Fraud Auditing, Detection, and Prevention Blog

Leonard W. Vona

Leonard W. Vona has more than 40 years of diversified fraud auditing and forensic accounting experience. His firm, Fraud Auditing, Inc., advises clients in areas of fraud risk assessment, fraud data analytics, fraud auditing, fraud prevention and litigation support.
Find me on:

Recent Posts

Is Fraud Risk Assessment Simply an Academic Exercise?

Jun 12, 2025 9:31:48 AM / by Leonard W. Vona posted in Fraud Schemes, Fraud Auditing, ...

Fraud risk assessment is alleged to be an essential part of protecting a company, but is it just an academic exercise?

Read More

The Fraud Auditor: What Does This Person Look Like?

May 18, 2025 9:05:30 AM / by Leonard W. Vona posted in Fraud Auditing, Fraud Definitions, ...

Please be advised, I will not be providing a job description of a Fraud Auditor. Rather, the thought process that is necessary to find the right person, with the right skill set.

I know this is a good technical question, but I do not know if there is a good technical answer. With that said, my suggestion to the CAE’s of the world would be to look for someone with the “Passion for the subject knowledge of fraud risk.” The passion would be for both the science of fraud risk and the passion for the practical application of fraud auditing.  I say this because, with any new profession, the person must have the passion to create, build, and polish the fraud audit approach. I am sure that this person will get pushback from the traditional auditor. I know I have.  

Read More

What is a Fraud Scheme?

Apr 24, 2025 11:57:52 AM / by Leonard W. Vona ...

Words have power, but words can also create confusion. 

One of my personal complaints about the professional literature regarding terms used to describe fraud risk. We use so many terms interchangeably that I believe it creates confusion. Let’s try to cut through that confusion by implementing better definitions. 

For instance, what is the difference between a fraud scheme, a fraud scenario, a fraud risk statement and a fraud risk?

And, is the phrase “fraud scheme” the correct phrase for our profession? I raise this question because the new standards use the phrase “fraud scheme”. 

Read More

Gaining a Deeper Understanding of Fraud Schemes

Mar 13, 2025 4:00:00 PM / by Leonard W. Vona posted in Fraud Schemes, Fraud Auditing, ...

Before I start, let me explain that in this blog I will not provide any answers to the phrase “Deeper Understanding of Fraud Schemes.” Rather, I will only raise questions regarding the phrase. To be honest, If I was a CAE, I am not sure what the profession wants me to do.

With that said, I praise the profession in recognizing the importance of gaining a deeper understanding of fraud schemes facing our companies. Maybe, I am talking out of both sides of my mouth. Remember, my blogs are designed to make you think.

So, think about this: Fraud is not predictable as to when it will occur but is fairly straight forward as to how it will occur. 

Read More

Proactive Approach to Fraud Detection: A New State of Mind

Feb 24, 2025 7:19:20 PM / by Leonard W. Vona posted in Fraud Auditing, Fraud Detection, ...

Many years ago, the IT auditor was created. In fact, I was an IT auditor in 1979. For the last 40 years, however, I have been a fraud auditor. Unfortunately, unlike IT, the profession does not recognize the title of fraud auditor. 

In my opinion, it is time for the title of Fraud Auditor to be created and recognized by the profession. Auditors are not born with fraud risk or fraud audit knowledge or fraud skills. I suspect that college courses are not designed to provide this knowledge.  If the profession is serious about a “more proactive approach to fraud detection” it is time to recognize that this will require auditors to develop and gain a new set of skills. I recommend that every audit department invests in human fraud risk intelligence.

Read More

Is Fraud Auditing About Mitigating or Managing Risk?

Jan 18, 2025 8:27:17 AM / by Leonard W. Vona posted in Fraud Risk Statements, Fraud Auditing, ...

Current audit standards call for us to use a mitigation standard when it comes to audits This means that unless you want to be an outlaw, your assessment will end with mitigate. However, the question I want you to ask yourself is, right now do we have enough information to properly assess the mitigate question?

Read More

A New Model for Assessing Fraud Risk Management

Dec 19, 2024 9:06:14 PM / by Leonard W. Vona posted in Fraud Risk Identification, Fraud Auditing ...

Let me introduce a new model for assessing fraud risk mitigation. Before you read my blog, remember sarcasm is good, if it makes you think. Remember our theme, to look behind the curtain. The curtain is the current professional audit standards.

Read More

Where are the Fraud Risk Professional Standards?

Nov 15, 2024 2:49:05 PM / by Leonard W. Vona posted in Fraud Risk Statements, Fraud Risk Identification, ...

We're continuing with my thought process of looking behind curtains in fraud risk, but with a slight change. This time, we're looking behind a new curtain.

Read More

Looking Behind a New Curtain to Improve Fraud Risk Assessment

Oct 18, 2024 8:15:00 AM / by Leonard W. Vona posted in Fraud Auditing, Fraud Detection, ...

This month I will present at a conference a new approach to fraud risk assessment. It is the cumulation of my 40 years of experience in building the fraud audit model.

Read More

A Peek Behind the Curtain to Look at Account Take Over Attacks

Sep 17, 2024 1:20:02 PM / by Leonard W. Vona posted in Fraud Auditing, Cyberattack, ...

Businesses face a growing threat of account take over attacks as fraudsters become more sophisticated and take advantage of advances in technology. This week, we're pulling back the curtain to take a closer look at them and how to add this to your fraud protection strategy. 

Fraud Trivia: Phishing

Phishing is a prevalent type of social engineering that aims to steal data from the message receiver. Typically, this data includes personal information, usernames and passwords, and/or financial information. Phishing is consistently named as one of the top 5 types of cybersecurity attacks.

Read More
Demystifying Fraud eBook CTA

Recent Posts

Subscribe to Email Updates