You are preparing for a three-section exam: Fraud Schemes and Financial Crimes (120 questions, 2.5 hours), Fraud Investigations and Legal Issues (120 questions, 2.5 hours), and Fraud Prevention and Deterrence (70 questions, 1.5 hours), under the version launched June 2, 2026. Passing requires 75% in each section, the application fee is $480, and you need 40 points to sit for the exam and 50 points plus two years of fraud-related experience to certify. Conceptually, adjacent scheme types — skimming and cash larceny, billing and payroll schemes, bribery and conflicts of interest, inherent and residual risk — turn on one or two decisive facts, so practice naming the scheme, stating that fact, and attaching the controls that fit the mechanics. The worked practice, comparison table, and self-checks below cover the heaviest-weighted topics in each section.
What the CFE exam covers and how it is structured
The CFE Exam has three sections: Fraud Schemes and Financial Crimes (120 questions, 2.5 hours), Fraud Investigations and Legal Issues (120 questions, 2.5 hours), and Fraud Prevention and Deterrence (70 questions, 1.5 hours). You must answer at least 75% of the questions in each section to pass, and the CFE Exam application fee is $480.
The Certified Fraud Examiner credential is issued by the Association of Certified Fraud Examiners (ACFE). Each section is a separate timed exam of multiple-choice and True/False questions, delivered remotely through Prometric's ProProctor or at an in-person Prometric test center, and Prometric emails your result for each section within 24 hours. You have five attempts to pass each section.
A new exam version built on the ACFE's 2024 Job Task Analysis launched on June 2, 2026, so prepare against the content outline updated in May 2026. After the ACFE approves your $480 application, you activate your eligibility and receive a 60-day window to complete the sections, each scheduled as its own appointment.
Eligibility runs on a point system: 40 points to sit for the exam, and 50 points plus a minimum of two years of fraud-related professional experience to be certified after passing. Points come from accredited education, approved professional affiliations, and fraud-related experience in categories such as accounting, investigation, and compliance, all set out in the Candidate Handbook. The domain weights in the outline are percentages of each section, not of the whole exam.
| Exam section | Questions | Time allotted |
|---|---|---|
| Fraud Schemes and Financial Crimes | 120 | 2.5 hours |
| Fraud Investigations and Legal Issues | 120 | 2.5 hours |
| Fraud Prevention and Deterrence | 70 | 1.5 hours |
Official sources: Access the Handbook; View the Content Outline; Exam Blueprint; About the CFE Exam
Where cash leaves the books: telling skimming from cash larceny
Skimming removes cash before it enters the accounting records, so nothing appears missing at first, while cash larceny takes cash that has already been recorded, which leaves a gap between the register log or deposit records and the cash on hand. The timing of the theft against the recording decides which detection tests fit.
The ACFE's scheme material defines skimming as the removal of cash before its entry in the accounting system, an off-book scheme that leaves no direct audit trail. Variants follow that timing: an unrecorded sale never reaches the books, an understated sale is posted but at a lower amount than the customer actually paid, and receivables skimming steals customer payments, often hidden through lapping — crediting one account with money abstracted from another.
Off-book does not mean the books stay untouched. A skimmer facing a past-due customer can make false entries to sales accounts, and skimming sales of goods always creates inventory shrinkage, a physical shortage against the perpetual records. Detection therefore compares the records against outside reality: net sales by employee, uncollectible accounts, cash as a percentage of assets over time, and customer complaints about payments not applied to their accounts.
Cash larceny is the opposite timing problem: the stolen funds were already reflected on the register log, so a straightforward register theft creates an imbalance between the log and the cash drawer. Deposit lapping replaces one day's deposit with the next day's receipts, and stolen deposits can be carried as deposits in transit, which should be traced to subsequent bank statements. Fitting tests include reconciling cash receipts to deposit slips, verifying that prenumbered receipts run in sequence, and asking whether cash handlers have taken vacation while someone else covered their duties.
Official sources: ACFE and COSO fraud risk exposures: published scheme descriptions; Anti-Fraud Data Analytics Tests
Billing schemes: three variants that fail against different controls
The ACFE's Fraud Examiners Manual names three principal billing schemes: false invoicing via shell companies, false invoicing via non-accomplice vendors, and personal purchases made with company funds. Each variant attacks the purchasing function differently, so the detection tests that catch one can miss another.
Billing schemes let the perpetrator misappropriate funds without handling cash at work, by making a false claim for payment that the company pays alongside its legitimate disbursements. Shell-company invoicing sets up phony vendors in the accounts payable system, while personal purchases simply run private items through company accounts — the ACFE classifies that as a billing scheme because the loss is the money spent on the purchase, not the theft of an item.
Detection analytics attack the paper trail the payment creates. The ACFE's test library flags invoices that never passed the three-way match of purchase order, goods receipt, and vendor invoice; vendors with incomplete profiles such as missing tax ID numbers or phone numbers; vendor master data matched against employee data on addresses and tax ID numbers; duplicate purchase orders, credits, and invoices; and disbursements where the same person approves the purchase and the payment.
