FRAUD RISK ASSESSMENT
Fraud Risk
Fraud Risk is a situation or an event that would make the organization vulnerable to both internal
and external fraud
Fraud Risks – that facilitate commission of Fraud as demonstrated in the Fraud Triangle
Cressey’s Fraud Triangle teaches that there are three interrelated elements that enable someone to
commit fraud: the motive or pressure that drives a person to want to commit the fraud, the
opportunity that enables him to commit the fraud, and the ability to rationalize the fraudulent
behavior.
The vulnerability that an organization faces from individuals capable of combining all three elements
of the Fraud Triangle is fraud risk. Fraud risk can come from sources both internal and external to
the organization.
Fraud risk assessment
Fraud risk assessment is a process aimed at proactively identifying and addressing an organization’s
vulnerabilities to internal and external fraud. A fraud risk assessment starts with an identification
and prioritization of fraud risks that exist in the business. The process evolves as the results of that
identification and prioritization begin to drive education, communication, organizational alignment,
and action around effectively managing fraud risk and identifying new fraud risks as they emerge.
Inherent Risks versus Residual Risks
When considering the fraud risks faced by an organization, it is helpful to analyze how significant a
risk is before and after risk response. Risks that are present before the effect of internal controls are
described as inherent risks. The risks that remain after the effect of internal controls are described as
residual risks.
For example, there is an inherent risk that the employee in charge of receiving customer payments
at a small company might embezzle incoming cash. Controls, such as segregation of duties and
oversight from the company owner, can be implemented to help mitigate this risk; however, even
with such controls in place, some residual risk will likely remain in that the bookkeeper might still
manage to embezzle funds.
1
The objective of the controls is to make the residual risk significantly smaller than the inherent
risk.
Examples of Inherent Risks
The fraud risk assessment team should brainstorm to identify the inherent fraud risks that could
apply to the organization. Brainstorming should include discussions regarding incentives, pressures,
and opportunities to commit fraud, including the incentive programs and how those might affect
employee behavior; the potential for management’s override of controls; and the universe of fraud
risks and the subset of risks, including reputation risk, pertaining to specific categories of fraud that
apply to a particular organization.
The benefits of conducting a fraud risk assessment
Every organization should conduct a fraud risk assessment and should create processes to keep the
assessment current and relevant. Not only is doing so a sound corporate governance strategy, but it
also makes good business sense. The benefits of conducting a fraud risk assessment include enabling
the organization to:
Improve communication and awareness about fraud.
Identify where it is most vulnerable to fraud and what activities put the company at the
greatest risk.
Know who puts the organization at the greatest risk.
Develop plans to mitigate risk.
Develop techniques to investigate and determine if fraud has occurred in areas of high risk.
Assess internal controls.
Comply with regulations and professional standards.
Objective of Fraud Risk Assessment
In the simplest terms, the objective of a fraud risk assessment is to help an organization identify
what makes it most vulnerable to fraud. Through a fraud risk assessment, the organization is able to
identify where fraud is most likely to occur, enabling proactive measures to be considered and
implemented to reduce the chance that it could happen.
The Right Sponsor for a Fraud Risk Assessment
Having the right sponsor for a fraud risk assessment is extremely important in ensuring its success
and effectiveness. The sponsor must be senior enough in the organization and command the
employees' respect to elicit full cooperation in the process. The sponsor has to be someone who is
committed to learning the truth about where the company’s fraud vulnerabilities really are. He can’t
be someone who is prone to rationalization or denial; he must be a truth seeker. In the ideal
situation, the sponsor would be an independent board director or audit committee member.
However, a good CEO or other internal senior leader can be equally as effective.
Factors that influence Fraud Risk in an Organisation
Many factors influence how at-risk an organization is to fraud. Some of the main factors are:
The nature of the business in which it is engaged (i.e., its industry and operations)
2
The environment in which it operates (e.g., physical storefront or Internet-based,
geographical location)
The effectiveness of the internal controls within the business processes
The ethics and values of the company and its employees
Fraud Risk Process
Both management and auditors have a responsibility for fraud risk management. However, each of
these parties has unique knowledge and perspective of the fraud risks faced by the organization.
