Skip to main content
Category: Fraud Risk Management

Certified Fraud Examiner

Also known as:
Simply put

A Certified Fraud Examiner (CFE) is a professional who holds a credential focused on preventing, detecting, and investigating fraud. The credential is issued by the Association of Certified Fraud Examiners (ACFE), described as an anti-fraud organization. CFEs are trained to work on matters such as identifying potential fraud and helping organizations protect against it.

Formal definition

The Certified Fraud Examiner (CFE) is a credential conferred by the Association of Certified Fraud Examiners (ACFE) that recognizes trained professionals with a specialized skill set spanning fraud prevention, detection, and investigation, including knowledge of complex fraud schemes. The CFE is a voluntary professional certification rather than a legal or regulatory requirement, and holding it does not itself confer statutory authority; specific eligibility criteria, examination requirements, and continuing obligations are set by the ACFE and are beyond the scope of this entry. Organizations may engage CFEs to assist with investigating suspected fraud or with proactive anti-fraud measures, though the precise role of a CFE within any governance, risk, or compliance function depends on how a given entity structures its assurance and investigative activities.

Why it matters

Fraud sits at the intersection of governance, risk, and compliance, but detecting and investigating it requires a specialized skill set that general audit or compliance training does not always provide. The Certified Fraud Examiner credential, conferred by the Association of Certified Fraud Examiners (ACFE), signals that a professional has been trained specifically in preventing, detecting, and investigating fraud, including knowledge of complex fraud schemes. For boards, general counsel, and chief compliance or risk officers, engaging or employing individuals with this background can be one way to strengthen an organization's anti-fraud capabilities, whether reactively when misconduct is suspected or proactively as part of a broader control environment.

It is important to keep the credential in proportion. The CFE is a voluntary professional certification, not a legal or regulatory requirement, and holding it does not by itself confer any statutory or investigative authority. Whether a CFE is involved in a given matter, and in what capacity, depends entirely on how an organization structures its assurance and investigative functions. A CFE's work does not replace the distinct responsibilities of internal audit, compliance monitoring, or the board's oversight role; rather, it may complement those functions where fraud-specific expertise is useful.

Because fraud can implicate financial reporting, regulatory obligations, and reputational risk simultaneously, the value of dedicated fraud expertise is often in bringing focused investigative methodology to matters that other functions may not be equipped to handle. Organizations should assess for themselves where such expertise best fits within their existing governance and risk architecture.

Who it's relevant to

Chief Compliance and Risk Officers
Compliance and risk leaders may consider fraud-specific expertise when assessing the organization's anti-fraud controls or when a matter requires investigative methodology that routine monitoring does not provide. A CFE can be a resource in these situations, though responsibility for the overall compliance and risk framework remains with the officer and the function, and the credential does not alter accountability for those programs.
General Counsel and Legal Teams
When potential fraud surfaces, general counsel often coordinate internal investigations and manage legal exposure. Engaging a professional with fraud examination training may support the investigative aspects of such matters, but the CFE credential confers no legal or statutory authority, and legal privilege, regulatory reporting, and related decisions remain the province of counsel and the organization.
Internal Audit and Assurance Functions
Internal auditors and other assurance professionals may work alongside CFEs where fraud-specific skills complement broader assurance activities. It is important to preserve the distinction between routine assurance work and dedicated fraud investigation; how the two interact depends on how the entity structures its assurance and investigative activities.
Boards and Audit Committees
Directors exercising oversight of fraud risk may wish to understand whether the organization has access to fraud examination expertise, whether in-house or external. The board's role is oversight rather than operational investigation, and the presence of CFEs within management or assurance functions is one factor the board may weigh when evaluating the adequacy of the organization's anti-fraud posture.

Inside CFE

Professional Credential
The Certified Fraud Examiner (CFE) is a professional designation conferred on individuals who demonstrate expertise in the prevention, detection, and investigation of fraud. It is a voluntary qualification rather than a legally mandated license, and holding it is not generally a statutory requirement to perform investigative or compliance work.
Body of Knowledge Domains
The credential typically covers core competency areas commonly described as fraud prevention and deterrence, fraud investigation, financial transactions and fraud schemes, and law as it relates to fraud. Practitioners should confirm the current examination structure with the credentialing body, as the specific domains and their emphasis may change over time.
Examination and Eligibility
Attaining the credential generally involves meeting eligibility criteria (which may include education and relevant experience) and passing an examination. The precise requirements are set by the credentialing organization and are subject to change; this entry does not specify particular thresholds, fees, or dates.
Ethical and Continuing Requirements
Holders are typically expected to adhere to a professional code of ethics and to maintain the credential through ongoing professional education. These are obligations of the credential itself and are distinct from any duties imposed by an employer, a regulator, or applicable law.
Relationship to Governance, Risk, and Compliance Functions
The credential signals fraud-specific expertise that can support, but does not by itself define, roles across compliance, internal audit, or investigations. Accountability for anti-fraud oversight, risk management, and assurance remains with the respective functions and governing bodies regardless of whether an individual holds the credential.

Common questions

Answers to the questions practitioners most commonly ask about CFE.