Worked mini-scenario: accounts payable shows a vendor with no tax ID on file, an address matching an employee's, and three invoices with no goods receipt. Paying because a manager approved the invoices is the plausible mistake; the records themselves justify holding payment and verifying the vendor against the employee master and purchase orders before anything further is disbursed.
- Ghost employees: someone on the payroll who does not actually work for the company; detect by matching payroll to HR records, flagging duplicate direct-deposit details, and listing employees with no vacation or sick leave.
- Falsified hours and commission manipulation: detect through supervisory approval of timecards before payroll, and recalculate incentive pay against reported sales.
- Expense reimbursement: detect by requiring original receipts, enforcing policy limits, and reviewing expenses that are always round numbers or exceed peer patterns.
- Check and payment tampering: detect by verifying check number sequences, comparing checks payable to employees or cash against normal payroll, and analyzing the check register for duplicates.
Official sources: ACFE and COSO fraud risk exposures: published scheme descriptions; Anti-Fraud Data Analytics Tests; View the Content Outline
Corruption payments: matching bribery, kickbacks, and conflicts of interest
Corruption schemes differ in who initiates the payment and what it buys: bribery includes gifts and kickbacks, a conflict of interest hides an economic stake in a counterparty, and economic extortion is the third scheme type the outline names. Learn each variant's elements rather than treating all corruption as one offense.
The ACFE's scheme descriptions illustrate kickback mechanics concretely: vendors pay the entity's purchasing agents to approve payment at inflated prices, so the return flows from the vendor to the employee who controls the award. Illegal payments rarely travel as labeled cash; they surface as inflated invoices, gifts, travel, or payments through intermediaries. That is why detection leans on data: comparing contract awards to bids, investigating sole-sourced or split contracts below bidding thresholds, profiling vendor wins by employee, and reviewing travel, charitable donations, gifts, and entertainment.
The exam treats anti-bribery statutes separately. The outline asks you to recognize the elements of the Foreign Corrupt Practices Act and the United Kingdom Bribery Act, so learn what each statute covers and how its elements differ rather than assuming one anti-bribery rule fits both. Knowing which elements attach to which scheme tells you which records and witnesses an examiner needs, which is exactly the linkage the outline's legal domain tests.
| Scheme | What distinguishes it | Detection that fits |
|---|---|---|
| Bribery, including gifts and kickbacks | Something of value offered to influence a decision | Gift and entertainment review; cash payments to agents, especially round-dollar amounts |
| Kickback | Part of a payment returned from the vendor to the employee who awarded it | Purchasing-rate comparisons by vendor; ratio of contract awards to bids submitted |
| Conflict of interest | Undisclosed relationship between an employee and a vendor | Match employee names, addresses, and account information against the vendor master file |
Official sources: ACFE and COSO fraud risk exposures: published scheme descriptions; Anti-Fraud Data Analytics Tests; View the Content Outline
Predication and the evidence decisions that follow from it
Predication is the factual basis that justifies examining an allegation, and the outline treats recognizing it as a distinct planning skill. Once work expands, evidence handling protects admissibility through authentication, chain of custody, and relevancy, and civil matters add the litigation hold that preserves records.
Treat predication as a threshold question that comes before scope decisions: the circumstances you can point to when asked why an examination is warranted. The outline pairs it with fraud response planning, awareness of potential legal proceedings, and confidentiality, so expect questions that test when expanding work is justified and how to keep it contained.
Evidence type drives handling. The outline distinguishes direct from circumstantial evidence and makes authentication, chain of custody, and relevancy the admissibility checkpoints: document who collected each item, when, from where, and how it was stored. It also asks you to differentiate digital forensics from e-discovery, recognize the volatility of electronic evidence, and describe the seizure, image acquisition, analysis, and reporting phases of a digital evidence investigation.
Mini-scenario: an analyst receives a tip about altered invoices and forwards the suspicious files to a personal account to review overnight. The mistake is moving originals casually, which risks altering metadata and breaking custody documentation. The defensible response preserves the originals, works from a properly acquired image, records each step, and preserves relevant records under a litigation hold, the civil-litigation preservation mechanism the outline recognizes.
Official sources: View the Content Outline
Civil versus criminal fraud: burden of proof and privilege traps
The outline names the civil burden of proof as the balance of probabilities, also called the preponderance of the evidence, and asks you to describe the criminal standard as well. Because legal standards vary across jurisdictions, anchor your answers in how the outline frames the distinction rather than in any single country's rule.
The distinction is practical rather than decorative: the same facts may support a civil claim in one proceeding that would not sustain a criminal charge in another, so an examiner's report should state findings without overstating what the proof carries. The outline's legal domains cover misrepresentation, fraudulent concealment and obstruction, breach of trust, mail and wire fraud, perjury, and conspiracy, plus the criminal process from charging document through first appearance, pretrial negotiations, trial, judgment, sentencing, and appeal, and corporate deferred prosecution agreements.