Consequently, the fraud risk assessment is most effective when management and auditors share
ownership of the process and accountability for its success.
Additionally, a good fraud risk assessment can be effectively conducted either by people inside the
organization or with external sources. Either way, it is critical that the people leading and conducting
the fraud risk assessment remain independent and objective throughout the assessment process.
Additionally, they must be perceived as independent and objective by others.
Furthermore, most honest people are not naturally inclined to think like a criminal. In fact, many
large-scale frauds that have occurred would have been deemed unthinkable by people closest to the
events. But a necessary part of conducting an effective fraud risk assessment involves thinking like a
fraudster. Thoughts of “it couldn’t happen here” should not be allowed to moderate the evaluation
of fraud risk.
Objectivity in Fraud Risk Assessment
A good fraud risk assessment can be effectively conducted either by people inside the organization
or with external sources. However, the people leading and conducting the fraud risk assessment
need to be independent and objective throughout the assessment process. Additionally, they must
also be perceived as independent and objective by others.
Communication about Fraud Risk Assessment
The fraud risk assessment process should be visible and communicated throughout the business.
Employees will be more inclined to participate in the process if they understand why it is being done
and what the expected outcomes will be. To that end, sponsors should be strongly encouraged to
openly promote the process. The more personalized the communication from the sponsor, the more
effective it will be in encouraging employees to participate in the process. Whether it is a video, a
town hall meeting, or a company-wide email, the communication should be aimed at eliminating any
reluctance employees have about participating in the fraud risk assessment process.
Opinions in Fraud Risk Assessment
Much instinct and judgment go into performing the fraud risk assessment. When reporting the
results of the assessment, however, the team must report only the facts and keep all opinions and
biases out of the report. A report that is interspersed with the assessment team’s subjective
perspective will dilute and potentially undermine the results of the work.
Eliminating Biases in Fraud Risk Assessment
The people leading and conducting the fraud risk assessment should be mindful about any personal
biases they might have regarding the organization and the people within it, and they should take
3
steps to reduce or eliminate all biases that might affect the fraud risk assessment process. For
example, if an employee on the fraud risk assessment team had a bad experience with someone in
the accounts payable department, he might allow that experience to affect his evaluation of the
fraud risks related to that area of the business. To preclude this possibility, someone else should
perform the fraud risk assessment work related to the accounts payable department’s activities.
Reporting of Results of the Fraud Risk Assessment
Less is often more when it comes to reporting the results of the fraud risk assessment. The team
should take care not to turn the report into a tedious list of things that management will have to sort
through and prioritize. Instead, the report should be presented in a way that focuses on what really
matters, clearly highlighting those things that are most important and that will make the most
impact on the organization’s fraud risk management efforts.
The success of the fraud risk assessment process
The success of the fraud risk assessment process depends on how effectively the results are
reported and what the organization then does with those results. A poorly communicated report can
undermine the entire process and bring all momentum established to a halt. The report should be
delivered in a style most suited to the language of the business. If management prefers succinct
PowerPoint presentations, the fraud risk assessment team should not deliver a 50-page Word
document
Effective Fraud Risk Assessment
Risk assessments created or performed by management and auditors without the input of the staff
performing the operational tasks will be ineffective. It is crucial to include members of all levels of
the organization in the risk assessment process to ensure that all relevant risks are addressed and
reviewed from many different perspectives. Additionally, asking employees at lower levels of the
organization specific questions about the company culture or eliciting ideas to strengthen internal
controls can provide incredibly valuable information that might not be obtainable from any other
source.
To make the most of the fraud risk assessment process
To make the most of the fraud risk assessment process, management should use the results to:
Begin a dialogue across the company that promotes awareness, education, and action
planning to reduce fraud risk.
Look for fraud in high-risk areas.
Hold action owners accountable for progress against agreed-upon plans.
Keep the assessment process alive and relevant.
Modify or create the code of conduct or ethics policy.
Monitor key internal controls.
