Part 4 · Forensics — is anyone lying to me? · Chapter 63
Building your own red-flag checklist
The whole of Part Four collapses into a short, personal checklist you run on every company — a handful of reconciliations grouped by statement — but the list is a question generator, not a verdict machine: one flag is a question, a cluster is a warning, and every threshold read against the sector or it is noise.
12 min
Prerequisites not yet complete
This module builds on Chapter 54: The forensic mindset, Chapter 55: Revenue games, Chapter 56: Expense games, Chapter 57: Balance sheet games, Chapter 58: Cash flow games, Chapter 59: The auditor as a signal, Chapter 60: The promoter playbook, Chapter 61: The tax cross-check, Chapter 62: Case library — accounting failures on Indian exchanges. You can read on, but the sequence is load-bearing.
The question
Part Four has handed you a catalogue of specific games — the revenue booked before it is earned, the expense parked on the balance sheet, the debt hidden in a subsidiary, the cash flow dressed up by moving a payment across a date, the auditor who resigns a week before results, the promoter quietly pledging another slice of his holding, the book profit that never quite agrees with the tax return. Each module taught one tie and one way it gets broken. The practical question that follows all of them is: when the next annual report lands on your desk, what do you actually do — in what order, against what numbers, and how do you keep from either missing the one that matters or drowning in false alarms?
The answer is a checklist — but not the kind that ticks toward a verdict. The value of writing the games down as a short, fixed list of reconciliations is that you stop relying on memory and mood, and you run the same checks on the dull company as on the exciting one, which is the only way an abnormal number ever stands out. The danger is the opposite temptation: to treat a fired item as a conviction, to read "flag" as "fraud." So the discipline has two halves that must be held together. The list makes you thorough. The judgement — one flag is a question, a cluster is a warning, and every threshold read against the sector — keeps the list honest. This is the capstone of the part, where the specific games become one reusable instrument you carry into every business you will ever read. illustrative
Knowledge of the games without a process degrades into two predictable failures. The first is checking whatever the report happens to draw your eye to, so the company with a clean, confident narrative gets the lighter examination — exactly backwards from what fraud incentives predict. The second is that, armed with a catalogue of frauds, you start seeing them everywhere, treat every wobble as a scandal, and eventually stop looking because the noise exhausts you. The checklist defeats both at once: it forces uniform coverage, and it forces proportion.
The checklist
A working checklist is short. If it runs to forty items you will not use it; the point is a handful of high-value reconciliations, grouped by the statement they live in, that you can run in twenty minutes on any company and that between them catch the large majority of the games from this part.
Group by statement, so nothing is skipped. Organise the list the way the accounts are organised, because grouping by statement is what guarantees coverage. Under revenue: does the top line tie to cash and to the — an illustrative trigger being receivable days rising more than two standard deviations above the company's own five-year history, a threshold set against its past rather than an absolute. Under the balance sheet: is growth funded by something that should not be growing — stalled for more than two years, or loans and advances and "other assets" outrunning sales. Under cash flow: does profit become cash — to averaging below 0.7 over three years catches the profit that never arrives. Under tax: does book profit agree with what is paid — an effective tax rate drifting far from statutory with no stated reason. Under governance: the signals around the numbers — an or resignation, a rising , a climbing share of . illustrative
One flag is a question; a cluster is a warning. This is the rule that makes the list usable rather than exhausting. Any single item firing is an ordinary event — honest companies routinely trip one threshold for an innocent reason: a late-year order, a one-off tax item, a genuine capex programme. So a lone flag is never a verdict; it is a question you carry into the notes and the concall. What changes the picture is coincidence: when three or four flags fire in the same direction at once — profit outrunning cash, receivables outrunning sales, tax lagging profit, a pledge creeping up — they are usually not four separate innocent stories but one story seen from four windows. Grouping by statement and running the whole list every time is precisely what makes that clustering visible.
Weight, and revisit. Not every flag deserves equal alarm. Weight the governance items heavily — an auditor walking out or a promoter pledging his stake is harder to explain innocently than a wobble in inventory days — and weight anything management refuses to decompose. Treat the list as a living instrument: after a company you flagged turns out fine, ask whether the threshold was set wrong for that sector and adjust it; after one you cleared turns out badly, ask which tie you were missing and add it. The checklist you finish the year with should not be the one you started it with — it gets sharper the more companies you run it on, because each one teaches you where the normal band really sits.
