0% found this document useful (0 votes)
13 views11 pages

Reading Material - Blended Learning - Module-3 Transcripts

The document discusses the use of big data and analytical tools in fraud detection and investigation, emphasizing the importance of understanding data collection and analysis techniques for identifying fraudulent activities. It highlights the role of perception of detection in fraud prevention and the necessity for fraud examiners to collaborate with IT departments to access relevant data. Additionally, it introduces Benford's Law as a statistical tool for data analysis, illustrating its application in identifying anomalies in financial data.

Uploaded by

Arisha Mirza
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views11 pages

Reading Material - Blended Learning - Module-3 Transcripts

The document discusses the use of big data and analytical tools in fraud detection and investigation, emphasizing the importance of understanding data collection and analysis techniques for identifying fraudulent activities. It highlights the role of perception of detection in fraud prevention and the necessity for fraud examiners to collaborate with IT departments to access relevant data. Additionally, it introduces Benford's Law as a statistical tool for data analysis, illustrating its application in identifying anomalies in financial data.

Uploaded by

Arisha Mirza
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

In the name of ALMIGHTY ALLAH (swt), the most Beneficent, the most Merciful

Video Transcripts:

MODULE-3: BIG DATA, BENFORD’S LAW, AND FINANCIAL ANALYTICS

Video-1: Using Data and Technology for Fraud Detection and Investigation:

All industries are struggling with the concept of big data. With servers across the country
capturing tens of thousands of terabytes of data each day regarding all facets of business,
the challenge is not finding usable data; the challenge today is how to effectively review
and manage the data you have. This section of the course will examine some of the
methods Fraud Examiners use to analyze data to help find fraudulent activity. It's important
for the fraud examiner and forensic accountant to understand how data is collected and
what are some of the specific tools and techniques that help you locate that fraud
needle in the business haystack. Fraud prevention is an important part of every
organization. If you do nothing to prevent fraud, it will flourish and ultimately consume your
business. But at the same time you cannot completely eliminate fraud. It is amazing how
often a fraud perpetrator can find the one hole in an otherwise solid set of internal
controls.

For example, failures may occur within internal control such as even duties are separated,
people work together to circumvent controls. Sharing or stealing usernames or passwords
belonging to other employees, they could then be used to commit fraud, or you may have a
situation where adequate controls are just not in place to stop a particular risk. One of the
keys are fraud prevention is a concept called perception of detection. Not only can data
analysis detect fraud, the fact that an organization regularly analyzes data for fraud can be
an effective control mechanism all by itself. If employees and vendors know that an
organization is conducting vigorous tests to detect fraud that may cause them to think
twice about committing it. One of the primary considerations is whether or not data are
available to find a particular type for fraud. But in order to know what data to look at, you
must also understand how particular frauds occur.

When designing data analysis tests, you must think about the various operations of the
business and how they are vulnerable to fraud. For example, let's say you have a
purchasing manager who's taking payments or kickbacks from a vendor for every order
placed. If these payments are made in cash to the manager outside working hours, then
how could you find this activity through data analysis? Is there any way to detect it?
Surprisingly to most people, there are several ways to possibly detect such a fraud. A
careful review of purchasing transactions can reveal if one vendor has seen a dramatic
increase in purchases. Additionally, tests can be run to determine whether there's been a
dramatic increase in inventory or supply.

Unusual activity should be reviewed to determine if there is a legitimate explanation for


anomalies or whether fraud could be at play. But being able to find such activity also
involves two other important items: one is understanding what the data should look like
(this requires not only knowledge of the business operations but an understanding up the
historical data available); additionally, effective data analysis means understanding the
software and other tools available to conduct the analysis. As we mentioned, one of the
problems today is the overabundance of data. Almost everything is captured
somewhere. It's important for the fraud examiner to work closely with the
information technology or IT department to identify the potential sources of data. Much
data are gathered inside the organization. If you are working with their foreign
organization, you and the IT representative can identify what types of data might be of most
assistance in proactive fraud detection analysis. The IT representative will understand what
data is collected but it will take the fraud examiner's skill to understand what types of
schemes the organization is at risk for. There are also a lot of data available external to the
organization. For example, if a company is publicly traded, a wealth of financial filings are
available from the SEC or other government regulators. Other types of non-financial
information are available through the Internet, newspaper, magazine articles, and trade
journal reports.

