Digital Forensics, e-Discovery, and Data Analytics for Fraud Investigations and Disputes
Forensic Technology Solutions (FTS) is the application of specialised digital investigation techniques to collect, preserve, analyse, and present electronic evidence in fraud investigations, litigation support, regulatory inquiries, and internal misconduct investigations. As business operations have moved to digital platforms — emails, ERP systems, cloud storage, mobile apps, UPI payment platforms, and social media — the evidence relevant to a financial fraud, contract dispute, intellectual property theft, or employment misconduct is overwhelmingly digital. Traditional accounting-based forensic investigation — examining paper vouchers and physical documents — is no longer sufficient to investigate modern business misconduct. Digital forensics provides the tools to: recover deleted emails and files; analyse transaction patterns in ERP and accounting systems for manipulation signatures; extract mobile phone data including WhatsApp conversations relevant to a dispute; analyse network access logs to identify who accessed what systems and when; and authenticate the integrity of digital documents presented in legal proceedings. For businesses in Pune — where financial fraud, employee misconduct, data theft by departing employees, and vendor fraud are among the most common business risks encountered — forensic technology is the investigative backbone of any serious misconduct inquiry.
N D Savla & Associates in Baner, Pune, combines financial investigation expertise with forensic technology tools to support fraud investigations, litigation matters, and regulatory inquiries for clients across Pune’s manufacturing and IT sectors. Our forensic technology practice integrates with our corporate intelligence services, financial misconduct investigation practice, and anti-bribery and corruption risk advisory to deliver end-to-end investigation capability.
Digital Evidence Types and Forensic Approaches
| Digital Evidence Type | Common Sources | Forensic Approach |
|---|---|---|
| Computer Forensics | Laptops, desktop PCs, servers; hard drives; USB drives; external storage | Forensic imaging (bit-by-bit copy) of the storage device using write-blocking; hash verification; file carving for deleted files; metadata analysis (creation/modification/access timestamps) |
| Email and Communication | Corporate email servers (Exchange, G-Workspace); archived email PST/OST files; messaging apps (WhatsApp, Telegram, Teams) | Forensic extraction of email archives; search by keywords, custodians, date range; reconstruction of communication threads; authentication of email metadata |
| Mobile Device Forensics | Smartphones, tablets; call logs; SMS; app data (WhatsApp, UPI apps, social media); GPS location data | Specialised mobile acquisition tools (Cellebrite UFED, Oxygen Forensic); logical or full file system extraction; analysis of app databases; location history extraction |
| Financial Data Analytics | ERP exports; accounting software data (Tally, SAP, Oracle); bank statements; transaction logs; payment gateway data | Data extraction and normalisation; Benford’s Law analysis for manipulation detection; journal entry testing; vendor analysis; duplicate payment detection; unusual pattern identification |
| Network Forensics | Network logs; firewall logs; Active Directory logs; VPN logs; SIEM (Security Information and Event Management) data | Log analysis for unauthorised access, data exfiltration, lateral movement; timeline reconstruction; IP address attribution; correlation of system access with financial transaction timing |
| Cloud and Social Media | Google Drive, OneDrive, Dropbox; LinkedIn, Twitter/X, Facebook; cloud-hosted ERP (SAP Cloud, Oracle Cloud) | Legal hold and preservation notices to cloud providers; data export through authorised APIs; metadata preservation; authentication of downloaded data |
Forensic Technology Service Areas
1. Digital Forensics and Evidence Preservation
The most critical phase of any digital investigation is the forensic preservation of evidence — done correctly at the outset, it ensures that all subsequent analysis is based on authentic, unaltered data; done incorrectly, it can render the entire investigation inadmissible or unreliable. Our forensic evidence preservation covers:
- Forensic imaging: creating a bit-by-bit forensic image (an exact copy) of hard drives, SSDs, USB drives, and other storage media using write-blocking hardware (which prevents any data being written to the original device during imaging). The forensic image is hashed (SHA-256 or MD5) to prove it is an exact and unaltered copy of the original
- Chain of custody documentation: every piece of evidence is documented from the moment it is collected: who collected it, when, from where, and what happened to it subsequently. An unbroken, documented chain of custody is essential for the evidence to be admissible in court proceedings or regulatory hearings
- Legal hold: when litigation is reasonably anticipated, a legal hold is issued requiring all relevant custodians to preserve potentially relevant electronic data and stop any routine data destruction (document retention policy overrides)
- Cloud and server preservation: for data stored on corporate servers, cloud platforms (Google Workspace, Microsoft 365, AWS), and SaaS applications, we work with the IT team and (if necessary) the service provider to extract and preserve the relevant data while maintaining metadata integrity
2. e-Discovery — Electronic Discovery for Litigation
