DRMLAW
Knowledge Article

The Difference Between a Forensic Report and a Confirmation Bias Exercise

By Rupak Ranjan Mukherjee, BE,CCLP,C.DPO.DA, Founder Partner · 2026-09-29 · Digital Forensics

DRMLAW KNOWLEDGE PORTAL · DIGITAL FORENSICS

The Difference Between a Forensic Report and a Confirmation Bias Exercise

How DRMLAW's Digital Forensics practice approaches Tally and financial-data examinations under the Bharatiya Sakshya Adhiniyam, 2023

By Rupak Ranjan Mukherjee — Chief Digital Forensics Investigator, DRMLAW LLP

• • •

When a dispute reaches the point of needing digital evidence certified, the temptation — for any examiner — is to go straight to the transactions already under suspicion. It's faster, it's what the client is paying attention to, and it usually confirms what everyone already believed going in.

It's also the least defensible way to build a forensic finding.

Start With the Whole History, Not the Suspected Window

A pattern that only appears when you already know where to look isn't evidence — it's confirmation bias with extra steps. Our practice is built around the opposite discipline: screen the complete transactional history of a business — every voucher, every counterparty, every year of operation — using the same rule-based tests throughout, before ever narrowing in on the disputed period.

If a concentration of activity, an unusual alteration pattern, or an anomalous entry only shows up under scrutiny of the disputed window, that tells you nothing. If the same pattern is genuinely absent from years of otherwise ordinary business activity, that's a finding worth putting your name behind — and one an opposing expert can't dismiss as selective framing.

Query the Database, Not the Report

Most native accounting software exports — including Tally's own “Export Data” function — pass through the application's own report-rendering layer before you ever see them. That layer can silently omit exactly the records that matter: voucher types with unusual structures, edge-case entries, anything that doesn't fit the report template's assumptions.

Our extraction methodology instead connects directly to the underlying data structures, pulling audit-trail fields — who altered a record, and when — that a rendered report was never built to expose in the first place.

It's the difference between reading a summary of the evidence and examining the evidence itself.

Hash Every Step, Not Just the Starting Point

Chain of custody doesn't end once a backup is received and hashed. Every workbook, every extraction, every intermediate output generated during an examination is independently hashed at the moment it's created — so the link between the original source and the final certified finding is never a gap someone has to take on faith.

Test the Client's Claims — Don't Just Repeat Them

Clients often arrive with their own reading of the data, sometimes remarkably precise ones. The instinct to simply validate that reading and move on is exactly the instinct a rigorous examination has to resist. Every figure a client brings to the table gets independently reproduced against the primary evidence before it appears in any certificate or report — confirmed where it holds up, corrected openly where it doesn't.

A report that only ever agrees with the party who commissioned it isn't a forensic report. It's a favor with a letterhead.

Built for Scrutiny, Not Just for Filing

Certification under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (the successor to the erstwhile Section 65B) requires more than procedural compliance — it requires a methodology that can be explained, reproduced, and defended under direct challenge. That's the bar we hold our own work to before anyone else gets the chance to.

• • •

ABOUT THE AUTHOR

Rupak Ranjan Mukherjee

Chief Digital Forensics Investigator, DRMLAW LLP — CHFI, CCLP, C.DPO.DA, AIGP

DRMLAW LLP

Digital Evidence & Forensic Certification Services

Kolkata · Bengaluru · info@drmlaw.in · www.drmlaw.in