These sources should also be reviewed for information that is relevant to the particular
case under investigation. There have been many instances of investigators finding
references in newspaper articles regarding company employees having been charged with
theft in previous jobs or locations. You won't find such information on the individual's
resume, but you may find it through careful records searching. Financial data analysis is an
extremely sophisticated endeavor. Not only is it necessary to understand what data is
available and how to capture it, but you also have to know what you're looking
for. Historical comparisons are extremely important. If there's an unexplained and dramatic
increase in one item from one period to the next, that could be a sign a fraud, or could
simply be normal operations.

In order to find out, you need to understand how the business operates and what you would
expect the numbers to show. For example, if sales remain steady but inventory goes
down dramatically, what is the cause? It could be that older obsolete inventory has
been written off the books, or it could mean that inventory is being stolen. You'll need to
review the records and conduct more inquiries to know for sure, but understanding the
business and its operations is critical to understanding the data you've analyzed.

Video-2: Data Analysis Tools

In general, the tools that a forensic accountant or fraud examiner uses are those common
to accountants and auditors. As noted in my bio, I testify based on cases and evidence that
I am asked to examine and my most common tool is the spreadsheet. I typically use Excel
but you can use any spreadsheet package with which you are familiar. Databases and
enterprise systems capture extensive amounts of information. The beauty of these capture
forms is that the data is already digital – ready to download. Organizing the downloads can
be quick or tedious depending on the case. As part of our program at WVU, we have used
both ACL and IDEA. Both are data-mining software packages that were designed with fraud
detection and forensic accounting in mind. As an example, both packages easily match
employee’s addresses to vendor addresses from the accounts payable system to
determine if an employee might have set up a shell company as a means for carrying out a
fraud act. Even without specialized packages such as ACL and IDEA, traditional statistics
packages like SAS, SPSS, Jump to name just a few can be used to analyze large amounts of
data.

The techniques of analytical review and ratio analysis entail looking at one financial period
in comparison to another. The period may be a year, quarter, month, a week or even a day
or hour. For example, let’s compare the costs as a percentage of sales for two periods: If
last month, you had sales of $1,000 and costs of $750, a cost-to-sales ratio would be $750
/ $1,000 or 0.75. This means that costs for the period were 75% of sales. If the current
month Cost of Sales = $900 and Sales = $1,000, the ratio is $900 / $1,000 or 0.90. An
increase from 75% to 90% MAY be a sign of a problem. Notice that I said, MAY be a sign,
rather than IS a sign. The source of the increase may be a valid increase in prices you
pay for the items you buy. BUT it may be a symptom of a tax fraud, for example.

While analytical tools and ratios can provide powerful signals or red flags, in and of
themselves, they are usually not compelling. The process of fraud examination and
forensic accounting begins with the anomalies and looks at the totality of the evidence
before drawing a conclusion. Anomalies come in all forms including: Shortages (inventory,
accounts receivable, or cash). Deviations from specifications, such as a managers
purchasing inferior product to receive a kick-back from the vendor. Excess scrap. Excess
voids. – I once worked for a retailer where the fraud prevention expert searched for excess
voids by sales associate to determine who was most likely stealing from the cash register.
Excess purchases.

