
Fraud Pattern Detection & Analysis Framework
Detect fraud schemes by analyzing transaction patterns and anomalies
What You Can Do
You can upload transaction datasets (bank feeds, GL exports, AP aging records) and have Claude analyze them for fraud indicators across embezzlement, invoice fraud, payroll manipulation, asset misappropriation, and vendor schemes. The skill identifies statistical anomalies, suspicious behavioral clusters, and cross-reference inconsistencies across multiple data sources to build prioritized investigation pathways and narrative timelines showing fraud evolution.
Features
identifies unusual sequences, frequency spikes, and behavioral deviations from normal activity
flags statistical outliers using frequency distribution and peer comparison methods
categorizes detected patterns against embezzlement, invoice fraud, payroll schemes, asset misappropriation, and vendor manipulation
connects related transactions across datasets to build forensic narratives and investigative timelines
ranks suspicious activity by fraud probability, dollar exposure, and scheme complexity
identifies inconsistencies and gaps across bank feeds, payroll, AP, and expense systems
produces structured evidence summaries with recommended next steps for corroboration
maps fraud evolution over months or years with milestone markers and escalation patterns
Example Output
Example 1: Embezzlement Detection
Input: 18 months of expense reports + GL coding
Output:
- Suspicious Pattern: Employee submitting 47 meal/entertainment expenses averaging $312 each, 3x peer average
- Anomaly Flags: All expenses coded to cost center with no matching projects; approver pattern shows same person approved 89% of flagged items
- Timeline: Expense increase begins month 3, accelerates month 9 after supervisor change
- Evidence Chain: 12 invoices lack supporting documentation; vendor registered to employee's home address
- Risk Score: 8.7/10 — recommend immediate payment hold and vendor verification
Example 2: Invoice Fraud
Input: 6 months AP transactions + vendor master file
Output:
- Scheme Indicator: Duplicate invoice payments to 3 vendors within 15-day windows (9 instances)
- Amount Pattern: All duplicates fall between $4,800–$5,200 (just below approval threshold)
- Vendor Anomaly: One "new" vendor shares bank account with established supplier but different legal entity
- Cross-Reference: Same check sequence numbers appear in two different months (system manipulation flag)
- Priority Actions: Reconcile payments with receiving records; interview AP staff about duplicate controls
Example 3: Payroll Manipulation
Input: 12 months payroll export + timekeeping system data
Output:
- Ghost Employee: 3 individuals on payroll with zero recorded hours; paid $156K total over period
- Hour Inflation: Manager's direct reports showing 18–22 hours/week unpaired with timekeeping entries
- Rate Anomalies: 7 employees received retroactive raises without HR documentation; total impact $94K
- Timeline: All manipulations tied to 2-week period when HR director on leave
- Evidence Summary: Cross-reference payroll GL postings, tax filings, and benefits enrollment for discrepancies
What's Included
- SKILL.md: Complete framework and usage guidelines
- Transaction Analysis Checklist: Data preparation and quality verification steps
- Fraud Typology Reference: Indicators and red flags for 7 common scheme types
- Evidence Mapping Template: Structured format for connecting transactions and building narratives
- Investigation Prioritization Matrix: Risk assessment framework for ranking suspicious activity
Who It's For
- Forensic accountants investigating suspected fraud or conducting post-incident analysis
- Internal audit teams conducting fraud risk assessments and testing control effectiveness
- Compliance and financial crime specialists building fraud detection systems and monitoring programs
- CFOs and controllers responding to fraud allegations or board-level investigations
- Law enforcement and regulatory investigators analyzing financial records in fraud cases
Best For
- Large dataset analysis — processing 10,000+ transactions to identify high-risk patterns
- Multi-scheme investigations — determining fraud type when initial scheme is unknown
- Temporal fraud mapping — building investigation timelines showing how fraud evolved over months/years
- Evidence synthesis — connecting disparate transactions across multiple systems into coherent narratives
- Risk-based prioritization — ranking suspicious activity by probability, exposure, and investigative complexity