4
Actions of individuals in relation to fraud risk
The actions of certain individuals can significantly increase the company’s vulnerability to fraud. The
risk can be driven from the way in which someone makes decisions, behaves, or treats others within
and outside the organization. A fraud risk assessment can help home in on those people and their
activities that might increase the company’s overall fraud risk
Fraud Risk Assessment Team
Before conducting the fraud risk assessment, the organization should build a fraud risk assessment
team consisting of individuals with diverse knowledge, skills, and perspectives that will lead and
conduct the fraud risk assessment. The size of the team will depend on the size of the organization
and the methods used to conduct the assessment. The team should have individuals who are
credible and who have experience in gathering and eliciting information. The team members might
include internal and external sources, such as accounting and finance personnel, operations
personnel, members of the legal department, internal auditors, internal security or investigative
personnel, external consultants with fraud and risk expertise, and any business leader with direct
accountability for the effectiveness of the organization’s fraud risk management efforts
The fraud risk assessment team members might include internal and external sources, such as:
Accounting and finance personnel who are familiar with the financial reporting processes
and internal controls
Nonfinancial business unit and operations personnel who have knowledge of day-to-day
operations, customer and vendor interactions, and issues within the industry
Risk management personnel who can ensure that the fraud risk assessment process
integrates with the organization’s enterprise risk management program
The general counsel or other members of the legal department
Members of any ethics or compliance functions within the organization
Internal auditors
Internal security or investigative personnel who are familiar with investigations of past fraud
incidents
External consultants with fraud and risk expertise
Any business leader with direct accountability for the effectiveness of the organization’s
fraud risk management efforts
Potential corruption risks include:
Payment of bribes or illegal gratuities to companies, private individuals, or public officials
Receipt of bribes, kickbacks, or illegal gratuities by employees or agents of the company
Aiding and abetting of fraud by outside parties, such as customers or vendors
Regulatory and legal misconduct
Regulatory and legal misconduct includes a wide range of risks, such as conflicts of interest, insider
trading, theft of competitor trade secrets, anti-competitive practices, environmental violations, and
trade and customs regulations in areas of import and export. Depending on the particular
organization and the nature of its business, some or all of these risks might be applicable and should
be considered in the fraud risk assessment process
5
External fraud risks include:
Fraud committed by customers (e.g., fraudulent customer payments)
Fraud committed by vendors (e.g., overbilling by a vendor or collusion between bidding
contractors to inflate contract price)
Fraud committed by competitors (e.g., corporate espionage)
Fraud committed by unrelated third parties (e.g., hacking)
Qualitative and Quantitative factors
The fraud risk assessment team should consider qualitative and quantitative factors when assessing
the organization's fraud risks. For example, a particular fraud risk that might only pose an immaterial
direct financial risk to the organization, but that could greatly affect its reputation, would likely be
deemed a significant risk to the organization.
Effective Internal Control System
No system of internal controls can fully eliminate the risk of fraud, but well-designed and effective
internal controls can deter the average fraudster by reducing the opportunity to commit the fraud
and increasing the perception of detection. With the right balance of preventive and detective
controls, a good system of internal controls can greatly reduce an organization’s vulnerability to
fraud.
Revaluation of Internal Control System
Many organizations rely heavily on their internal control system to prevent and detect fraud.
Although internal control plays a critical role in fraud prevention and detection, it is a dynamic
system that requires constant reevaluation of its weaknesses. Performing a fraud risk assessment
provides management with the opportunity to review the company’s internal control system for
effectiveness, taking into account the following considerations:
Controls that might have been eliminated due to restructuring efforts (e.g., elimination of
separation of duties due to downsizing)
Controls that might have eroded over time due to reengineering of business processes
New opportunities for collusion
Lack of internal controls in a vulnerable area
Nonperformance of control procedures (e.g., control procedures compromised for the sake
of expediency)
Inherent limitations of internal controls, including opportunities for those responsible for a
control to commit and conceal fraud (e.g., through management and system overrides)
High Fraud Risk Area
Assessing an area as having a high level of fraud risk does not conclusively mean that fraud is
occurring there. However, the fraud risk assessment is useful in identifying areas to proactively
investigate to determine whether fraud has in fact occurred. In addition, putting activity in high-risk
areas under increased scrutiny can deter potential fraudsters by increasing their perception of
detection.