Non-financial numbers that do not correlate with account balances and numbers
presented in the financial statements In every case I work, I attempt to obtain non-financial
numbers – e.g., include dekatherms of natural gas produces, ton of coal extracted from the
ground, cubic yards of concrete, even number of employees, square footage of retail
outlets. All of these can be combined with financial data to examine the reasonableness of
that data. Other anomalies include strange financial relationships: Let's assume revenues
are up by 8% While Accounts receivables are up by 30% And Operating Cash flows
increasing only slightly at 1%. This example does not make sense – at least on the
surface. Normally, one would expect accounts receivable to move with sales and cash
flows to reflect those sales increases. One of the keys to identifying anomalies is having an
expectation – meaning estimating what you expect to see before you look. This is
particularly important because with concealment, the fraudster is going to try to make
things look “normal.”

Without some kind of expectation, you may unknowingly go down the path the
fraudster wants and miss what they don’t want you to see. Adjusting journal entries are an
important area of examination. Some of the largest frauds were committed by something
called management override or management overriding the normal system of internal
controls. A common mean by which management override can occur is by concealing the
fraudulent act with journal entries. The adjustments to the accounting records make the
income statement, the balance sheet and the cash flows look normal but only because the
true financial performance is masked by falsified journal entries. During my auditor days
with one of the large accounting firms, we looked at every journal entry, especially those
increasing income. Entries increasing Income were a red flag or anomaly that we typically
investigated. Out of the ordinary items may be recorded manually into the system.
Normally unusual and one-time manual transactions are another source that deserves
scrutiny.

One method for recording fraudulent transactions is through the use of adjusting journal
entries. WorldCom provides us a classic example of fraud executed in this manner.
According the US Securities and Exchange Commission, one part of the WorldCom fraud
was using journal to record the capitalization of LINE costs expenses. Let’s spend a
moment refreshing our memories of some key accounting terms. An EXPENSE is a
resource used in the current accounting year. For example, your utility bills are expenses.
You used the utilities in the current year, and there is no benefit to future years. In contrast,
an ASSET, is a resource that lasts beyond the current year. If you purchase a desk to use, it
will benefit you in future years, so the cost is written off over the life of the desk.

When you have an item that you buy, if you CAPITALIZE it, you are saying it is an asset that
will last beyond the current year. Back to WorldCom – WorldCom had something called line
costs – When the company’s customer makes a call that is outside of the company’s
network, the company has to pay the owner of the other network line, the costs to carry the
call. The charges, or LINE COSTS, occur each time a call is made. You can see that line
costs are tied to specific calls – they have NO future benefit to the company that has to pay
them! WorldCom, through journal entries, chose to capitalize these cost, therefore making
them appear to be an asset, or resource available in a future period. The impact on the
financial statements, was less expenses, and what appeared to be outstanding profits -
when they were actually LOSING money! Additionally, there appeared to be more assets for
future use than actually existed. The SEC indicates that there were over 9 BILLION US
dollars in false or unsupported accounting entries. Many of you may know the end of the
story, it ended with WoldComs bankruptcy.

This control chart displays the quarterly cost of goods sold of WorldCom, as
originally reported, compared to the remainder of the telecommunications industry. The
time covered includes the fraudulent years. For comparability purposes, the chart has
been scaled to a moving industry average, removing company size differences. Using a
control chart, such as this one indicates there is a systematic problem if 7 or more data
points in a row are above or below the average (middle) line. You can see from this chart
that the costs of WorldCom are below the average for eleven consecutive quarters. Using
tools and techniques such as control charts helps identify red flags that may ultimately
point to the existence of fraud. The WorldCom fraud was discovered in the same manner of
most frauds – through tips. The tips were provided to the company’s internal auditors.

