| Course | ACC 693 Investigating with Computers |
|---|---|
| Module | Module 10 |
| Paper type | graduate final project digital fraud investigation report with an authentication plan |
| Length | About 1,060 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Accounting |
| Updated | October 2026 |
Free sample paper for ACC 693 Module 10
Report of Investigation: Flashing Subcontractor Payments, 2023-2025
[Student Name]
Southern New Hampshire University
ACC 693: Investigating with Computers
Final Project
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Report of Investigation: Flashing Subcontractor Payments, 2023-2025
Executive Summary
This report, prepared for the company's general counsel, presents the results of an investigation into payments to a sheet-metal flashing subcontractor between April 2023 and May 2025. The evidence shows that the subcontractor was organized by a senior project manager's brother-in-law using a domain the project manager registered, that he produced all seventy-four of its invoices on his own company computer and then approved them himself, that the work billed was performed by the company's own crews, and that most of the money reached an account he holds jointly. The loss is $1,104,350. On the night he was interviewed, someone using his access erased data on that computer. The evidence was preserved before that event and can be authenticated as described in this report.
Scope and Methods
The investigation covered vendor payments from January 2023 to May 2025, the project manager's company accounts and devices, the records of fourteen projects and the subcontractor's public filings and bank account. Methods included whole-population analytics on 51,412 payables invoices, preservation of nine evidence sources under a legal hold, forensic imaging of the laptop with a hardware write blocker and SHA-256 verification, a consent-limited phone extraction, analysis of document metadata, email headers and laptop artifacts, link analysis and a normalized timeline. Kent et al. (2006) describe this sequence of collection, examination, analysis and reporting, and each stage is documented in the workpapers.
Findings
How the subcontractor began. State records name the project manager's brother-in-law as the LLC's organizer, and an archived registration record shows the invoices' web domain was signed up under his private email account, three days after the filing and before privacy protection was added. A day before the vendor request was submitted from his account, he emailed himself a draft invoice in the subcontractor's name (Exhibits 1 to 4). These records establish findings one and two: he was involved before the vendor existed.
Who produced the invoices. Each of the seventy-four PDFs names his Windows profile as author, the template that produced them sat in a personal folder on his laptop, and operating system records show it opened on every invoice date. Forty-one of the emails carrying the invoices entered the mail system from the company's own internet address at times his badge shows him at his desk (Exhibits 5 to 10). These support findings three and four.
Whether work was done. For every day the subcontractor billed, the job logs list only the company's crews, the superintendent's timesheets charge flashing hours to the company's own sheet-metal workers and the site photographs show those workers installing it (Exhibits 11 to 13). Finding five follows: the company paid twice for the same flashing and received nothing from the subcontractor.
Where the money went. The company's payment files show every payment went to one credit union account, and statements produced under subpoena show that about three of every five dollars deposited were then moved to an account in the names of the project manager and his wife (Exhibits 14 and 15), which is finding six.
Conduct after the interview. Network, device management and cloud logs record a wiping program installed and run on his laptop over a home connection the same night he was interviewed, and his OneDrive emptied; the device record shows his personal phone reset after counsel's preservation letter (Exhibits 16 to 18). That is finding seven.
Loss summary
| Item | Amount |
|---|---|
| Payments to the subcontractor, 74 invoices | $1,104,350 |
| Legitimate value received | $0 |
| Fraud loss | $1,104,350 |
| Investigation costs, claimed separately | About $86,000 |
Authenticating the Evidence
A court will admit digital evidence only if there is enough proof that it is what the company says it is. A widely cited federal decision set out the questions courts ask about electronically stored information, including authenticity, hearsay and the original-writing rule (Lorraine v. Markel American Insurance Co., 2007). The table pairs key exhibits with their routes.
Authentication plan for key exhibits
| Exhibit | Route | Witness or certification |
|---|---|---|
| Laptop image and artifacts | Testimony of the forensic examiner; matching hash values | Forensic examiner; acquisition worksheet and custody forms |
| Data copied from the laptop and phone | Certification of data copied from a device, verified by hash | Forensic firm's qualified person |
| Payables records, change log, approvals | System-generated records and business records | Finance systems administrator, by certification or testimony |
| Email and headers | Testimony on collection from the mail system; distinctive content | IT director; forensic examiner |
| Badge, VPN and cloud audit logs | System-generated records | IT director, by certification |
| Domain registration history | Screenshots with retrieval details | Examiner who retrieved them |
| Bank records | Business records produced under subpoena | Credit union custodian's certification |
| Job logs, photos, timesheets | Business records; photo metadata | Site superintendent |
Casey (2011) observes that the strength of digital evidence in court depends less on the sophistication of the analysis than on whether its handling can be shown step by step, and the custody records support every row.
Limits
The home internet addresses behind thirty-three of the emails are still unidentified. Most deleted invoice files were lost to the drive's own cleanup, though shortcut files and cloud copies survive. Account activity shows what his credentials and devices did; badge records and the sequence of events are offered as evidence that he was the user. Whether his wife or brother-in-law knew of the scheme is outside the scope of this report.
Recommendations
First, new vendors should be verified by procurement, independently of the person requesting them, through a check of state registration, ownership, taxpayer number and physical address. Second, no employee who requests a vendor should approve its invoices for twelve months. Third, invoices within 10 percent of an approver's limit should be routed for a second approval. Fourth, internal audit should run the vendor-to-employee, threshold and single-approver tests monthly. Fifth, subcontractor invoices should be matched to daily logs before payment. Sixth, the device policy should require return of company laptops before any interview of the user and should keep cloud deletion logs for at least two years.
