1/96
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
According to _________ Fraud and Internal Audit Position Paper, fraud can be defined as any illegal act characterized by deceit, concealment, or violation of trust. These acts are not dependent upon the threat of violence or physical force. Frauds are perpetrated by parties and organizations to obtain money, property, or services; to avoid payment or loss of services; or to secure personal or business advantage.
Institute of Internal Auditors
It defines fraud as all multifarious means which human ingenuity can devise, which are resorted to by one individual to get an advantage over another by false suggestions or suppression of truth. It includes all surprise, trick, cunning or dissembling, and any unfair way by which another is cheated
Black's Law Dictionary
It defines fraud as a knowing misrepresentation of the truth or concealment of a material fact to induce another to act to his or her detriment.
Black's Law Dictionary. 8th Ed (2004)
Under common law, three elements are required to prove fraud.
Material false statement
Knowledge that the statement was false when it was uttered
Reliance on the false statement by the victim
Damages as a result
According to Albrecht (Fraud Examination), Fraud is deception that includes the following elements.
A representation
About a material point
Which is false
And intentionally or recklessly so
Which is believed
And acted upon by the victim
To the victim's damage
It is the possibility that fraud will occur and the potential effects to the organization when it occurs.
Fraud Risk
Fraud Classification
CAO
Committed against organizations, and committed on behalf of organization
According to victim
Occupational Fraud
In this classification of fraud, the victim of the fraud is the employee’s employer.
Committed against organizations
In this classification of fraud, executives usually commit this to make the company’s reported financial results look better than they actually are.
Committed on behalf of organization
Types of Fraud According to Victim
Companies are the victim
Investors and creditors are the victim
Customers are the victim
Fraud which companies are the victim
Employee Embezzlement
Vendor Fraud
Customer Fraud
Fraud which investors and creditors are the victim
Management Fraud (Financial Statement Fraud)
Fraud which customers are the victim
Investment scams and other consumer frauds (Ponzi/pyramid schemes, Advance Fees schemes (Nigerian prince), pump and dump security trading, affinity fraud)
A type of fraud which an employee, manager, officer, or owner of an organization commits fraud to the organization’s detriment
Occupational Fraud
Three Major Types of Occupational Fraud
Asset Misappropriation
Corruption
Fraudulent Statements
It is by far the most common of all occupational frauds.
Asset Misappropriation
Three Major Categories of Asset Misappropriation Schemes
Cash Receipts Schemes
Fraudulent Disbursements
Inventory and Other Assets
Two Categories of Cash Receipts Schemes:
Skimming
Larceny
It is the removal of cash from a victim entity prior to its entry in an accounting system. It is also known as the off-book fraud, meaning money is stolen before it is recorded in the victim organization’s accounts.
Skimming
Examples of Skimming Schemes
Collecting cash, but not recording the sale
Collecting cash, keeping a portion of the cash, and underreporting the sale amount
Collecting a customer’s payment, but not crediting the amount to the customer’s account
Collecting cash and holding it in a personal interest-bearing account before depositing it into the company account
It is the intentional taking of employer’s cash without the consent and against the will of the employer. It can take place in any circumstance in which an employee has access to cash.
Larceny
Examples of Larceny Schemes:
Stealing cash at the point of sale or register
Stealing cash receipts posted to sales and receivable journals
Stealing cash from bank deposits
Categories of Fraudulent Disbursement Schemes:
Register Disbursement Schemes
Check Tampering Schemes
Billing Schemes
Payroll Fraud Schemes
Expense Reimbursement Schemes
Examples of Register Disbursement Schemes:
False refunds schemes
False voids schemes
Examples of Check Tampering Schemes:
Forged maker schemes
Forged endorsement schemes
Altered payee schemes
Authorized maker schemes
Examples of Billing Schemes:
Shell company schemes
Non-accomplice vendors / Pay-and-return schemes
Personal purchase schemes
Examples of Payroll Schemes:
Ghost employee schemes
Overpayment schemes
Commission schemes
Examples of Reimbursement Schemes:
Mischaracterized expense schemes
Overstated expense schemes
Fictitious expense schemes
Multiple reimbursement schemes
Examples of Misappropriation of Inventory and Other Assets:
Misuse of inventory and other assets
Theft of inventory and other assets
Fake sale schemes
Purchasing schemes
Receiving schemes
False shipment schemes
Misuse of company assets
Larceny schemes
Misappropriation of intangible assets
Four Major Categories of Corruption Schemes
Bribery
Conflict of Interest
Illegal Gratuities
Economic Extortion
It is the wrongful use of influence to procure a benefit for the actor or another person, contrary to the duty or the rights of others.
