1. Brief of the Application
ForenShastra AI is an offline-first forensic accounting and audit-intelligence platform built specifically for Chartered Accountants in India. The name joins Foren, for forensic, with Shastra, a disciplined body of knowledge. It is designed for the reality of professional practice, where a firm receives large, inconsistent and unstructured accounting data and is expected to surface fraud risk, error and control failure quickly, defensibly and without breaching client confidentiality.
The platform ingests data in any shape, runs a deterministic battery of computer-assisted audit techniques and statistical laboratories, layers masked artificial-intelligence reasoning on top, and produces evidence-linked, presumption-neutral observations and working papers a firm can actually issue. It is built on one non-negotiable rule: the tool surfaces risk and evidence, but it never concludes fraud on its own. A human Chartered Accountant always forms and signs the conclusion.
| One number, one story | A single Chartered Accountant, on a single laptop, with no data ever leaving the machine, can triage more than 2.7 lakh transactions against 104 forensic rules and 14 analytical laboratories in minutes, fully masked, fully audit-trailed and defensible line by line. |
2. Problem and Proposed Solution
| Current pain point in CA practice | How ForenShastra AI addresses it |
| Firms receive vast, inconsistent, unstructured accounting data, and manual review does not scale. | Aakar ingests arbitrary formats and normalises them to a canonical schema, then the engines triage every register automatically. |
| Spreadsheets miss cross-cutting patterns that only show up across registers and parties. | 104 CAAT rules and 14 laboratories run across sales, purchase, bank, cash, journal, payroll, inventory, fixed asset, GST and TDS in one pass. |
| Generic AI tools leak confidential client data and over-claim conclusions a professional can never sign. | Kavach masks every direct, indirect and contextual identifier before any AI call, and a prohibited-words validator blocks conclusory language. |
| Findings are hard to defend without a clear evidence trail. | Rule-linked flags, evidence cards, versioned working papers and a hash-chained Praman audit trail make every figure traceable to source. |
| Confidentiality duties under DPDP-era expectations are difficult to honour with cloud tools. | The platform runs fully offline by default; the only outbound call is an explicitly masked, user-initiated AI request. |
3. Users, Scope and Professional Outputs
| Primary users | Forensic auditors, statutory and internal auditors, management auditors, fraud-risk consultants, CFO and compliance teams, and the engagement staff of a Chartered Accountant firm. |
| Engagement scope | Forensic accounting reviews, audit support, fraud-risk assessment, transaction testing, ledger scrutiny, journal-entry testing, related-party review, and listed-company screening. |
| Operating model | Local SQLite store with tuned indexing, deterministic offline engines by default, and optional Gemini-assisted reasoning only behind the Kavach masking gate when online features are explicitly enabled. |
| Professional outputs | Evidence cards, observation registers, versioned working papers, executive summaries, draft forensic reports, gap assessments and a Praman certificate, exported as letterheaded Word, PDF and Excel. |
4. Core Functional Modules
Modules are bifurcated into those that operate on the selected client engagement and general tools that need no client. Names are Sanskrit with English subtitles.
4.1 Client workspace
| Mission Control | Forensic dashboard with severity, trend, concentration and value-at-flag visuals, each with a plain-language caption. |
| Aakar (Data Refinery) | Universal ingestion of any-format, unstructured data normalised to a canonical schema with mapping targets. |
| Niyam Yantra (CAAT) | The 104-rule computer-assisted audit battery across every register. |
| Labs | Fourteen analytical laboratories spanning Benford, Beneish, distress, outlier, fuzzy, graph, sampling, ratio, time, ML, scoring and text forensics. |
| Manas (Behavioural Lens) | Fraud-diamond behavioural forensics with a holistic read and a subject dossier. |
| Bandhan (Network Graph) | Relationship and graph analytics for circular trading and rings. |
| Kaal Rekha (Chronology) | Event timeline and sequencing of exceptions. |
| Evidence Cards | The spine of the workflow: promotes non-safe observations to evidence and working papers. |
| Working Papers | Authored in-app, versioned and downloadable as letterheaded Word. |
| Report Studio | Working-paper pack, observation register, executive summary, draft report and gap assessment in Word, PDF and Excel. |
| Sutra (Agents) | A live five-agent workflow producing masked cross-signal scheme hypotheses and an outbox. |
| Kavach (The Shield) | Masking, identifier detection and the AI pre-flight inspector. |
4.2 General tools
| Drishti (Public Screener) | Listed-company screen using Beneish, ratios and a forensic narrative. |
| Gyan Kosh (Knowledge Portal) | Forensic knowledge base for Chartered Accountants. |
| Guru (Forensic Mentor AI) | Restricted forensic question-and-answer citing standards, online-gated. |
| Maya (Demo Data) | Loads or clears the fictional demo universe on an explicit click only. |
| Pariksha (Self Test) | Runs the integrity suite from the interface and shows results. |
| Settings | Theme, Trust Dial, Gemini key and SMTP status and test. |
5. Forensic Lifecycle
ForenShastra AI mirrors how a Chartered Accountant actually runs a forensic engagement, from acceptance to closure, so the workflow is professional rather than merely analytical.
