Fraud and Errors

Threats to AIS

  • Natural and political disasters
  • Software errors and equipment malfunctions
  • Unintentional acts
  • Intentional acts

Fraud

  • Definition: Gaining an unfair advantage over another person.
  • Legal traits:
    • False statement, representation, or disclosure
    • A material fact that induces action
    • Intent to deceive
    • Justifiable reliance by the victim
    • Injury or loss suffered by the victim

Common Categories of Fraud

  • Corruption: Dishonest conduct by those in power.
  • Misappropriation of assets: Theft of company assets.
  • Fraudulent financial reporting: Intentionally misleading financial statements.

Auditor’s Responsibility (SAS 99)

  • Understand fraud risks.
  • Discuss material misstatement risks.
  • Obtain information to identify and assess risks.
  • Evaluate audit test results.
  • Document and communicate findings.
  • Incorporate a technology focus.

Conditions for Fraud (Fraud Triangle)

  • Pressure: Incentive or motivation.
  • Opportunity: Ability to commit and conceal.
  • Rationalization: Justification for illegal behavior.

Computer Fraud Classifications

  • Definition: Fraud requiring technology to perpetrate.
    • Input
    • Processor
    • Computer instruction
    • Data
    • Output

Input Fraud

  • Altering or falsifying computer input, such as phony source documents.

Processor Fraud

  • Unauthorized system use.

Computer Instructions Fraud

  • Tampering with software, illegal copying, unauthorized use, or developing unauthorized software.

Data Fraud

  • Illegally using, copying, browsing, searching, or damaging company data.

Output Fraud

  • Altering or falsifying computer output.

Preventing and Detecting Fraud

  • Create a culture of integrity.
  • Adopt a structure that minimizes fraud.
  • Assign authority and ensure accountability.
  • Communicate policies and develop security measures.
  • Implement strong internal controls and segregate accounting functions.
  • Require independent checks and reconciliations.
  • Restrict access through system authentication.
  • Implement computer controls.
  • Use encryption and regularly update systems.
  • Assess fraud risk and conduct audits.
  • Establish a fraud hotline and maintain an audit trail.
  • Install fraud detection software and monitor system activities.
  • Maintain insurance and implement business continuity plans.
  • Store backup copies securely off-site.

Using Data Analytics

  • Data analytics software tools are effective for examining data populations.
  • Techniques include:
    • Outlier detection
    • Anomaly detection
    • Regression analysis
    • Semantic modeling
    • Benford’s Law