In the simplest of terms, as part of internal auditor Cynthia Cooper’s investigation, she
asked for documents to support the adjusting entries related to line charge
capitalizations. No documentation existed, because the entries didn't actually reflect
events. WorldCom continues to be known as a classic case of financial statement fraud.
Top management, trying to show increasing profits, in a competitive and turbulent market,
resorted to demanding the manipulation of accounts through a series of adjusting journal
entries. There were many warning signs of problems, but ultimately, tips, investigated by
internal auditors brought the fraud into the open. Today, there are many tools and
techniques available to detect fraud. One of the benefits of accumulating large amounts of
data within an organization’s system, is the possibility of MINING the data.
DATA MINING involves analyzing large sets of data, using sophisticated statistical or visual
tools to look for unusual trends or data points that are outliers and not consistent with the
remainder of the data. Data mining works best on detailed data, such as individual sales
transactions or payments. Data covering several years also gives a perspective over time
which is important in most frauds. For example, if looking for sales fraud, looking at 10
years of details is more likely to discover a problem than looking at customer total sales for
one month. Next, let’s look at some real life examples of data mining to prevent
fraud. Credit card companies usually maintain a history of every transaction occurring for
each card they issue. They are constantly analyzing historical fraud data and looking for
fraudulent card use in real time, to stop transactions before they occur. If they can prevent
a fraudster from walking away from a retailer with merchandise charged to YOUR card, the
process is successful.

Credit card companies and other organizations use a wide range of data mining tools and
techniques looking for specific fraud patterns. Most of these are not disclosed for one
obvious reason– fraudsters would simply adjust their frauds to avoid the rules. One red flag
for credit card purchasing is the combination of using a card at a retailer you have not
previously purchased from when the purchase is a HIGH RISK and HIGH PRICED item.
Examples of high risk items would include electronics and other items that are easy to
sell. If you use a credit card, you may have been exposed to the results of data mining
performed by your credit card company looking for fraudulent transactions. Twice, I have
received a call from a credit card company asking about specific purchases. In the first
instance, I was asked if on the previous day I had attempted to use my card at two specific
stores. When I replied no, my card was instantly cancelled, and a replacement was sent.
Ironically, in the past I had made purchases at the two stores, but not on the day identified.
The sophisticated analysis by the credit card company somehow knew something was out
of the ordinary for these specific transactions. The second call occurred while I was
making a second purchase within an hour at a retail store. I believe this call was probably
due to the “Multiple purchases at the same store in a relatively short time” rule. Retail fraud
sometimes happens when you forget your card, or it duplicated by a clerk.

While some think data mining by credit card companies is annoying, the end result of
the process is lower fraud losses, and lower overall costs to the consumer.
Video-3: Benford’s Law

One Commonly used data mining tool based on statistics is Benford Analysis. Today we
have Benford Expert WVU Professor Mark Nigrini with us. Professor Nigrini, will you tell us
about Benford Analysis? Sure, Frank Benford was a physicist in the 1920s. He noticed that
the first few pages of his logarithm tables were more worn than the last few pages. He
concluded that he was looking up the logs of numbers with low first digits more often than
he was looking up the logs of numbers with high first digits. The first digit of a number is the
leftmost digit. We have 32,340 students at WVU and the first digit of that number is a 3.
There are 9 possible first digits. Zero can never be a first digit. Minus signs are ignored when
we calculate the first digit.

Benford examined 20 lists of numbers with 20,000 records in total. His results showed that
30.6 percent of the numbers started with a “1” and 18.5 percent of the numbers started
with a “2.” This means that 49 percent of the numbers started with a 1 or a 2 while the other
51 percent started with 3, 4, 5, 6, 7, 8, or 9. He made some assumptions about the
properties of numbers and using some calculus he calculated the expected frequencies of
the digits in natural numbers. In the first position there is a large bias towards the low digits.
Zero can be a second digit and so from the second digit onwards there are ten possible
digits. The bias gets less and less as we move on to the second and third digits and from the
fourth digit onwards the ten possible digits are, for all practical purposes, equally likely.

Why is this so? If we take the Dow Jones index at 1,000 where it has a first digit 1, we need a
100 percent increase before the 1 becomes a first digit 2. At 5,000 the Dow only needs a 20
percent increase to change the first digit 5 to a first digit 6. At 9,000 the Dow only needs an
11 percent increase before we get a new first digit, 1, at 10,000. And now we again need a
100 percent increase before the first digit changes to a 2. The Dow will have a first digit 1 for
far longer than any other first digit. Benford’s Law does not apply to all sets of numbers.