Conclusion
The investigation found a scheme planned before the subcontractor existed, carried out from the project manager's account and laptop, funded by $1,104,350 of company payments and then met by deliberate destruction on the night of his interview. Because the evidence was preserved first and documented throughout, each exhibit has a route into court, and the recommended controls address the gaps that allowed the scheme to run for twenty-six months.
References
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.
Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86
Lorraine v. Markel American Insurance Co., 241 F.R.D. 534 (D. Md. 2007).
What the ACC 693 Module 10 instructions ask for
The ACC 693 Final Project asks for a complete report of a computer-assisted investigation, usually addressed to counsel or management, together with an explanation of how the digital evidence would be presented and authenticated. Guidelines typically require an executive summary, scope, methods and tools, findings supported by evidence, the loss, the plan for authenticating evidence, limitations and recommendations. The report must be understandable to nontechnical readers while precise enough for an opposing expert, which usually means plain language in the body and technical detail in appendices. Strong projects show that each finding rests on evidence that was properly preserved and can be admitted, and they recommend controls that respond to the weaknesses the investigation revealed.
How this ACC 693 Module 10 final project example is built
The report opens with a summary: a project manager created and operated a sham flashing subcontractor, approving $1,104,350 of invoices for work done by the company's own crews. It describes the scope and methods, from analytics on 51,412 invoices to imaging, document and email analysis, link analysis and the timeline. Seven findings follow. An authentication table pairs each exhibit with its route: the laptop image through the forensic examiner and hash certification, payables records as system-generated records, the domain history through screenshots and the retrieving examiner. Limits are stated, and six controls are recommended, including verification of new vendors, separation of vendor introduction from invoice approval and monthly analytics.
Where the ACC 693 Module 10 rubric puts the points
Final Project grading typically considers the executive summary, scope and methods, findings and their support, loss quantification, authentication and admissibility, limitations, recommendations and professional presentation. High-scoring reports are organized so a reader can find each element quickly, cite exhibits for every finding, explain technical steps plainly and show how each exhibit will be authenticated under the rules of evidence. They acknowledge limits and recommend controls tied to specific failures, each with an owner and a date. A short appendix of tool versions and hash values often earns credit too. Reports lose credit for technical jargon without explanation, for findings without exhibits, for ignoring authentication or chain of custody and for generic recommendations.
ACC 693 Module 10 help: the mistakes that cost points
A frequent weakness in the closing report here is authentication, describing what the evidence shows without explaining how it will get in front of a judge or jury. For each key exhibit, name the witness who can testify to it or the certification that will be used, and refer to the hash values and custody records. Another weakness is writing for a technical audience; keep the body plain and move tool details to an appendix. Make the recommendations specific to what went wrong, such as allowing one person to introduce a vendor and approve its invoices, and give each an owner. Readers of the final report will include people who never saw the milestones, so the report must stand on its own.
Get ACC 693 Module 10 written to your instructions
Share your ACC 693 Final Project instructions along with the three milestones. You receive a report ready for counsel: scope, methods, findings and loss, each exhibit matched to its route into evidence, and controls. About two days; a first final project costs nothing. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More ACC 693 papers and related MS Accounting samples
- ACC 693 Module 1 Discussion: What Computers Changed About Fraud Investigation
- ACC 693 Module 2 Data Analytics Assignment: Testing Three Years of Payables
- ACC 693 Module 3 Milestone One: The Digital Evidence Plan
- ACC 693 Module 4 Discussion: Personal Phones, Private Email and the Employer's Reach
- ACC 693 Module 5 Forensic Imaging Assignment: Acquiring the Laptop and the Phone
- ACC 693 Module 6 Milestone Two: What the Email and Invoice Files Show
- ACC 693 Module 7 Discussion: A Wiped Drive and What It Costs
- ACC 693 Module 8 Link Analysis Assignment: Connecting the Subcontractor to the Manager
- ACC 693 Module 9 Milestone Three: The Timeline and the Findings
- ACC 660 Module 2 Close Process Assignment: From a 12-Day Close to Five
- ACC 620 Module 9 Milestone Three: Consolidating a Monterrey Subsidiary
- MBA 540 Module 8 Final Project Strategic Planning Proposal
- ACC 640 Module 5 Internal Control Assignment: Controls Over Online Sales
ACC 693 Module 10 questions, answered
Where can I find a free ACC 693 Module 10 Final Project sample?
The complete ACC 693 Final Project is on this page: a digital investigation report on a sham flashing subcontractor with an authentication plan.
How is digital evidence authenticated in court?
By evidence sufficient to show it is what it claims to be, such as testimony from the person who collected it, hash values showing it is unchanged, certifications for system-generated records and distinctive characteristics.
What are self-authenticating electronic records?
Under federal rules adopted in 2017, records generated by an electronic system and data copied from devices can be authenticated by a qualified person's certification, including hash verification, rather than live testimony.
What should a digital investigation report include?
An executive summary, scope, methods and tools, findings with exhibits, the loss, authentication of evidence, limitations and recommendations.
How can companies prevent fictitious vendor schemes?
By verifying new vendors independently, separating who introduces a vendor from who approves its invoices, running regular vendor analytics and requiring evidence that work was performed.