Corruption
It is offering, giving, receiving, or soliciting anything of value to influence an outcome (e.g., kickbacks)
Bribery
Examples of Bribery:
Kickback Schemes
Bid-rigging Schemes
It is an undisclosed personal economic interest in a transaction that adversely affects the organization or its shareholders.
Conflict of Interest
Examples of Conflict of Interest:
Purchase Schemes
Sales Schemes
It involves the giving or receiving something of value to reward a business decision.
Illegal Gratuities
It occurs when an employee demands payment from a vendor for a decisions made in the vendor’s favor. Refusal to pay the extorter results in harm to the vendor.
Economic Extortion
It is the deliberate misrepresentation of the financial condition of an enterprise accomplished through the intentional misstatement or omission of amounts or disclosure in the financial statements to deceive financial statement users.
Fraudulent Statements
Three interrelated elements enable someone to commit fraud:
Motivation
Opportunity
Rationalization
Elements of Pressure (Motivation)
Financial Pressures
Vice Pressures
Work-related Pressures
Other Pressures
Examples of Financial Pressures for:
Individual Perpetrators:
Organizations (Management Fraud):
Individual Perpetrators - common real or perceived financial pressures associated with fraud that benefits perpetrators directly.
Greed
Living beyon one’s means
Inability to pay bills or personal debt
Organizations (Management Fraud) - companies overstate assets on the balance sheet and net income on the income statement. Some causes of pressure:
A poor cash position
Receivables that aren’t collectible
A loss of customers, obsolete inventory
Closely related to financial pressures are motivation created by ________. Examples of this are:
vices
Gambling
Drugs
Alcohol
Expensive extramarital relationship
It is a motivation (pressure) committed by some people to get even with their employer or others.
Examples of Motivating factors of this:
Work-related pressures
Getting little recognition for job performance
Having a feeling of job dissatisfaction
Fearing losing one’s job
Being overlooked for a promotion
Feeling underpaid
Elements of Opportunity:
(LIFLIL)
Lack of internal controls that prevent and/or detect fraudulent behavior
Inability to judge quality of performance
Failure to discipline fraud perpetrators
Lack of access to information or asymmetrical information
Ignorance, apathy, or incapacity
Lack of an audit trail
It can be used to eliminate or reduce the opportunity for employees and others to commit fraud against the organization.
The 2012 COSO Internal Control Framework
It is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization.
Control Environment
It involves the dynamic and iterative process for identifying and assessing risks to the achievement of the objective.
Risk Assessment
These are actions established through policies and procedures that help ensure that management’s directives to mitigate risks to the achievement of objectives are carried out.
Control Activities
The control procedures that are relevant to financial statement audit include:
(APIPS)
Authorization
Performance Reviews
Information Processing Controls
Physical Controls
Segregation of Duties
It is necessary for the entity to carry out internal control responsibilities while communication is the continual, iterative process of providing, sharing, obtaining necessary information.
Fraud-related Information and Communication
These are the ongoing evaluations, separate evaluations, or some combination of the two to ascertain whether each of the five components of internal controls is present and functioning.
Monitoring
It is often difficult to know whether you are paying an excessive amount or receiving inferior service or products. It is easy for service provider to overcharge, perform work not needed, provide inferior service, or charge for work not performed.
Inability to judge quality of performance
It occurs when one party has information about products or situations and the other party does not.
Asymmetrical Information
Elements of Rationalization:
The organization owes me
I am only borrowing the money and will pay it back
Nobody will get hurt
I deserve more
It’s for a good purpose
We’ll fix the books as soon as we get over this financial difficulty
Something has to be sacrificed - my integrity or my reputation
It was developed by Albercht, which includes the components of situational pressures, opportunities to commit fraud and personal integrity and how they impact the assessment of fraud risks.
Fraud Scale
When situational pressures and opportunities to commit fraud are high, fraud is more likely to occur when personal integrity is low (T/F)
True
Elements of Fraud Diamond
Motivation
Opportunity
Rationalization
Capability
Indicators of Fraud
Accounting/document anomalies
Internal control weaknesses
Analytical/operational anomalies
Lifestyle
Behavior
Tips and complaints
Examples of Accounting/document Anomalies:
Source documents
Faulty journal entries
Inaccuracies in ledgers
Two sets of book
Examples of Control Weaknesses:
Lack of segregation of duties
Lack of physical safeguards
Lack of independent checks
Lack of proper authorization
Lack of proper documents and records
Overriding of existing controls
Inadequate accounting system
Examples of Analytical/Operational Anomalies:
These are procedures or relationships that are unusual or too unrealistic to be believable:
Unrealistic company goals/targets
Unexplained inventory shortages or adjustments
Deviations from specificatins
Increased scrap
Excess purchases
Too many debit or credit memos
Significant increases or decreases in account balances, ratios, or relationships
Physical abnormalities
Cash shortages or overages
Excessive late charges
Unreasonable expenses or reimbursements
Excessive turnover of executives
Strange financial statement relationships
Reliance to a single source vendor
Examples of Fraud Indicators Related to Lifestyle:
Living beyond means
Financial difficulties
Divorce/family problems
Addiction problems
Social isolation
Past legal problems
Examples of Fraud Indicators Related to Behavior:
Unusual close association with a vendor or customer
Excessive control issues or unwillingness to share duties
Irritability, suspiciousness, or defensiveness
“Wheeler-dealer” attitude
Complained about inadequate pay or lack of authority
Refusal to take vacations
Standard for Due Professional Care
Standard 4.2
Requirement of Standard 4.2: Internal auditors must exercise due professional care by assessing the nature, circumstances, and requirements of the services to be provided, including:
The organization’s strategy and objectives.