For it to apply the numbers must reflect the size of some phenomenon; big numbers must
refer to big things. There must be no built-in maximum or minimum values. All though zero
can be a minimum number. Tax returns for example have minimum or maximum amounts
in various places. The numbers must not be labels such as highway numbers, social
security numbers, or flight numbers. A data set that conforms very nicely to Benford’s Law
is the populations of the 19,000 towns and cities in the United States. Every population
count has a first digit and the graph shows the expected Benford proportions as a line, and
the actual proportions as the nine bars. Each possible first digit is shown as a bar and the
proportions are shown on the y-axis. The top of the bar is pretty close to the line in all
cases, meaning we have a very nice fit to Benfords law.
Every number also has first-two digits. The first-two digits range from 10 to 99. We use a line
to represent the expected proportions. The first-two digits also conform closely to
Benford’s Law. This graph shows streamflow statistics for 140 years that conform almost
perfectly to Benford’s Law. And the last graph here, are the 80,000 ledger balances for a
large company also conformed closely to Benford’s Law. Now for a little fraud data...

A State of Arizona employee processed 23 checks for non-existent services performed by a


fictitious vendor. The numbers that he invented had many more 7s, 8s, and 9s than would
be expected under Benford’s Law, and for that matter, than would be expected if the digits
were equally likely. This graph shows the credits issued for kilowatt hours by an electric
utility company. We investigated the spike at “99” and it turned out that several employees
were fraudulently giving customers credits for numbers just below 1 million and just below
100,000 KwH. Those customers would in turn give the employees a nice present in
exchange for their credit. To summarize, Benford Law works well to detect invented
numbers when, One person invents all the numbers, or, lots of different people each have
some incentive to manipulate numbers in the same way (such as on tax returns) It is a
useful start that gives us a better understanding of our data We use it together with other
more focused drill down tests to detect fraud, errors, biases, and other anomalies We
should have a winning combination.

Video-4: Availability of Data and Text Analysis

So far, we've been focusing on the analysis of numerical data to detect fraud. But textual
data can also be used to find fraud. Organizational frauds, as imagine, typically aren’t
perpetrated by one person. Bribes to foreign officials, conspiracies to falsely inflate
financial statements you might, or price fixing don’t occur in isolation. Many people can be
involved, and typically those people communicate by email. An analysis of email
communications within an organization could lead to discovery of these frauds. But textual
analytics can be used to review all types of documents, not just email. For example,
consider Management Discussion and Analysis in a set of financial statements.

Frequent use of words such as “adjustment,” “anomaly,” “irregularity,”


“inconsistency” might be a red flag to conduct further inquiries. Often, fraud examiners
can look for certain “key words” that are associated with certain types of fraud schemes.
For example, groups of emails containing terms such as “override,” “write off,” “adjust,”
“just once” “won’t get caught” could be indicative of a financial statement fraud scheme as
well as many other types of schemes. Machine assisted review of emails containing words
potentially indicative of fraud can help identify schemes before they occur. But while
automated review can assist in reviewing large amounts of documentation, careful human
analysis is just as important. Careful analysis of management statements and other
official company communications can reveal areas where the company may be avoiding
discussing sensitive issues or using vague terms or words to hide the truth. Data exists in
many forms and in many locations.

Obviously, as we mentioned, the fraud examiner will want to work with the IT department
to review the accounting and enterprise information systems data collected by the
organization. But there are other sources as well. Public records can be a great source of
information about individuals and businesses. For example, a criminal conviction search
can identify previous instances of misconduct or financial misdeeds by people or
companies. Social media and the web can lead to valuable information about individuals
or businesses who may be subjects of your investigation. People will often post things to
social media sites that may be of interest to a fraud examiner. For instance, let’s say you
suspect a particular employee of engaging in a kickback scheme. Recent posts by that
employee showing expensive purchases or vacations might be evidence of unexplained
wealth.

