in fraud and other financial crimes</article-title>&#x2019;, <source><italic>Managerial Auditing Journal</italic></source> <volume>34</volume>(<issue>3</issue>), <fpage>247</fpage>&#x2013;<lpage>267</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/MAJ-01-2018-1768">https://doi.org/10.1108/MAJ-01-2018-1768</ext-link></comment></mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>PricewaterhouseCoopers (PwC)</collab></person-group>, <year>2022</year>, <source><italic>Protecting the perimeter: The rise of external fraud</italic></source>, <publisher-name>Global Economic Crime and Fraud Survey conducted by PricewaterhouseCoopers</publisher-name>, <publisher-loc>London</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Putra</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Diah</surname>, <given-names>E</given-names></string-name>., <string-name><surname>Hidayat</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Rahayu</surname>, <given-names>S</given-names></string-name></person-group>., <year>2022</year>, <source><italic>Literature review: Whistleblowing system activist simultancy, Big Data analytics on fraud prevention</italic></source>, <comment>Faculty of Economic and Business</comment>, <publisher-name>University of Jambi</publisher-name>, <publisher-loc>Jambi</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rakipi</surname>, <given-names>R</given-names></string-name>., <string-name><surname>De Santis</surname>, <given-names>F</given-names></string-name>. &#x0026; <string-name><surname>D&#x2019;Onza</surname>, <given-names>G</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Correlates of the internal audit function&#x2019;s use of data analytics in the Big Data</article-title>&#x2019;, <source><italic>Journal of International Accounting, Auditing and Taxation</italic></source> <volume>42</volume>, <fpage>100357</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.intaccaudtax.2020.100357">https://doi.org/10.1016/j.intaccaudtax.2020.100357</ext-link></comment></mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ramaswamy</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Rastogi</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Shim</surname>, <given-names>K</given-names></string-name></person-group>., <year>2000</year>, &#x2018;<article-title>Efficient algorithms for mining outliers from large data sets</article-title>&#x2019;, <source><italic>ACM SIGMOD Record</italic></source> <volume>29</volume>(<issue>2</issue>), <fpage>427</fpage>&#x2013;<lpage>438</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/335191.335437">https://doi.org/10.1145/335191.335437</ext-link></comment></mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Renner-Micah</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Effah</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Boateng</surname>, <given-names>R</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Understanding business process transformation: An institutionalisation perspective</article-title>&#x2019;, in <conf-name>UK Academy for information systems conference proceedings 2023 (Paper 10)</conf-name>, <conf-loc>Association for Information Systems, Kent, United Kingdom</conf-loc>, <conf-date>April 20&#x2013;21, 2023</conf-date>, <comment>Article 10</comment>.</mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Runkler</surname>, <given-names>T.A</given-names></string-name></person-group>., <year>2012</year>, <source><italic>Data analytics: Models and algorithms for intelligent data analysis</italic></source>, <publisher-name>Springer Vieweg</publisher-name>, <publisher-loc>Wiesbaden</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>SAFLII</collab></person-group>, <year>2007</year>, <source><italic>State V Friedman</italic></source>, <publisher-name>Southern African Legal Information Institute</publisher-name>, <publisher-loc>Johannesburg</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Saha</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Aanand</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Shah</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Khatwani</surname>, <given-names>R</given-names></string-name>., <string-name><surname>Mitra</surname>, <given-names>P.K</given-names></string-name>. &#x0026; <string-name><surname>Sekhar</surname>, <given-names>R</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Comparative analysis of ML algorithms for fraud</article-title>&#x2019;, in <conf-name>First international conference on advances in electrical, electronics and computational intelligence</conf-name>, <conf-loc>Tiruchengode, India</conf-loc>, <conf-date>October 19&#x2013;20, 2023</conf-date>, pp. <fpage>359</fpage>&#x2013;<lpage>364</lpage>.</mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Samagaio</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Diogo</surname>, <given-names>T.A</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>Effect of computer assisted audit tools on corporate sustainability</article-title>&#x2019;, <source><italic>Sustainability</italic></source> <volume>14</volume>(<issue>2</issue>), <fpage>705</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/su14020705">https://doi.org/10.3390/su14020705</ext-link></comment></mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sawangarreerak</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Thanathamathee</surname>, <given-names>P</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Detecting and analyzing fraudulent patterns of financial statement for open innovation using discretization and association rule mining</article-title>&#x2019;, <source><italic>Journal of Open Innovation: Technology, Market, and Complexity</italic></source> <volume>7</volume>(<issue>2</issue>), <fpage>128</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/joitmc7020128">https://doi.org/10.3390/joitmc7020128</ext-link></comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Seify</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Sepehri</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Hosseinian-Far</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Darvish</surname>, <given-names>A</given-names></string-name></person-group>., <year>2022</year>, <source><italic>Fraud