Privileges and employee rights appear in both domains. The outline lists attorney-client and work-product privileges together with waiver of privilege, and employee-side risks including defamation, emotional distress, invasion of privacy, and false imprisonment. Workplace searches, surveillance, and the duty to cooperate all turn on expectations of privacy and contractual rights, so study this as decision-making: what may be searched, when counsel should be involved, and how interviews are documented.
Official sources: View the Content Outline
Inherent versus residual risk in fraud risk assessment
Inherent risk is the fraud exposure before considering controls; residual risk is what remains after controls are weighed. The assessment maps schemes and controls at both levels, then responds to residual risk — assume, mitigate, avoid, or transfer — based on the organization's risk appetite.
Keep fraud and fraud risk apart: fraud is an actual scheme, while fraud risk is the potential for one. The outline requires you to identify the steps, techniques, controls, and team involved in conducting a fraud risk assessment; a common general framing runs from identifying specific schemes and their incentives, to mapping existing controls, to evaluating what residual risk remains, to responding and reporting. The Fraud Triangle, pressure, opportunity, and rationalization, functions as a brainstorming lens here: for each process, ask what pressures exist, what opportunities the controls leave open, and what rationalizations a position might support. External and internal fraud risks are assessed distinctly because their information sources differ.
Success factors deserve explicit study: knowledge of anti-fraud concepts and of the business's operations, management buy-in, a structured approach, and objectivity. On the management side, fraud risk management connects to enterprise risk management through frameworks such as COSO ERM and ISO 31000, with the ACFE/COSO fraud risk management guidance specifying roles and responsibilities. COSO's five components of internal control anchor the control-mapping step, and third-party monitoring extends the assessment to vendors and intermediaries where corruption and billing schemes typically live.
Official sources: View the Content Outline
A multi-week sequence and a self-check rubric for CFE readiness
Sequence study around the heaviest scheme and assessment topics first, then compress into mixed practice. Test yourself by classifying scenarios and naming controls, not by rereading outlines, and use the rubric below as a milestone check.
A realistic adaptable sequence: spend weeks one and two on fraud schemes, starting with fraudulent disbursements, procurement fraud, cash receipts, and corruption, then money laundering, financial institution fraud, and payment fraud. Give week three to investigations and legal issues, centering on evidence collection, interviews, predication, and civil versus criminal process. Devote week four to prevention and deterrence. Reserve weeks five and six for mixed scenario practice and targeted repair of weak classifications. Adjust the length to your available hours; the ordering follows the within-section weights in the exam content outline, where fraudulent disbursements (15 questions), procurement fraud (10), evidence collection (13), interviews (11), fraud risk assessment (14), prevention programs (11), and ethics (10) carry the largest question counts.
Self-check rubric: after working the exercise below and similar practice items, you can name the scheme and its decisive fact in one sentence, attach one prevention and one detection control that fit the mechanics, draft a two- or three-sentence predication statement in under five minutes, and answer burden-of-proof and privilege questions without notes. If a paired concept trips you up, write the two variants side by side, state the fact that separates them, and retest with fresh practice items.
Practice exercise
Meridian Components' anti-fraud policy (fictional for this exercise) requires every employee involved in vendor selection to disclose in writing any immediate-family ownership stake in a current or prospective vendor, and to recuse from award decisions until the ethics office completes a review. A purchasing manager recommends a bid from a vendor he does not disclose; a public registry record later lists the vendor's co-owner as his sister-in-law. Under the stated policy, classify the situation, name the next step, and explain why it would be premature to declare a proven conflict of interest or fraud.
Show answer
Under Meridian's policy this is a potential undisclosed conflict of interest: the policy required written disclosure of immediate-family vendor ownership, and the registry connection was never disclosed. The next step is to escalate to the ethics office, preserve the bid recommendation and the registry record, and let the policy's review process establish the facts. It is premature to declare a proven conflict because the registry entry shows a family member's co-ownership, not the manager's own beneficial interest, and the classification depends on what the review and any examination find.
The exercise separates three layers: the policy duty (written disclosure was required and skipped), the investigative step (escalation and preservation rather than private accusation), and the evidentiary limit (a sister-in-law's stake is not proof of the manager's ownership, and a policy violation is not by itself a fraud conclusion). On the exam, conflict-of-interest questions reward recognizing the undisclosed relationship as a red flag and matching it to due-diligence and disclosure controls, not declaring guilt from a relationship alone.
- Readiness check 1: define paired look-alike concepts cold, such as skimming versus larceny and inherent versus residual risk.
- Readiness check 2: for any scheme you name, attach one prevention and one detection control that matches its mechanics.
- Readiness check 3: draft a predication statement and a fact-based report paragraph for a given scenario.
- Readiness check 4: explain the civil and criminal burdens of proof and identify which privilege applies to a described document.
- Readiness check 5: complete a one-page scheme decision tree from memory covering cash receipts, disbursements, corruption, and data theft.
Official sources: View the Content Outline
Official sources
Exam facts checked against ACFE sources:
