Fraud Risk

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/96

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:28 AM on 7/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

97 Terms

1
New cards

According to _________ Fraud and Internal Audit Position Paper, fraud can be defined as any illegal act characterized by deceit, concealment, or violation of trust. These acts are not dependent upon the threat of violence or physical force. Frauds are perpetrated by parties and organizations to obtain money, property, or services; to avoid payment or loss of services; or to secure personal or business advantage.

Institute of Internal Auditors

2
New cards

It defines fraud as all multifarious means which human ingenuity can devise, which are resorted to by one individual to get an advantage over another by false suggestions or suppression of truth. It includes all surprise, trick, cunning or dissembling, and any unfair way by which another is cheated

Black's Law Dictionary

3
New cards

It defines fraud as a knowing misrepresentation of the truth or concealment of a material fact to induce another to act to his or her detriment.

Black's Law Dictionary. 8th Ed (2004)

4
New cards

Under common law, three elements are required to prove fraud.

  • Material false statement

  • Knowledge that the statement was false when it was uttered

  • Reliance on the false statement by the victim

  • Damages as a result

5
New cards

According to Albrecht (Fraud Examination), Fraud is deception that includes the following elements.

  1. A representation

  2. About a material point

  3. Which is false

  4. And intentionally or recklessly so

  5. Which is believed

  6. And acted upon by the victim

  7. To the victim's damage

6
New cards

It is the possibility that fraud will occur and the potential effects to the organization when it occurs.

Fraud Risk

7
New cards

Fraud Classification

CAO

  • Committed against organizations, and committed on behalf of organization

  • According to victim

  • Occupational Fraud

8
New cards

In this classification of fraud, the victim of the fraud is the employee’s employer.

Committed against organizations

9
New cards

In this classification of fraud, executives usually commit this to make the company’s reported financial results look better than they actually are.

Committed on behalf of organization

10
New cards

Types of Fraud According to Victim

  1. Companies are the victim

  2. Investors and creditors are the victim

  3. Customers are the victim

11
New cards

Fraud which companies are the victim

  • Employee Embezzlement

  • Vendor Fraud

  • Customer Fraud

12
New cards

Fraud which investors and creditors are the victim

Management Fraud (Financial Statement Fraud)

13
New cards

Fraud which customers are the victim

Investment scams and other consumer frauds (Ponzi/pyramid schemes, Advance Fees schemes (Nigerian prince), pump and dump security trading, affinity fraud)

14
New cards

A type of fraud which an employee, manager, officer, or owner of an organization commits fraud to the organization’s detriment

Occupational Fraud

15
New cards

Three Major Types of Occupational Fraud

  1. Asset Misappropriation

  2. Corruption

  3. Fraudulent Statements

16
New cards

It is by far the most common of all occupational frauds.

Asset Misappropriation

17
New cards

Three Major Categories of Asset Misappropriation Schemes

  1. Cash Receipts Schemes

  2. Fraudulent Disbursements

  3. Inventory and Other Assets

18
New cards

Two Categories of Cash Receipts Schemes:

  1. Skimming

  2. Larceny

19
New cards

It is the removal of cash from a victim entity prior to its entry in an accounting system. It is also known as the off-book fraud, meaning money is stolen before it is recorded in the victim organization’s accounts.

Skimming

20
New cards

Examples of Skimming Schemes

  • Collecting cash, but not recording the sale

  • Collecting cash, keeping a portion of the cash, and underreporting the sale amount

  • Collecting a customer’s payment, but not crediting the amount to the customer’s account

  • Collecting cash and holding it in a personal interest-bearing account before depositing it into the company account

21
New cards

It is the intentional taking of employer’s cash without the consent and against the will of the employer. It can take place in any circumstance in which an employee has access to cash.

Larceny

22
New cards

Examples of Larceny Schemes:

  • Stealing cash at the point of sale or register

  • Stealing cash receipts posted to sales and receivable journals

  • Stealing cash from bank deposits

23
New cards

Categories of Fraudulent Disbursement Schemes:

  • Register Disbursement Schemes

  • Check Tampering Schemes

  • Billing Schemes

  • Payroll Fraud Schemes

  • Expense Reimbursement Schemes

24
New cards

Examples of Register Disbursement Schemes:

  • False refunds schemes

  • False voids schemes

25
New cards

Examples of Check Tampering Schemes:

  • Forged maker schemes

  • Forged endorsement schemes

  • Altered payee schemes

  • Authorized maker schemes

26
New cards

Examples of Billing Schemes:

  • Shell company schemes

  • Non-accomplice vendors / Pay-and-return schemes

  • Personal purchase schemes

27
New cards

Examples of Payroll Schemes:

  • Ghost employee schemes

  • Overpayment schemes

  • Commission schemes

28
New cards

Examples of Reimbursement Schemes:

  • Mischaracterized expense schemes

  • Overstated expense schemes

  • Fictitious expense schemes

  • Multiple reimbursement schemes

29
New cards

Examples of Misappropriation of Inventory and Other Assets:

  • Misuse of inventory and other assets

  • Theft of inventory and other assets

    • Fake sale schemes

    • Purchasing schemes

    • Receiving schemes

    • False shipment schemes

    • Misuse of company assets

    • Larceny schemes

  • Misappropriation of intangible assets

30
New cards

Four Major Categories of Corruption Schemes

  1. Bribery

  2. Conflict of Interest

  3. Illegal Gratuities

  4. Economic Extortion

31
New cards

It is the wrongful use of influence to procure a benefit for the actor or another person, contrary to the duty or the rights of others.

Corruption

32
New cards

It is offering, giving, receiving, or soliciting anything of value to influence an outcome (e.g., kickbacks)

Bribery

33
New cards

Examples of Bribery:

  • Kickback Schemes

  • Bid-rigging Schemes

34
New cards

It is an undisclosed personal economic interest in a transaction that adversely affects the organization or its shareholders.

Conflict of Interest

35
New cards

Examples of Conflict of Interest:

  • Purchase Schemes

  • Sales Schemes

36
New cards

It involves the giving or receiving something of value to reward a business decision.

Illegal Gratuities

37
New cards

It occurs when an employee demands payment from a vendor for a decisions made in the vendor’s favor. Refusal to pay the extorter results in harm to the vendor.

Economic Extortion

38
New cards

It is the deliberate misrepresentation of the financial condition of an enterprise accomplished through the intentional misstatement or omission of amounts or disclosure in the financial statements to deceive financial statement users.

Fraudulent Statements

39
New cards

Three interrelated elements enable someone to commit fraud:

  1. Motivation

  2. Opportunity

  3. Rationalization

40
New cards

Elements of Pressure (Motivation)

  1. Financial Pressures

  2. Vice Pressures

  3. Work-related Pressures

  4. Other Pressures

41
New cards

Examples of Financial Pressures for:

Individual Perpetrators:

Organizations (Management Fraud):

Individual Perpetrators - common real or perceived financial pressures associated with fraud that benefits perpetrators directly.

  • Greed

  • Living beyon one’s means

  • Inability to pay bills or personal debt

Organizations (Management Fraud) - companies overstate assets on the balance sheet and net income on the income statement. Some causes of pressure:

  • A poor cash position

  • Receivables that aren’t collectible

  • A loss of customers, obsolete inventory

42
New cards

Closely related to financial pressures are motivation created by ________. Examples of this are:

vices

  • Gambling

  • Drugs

  • Alcohol

  • Expensive extramarital relationship

43
New cards

It is a motivation (pressure) committed by some people to get even with their employer or others.

Examples of Motivating factors of this:

Work-related pressures

  • Getting little recognition for job performance

  • Having a feeling of job dissatisfaction

  • Fearing losing one’s job

  • Being overlooked for a promotion

  • Feeling underpaid

44
New cards

Elements of Opportunity:

(LIFLIL)

  1. Lack of internal controls that prevent and/or detect fraudulent behavior

  2. Inability to judge quality of performance

  3. Failure to discipline fraud perpetrators

  4. Lack of access to information or asymmetrical information

  5. Ignorance, apathy, or incapacity

  6. Lack of an audit trail

45
New cards

It can be used to eliminate or reduce the opportunity for employees and others to commit fraud against the organization.

The 2012 COSO Internal Control Framework

46
New cards

It is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization.

Control Environment

47
New cards

It involves the dynamic and iterative process for identifying and assessing risks to the achievement of the objective.

Risk Assessment

48
New cards

These are actions established through policies and procedures that help ensure that management’s directives to mitigate risks to the achievement of objectives are carried out.

Control Activities

49
New cards

The control procedures that are relevant to financial statement audit include:

(APIPS)

  • Authorization

  • Performance Reviews

  • Information Processing Controls

  • Physical Controls

  • Segregation of Duties

50
New cards

It is necessary for the entity to carry out internal control responsibilities while communication is the continual, iterative process of providing, sharing, obtaining necessary information.

Fraud-related Information and Communication

51
New cards

These are the ongoing evaluations, separate evaluations, or some combination of the two to ascertain whether each of the five components of internal controls is present and functioning.

Monitoring

52
New cards

It is often difficult to know whether you are paying an excessive amount or receiving inferior service or products. It is easy for service provider to overcharge, perform work not needed, provide inferior service, or charge for work not performed.

Inability to judge quality of performance

53
New cards

It occurs when one party has information about products or situations and the other party does not.

Asymmetrical Information

54
New cards

Elements of Rationalization:

  • The organization owes me

  • I am only borrowing the money and will pay it back

  • Nobody will get hurt

  • I deserve more

  • It’s for a good purpose

  • We’ll fix the books as soon as we get over this financial difficulty

  • Something has to be sacrificed - my integrity or my reputation

55
New cards

It was developed by Albercht, which includes the components of situational pressures, opportunities to commit fraud and personal integrity and how they impact the assessment of fraud risks.

Fraud Scale

56
New cards

When situational pressures and opportunities to commit fraud are high, fraud is more likely to occur when personal integrity is low (T/F)

True

57
New cards

Elements of Fraud Diamond

  1. Motivation

  2. Opportunity

  3. Rationalization

  4. Capability

58
New cards

Indicators of Fraud

  1. Accounting/document anomalies

  2. Internal control weaknesses

  3. Analytical/operational anomalies

  4. Lifestyle

  5. Behavior

  6. Tips and complaints

59
New cards

Examples of Accounting/document Anomalies:

  • Source documents

  • Faulty journal entries

  • Inaccuracies in ledgers

  • Two sets of book

60
New cards

Examples of Control Weaknesses:

  • Lack of segregation of duties

  • Lack of physical safeguards

  • Lack of independent checks

  • Lack of proper authorization

  • Lack of proper documents and records

  • Overriding of existing controls

  • Inadequate accounting system

61
New cards

Examples of Analytical/Operational Anomalies:

These are procedures or relationships that are unusual or too unrealistic to be believable:

  • Unrealistic company goals/targets

  • Unexplained inventory shortages or adjustments

  • Deviations from specificatins

  • Increased scrap

  • Excess purchases

  • Too many debit or credit memos

  • Significant increases or decreases in account balances, ratios, or relationships

  • Physical abnormalities

  • Cash shortages or overages

  • Excessive late charges

  • Unreasonable expenses or reimbursements

  • Excessive turnover of executives

  • Strange financial statement relationships

  • Reliance to a single source vendor

62
New cards

Examples of Fraud Indicators Related to Lifestyle:

  • Living beyond means

  • Financial difficulties

  • Divorce/family problems

  • Addiction problems

  • Social isolation

  • Past legal problems

63
New cards

Examples of Fraud Indicators Related to Behavior:

  • Unusual close association with a vendor or customer

  • Excessive control issues or unwillingness to share duties

  • Irritability, suspiciousness, or defensiveness

  • “Wheeler-dealer” attitude

  • Complained about inadequate pay or lack of authority

  • Refusal to take vacations

64
New cards

Standard for Due Professional Care

Standard 4.2

65
New cards

Requirement of Standard 4.2: Internal auditors must exercise due professional care by assessing the nature, circumstances, and requirements of the services to be provided, including:

  • The organization’s strategy and objectives.

  • The interest of those for whom internal audit services are provided and the interests of other stakeholders.

  • Adequacy and effectiveness of governance, risk management, and control processes.

  • Cost relative to potential benefits of the internal audit services to be performed.

  • Extent and timeliness of work needed to achieve the engagement’s objectives.

  • Relative complexity, materiality, or significance of risks to the activity under review.

  • Probability of significant errors, fraud, noncompliance, and other risks that might affect objectives, operations, or resources.

  • Use of appropriate techniques, tools, and technology.

66
New cards

This standard emphasizes fraud as a core risk consideration, placing it on equal footing with errors and noncompliance in audit planning and execution.

Standard 4.2: Due Professional Care

67
New cards

Standard for Internal Audit Plan

Standard 9.4

68
New cards

Requirement of Standard 9.4: The CAE must create an internal audit plan that supports the achievement of the ___________ .

The CAE must base the internal audit plan on a documented __________, ________, _______. This assessment must be informed by input from the board and senior management as well as the chief audit executive’s understanding of the organization’s governance, risk management, and control processes. The assessment must be performed at least _________.

organization’s objectives

assessment of the organization’s strategies, objectives, and risks

annually

69
New cards

The internal audit plan must:

  • Consider the internal audit mandate and the full range of agreed-to internal services.

  • Specify internal audit services that support the evaluation and improvement of the organization’s governance, risk management, and control processes.

  • Consider coverage of information technology governance, fraud risk, the effectiveness of the organization’s compliance and ethics programs, and other high-risk areas.

  • Identify the necessary human, financial, and technological resources necessary to complete the plan.

  • Be dynamic and updated timely in response to changes in the organization’s business risks operations, programs, systems, controls, and organizational culture

70
New cards

It positions fraud risk as a planning priority, requiring the CAE to proactively integrate it into the internal audit plan, alongside other critical areas such as IT governance and compliance.

It emphasizes that fraud is a high-risk area that must be addressed through targeted audits, risk assessments, or continuous monitoring.

Standard 9.4: Internal Audit Plan

71
New cards

Standards for Engagement Risk Assessment

Standard 13.2

72
New cards

Requirement of Standards 13.2

Internal auditors must review the gathered information to understand how processes are intended to operate.

Internal auditors must identify the risks to review by:

  • Identifying the potentially significant risks to the objectives of the activity under review

  • Considering specific risks related to fraud.

  • Evaluating the significance of the risks and prioritizing them for review.

Internal auditors must identify the criteria that management uses to measure whether the activity is achieving its objectives.

When internal auditors have identified the relevant risks for an activity under review in past engagements, only a review and update of the previous engagement risk assessment is required.

73
New cards

This standard mandates that internal auditors must explicitly consider fraud risk during engagement planning, reinforcing accountability and ensuring that one of the most damaging types of risk is properly addressed.

It integrates fraud as a key element of risk-based auditing, particularly in areas with significant financial, operational, or reputational impact. Moreover, fraud risks must be evaluated and prioritized alongside other risks during scoping, ensuring they are not overlooked in the audit process.

Standard 13.2

74
New cards

There are four fraud-fighting elements/activities that organizations can use for an effective fraud management program:

  1. Fraud prevention

  2. Fraud detection

  3. Fraud investigation

  4. Follow-up legal action and/or resolution

75
New cards

It is generally the most cost-effective way to reduce losses from fraud. It encompasses policies, procedures, training, and communication that stop fraud from occurring,

Fraud Prevention

76
New cards

Effective fraud prevention involves:

  • Taking steps to create and maintain a culture of honesty and high ethics.

    • Tone at the top (proper modeling)

    • Hiring the right kind of employees

    • Communicating expectations of honesty and integrity

    • Creating a positive work environment

    • Proper handling of fraud and fraud perpetrators when fraud occurs

  • Assessing the risks for fraud and developing concrete responses to mitigate the risks and eliminate the opportunities for fraud

77
New cards

Ways to assess and mitigate the risk of fraud:

  • Accurately identifying sources and measuring risks

  • Implementing appropriate preventive and detective controls to mitigate those risks

  • Creating widespread monitoring by employees

  • Having internal and external auditors who provide independent checks on performance

78
New cards

It usually begins by identifying symptoms, indicators, or red flags that tend to be associated with fraud. It focuses on activities and techniques that promptly recognize timely whether fraud has occurred or is occurring.

Fraud Detection

79
New cards

Important detection methods include.

  • An anonymous reporting mechanism (whistleblower hotline)

  • Process controls

  • Proactive fraud detection procedures specifically designed to identify fraudulent activity

80
New cards

It is one of the more effective measures organizations can implement as part of their fraud risk assessment program.

Whistleblower Hotline

81
New cards

It specifically designed to detect fraudulent activity, as well as errors, include reconciliations, independent reviews, physical inspections/counts, analyses, and audits

Process Controls

82
New cards

In addition to detective process controls, organizations may be able to use data analysis, continuous auditing techniques, and other technology tools effectively to detect fraudulent activity

Proactive Fraud Detection Procedures

83
New cards

They has the responsibility to ensure that management designs effective fraud risk management documentation to encourage ethical behavior and to empower employees, customers, and vendors to insist those standards are met every day.

Board of Directors

84
New cards

They are committed to a proactive approach to fraud risk management maintains an active role in the oversight of the organization's assessment of fraud risks and uses internal auditors, or other designated personnel, to monitor fraud risks.

Audit Committee

85
New cards

They has overall responsibility for the design and implementation of a fraud risk management program.

Management

86
New cards

All levels of staff, including management, should:

  • Have a basic understanding of fraud and be aware of the red flags.

  • Understand their roles within the internal control framework. Staff members should understand how their job procedures are designed to manage fraud risks and when noncompliance may create an opportunity for fraud to occur or go undetected.

  • Read and understand policies and procedures (e.g. the fraud policy, code of conduct, and whistleblower policy), as well as other operational policies and procedures, such as procurement manuals.

  • As required, participate in the process of creating a strong control environment and designing and implementing fraud control activities, as well as participate in monitoring activities.

  • Report suspicions or incidences of fraud.

  • Cooperate in investigations.

87
New cards

A reporting process should be in place to solicit input on potential fraud, and a coordinated approach to investigation and corrective action should be used to help ensure potential fraud is addressed appropriately and timely

Fraud Investigation

88
New cards

Potential fraud may come to the organization's attention in many ways, including tips from employees, customers, or vendors; internal audits; process control identification; external audits; or by accident The board should ensure that the organization develops a system for prompt, competent, and confidential review, investigation, and resolution of allegations involving potential fraud or misconduct

Receiving the Allegation

89
New cards

Once an allegation is received, the organization should follow the process approved by the board to evaluate the allegation. The process should include designating an individual or individuals with the necessary authority and skills to conduct an initial evaluation of the allegation and determine the appropriate course of action to resolve it. In cases that involve the board or senior management, the board may want to hire outside independent advisers to assist in this evaluation.

Evaluating the Allegation

90
New cards

Investigations should be performed by protocols approved by the board. A consistent process for conducting investigations can help the organization mitigate losses and manage risks associated with the investigation.

Investigation Protocols

91
New cards

Factors to consider in developing the investigation plan include.

  • Time-sensitivity

  • Notification

  • Confidentiality

  • Legal privileges

  • Compliance

  • Securing evidence

  • Objectivity

  • Goals

92
New cards

Investigations generally include:

  • Interviewing

    • Neutral third-party witnesses

    • Corroborative witnesses

    • Possible co-conspirators

    • The accused

  • Evidence Collection

    • Internal documents

      • Personnel files

      • Internal phone records

      • Computer files and other electronic devices

      • E-mail

      • Financial records

      • Security camera videos

      • Physical and IT system access records

    • External records

      • Public records

      • Customer/vendor information

      • Media reports

      • Information held by third parties

      • Private detective reports

  • Computer Forensic Examinations

  • Evidence Analysis

    • Review and categorization of information collected

    • Computer-assisted data analysis

    • Development and testing of hypotheses

93
New cards

The investigation team should report its findings to the party overseeing the investigation, such as senior management, directors, or legal counsel.

Where legal counsel is supervising the investigation, counsel will determine the appropriate form of the report.

The nature and distribution of the report may be affected by the goals of protecting legal privileges and avoiding defamatory statements. For similar reasons, advice of counsel should be sought before the party overseeing the investigation makes public statements or other communications regarding the investigation.

Reporting the Results

94
New cards

After the investigation has been completed, the organization will need to determine what action to take in response to the findings. Any findings of actual or potential material impact may need to be reported to the board, the audit committee, and the external auditor if they are not receiving investigation reports directly. Notification may also be required to legal and regulatory agencies and the organization's insurers.

Corrective Action

95
New cards

Possible actions include available for organizations:

  • Criminal referral

  • Civil action

  • Disciplinary action

  • Insurance claim

  • Extended investigation

  • Business process remediation

  • Internal control remediation

96
New cards

In _________, auditing skills are applied to in-depth investigations that have potential legal implications or consequences (for example, money laundering, funding terrorists or organized crime).

Forensic Auditing

97
New cards

The _____ helps the internal auditor gather evidence to prove or disprove suspicions, identify the parties involved, and acquire and maintain evidence that may be presented in disciplinary or criminal proceedings.

Forensic Expert