- Engagement context. Select the client and engagement once; downstream modules work in that same client context.
- Data refinery. Ingest the raw accounting data in any format through Aakar; it is normalised to a canonical schema and masked at the Kavach gate.
- Risk scanning. Run the 104 CAAT rules and the 14 laboratories across every register, with Mulya producing an explainable composite risk score.
- Behavioural and network read.Review behavioural signals in Manas and relationship patterns in Bandhan, then sequence exceptions in Kaal Rekha.
- Cross-signal synthesis. Optionally run Sutra in Guarded mode for masked cross-signal scheme hypotheses and a targeted investigation plan.
- Evidence mapping. Promote non-safe observations to evidence cards and author versioned working papers.
- Reporting and closure. Generate letterheaded reports in Report Studio, subject to partner review, with the Praman audit trail recording every action.
6. Analytical Depth and Forensic Scope
The deterministic core is organised in two tiers and supported by a behavioural layer, so risk is assessed at the level of the whole financial statement and at the level of the individual voucher.
| CAAT rule library | 104 rules across P2P, O2C, JE, PAY, BNK, GST, TDS, MST and INV register families. |
| Statement-level tests | Beneish 8-index M-Score with threshold −2.22, Benford first-digit and matrix, Altman, Piotroski, Ohlson and Sloan. |
| Analytical laboratories | 14 laboratories covering fuzzy, graph, outlier, ABC, time-sequence, sampling, ratio, text and ML analytics. |
| Behavioural layer | Manas fraud-diamond across pressure, opportunity, rationalisation and capability. |
| Listed-company screen | Drishti applies Beneish, ratios and a forensic narrative to public companies. |
| Traceability | Every flag carries a rule code, the transaction or party, a severity and a plain-language meaning, and drills down to source. |
7. AI, Security and Governance Layer
| Layer | Control | Professional significance |
| Trust Dial | Sovereign offline by default; Guarded enables masked Gemini with a key; Open enables reviewed webhook workflows. | The firm decides, per engagement, whether any data leaves the machine. |
| Kavach masking | Detects PAN, GSTIN checksum, Aadhaar Verhoeff, mobile, email, IFSC and names, and de-identifies every AI payload to counts and codes. | Privacy by construction; confidential client data is never transmitted. |
| Sutra agents | Five cooperating agents (plan, execute, synthesise, validate, watch) produce cross-signal hypotheses, not summaries. | Reasoning across patterns single rules cannot connect, while staying presumption-neutral. |
| AI governance | A prohibited-words validator blocks conclusory language; outputs are classified for human review. | The AI never acts as final authority; the Chartered Accountant validates before reliance. |
| Security | Local-only data, secrets in .env, CSRF on every form, secure-delete and encrypted backup, hash-chained audit trail. | Supports confidentiality, integrity and partner review under a DPDP-era duty of care. |
8. Technology Stack
| Component | Implemented stack |
| Backend and application | Python and Flask with an app-factory and blueprints, server-rendered Jinja2 templates and vanilla JavaScript, packaged as a portable Windows executable. |
| Visualisation | A dependency-free SVG chart layer with one vendored Chart.js file; no React, no npm and no build step. |
| Database | Local SQLite with Write-Ahead Logging, tuned pragmas and more than fifteen purpose-built indexes. |
| Analytics | pandas, numpy, scipy, scikit-learn, networkx and rapidfuzz for vectorised analytics, statistics, ML, graph analytics and fuzzy resolution. |
| Documents and exports | python-docx for Word, reportlab for PDF and openpyxl for filterable Excel. |
| AI and internet | Google Gemini 2.5-flash with a fallback ladder, reached only through the Kavach masking gate and only when online features are enabled; a full offline fallback otherwise. |
| Security layer | cryptography for encrypted backup and secure-delete, masked keys, local database, audit hash chain and controlled export design. |
| Packaging | PyInstaller one-file build with svglib icon rasterisation; requirements.txt as the single dependency manifest. |
9. Assurance, Demo Universe and Verification
Every claim in this summary is as-built and verified against the packaged application. The demo universe, Maya, is a fictional, seeded dataset that lets a jury reconcile the tool's findings against a sealed answer key.