Read against the sector
The same threshold on the same line fires for one sector and must be silenced for another. This is not a caveat to the checklist; it is the checklist, because a rule applied identically everywhere flags the wrong companies with total confidence.
Flag LIVE. A short, cash-collected cycle means receivables should stay small and steady, so a jump in receivable days is the profit failing to become cash — the classic channel-stuffing signature. Here the threshold fires and deserves a hard question.
Flag MUTED. The same high receivable days are structural: retention money the client holds until completion, plus percentage-of-completion revenue recognised before it can be billed. If the balance tracks the order book and milestone schedule, the threshold that damns an FMCG firm is silent here. Read it against the contract, not the norm.
Wrong line entirely. A lender has no trade receivable to read this way; its equivalent is the provision against a growing stock of bad loans. Point the receivable rule at a bank and you check nothing — swap it for the provision-to-NPA tie.
Subsumed into collections. A developer's revenue is a recognition lever and the receivable is less telling than the cash actually collected from buyers. The tie to run is reported revenue against pre-sales and collections, not receivable days.
Migrates to unbilled. On fixed-price and milestone work, the receivable-like risk sits in unbilled revenue rather than trade receivables. The threshold is real but you must read it on the unbilled line, watching it against billings quarter by quarter.
A single threshold — "receivable days well above the historical band" — is a genuine warning in one sector, a structural certainty to be ignored in another, a check aimed at the wrong line in a third, and a signal that has migrated to a different account in the rest. The FMCG company that trips it owes you an urgent answer, because its cash cycle should close on its own; the EPC contractor that trips it usually owes you nothing, because and percentage-of-completion revenue are the ordinary furniture of the business. Aim the same rule at a bank and it is the wrong instrument — a lender's revenue-quality risk lives in its against a rising bad-loan book, not in a trade receivable it barely has. Run the threshold identically across all five and you will confidently flag the contractor whose receivables are perfectly normal and wave through the consumer company whose receivables have quietly gone bad — the exact inversion of the truth. So the last instruction of Part Four is not "here is the list" but "tune every item on the list to the business in front of you." The checklist is sector-aware, or it is a machine for generating wrong answers with a straight face.
Read it live
Take a composite mid-cap consumer company that posted a confident year — revenue up 34%, profit up 41%, management all momentum. Run the list, group by group, and see what it generates. illustrative
Revenue: reported profit was ₹610 crore but operating cash was ₹210 crore, and receivable days stretched from 68 to 121 — the cash-conversion and receivable triggers both fire. Balance sheet: "other financial assets" and loans and advances rose faster than sales, and a line of CWIP has sat unchanged for three years — two more flags. Tax: cash tax barely moved against the 41% profit jump, and the effective rate fell well below statutory with no explanation in the notes. Governance: the statutory auditor was changed at the last AGM, and the promoter's pledged shareholding ticked up from 12% to 19% — two governance flags, the heavily weighted kind. That is seven triggers across four of the five groups. illustrative
Any one of these, alone, would be a question and quite possibly an innocent one: a single late-year order stretches receivables, a genuine capex programme parks money in CWIP, a real exemption lowers the tax rate. But seven flags firing together, across revenue, balance sheet, tax and governance, are not seven innocent stories — they are one story told from seven windows: growth booked into the P&L faster than it became real, funded and disguised across several statements at once, while the two people best placed to see it (the auditor and the promoter, through his pledge) send their own signals. Crucially, before you weight the cluster you re-read each threshold against the sector: this is an FMCG business, so the high receivable days should be alarming — if the same seven flags appeared on an EPC contractor, you would silence the receivable and cash-conversion items as structural and be left with a much thinner, less coherent signal. The list did not deliver a verdict. It delivered, in twenty minutes, the precise set of questions to carry into the notes, the concall and the ten-year history — and a strong prior about how much they matter, because of how many fired and how tightly they cluster in a sector where they should not.
In the concall
When a cluster fires on one company, the concall is where you test whether the flags have an innocent common cause. You do not read out your whole list; you name the two or three tightest flags and ask management to reconcile them together: "Receivable days went from 68 to 121, operating cash was a third of profit, and the effective tax rate dropped well below statutory — can you walk us through whether these are one connected thing, and how much of the receivable is over ninety days?" The question does not accuse; it presents the cluster and asks for the single explanation that would dissolve it.