Also be aware that company policies often allow for search of personal electronic
devices such as smart phones and tablets. Such searches should only be conducted when
necessary, and of course, counsel should be consulted beforehand, but they can provide
valuable information in some circumstances such as a data security breach. Digital data
has a greater life cycle than most people realize. Just because a subject deletes data from
a hard drive, mobile device, or peripheral device such as a USB drive, that does not mean
that it is unrecoverable. With the right software tools, digital forensic experts can often
recover data even if the user attempted to delete it. It is important to remember not to
destroy or change data inadvertently, however. For example, if a device is off, you should
never turn it on. Doing so changes important time and date information on the system.
Likewise, shutting a system down using normal procedures will also change important
information. The best practice is to leave everything as is and ask a digital forensic
professional to assist you. He or she will use approved hardware and software systems to
make an image of the hard drive. This can be done without harming or altering the original
drive. That way any evidence found on the drive will be preserved for use in judicial
proceedings. This week covered a variety of topics, mostly in the digital space, including big
data and technology-based tools and techniques.

We started with a need to identify the correct type and amount of data. From a
practical perspective, no case is investigated with an “open checkbook.” The fraud
examiner and forensic accountant needs to develop evidence to support their opinions and
ensure that no disconfirming evidence exists. Our next topic looked at the some of the
tools and techniques used to analyze data and showed how some of the tools and
techniques were used to perpetrate and conceal the WorldCom fraud as well as those
used to detect it. We wrapped with a discussion of data mining including the electronic
evaluation of text evidence. As with all of our material, you can learn more by visiting the
West Virginia University and Association of Certified Fraud Examiner websites. Thank you
for your participation. We look forward to working with you in the next section.

Video-5: Making Crime Pay – How to locate hidden assets - Steve Comisar

I realized that the authorities, how they catch you is they follow the money and if they're
going to follow the money to a dead end, for example they go to a bank and they say "Who
owns this bank account?" and it's Polly Prostitute address unknown, it's going to be awfully
hard to find her. And about the same person who has the post office box and the DBA, it's
going to be awfully hard to find that person. When the checks would come to the mail drop
address, I would sneak over there like 2 or 3 in the morning, because you know, you get a
key to the front door and a key to the box, and I'd make sure nobody was around. I'd get the
checks out and then I would put the checks in the night depository so that nobody would
ever see me. I'd put on my surgical gloves because you know that paper gives off a very
good fingerprint. After money was deposited into one account, a check would be written
and put into another one and another one so if the authorities were to follow me they would
have to go from bank to bank to bank and law enforcement agents do not like to work.

The longer you make them work, the harder you make them work, the more they are going
to go on to another case, especially in a big city like Los Angeles. I would purchase stock
through company checks and then have that converted into cash by selling the stock and
having the check made out to a person who would then cash the check. So what you would
do is you would receive my check. I'd buy stock, let's say in Microsoft or a solid company
and then after a little while I would sell all the stock, maybe leaving a little bit of it left. Well
the stock brokerage firm would write a check to anyone you want to for the sale of the
stock, whatever you had in your account. That could go into one account and that account
could write a check into another account and it just makes the trail a lot harder to find. You
find a branch manager at your bank and you befriend him and you offer him amounts of
cash that when you come in and cash a check or receive cash, $80,000 or $100,000 that
he's going to lose that report or not file one.
I took a risk. I wanted to have money. I wanted to have power. I wanted it all and it's not
worth it. All the millions I made, all the fun that I thought I had, it's not worth it.

Discussion on: Edward Snowden

NSA & Snowden. Does how you get information matter? Is Snowden an accidental
fraudster, predator, traitor or good citizen (whistle-blower)?

You might also like