9.1 The Maya demo universe
| Demo companies (engagements) | 3 |
| Parties | 15,350 |
| Transactions | 277,423 |
| Flags raised | 92,098 |
| Financial statements | 1,922 |
| Answer-key typologies | 20 |
| Registers covered | Sales, purchase, bank, cash, journal, payroll, inventory, fixed asset, GST and TDS (ten register types) |
The demo is reproducible from code through the in-app Maya load, which is deterministic and seeded, and the packaged executable ships with it pre-installed. No real company, person or brand name appears anywhere; fictional names only, with a coincidence disclaimer in the footer and every report.
9.2 Engineering assurance
| Automated tests | 409 tests pass across ingestion, engines, exports, security and the user interface. |
| Golden fixtures | The labs are pinned to known-good outputs for Beneish, Benford, Altman, Piotroski, Ohlson, Sloan, relative-size factor, sampling and Kavach checksums. |
| Determinism | Identical inputs always produce identical outputs. |
| Boot integrity | The application boots clean across 115 routes with all static assets resolving. |
| Guardrails | Demo isolation, prohibited-words validation and a launcher smoke test are enforced by tests. |
10. Benefits to Chartered Accountant Firms
- Compresses days of manual triage into minutes, with broader and more consistent coverage than spreadsheet review.
- Produces defensible, evidence-linked deliverables on the firm's own letterhead, ready for partner review.
- Protects client confidentiality by construction, with local-only processing, absolute masking and a full audit trail, aligned with a DPDP-era duty of care.
- Runs as a single, offline, reusable instrument across every engagement on an ordinary laptop, with no server or subscription dependency.
- Strengthens, rather than replaces, professional judgement, keeping a human Chartered Accountant as the reviewer and signatory at every critical stage.
- Opens new professional service opportunities in forensic review, fraud-risk assessment, listed-company screening and audit-analytics support.
11. Standards and Professional Alignment
The platform is designed to support professional judgement, and applies the following frameworks as guidance for risk assessment, evidence, documentation and skepticism, subject to engagement scope.
| Domain | Frameworks referenced |
| Forensic and audit | ICAI Forensic Accounting and Investigation Standards; SA 200, SA 230, SA 240, SA 315, SA 500, SA 520 and SA 550 as guidance. |
| Professional conduct | Chartered Accountants Act, 1949 and the ICAI Code of Ethics, including confidentiality. |
| Company and tax law | Companies Act, 2013 with CARO 2020 considerations; Income Tax and GST implications framed as risk indicators. |
| Data and evidence | Digital Personal Data Protection Act, 2023; Information Technology Act and Indian Evidence Act considerations for digital records. |
| Submission conclusion | ForenShastra AI demonstrates how a Chartered Accountant firm can run fast, broad and defensible forensic reviews on an ordinary laptop, with confidential data never leaving the machine, every figure traceable to source, and a human reviewer in control of every conclusion. It is positioned as a practical, scalable and professionally defensible forensic instrument for the Indian Chartered Accountant ecosystem. |