In my last blog, we discussed a new rating system for fraud risk assessments. I introduced the idea that the residual risk calculation should not be the end point but rather the beginning of your strategy. In this blog, we will discuss rating an internal control strategy.
This new model focuses on the adequacy of the design of internal control rather than the operating effectiveness. We will determine whether the design of our internal control procedure can reasonably prevent or detect a fraud risk statement. Remember, fraud is an intentional and concealed act. One of the key tenets of our new model is that the fraud risk statement is described in sufficient detail to ensure the nuances of the fraud risk statement are identified. It is also vital that the person rating the risk statement has sufficient fraud and control knowledge. Here are the ratings we will use:
1. Internal control procedures, as designed, are unable to prevent or detect the fraud risk statement
2. Internal control procedures, as designed, are unable to prevent but can detect the scheme if it is occurring.
3. Internal control procedures, as designed, are able to prevent or detect the scheme at an acceptable level
This is not a fatalist approach. It is an honest approach. The reality is that it is impossible to eliminate all fraud in all organizations. As ACFE President and CEO Bruce Dorris once said, “Effective leaders address fraud risk as they do any risk — they manage it.” He nailed it, in my opinion.
To establish a baseline understanding of what we are evaluating, let’s take a closer look at three fundamental strategies to manage fraud risk: Fraud Deterrence Controls, Fraud Prevention Controls, and Fraud Monitoring Controls.
This links to the governance philosophy contained in the COSO model. It would include fraud policies, whistleblower programs, enhancing management's fraud intelligence, creating an anti- fraud culture, fraud education, promptly and thoroughly investigating allegations or red flags of fraud, using a fraud audit approach in internal audits, and lastly, consequences to people’s actions. I am sure there is more to discuss, but you get the idea.
In last month’s blog, we showed that many fraud risk statements simply cannot be prevented from occurring or detected through fraud monitoring controls. Therefore, we must rely on creating an environment that causes people to think twice about committing a fraud scheme. If they choose to commit a scheme, then our governance controls will cause the scheme to be detected in a timely manner.
The bottom line is that we are relying on our employees to stop fraud from continuing to occur more than relying on a control procedure to stop the scheme from occurring. Please give this some thought.
Next month, I will discuss calibrating for the sophistication of the person committing the scheme. This will somewhat contradict what I am now saying. Nobody has ever said this is easy.
For this, I would look to the control procedures section of the COSO model. Fraud prevention would include items such as separation of duties, authority and responsibility limits, audit trails, reconciliation procedures, etc., transactional control procedures such as password controls, edit checks, etc.
From my perspective, fraud prevention controls provide the foundation for fraud monitoring and fraud deterrence controls.
I have intentionally not used the phrase “fraud detection controls” because I think it creates a false expectation.
The key to effective fraud monitoring is the implementation of proactive data monitoring. There is a lot of literature available on this topic. I need to stress that you need IT support to create these automated monitoring systems. The data analytics must be fraud risk statement-based rather than relying on kicking out data anomalies. Secondly, you need to ensure that staff have sufficient knowledge and practical experience to investigate and report their findings.
Fraud monitoring can include awareness of employee behavior. I am not suggesting invading their personal life without cause. But training management on the red flags of behavior can help them spot the need for an investigation.
And as I have often said, increasing the perception of detection should be the goal of all fraud risk management programs.
Now, you can evaluate the controls you have in place using the new rating system.
1. Internal control procedures, as designed, are unable to prevent or detect the fraud risk statement.
We recognize that fraud risk statements with this rating can occur in theory because we cannot prevent or detect with traditional controls. We rely on what is often referred to as “soft controls” or our fraud deterrence controls.
2. Internal control procedures, as designed, are unable to prevent but can detect the scheme if it is occurring.
We recognize that fraud risk statements with this rating can occur in theory, but our fraud monitoring controls should be able to detect the scheme in a stated period of time or before dollar losses exceed our fraud risk tolerance.
3. Internal control procedures, as designed, are able to prevent or detect the scheme at an acceptable level.
No set of controls can provide absolute assurance for fraud prevention. But based on the traditional controls defined in the control procedure section of COSO, you would have reasonable assurance that a fraud risk statement will not occur. However, if someone attempts to commit a fraud risk statement, our fraud monitoring or our fraud deterrence procedures would identify and stop the scheme.
FYI, when I spoke at the ACFE Global Fraud Conference in Boston and the Chartered ANZ Audit Conference, my presentation started with the following question: Do you have an open mind? I know what I am suggesting is a new way to think about fraud risk management. It may even be scary because we are going to tell management that there is a whole host of fraud schemes that we cannot stop from occurring.
But the good news is that with the right anti-fraud attitude, maybe we can convince fraudsters that this is the wrong company in which to carry out the fraud risk statement.
As you know, Edwin Sutherland was Dr. Cressey's mentor, but what do you know about Sutherland?
1. He is best known for the development of what theory? Differential Association Theory. Differential Association Theory proposes that deviant behavior is learned through social interactions, particularly within primary and intimate social groups.
2. What award is named for Sutherland? Edward H. Sutherland Award is an annual award that has been given by the American Society of Criminology (ASC) since 1960.
3. What do Larry Bird and Sutherland have in common? Nothing, exactly. Sutherland did teach as the Head of the Sociology Department at Indiana University. Bird played basketball at Indiana State. Close!
4. What common phrase did Sutherland coin? White Collar Criminal
5. Why was the first edition of Edwin Sutherland's White-Collar Crime heavily censored by Dryden Press? It identified 70 of the largest corporations by name.
6. By whom, and when was the book finally issued without censorship? Yale University Press in 1983.