Methods of Conducting Fraud Risk Assessment
6
There are many ways to go about conducting the fraud risk assessment. Picking a method or
combination of methods that is culturally right for the organization will help to ensure its success.
The assessment team should also consider the best ways to gather candid, truthful information from
people throughout all levels of the organization, starting by understanding what techniques are
commonly and effectively used throughout the organization.
Methods and Techniques of gathering information
Several techniques can be successfully used to gather information as part of a fraud risk assessment.
These include:
Interviews, which can be an effective way to conduct candid one-on-one conversations with
employees
Focus groups, which can enable the assessor to observe the interactions among a group of
employees as they collectively discuss a question or issue
Surveys, which are electronic or paper questionnaires that can be either anonymous or
directly attributable to the individual participants
Anonymous feedback mechanisms, which can include means for anonymous employee
suggestions or responses to questions posed
Response to Fraud Risks
Mitigating the Risk
When responding to the organization’s residual fraud risks, management can help mitigate a risk by
implementing appropriate countermeasures, such as prevention and detection controls. The fraud
risk assessment team should evaluate each countermeasure to determine if it is cost effective and
reasonable given the probability of occurrence and impact of loss.
Transferring the Risk
When responding to the organization’s residual fraud risks, management may transfer some or all of
the risk by purchasing fidelity insurance or a bond. The cost to the organization is the premium paid
for the insurance or bond. The covered risk of loss is then transferred to the insurance company.
Assuming the Risk
Management may choose to assume the risk if it determines that the probability of occurrence and
impact of loss are low. Management may decide that it is more cost effective to assume the risk than
it is to eliminate the asset or discontinue the activity, buy insurance to transfer the risk, or
implement countermeasures to mitigate the risk.
Avoiding the Risk
When responding to the organization’s residual fraud risks, management may decide to avoid a risk
by eliminating an asset or discontinuing an activity if the control measures required to protect the
organization against an identified threat are too expensive. This approach requires the fraud risk
assessment team to complete a cost-benefit analysis of the value of the asset or activity to the
organization compared to the cost of implementing measures to protect the asset or activity.
7
Types of Preventive Controls
Preventive controls, which are intended to prevent fraud before it occurs, include:
Bringing awareness of the fraud risk management program to personnel throughout the
organization
Performing background checks on employees (where permitted by law)
Hiring competent personnel and providing them with anti-fraud training
Conducting exit interviews
Implementing policies and procedures
Segregating duties
Implementing physical security measures
Implementing security measures to restrict electronic access to data
Ensuring proper alignment between an individual’s authority and level of responsibility
Reviewing third-party and related-party transactions
Detective controls, which are intended to detect fraud if it does occur, include:
Establishing and marketing the presence of a confidential reporting system, such as a
whistleblower hotline
Implementing proactive controls for the fraud detection process, such as independent
reconciliations, reviews, physical inspections and counts, analysis, and audits
Implementing proactive fraud detection procedures, such as data analysis and continuous
auditing techniques
Performing surprise audits
Fraud Risk Assessment and influencing the Audit Process
The fraud risk assessment should play a significant role in informing and influencing the audit
process. In addition to being used in the annual audit planning process, the fraud risk assessment
should drive thinking and awareness in the development of audit programs for areas that have been
identified as having a moderate-to-high risk of fraud. Although auditors should always be on guard
for things that might be indicators of fraud risk, the results of the fraud risk assessment can help
them design audit procedures in a way that enables them to look for fraud in known areas of high
risk.
Assessing an area as having a high level of fraud risk does not conclusively mean that fraud is
occurring there. However, the fraud risk assessment is useful in identifying areas to proactively
investigate to determine whether fraud has in fact occurred. In addition, putting activity in high-risk
areas under increased scrutiny can deter potential fraudsters by increasing their perception of
detection.