Wed, Oct 07, 2026
The volume of corporate data is growing in India, creating the perfect ground for artificial intelligence (AI) to step into financial fraud detection.
Corporate investigations have always been resource-intensive, with teams ploughing through millions of documents, transactions, and digital communications to identify the few pieces of information that may actually matter.
The biggest challenge is not necessarily the technology but building the right data and controls around it
- Sodhi, Partner, EY Forensic and Integrity Services
A new EY-JSA report, “Investigations Readiness for a New Risk Reality”, says an average internal investigation can include over 6.5 million documents, and large investigations can include up to 70 million documents. Median case closure time is up 33% YoY from 2025 to 2026.
This is where AI can step in, doing much of the initial sorting and analysis, helping investigators identify unusual patterns, group-related information, and prioritise what needs closer human attention.
But here’s the problem.
Do Indian companies have the data, governance, and legal safeguards to use AI reliably?
“The biggest challenge is not necessarily the technology but building the right data and controls around it,” Saguna Sodhi, Partner, EY Forensic and Integrity Services, told The Secretariat.
“Investigators need to know where the data sits, whether they are permitted to access and process it, and whether the evidence can be preserved and relied upon. There also needs to be a clear process for validating AI outputs,” Sodhi said.
AI can recognise a pattern without understanding what it means, so it is a human who must first determine if the evidence indicates misconduct.
Sodhi says AI works best “as an accelerator rather than an autonomous investigator” because investigators still have to determine what a pattern means and whether it supports a conclusion.
That distinction is especially important when an AI-driven evaluation might impact employee action, disclosure to regulators or legal action.
A 2026 Exterro survey of 100 senior technology, security, legal, and risk professionals across more than 70 Indian organisations found that 39% saw encrypted and ephemeral messaging platforms as a major investigative blind spot, while 36% pointed to cloud-based software platforms.
Only 38% said they could begin forensic imaging within four hours of an incident. At the same time, 43% said reducing response time through automation was their primary priority for the next 12 months.
The US and China provide good examples of changes in technology when it comes to the detection of large-scale events.
For instance, the Securities and Exchange Commission (SEC) in the US has applied machine-learning algorithms to analyse massive amounts of data to detect unusual reporting practices.
In one exercise, the models were five times better than random at identifying language that could merit an enforcement referral. The SEC also pointed out that there was a possibility of false positive results, and experts had to assess the results.
AI is increasingly being used as an investigator’s force multiplier
- Jaspreet Singh, Partner, Grant Thornton Bharat LLP
China has also been using technology to control financial crime. The People’s Bank of China mandates financial institutions to implement transaction-monitoring mechanisms and perform human reviews of transactions identified by a financial institution’s own monitoring mechanisms, with the reasons for the decisions documented.
The common denominator in these examples: using technology to filter out huge quantities of data into signals, which investigators can then study.
AI and advanced analytics can sort and prioritise documents, recognise relevant correspondence, discover unusual transactions, establish links and create timelines between various data sources.
“AI is increasingly being used as an investigator’s force multiplier, particularly where investigations involve very large volumes of emails, messages, documents, financial transactions and digital evidence,” says Jaspreet Singh, Partner, Grant Thornton Bharat LLP.
Generative AI can also be used to conduct searches and summarise massive evidence sets via natural language.
MuleHunter.AI by the Reserve Bank Innovation Hub (RBIH) uses AI and Machine Learning (ML) to analyse transaction patterns and help identify potential mule accounts. The system was live across 26 banks as of March 2026 and is being scaled further.
The Indian Cyber Crime Coordination Centre is also sharing suspect-account intelligence with RBIH to strengthen AI-driven fraud detection models.
The biggest advantage of AI may be its ability to reduce the time investigators spend searching for relevant information.
Sodhi says, “We are increasingly seeing AI move from being an experimental tool to a practical enabler across the investigation lifecycle. AI and advanced analytics are being leveraged to review large volumes of data, identify anomalies, detect potential misconduct, prioritise high-risk issues and accelerate evidence analysis.”
In an investigation involving the processing of millions of records, this could translate to identifying clusters, unusual transactions, connections between entities or recurring themes that deserve further investigation and analysis, rather than manually reviewing each record.
The EY-JSA investigation readiness playbook points out that evidence currently exists in the cloud, chat and collaboration tools, identity logs, mobile devices, transaction systems and third-party data.
It suggests approved AI tools, source traceability, validation sampling, and documentation and review by humans on how the technology is being applied.
The bigger problem for Indian businesses lies under the AI layer.
Corporate evidence may be stored in disparate enterprise resource planning systems, email, collaboration apps, mobile devices, cloud and HR systems, and third-party systems. Without proper identification and preservation of this information, AI may have to work with incomplete or unreliable information.
A flag should be treated as a lead, not a finding
- Rupinder Malik, Senior Partner, JSA and Archit Sehgal, Senior Associate, JSA
Forensic data readiness is identified as a critical requirement in the EY-JSA report.
This encompasses data maps, preservation processes, a secure evidence repository and integrity controls. It also highlights the importance of understanding privacy and cross-border barriers prior to the examination and transfer of data.
There is one more layer of formality.
Any records such as emails, server logs, messages and computer or smartphone files are subject to the Bharatiya Sakshya Adhiniyam (BSA), which regulates electronic records as evidence. Original evidence, metadata, and audit trails can thus be vital in cases where investigative findings may be subject to legal or regulatory review.
JSA’s Rupinder Malik, Senior Partner, and Archit Sehgal, Senior Associate, put the principle simply. “A flag should be treated as a lead, not a finding. AI can help identify which documents, transactions or communications warrant closer attention, but a material conclusion should be traced back to the underlying evidence and reviewed by a person,” Malik told The Secretariat.
This requires that material findings be traced back to original evidence and verified independently. Human judgement is necessary due to the risk of false positives, hallucinations or making incorrect associations.