Fraud Auditing, Detection, & Prevention Blog

Fraud Risk Assessment: A New Model and New Approach

Written by Leonard W. Vona | Sep 24, 2026, 4:25:20 PM

In July, I discussed a new rating system for fraud risk assessments. I said the residual risk calculation should not be the end point but the beginning of your strategy.

In August, I discussed whether the design of our internal control procedure can reasonably prevent or detect a fraud risk statement. Remember, fraud is an intentional and concealed act. One of the key tenets of our new model is that the fraud risk statement is described in sufficient detail to ensure that the nuances of the fraud risk statement are identified.

New Model and New Approach

Fraud risk assessments need to describe a fraud risk statement in a way that a layperson would understand the fraud risk. In this way, we can determine how to best manage the fraud risk or the best way to audit the fraud risk. If we do not sufficiently understand the nuances of the fraud risk statement, I personally guarantee that there will be gaps in your assessment or missed opportunities for detection.

In that context, let’s discuss the importance of understanding fraud risk. For this discussion, we’ll use the four levels of proficiency in the IIA Internal Auditing Competency Framework. We will only focus on fraud knowledge.

  • Basic proficiency: Individuals demonstrate awareness through education and experience.
  • Intermediate proficiency: Individuals apply knowledge, skills or experience with certain processes, though they do not have the skills to lead engagements.
  • Advanced proficiency: Individuals demonstrate the ability to lead and train others in a knowledge and skill subcategory.
  • Expert proficiency: Individuals demonstrate significant insight and are considered trusted advisors and thought leaders of a knowledge or skill subcategory.

The importance of these levels of proficiency will become more relevant in next month’s blog. But for now, as you read the remainder of the blog, ask yourself the following question: How would you rate your fraud knowledge proficiency?

Illustrative Examples of Fraud Risk Statements

 As always, I searched the internet for examples of fraud risk statements. These are illustrative examples of what I found:

1.  Inappropriate journal entries

2. Fraudulent disbursements: Billing schemes or use of phony vendors

3. Expenses are capitalized

4. Corporate cards are issued inappropriately, resulting in fraudulent expenses

  1.  

Comparison of Fraud Risk Statement

Compare the following internet examples to my examples and rate the internet proficiency compared to mine:

Internet Example: Inappropriate journal entries

Leonard’s Example: Controller records a false journal entry for accrued expenses for a false vendor invoice for a real vendor at month-end to inflate incurred costs, thereby inflating revenue on the percentage of completion accounting principle, thereby overstating revenue

Internet Example: Fraudulent disbursements: Billing schemes or use of phony vendors

Leonard's Example:  Accounts payable acting alone or in collusion take over the identity of a real company in the marketplace but not on the master file causes the real company to be added to the accounts payable master file, then processes a fake invoice for goods or services not provided, resulting in the diversion of company funds.

What makes an understandable fraud risk statement?

To illustrate the concept, I will dissect the first of my examples: journal entries

In describing the fraud risk statement, each element should be directly stated or implied by the wording. In some ways, this is a matter of style. So, what are the elements of a comprehensive and complete fraud risk statement?

  • Intentional act: Records a false journal entry
  • Element of misrepresentation: False vendor.
  • Identify the perpetrator: Controller records
  • Identify the act being committed: Inflate incurred costs
  • Identify the impact: Overstate Revenue

That is better, but what level of proficiency does this really demonstrate? There

are over 15 fundamental permutations of false vendors. And, once you consider specific industries, the number of permutations could go up dramatically.

Assess the knowledge proficiency

So, what level of knowledge or proficiency do the internet statements demonstrate? While I am not trying to be sarcastic or mean-spirited, as the internet fraud risk is written, I would assess the knowledge as below basic. Let me tell you why.

The fraud definition has two key elements: concealment and intent. As to item 1, I guess I can see the fraud concept. But items 2-4 fail to describe the intent or the concealment factor.

Here is what I would expect for the journal entry example based on level of knowledge proficiency:

Basic Proficiency: Inappropriate journal entries

Intermediate Proficiency: In my opinion, fraud risk statements have five elements: the perpetrator, the entity structure, action statement, impact, and the fraud conversion. But they must have the two elements of the fraud definition, either implied or directly stated.

Advanced Proficiency: In reading the definition, it has more to do with leadership than how to describe a fraud risk. While this is very important, it is not relevant for this discussion.

Expert Proficiency: would understand the industry knowledge associated with the fraud risk statement.

Application of the New Approach

As you can see, I believe how you describe the fraud risk statement is the most important part of the fraud risk assessment process.

I believe our profession needs to provide better guidance on how to describe a fraud risk statement consistent with the Competency Framework.

Next month’s blog will be written for CAEs.

The "Holy Three" (or Holy Trinity) of criminology refers to the founders of the Italian School of Positivist Criminology in the late 19th century

  1. What are their names?
  2. Who is often referred to as the father of criminology?
  3. What theory did Lombroso present?
  4. How did Ferri expand Lombroso's theory?
  5. The term criminology was most likely coined in 1885 by:

 

Edwin Sutherland, up close and personal

  1. What was Edwin Sutherland's birthdate? 08/13/1883
  2. What was Sutherland's occupation before he received his PHD? High School Teacher
  3. How many books did Sutherland publish? Four.
  4. What was the title of his first book? Twenty Thousand Homeless Men (1936)
  5. How did Sutherland define white-collar crime? “Approximately as a crime committed by a person of respectability and high social status in the course of his occupation.”