A good answer takes the cluster apart:
"They're partly connected and partly not, and I'll separate them. About ₹300 crore of the receivable is one large modern-trade customer we moved to extended terms this year — it's current and we've collected a third since year-end, which is why cash converges next quarter. The lower tax rate is the new plant's accelerated depreciation, which reverses over three years; the note references it and I'll make it clearer next time. The CWIP you flagged is that same plant, commissioning this quarter. Happy to give you the receivable ageing offline." illustrative
It names the customer, ties several flags to a single real cause, concedes where disclosure was thin, and commits to numbers you can hold it to. A cluster with an innocent common cause can be reconciled item by item, and this does exactly that.
An evasive answer reassures without reconciling:
"Look, the balance sheet has never been in better shape and our collection record speaks for itself. Cash is lumpy quarter to quarter and we run this business for the full year, not for one line item. The tax rate simply reflects an optimised structure. The auditors are fully on board, and we stay confident on demand and where the growth is heading."
It names no customer, no ageing, no cause for the tax drop, and reaches for "optimised structure," the auditor and "momentum" in place of the decomposition the question asked for. A cluster that would survive being broken down is broken down gladly; one that would not is met with confidence and generalities. The follow-up that separates them is the one nobody asks: "Of the receivable, how much is over ninety days and over a year — and given you changed auditors this year, was there any disagreement with the outgoing firm on revenue recognition?" If "collections have always been strong" is allowed to stand next to an unprobed auditor change, you have accepted a reassurance in place of a reconciliation. The silence is the tell.
What the list cannot do, and how it fools you
A checklist locates questions; it does not answer them. Every flag is consistent with an innocent explanation and a guilty one, and the list has no way to tell them apart — that is the work of the notes, the segment detail, the concall and the history, which is why the checklist is the beginning of the reading and never the end. It cannot catch what it has no item for, or what has been engineered to keep every visible tie closed: a company that borrows to convert fake profit into real-looking cash can pass the cash-conversion check. A clean run lowers suspicion; it does not eliminate it. And it cannot set its own thresholds — the trigger levels are illustrative starting points, and a reader who treats them as universal constants has misunderstood the instrument. The checklist is a frame for judgement, not a substitute for it.
Three failures follow directly from forgetting that. The first is treating the list as a verdict machine — the flags are specific, they cluster, the story writes itself, and the reader shorts or dumps on the strength of the list alone, skipping the investigation the checklist was built to start. A cluster that looks damning can still have a single innocent cause the notes would have revealed; convicting on the list produces confident, expensive errors. The second is running the list sector-blind — applying the same receivable-days and cash-conversion thresholds to a contractor, a consumer company and a lender, and flagging the businesses whose numbers are structurally normal while clearing the one whose numbers have quietly gone wrong. A threshold detached from the business is not rigour; it is a random-answer generator with a confident interface. The third is confusing a long list with a good one, and then not using it: a checklist swollen to forty items gets skipped under time pressure, which returns the reader to reacting to headlines — the exact state the list was meant to cure. The instrument only works if it is short enough to run on every company, every time, including the dull, clean ones, because the clean runs are what build the sense of normal that lets an abnormal cluster stand out.
Decide
Test your reading, not your memory — short decisions under incomplete information. The answer only shows after you commit.
All figures are illustrative — constructed to demonstrate a judgement, not reported as fact.
Carry forward
- Part Four collapses into one short, reusable checklist — a handful of reconciliations grouped by statement (revenue/P&L, balance sheet, cash flow, tax, governance) — that you run on every company, clean or not, so the abnormal number has a library of normal to stand out against.
- The checklist is a question generator, not a verdict machine. One flag firing is an ordinary event and only a question; a cluster of flags firing together across statements, in the same direction, is the warning — and even then it locates the investigation rather than concluding it.
- Every threshold is read against the sector or it is noise. The same 'high receivable days' rule is a live warning for an FMCG firm, a structural certainty to be silenced for an EPC contractor, the wrong line entirely for a bank, and a signal that has migrated to unbilled revenue for an IT firm. Carry the list; tune every item.
Enables: 064 Why the promoter outranks the business here
Run the same short list on everyone; let one flag be a question and a cluster be a warning; and never read a threshold without asking what that line is made of in this sector.