Managing Internal Control System

Fraud Risk Management Strategy

Fraud prevention:

The aim of preventative controls is to reduce opportunity and remove temptation from potential offenders.

Some specific examples of fraud prevention include:

  • An anti-fraud culture
  • Risk awareness
Fraud Detection:

A common misbelief is that external auditors find fraud. This is actually rarely the case – in fact their letters of engagement typically state that it is not their responsibility to look for fraud. Most frauds are discovered accidentally, or as a result of information received (whistleblowing).

Some methods of discovering fraud are:

  • Performing regular checks, e.g. stocktaking and cash counts.
  • Warning signals or fraud risk indicators
Fraud Response:

The fraud response plan sets out the arrangements for dealing with suspected cases of fraud, theft or corruption.


Fraud prevention:

The aim of preventative controls is to reduce opportunity and remove temptation from potential offenders. Prevention techniques include the introduction of policies, procedures and controls, and activities such as training and fraud awareness to stop fraud from occurring.

 

Some specific examples of fraud prevention include:

– An anti-fraud culture;

– Risk awareness;

– Whistleblowing;

– Sound internal control systems.

 

A fraud policy statement, effective recruitment policies and good internal controls can minimise the risk of fraud.

 

Fraud Detection:

A common misbelief is that external auditors find fraud. This is actually rarely the case – in fact their letters of engagement typically state that it is not their responsibility to look for fraud. Most frauds are discovered accidentally, or as a result of information received (whistleblowing).

 

Some methods of discovering fraud are:

– Performing regular checks, e.g. stocktaking and cash counts.

– Warning signals or fraud risk indicators (see previous section). For example:

  •  Failures in internal control procedures
  • Lack of information provided to auditors
  • Unusual behaviour by individual staff members
  • Accounting difficulties.

– Whistle blowers

 

Fraud Response:

The fraud response plan sets out the arrangements for dealing with suspected cases of fraud, theft or corruption.

 

It provides procedures for evidence-gathering that will enable decision making and that will subsequently be admissible in any legal action.

 

The fraud response plan also has a deterrent value and can help to restrict damage and minimise losses to the organisation.

 

The organisation’s response to fraud may include:

– Internal disciplinary action, in accordance with personnel policies.

 

– Civil litigation for the recovery of loss.

 

– Criminal prosecution through the police.

Fraud Prevention and Detection:

When the Internet first became widely used and accepted, everyone needed a firewall to protect their computers from hackers. If the firewall was configured for maximum security you couldn’t use half the websites on the Internet, so you’d have to create enough permissions (often referred to as holes in the firewall) to allow you to leverage valuable websites. To cover the risk from these holes, companies deployed intrusion detection software to identify any hacker activity.  This blend of preventive controls (firewalls) and detective controls (intrusion detection) struck the balance between risk and getting business done.

 

Fraud response responsibility should be allocated as below,

– Managers, who should take responsibility for detecting fraud in their area.

 

– Finance Director, who has overall responsibility for the organisational response to fraud including the investigation. This role may be delegated to a fraud officer or internal security officer.

 

– Personnel (Human Resources Department), who will have responsibility for disciplinary procedures and issues of employment law and practice.

 

– Audit committee, which should review the details of all frauds and receive reports of any significant events.

 

– Internal auditors, who will most likely have the task of investigating the fraud.

 

– External auditors, to obtain expertise.

 

– Legal advisors, in relation to internal disciplinary, civil or criminal responses.

Video temporarily unavailable

This lesson is waiting for its secure Vimeo video.

Fraud Risk Management Strategy

Request Callback Say Hi! on WhatsApp