detection in supply chain with machine learning</italic></source>, <comment>School of Management and Law</comment>, <publisher-name>University of Northampton</publisher-name>, <publisher-loc>Northampton</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Smidt</surname>, <given-names>L.A</given-names></string-name></person-group>., <year>2016</year>, <source><italic>A maturity level assessment of the use of generalised audit software by internal audit functions in the South African banking industry</italic></source>, pp. <fpage>121</fpage>&#x2013;<lpage>124</lpage>, <publisher-name>University of the Free State</publisher-name>, <publisher-loc>Bloemfontein</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Snyman</surname>, <given-names>C.R</given-names></string-name></person-group>., <year>2002</year>, <source><italic>Criminal law</italic></source>, <edition>4th edn.</edition>, <publisher-name>LexisNexis</publisher-name>, <publisher-loc>Durban</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Stripling</surname>, <given-names>E</given-names></string-name>., <string-name><surname>Baesens</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Chizi</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>Broucke</surname>, <given-names>S.V</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Isolation-based conditional anomaly detection on mixed-attribute data to uncover workers&#x2019; compensation fraud</article-title>&#x2019;, <source><italic>Decision Support Systems</italic></source> <volume>111</volume>, <fpage>13</fpage>&#x2013;<lpage>26</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.dss.2018.04.001">https://doi.org/10.1016/j.dss.2018.04.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Suyts</surname>, <given-names>V.P</given-names></string-name>., <string-name><surname>Shadrin</surname>, <given-names>A.S</given-names></string-name>. &#x0026; <string-name><surname>Leonov</surname>, <given-names>P.Y</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>The analysis of big data and the accuracy of financial reports</article-title>&#x2019;, in <conf-name>Proceedings of the 2017 IEEE international conference on Future IoT and Cloud Workshops (FiCloudW)</conf-name>, <conf-loc>IEEE, Prague, Czech Republic</conf-loc>, <conf-date>August 21&#x2013;23, 2017</conf-date>, pp. <fpage>53</fpage>&#x2013;<lpage>56</lpage>.</mixed-citation></ref>
<ref id="CIT0054"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tickner</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Button</surname>, <given-names>M</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Deconstructing the origins of Cressey&#x2019;s Fraud Triangle</article-title>&#x2019;, <source><italic>Journal of Financial Crime</italic></source> <volume>28</volume>(<issue>3</issue>), <fpage>722</fpage>&#x2013;<lpage>731</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/JFC-10-2020-0204">https://doi.org/10.1108/JFC-10-2020-0204</ext-link></comment></mixed-citation></ref>
<ref id="CIT0055"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Van Wyk</surname>, <given-names>P</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>VBS Mutual Bank: The tragedy of the &#x201C;dream defrauded&#x201D;</article-title>&#x2019;, <source><italic>Daily Maverick</italic></source>, <comment>8 October, 2020</comment>.</mixed-citation></ref>
<ref id="CIT0056"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vanasco</surname>, <given-names>R.R</given-names></string-name>., <string-name><surname>Skousen</surname>, <given-names>C.R</given-names></string-name>. &#x0026; <string-name><surname>Verschoor</surname>, <given-names>C.C</given-names></string-name></person-group>., <year>1995</year>, &#x2018;<article-title>Reporting on the entity&#x2019;s control structure: An international perspective</article-title>&#x2019;, <source><italic>Managerial Auditing Journal</italic></source> <volume>10</volume>(<issue>6</issue>), <fpage>17</fpage>&#x2013;<lpage>48</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/02686909510147084">https://doi.org/10.1108/02686909510147084</ext-link></comment></mixed-citation></ref>
<ref id="CIT0057"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Vera-Baquero</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Colomo-Palacios</surname>, <given-names>R</given-names></string-name></person-group>., <year>2013</year>, <source><italic>Business process analytics using a Big Data approach</italic></source>, <publisher-name>Universidad Carlos III de Madrid Owen Molloy, National University of Ireland</publisher-name>, <publisher-loc>Los Alamitos, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0058"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Villaescusa</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Amat</surname>, <given-names>O</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>When collusion meets the fraud triangle: A case study approach</article-title>&#x2019;, <source><italic>Journal of Financial Crime</italic></source> <volume>29</volume>(<issue>3</issue>), <fpage>805</fpage>&#x2013;<lpage>815</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/JFC-05-2021-0111">https://doi.org/10.1108/JFC-05-2021-0111</ext-link></comment></mixed-citation></ref>
<ref id="CIT0059"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wangrow</surname>, <given-names>D.B</given-names></string-name>., <string-name><surname>Schepker</surname>, <given-names>D.J</given-names></string-name>. &#x0026; <string-name><surname>Barker</surname>, <given-names>V.L</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Managerial discretion: An empirical review and focus on future research directions</article-title>&#x2019;, <source><italic>Journal of Management</italic></source> <volume>41</volume>(<issue>1</issue>), <fpage>99</fpage>&#x2013;<lpage>135</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/0149206314554214">https://doi.org/10.1177/0149206314554214</ext-link></comment></mixed-citation></ref>