e-Discovery is the process of identifying, preserving, collecting, processing, reviewing, and producing electronically stored information (ESI) that is relevant to a legal dispute or investigation. For commercial litigation in India (before civil courts, NCLT, arbitral tribunals, or SEBI), increasingly in international arbitration where India is a party, and in US or UK litigation affecting Indian entities, e-Discovery is essential for:
- Identifying all potentially relevant electronic documents across all custodians and data sources
- Processing collected data: deduplication (removing duplicate copies of the same document); near-deduplication (identifying documents that are very similar but not identical); threading of email conversations; OCR of scanned documents to make them searchable
- Keyword search and culling: applying agreed search terms and custodian filters to reduce the collected universe to a manageable review set
- Technology Assisted Review (TAR): using machine learning to prioritise documents for human review based on relevance predictions — significantly more efficient than linear review for large document sets
- Document review and privilege review: reviewing the culled document set for relevance, privilege (attorney-client, work product), and responsiveness to the specific discovery requests
- Production: producing the relevant, non-privileged documents in the agreed format (typically TIFF images with extracted text and metadata load files, or PDF)
3. Financial Data Analytics for Fraud Detection
Financial data analytics is the systematic analysis of large volumes of financial transaction data to identify patterns, anomalies, and indicators of fraud or manipulation that would not be visible through manual sampling. Our financial analytics capabilities:
- Benford’s Law analysis: the first significant digit of naturally occurring transaction amounts follows a predictable distribution (Benford’s distribution); manipulation of transaction amounts — particularly round-number fabrication or amount-splitting to avoid approval thresholds — typically violates this distribution and can be detected statistically
- Journal entry testing: analysis of all general ledger journal entries for characteristics associated with fraud: weekend/holiday entries, entries with round number amounts, entries reversed within a short period, entries made by unusual users, entries to low-activity accounts
- Vendor and payment analysis: identification of vendor relationships that show fraud indicators (vendors sharing bank accounts with employees, vendors without a verifiable address, duplicate invoice numbers, payments just below approval thresholds, vendors added by the same employee who authorises their payments)
- Purchase card / expense claim analysis: analysis of corporate card and expense claim data for abuse patterns (weekend claims, duplicate claims, claims at unusual vendors, claims just below policy limits)
- Procurement anomalies: analysis of purchase order, goods receipt, and vendor invoice data for three-way match failures; split orders to avoid competitive tendering thresholds; price anomalies (same item from same vendor at significantly different prices across periods)
4. Mobile Device Forensics
For many business misconduct investigations in Pune — particularly those involving fraud, data theft, and anti-bribery — mobile phone data (WhatsApp conversations, call logs, UPI transaction histories, GPS location data, and deleted messages) is among the most evidentially valuable material. Mobile device forensics uses specialised acquisition tools to extract this data:
- Physical extraction: the most comprehensive form of mobile acquisition, extracting all data from the phone’s memory including deleted data not accessible through the phone’s operating system. Requires a PIN/passcode bypass capability or the subject’s cooperation
- Logical extraction: extracting the data through the phone’s own backup and export mechanisms (iTunes backup, Android ADB backup). Less comprehensive than physical extraction but available without breaking the phone’s security
- Cloud extraction: for phones with enabled iCloud or Google account synchronisation, cloud extraction from the account (with appropriate legal authority) can provide access to data even where the physical device is unavailable
- WhatsApp and messaging apps: WhatsApp data is stored in an encrypted database on the device; with appropriate extraction and decryption, the complete message history, media, and call logs from WhatsApp can be recovered
Forensic Technology for Pune’s Business Disputes
Specific forensic technology applications that arise frequently in Pune’s business context: Employee data theft investigations (when a departing employee takes customer lists, product designs, or client contracts to a competitor, forensic imaging of their work laptop and email archive identifies what was taken, when, and where it went); ERP fraud investigation (manipulation of SAP or Tally data to conceal fraud — journal entry testing and GL analysis identifies the manipulation); Vendor fraud (analysis of payment transaction data and email correspondence between employees and vendors to establish collusion); and Employment dispute evidence collection (WhatsApp group communications, email evidence for workplace harassment and wrongful termination claims).
FAQs — Forensic Technology Solutions
Is forensic technology evidence admissible in Indian courts?
Can we investigate a suspected fraud without alerting the suspect?
Forensic Technology Solutions
Forensic technology solutions for digital investigations, e-discovery, and fraud analytics in Pune.
- Phone: +91 98219 32683
- WhatsApp: +91 97650 00966
- Email: info@ndsavla.in
Monday to Saturday | 10:00 AM – 7:30 PM