In July, I discussed a new rating system for fraud risk assessments. I said the residual risk calculation should not be the end point but the beginning of your strategy.
In August, I discussed whether the design of our internal control procedure can reasonably prevent or detect a fraud risk statement. Remember, fraud is an intentional and concealed act. One of the key tenets of our new model is that the fraud risk statement is described in sufficient detail to ensure that the nuances of the fraud risk statement are identified.
Fraud risk assessments need to describe a fraud risk statement in a way that a layperson would understand the fraud risk. In this way, we can determine how to best manage the fraud risk or the best way to audit the fraud risk. If we do not sufficiently understand the nuances of the fraud risk statement, I personally guarantee that there will be gaps in your assessment or missed opportunities for detection.
In that context, let’s discuss the importance of understanding fraud risk. For this discussion, we’ll use the four levels of proficiency in the IIA Internal Auditing Competency Framework. We will only focus on fraud knowledge.
The importance of these levels of proficiency will become more relevant in next month’s blog. But for now, as you read the remainder of the blog, ask yourself the following question: How would you rate your fraud knowledge proficiency?
1. Inappropriate journal entries
2. Fraudulent disbursements: Billing schemes or use of phony vendors
3. Expenses are capitalized
4. Corporate cards are issued inappropriately, resulting in fraudulent expenses
Compare the following internet examples to my examples and rate the internet proficiency compared to mine:
Internet Example: Inappropriate journal entries
Leonard’s Example: Controller records a false journal entry for accrued expenses for a false vendor invoice for a real vendor at month-end to inflate incurred costs, thereby inflating revenue on the percentage of completion accounting principle, thereby overstating revenue
Internet Example: Fraudulent disbursements: Billing schemes or use of phony vendors
Leonard's Example: Accounts payable acting alone or in collusion take over the identity of a real company in the marketplace but not on the master file causes the real company to be added to the accounts payable master file, then processes a fake invoice for goods or services not provided, resulting in the diversion of company funds.
To illustrate the concept, I will dissect the first of my examples: journal entries
In describing the fraud risk statement, each element should be directly stated or implied by the wording. In some ways, this is a matter of style. So, what are the elements of a comprehensive and complete fraud risk statement?
That is better, but what level of proficiency does this really demonstrate? There
are over 15 fundamental permutations of false vendors. And, once you consider specific industries, the number of permutations could go up dramatically.
So, what level of knowledge or proficiency do the internet statements demonstrate? While I am not trying to be sarcastic or mean-spirited, as the internet fraud risk is written, I would assess the knowledge as below basic. Let me tell you why.
The fraud definition has two key elements: concealment and intent. As to item 1, I guess I can see the fraud concept. But items 2-4 fail to describe the intent or the concealment factor.
Here is what I would expect for the journal entry example based on level of knowledge proficiency:
Basic Proficiency: Inappropriate journal entries
Intermediate Proficiency: In my opinion, fraud risk statements have five elements: the perpetrator, the entity structure, action statement, impact, and the fraud conversion. But they must have the two elements of the fraud definition, either implied or directly stated.
Advanced Proficiency: In reading the definition, it has more to do with leadership than how to describe a fraud risk. While this is very important, it is not relevant for this discussion.
Expert Proficiency: would understand the industry knowledge associated with the fraud risk statement.
As you can see, I believe how you describe the fraud risk statement is the most important part of the fraud risk assessment process.
I believe our profession needs to provide better guidance on how to describe a fraud risk statement consistent with the Competency Framework.
Next month’s blog will be written for CAEs.
The "Holy Three" (or Holy Trinity) of criminology refers to the founders of the Italian School of Positivist Criminology in the late 19th century