<ref id="CIT0060"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>West</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Bhattacharya</surname>, <given-names>M</given-names></string-name></person-group>., <year>2016a</year>, &#x2018;<article-title>Intelligent financial fraud detection: A comprehensive review</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>57</volume>, <fpage>47</fpage>&#x2013;<lpage>66</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2015.09.005">https://doi.org/10.1016/j.cose.2015.09.005</ext-link></comment></mixed-citation></ref>
<ref id="CIT0061"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>West</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Bhattacharya</surname>, <given-names>M</given-names></string-name></person-group>., <year>2016b</year>, <source><italic>Some experimental issues in financial fraud mining</italic></source>, <comment>School of Computing and Mathematics</comment>, <publisher-name>Charles Sturt University</publisher-name>, <publisher-loc>Port Macquarie</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0062"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Widuri</surname>, <given-names>R</given-names></string-name>., <string-name><surname>Handoko</surname>, <given-names>B.L</given-names></string-name>. &#x0026; <string-name><surname>Riantono</surname>, <given-names>I.E</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Perception of accounting student on learning of generalized audit software</article-title>&#x2019;, in <conf-name>2019 international conference on information management and technology</conf-name>, <conf-loc>Jakarta &#x0026; Bali, Indonesia</conf-loc>, <conf-date>August 19&#x2013;20, 2019</conf-date>, pp. <fpage>115</fpage>&#x2013;<lpage>119</lpage>.</mixed-citation></ref>
<ref id="CIT0063"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Wiesm&#x00FC;ller</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Bauer</surname>, <given-names>M</given-names></string-name></person-group>., <year>2023</year>, <source><italic>Governance of collaborative AI development strategies</italic></source>, <person-group person-group-type="editor"><string-name><given-names>R.</given-names> <surname>Altenburger</surname></string-name> (ed.)</person-group>, <publisher-name>Springer International Publishing AG</publisher-name>, <publisher-loc>Cham</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0064"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Williams</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Moser</surname>, <given-names>T</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The art of coding and thematic exploration in qualitative research</article-title>&#x2019;, <source><italic>International Management Review</italic></source> <volume>15</volume>(<issue>1</issue>), <fpage>45</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="CIT0065"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wood</surname>, <given-names>L.M</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Application of rigour and credibility in qualitative document analysis: Lessons learnt from a case study</article-title>&#x2019;, <source><italic>Qualitative Report</italic></source> <volume>25</volume>(<issue>2</issue>), <fpage>456</fpage>&#x2013;<lpage>470</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.46743/2160-3715/2020.4240">https://doi.org/10.46743/2160-3715/2020.4240</ext-link></comment></mixed-citation></ref>
<ref id="CIT0066"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname>, <given-names>H</given-names></string-name>., <string-name><surname>Sun</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Fu</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Fan</surname>, <given-names>X</given-names></string-name>., <string-name><surname>Jiang</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Hu</surname>, <given-names>S</given-names></string-name>. <etal>et al</etal></person-group>., <year>2020</year>, &#x2018;<article-title>A distributed approach of Big Data mining for financial fraud detection in a supply chain</article-title>&#x2019;, <source><italic>Computers, Materials &#x0026; Continua</italic></source> <volume>64</volume>(<issue>2</issue>), <fpage>1091</fpage>&#x2013;<lpage>1105</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.32604/cmc.2020.09834">https://doi.org/10.32604/cmc.2020.09834</ext-link></comment></mixed-citation></ref>
<ref id="CIT0067"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname>, <given-names>X</given-names></string-name>., <string-name><surname>Ao</surname>, <given-names>X</given-names></string-name>., <string-name><surname>Qin</surname>, <given-names>Z</given-names></string-name>., <string-name><surname>Chang</surname>, <given-names>Y</given-names></string-name>., <string-name><surname>Liu</surname>, <given-names>Y</given-names></string-name>., <string-name><surname>He</surname>, <given-names>Q</given-names></string-name>. <etal>et al</etal></person-group>., <year>2021</year>, &#x2018;<article-title>Intelligent financial fraud detection practices in post-pandemic era</article-title>&#x2019;, <source><italic>Innovation</italic></source> <volume>2</volume>(<issue>4</issue>), <fpage>100176</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.xinn.2021.100176">https://doi.org/10.1016/j.xinn.2021.100176</ext-link></comment></mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Maruatle, L.D. &#x0026; Rama, P., 2026, &#x2018;Forensic data analytics as an information management capability for fraud detection&#x2019;, <italic>South African Journal of Information Management</italic> 28(1), a2162. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v28i1.2162">https://doi.org/10.4102/sajim.v28i1.2162</ext-link></p></fn>
</fn-group>
</back>
</article>