The interest of those for whom internal audit services are provided and the interests of other stakeholders.
Adequacy and effectiveness of governance, risk management, and control processes.
Cost relative to potential benefits of the internal audit services to be performed.
Extent and timeliness of work needed to achieve the engagement’s objectives.
Relative complexity, materiality, or significance of risks to the activity under review.
Probability of significant errors, fraud, noncompliance, and other risks that might affect objectives, operations, or resources.
Use of appropriate techniques, tools, and technology.
This standard emphasizes fraud as a core risk consideration, placing it on equal footing with errors and noncompliance in audit planning and execution.
Standard 4.2: Due Professional Care
Standard for Internal Audit Plan
Standard 9.4
Requirement of Standard 9.4: The CAE must create an internal audit plan that supports the achievement of the ___________ .
The CAE must base the internal audit plan on a documented __________, ________, _______. This assessment must be informed by input from the board and senior management as well as the chief audit executive’s understanding of the organization’s governance, risk management, and control processes. The assessment must be performed at least _________.
organization’s objectives
assessment of the organization’s strategies, objectives, and risks
annually
The internal audit plan must:
Consider the internal audit mandate and the full range of agreed-to internal services.
Specify internal audit services that support the evaluation and improvement of the organization’s governance, risk management, and control processes.
Consider coverage of information technology governance, fraud risk, the effectiveness of the organization’s compliance and ethics programs, and other high-risk areas.
Identify the necessary human, financial, and technological resources necessary to complete the plan.
Be dynamic and updated timely in response to changes in the organization’s business risks operations, programs, systems, controls, and organizational culture
It positions fraud risk as a planning priority, requiring the CAE to proactively integrate it into the internal audit plan, alongside other critical areas such as IT governance and compliance.
It emphasizes that fraud is a high-risk area that must be addressed through targeted audits, risk assessments, or continuous monitoring.
Standard 9.4: Internal Audit Plan
Standards for Engagement Risk Assessment
Standard 13.2
Requirement of Standards 13.2
Internal auditors must review the gathered information to understand how processes are intended to operate.
Internal auditors must identify the risks to review by:
Identifying the potentially significant risks to the objectives of the activity under review
Considering specific risks related to fraud.
Evaluating the significance of the risks and prioritizing them for review.
Internal auditors must identify the criteria that management uses to measure whether the activity is achieving its objectives.
When internal auditors have identified the relevant risks for an activity under review in past engagements, only a review and update of the previous engagement risk assessment is required.
This standard mandates that internal auditors must explicitly consider fraud risk during engagement planning, reinforcing accountability and ensuring that one of the most damaging types of risk is properly addressed.
It integrates fraud as a key element of risk-based auditing, particularly in areas with significant financial, operational, or reputational impact. Moreover, fraud risks must be evaluated and prioritized alongside other risks during scoping, ensuring they are not overlooked in the audit process.
Standard 13.2
There are four fraud-fighting elements/activities that organizations can use for an effective fraud management program:
Fraud prevention
Fraud detection
Fraud investigation
Follow-up legal action and/or resolution
It is generally the most cost-effective way to reduce losses from fraud. It encompasses policies, procedures, training, and communication that stop fraud from occurring,
Fraud Prevention
Effective fraud prevention involves:
Taking steps to create and maintain a culture of honesty and high ethics.
Tone at the top (proper modeling)
Hiring the right kind of employees
Communicating expectations of honesty and integrity
Creating a positive work environment
Proper handling of fraud and fraud perpetrators when fraud occurs
Assessing the risks for fraud and developing concrete responses to mitigate the risks and eliminate the opportunities for fraud
Ways to assess and mitigate the risk of fraud:
Accurately identifying sources and measuring risks
Implementing appropriate preventive and detective controls to mitigate those risks
Creating widespread monitoring by employees
Having internal and external auditors who provide independent checks on performance
It usually begins by identifying symptoms, indicators, or red flags that tend to be associated with fraud. It focuses on activities and techniques that promptly recognize timely whether fraud has occurred or is occurring.