Does hiring a Certified Fraud Examiner mean an organization has satisfied its fraud risk management obligations?
No. A CFE is an individual professional credential, not a control framework or a compliance program. Engaging a CFE can strengthen an organization's fraud detection, investigation, or prevention capabilities, but it does not by itself discharge the board's oversight duty or management's responsibility to design and operate an effective anti-fraud program. Accountability for fraud risk management typically remains with management, with board or audit committee oversight, regardless of who performs specific investigative tasks. Whether particular fraud-related controls are required depends on jurisdiction, sector, entity type, and applicable law or framework.
Is the Certified Fraud Examiner designation a legal or regulatory requirement, or does it grant legal authority to a holder?
Generally, no. The CFE is a voluntary professional certification administered by a professional association rather than a licensing regime imposed by statute. Holding it does not, in itself, confer legal powers such as compelling testimony, executing searches, or making arrests; those authorities rest with courts, regulators, or law enforcement as provided by law. In most jurisdictions a CFE credential is neither mandated for, nor a substitute for, roles that require a specific license, bar admission, or public-office appointment. Requirements vary by jurisdiction and role.
Where does a Certified Fraud Examiner typically fit within the three lines model?
It depends on the role the individual holds, not on the credential itself. A CFE embedded in a management function performing operational fraud prevention or investigation may sit in the first or second line; a CFE working within internal audit typically supports the third line providing independent assurance. The credential can accompany any of these positions, but the line of defense, and the associated independence and reporting expectations, is determined by the organizational role, reporting relationships, and mandate, not by certification. Organizations should define these placements explicitly to avoid conflicts between investigative and assurance duties.
How might a board or audit committee use CFE expertise in its oversight of fraud risk?
The board or audit committee generally retains an oversight role rather than an operational one, so it typically draws on CFE expertise indirectly, through reports, investigation findings, and assessments provided by management or assurance functions that employ or engage CFEs. Committees may consider whether the organization has access to appropriately skilled fraud expertise, whether investigations are conducted with sufficient independence, and whether findings are escalated appropriately. This is an oversight consideration and does not transfer investigative execution to the board.
What should an organization consider when deciding whether to use an internal CFE versus engaging an external one for an investigation?
Considerations often include the independence and objectivity required given who may be implicated, potential conflicts of interest, the need for specialized skills, capacity, cost, confidentiality, and whether legal privilege or regulatory expectations favor external counsel-directed work. Sensitive matters involving senior management or the potential for litigation or regulatory reporting frequently warrant external, independent resources. These are fact-specific judgments that typically involve legal counsel; this entry is educational and not legal, audit, or compliance advice.
How does a CFE credential relate to other assurance and governance functions such as internal audit or compliance monitoring?
The CFE reflects specialized knowledge in fraud examination, which is a distinct discipline from the broader mandates of internal audit, compliance monitoring, or enterprise risk management. A CFE may support any of these functions but does not replace them: internal audit provides independent assurance, compliance monitors adherence to obligations, and risk functions coordinate risk management, each with its own accountability. Organizations generally integrate fraud expertise into these functions rather than treating the credential as a standalone function, and should define ownership of each anti-fraud activity clearly.

Common misconceptions

A Certified Fraud Examiner is legally required to conduct fraud investigations within an organization.
The credential is a voluntary professional designation, not a statutory license. In most jurisdictions there is no general legal requirement that fraud investigations, compliance monitoring, or internal audit work be performed by a CFE. Legal, licensing, and professional practice requirements vary by jurisdiction, sector, and entity type.
Holding the credential means an individual is responsible for the organization's overall fraud risk oversight.
The credential reflects individual expertise, not an organizational accountability structure. Oversight of fraud risk typically rests with the board or an appropriate committee, day-to-day management of anti-fraud controls sits with management, and independent assurance sits with functions such as internal audit. A credentialed individual may contribute to any of these but does not, by virtue of the credential, assume the associated oversight or assurance duties.
A Certified Fraud Examiner's work substitutes for legal, audit, or compliance advice.
The credential denotes specialized fraud knowledge but does not confer the authority of a licensed attorney, an external auditor's opinion, or a formal compliance determination. Conclusions in any specific matter depend on the facts, the applicable jurisdiction, and the professional's own judgment within their defined role.

Best practices

Confirm current eligibility criteria, examination domains, ethics requirements, and continuing education obligations directly with the credentialing body rather than relying on assumptions, as these can change over time.
Clarify in role descriptions and engagement scopes where accountability sits, distinguishing the credentialed individual's investigative or advisory contribution from the oversight duties of the board and the assurance role of internal audit.
Treat the credential as a signal of fraud-specific expertise that complements, rather than replaces, licensed legal advice, external audit opinions, and formal compliance determinations.
Position anti-fraud work within the organization's broader governance, risk, and compliance structure so that fraud prevention, detection, and investigation activities are coordinated with the relevant lines of defense.
Maintain adherence to the applicable professional code of ethics and document the basis for investigative conclusions, recognizing that outcomes in any specific matter depend on the facts and applicable jurisdiction.
Verify jurisdiction- and sector-specific requirements before assuming any particular credential is necessary or sufficient for a given role, since legal and professional practice requirements vary.