Fraud Detection
Important detection methods include.
An anonymous reporting mechanism (whistleblower hotline)
Process controls
Proactive fraud detection procedures specifically designed to identify fraudulent activity
It is one of the more effective measures organizations can implement as part of their fraud risk assessment program.
Whistleblower Hotline
It specifically designed to detect fraudulent activity, as well as errors, include reconciliations, independent reviews, physical inspections/counts, analyses, and audits
Process Controls
In addition to detective process controls, organizations may be able to use data analysis, continuous auditing techniques, and other technology tools effectively to detect fraudulent activity
Proactive Fraud Detection Procedures
They has the responsibility to ensure that management designs effective fraud risk management documentation to encourage ethical behavior and to empower employees, customers, and vendors to insist those standards are met every day.
Board of Directors
They are committed to a proactive approach to fraud risk management maintains an active role in the oversight of the organization's assessment of fraud risks and uses internal auditors, or other designated personnel, to monitor fraud risks.
Audit Committee
They has overall responsibility for the design and implementation of a fraud risk management program.
Management
All levels of staff, including management, should:
Have a basic understanding of fraud and be aware of the red flags.
Understand their roles within the internal control framework. Staff members should understand how their job procedures are designed to manage fraud risks and when noncompliance may create an opportunity for fraud to occur or go undetected.
Read and understand policies and procedures (e.g. the fraud policy, code of conduct, and whistleblower policy), as well as other operational policies and procedures, such as procurement manuals.
As required, participate in the process of creating a strong control environment and designing and implementing fraud control activities, as well as participate in monitoring activities.
Report suspicions or incidences of fraud.
Cooperate in investigations.
A reporting process should be in place to solicit input on potential fraud, and a coordinated approach to investigation and corrective action should be used to help ensure potential fraud is addressed appropriately and timely
Fraud Investigation
Potential fraud may come to the organization's attention in many ways, including tips from employees, customers, or vendors; internal audits; process control identification; external audits; or by accident The board should ensure that the organization develops a system for prompt, competent, and confidential review, investigation, and resolution of allegations involving potential fraud or misconduct
Receiving the Allegation
Once an allegation is received, the organization should follow the process approved by the board to evaluate the allegation. The process should include designating an individual or individuals with the necessary authority and skills to conduct an initial evaluation of the allegation and determine the appropriate course of action to resolve it. In cases that involve the board or senior management, the board may want to hire outside independent advisers to assist in this evaluation.
Evaluating the Allegation
Investigations should be performed by protocols approved by the board. A consistent process for conducting investigations can help the organization mitigate losses and manage risks associated with the investigation.
Investigation Protocols
Factors to consider in developing the investigation plan include.
Time-sensitivity
Notification
Confidentiality
Legal privileges
Compliance
Securing evidence
Objectivity
Goals
Investigations generally include:
Interviewing
Neutral third-party witnesses
Corroborative witnesses
Possible co-conspirators
The accused
Evidence Collection
Internal documents
Personnel files
Internal phone records
Computer files and other electronic devices
Financial records
Security camera videos
Physical and IT system access records
External records
Public records
Customer/vendor information
Media reports
Information held by third parties
Private detective reports
Computer Forensic Examinations
Evidence Analysis
Review and categorization of information collected
Computer-assisted data analysis
Development and testing of hypotheses
The investigation team should report its findings to the party overseeing the investigation, such as senior management, directors, or legal counsel.
Where legal counsel is supervising the investigation, counsel will determine the appropriate form of the report.
The nature and distribution of the report may be affected by the goals of protecting legal privileges and avoiding defamatory statements. For similar reasons, advice of counsel should be sought before the party overseeing the investigation makes public statements or other communications regarding the investigation.
Reporting the Results
After the investigation has been completed, the organization will need to determine what action to take in response to the findings. Any findings of actual or potential material impact may need to be reported to the board, the audit committee, and the external auditor if they are not receiving investigation reports directly. Notification may also be required to legal and regulatory agencies and the organization's insurers.
Corrective Action
Possible actions include available for organizations:
Criminal referral
Civil action
Disciplinary action
Insurance claim
Extended investigation
Business process remediation
Internal control remediation
In _________, auditing skills are applied to in-depth investigations that have potential legal implications or consequences (for example, money laundering, funding terrorists or organized crime).
Forensic Auditing
The _____ helps the internal auditor gather evidence to prove or disprove suspicions, identify the parties involved, and acquire and maintain evidence that may be presented in disciplinary or criminal proceedings.
Forensic Expert