ZenGRC

Internal Controls and Fraud Prevention

The article emphasizes the pervasive risk of corporate fraud—encompassing corruption, asset misappropriation, and financial statement fraud—and underscores the critical need for organizations to implement robust internal controls to detect, prevent, and mitigate the significant financial and reputational damage caused by deliberate, often concealed fraudulent activities by insiders or external perpetrators.

Fraud is a constant concern for businesses and organizations. According to PwC’s Global Economic Crime and Fraud Survey 2020, 47 percent of U.S. companies had experienced fraud in the previous 24 months, and another 35 percent were asked to pay a bribe. The Association of Certified Fraud Examiners (ACFE) found in 2021 that 71 percent of anti-fraud experts believed fraud levels would increase in the coming year.

These findings show that fraud is a widespread risk that can affect any organization, its business continuity, and its reputation. So what can your organization do to minimize the possibility of fraud and mitigate its potential harm? Strong internal controls are essential.

This article explores why your organization needs robust internal anti-fraud controls and explains six essential controls that should be part of your internal control system.

What Is Corporate Fraud?

Corporate fraud refers to illegal or deceptive actions committed by an internal or external perpetrator against a business for personal or financial gain. Unlike inadvertent errors or mistakes, fraud involves deliberate and malicious acts. Fraud can cause irrevocable harm to employees, investors, customers, partners, and creditors.

Fraud is often difficult to detect. Internal fraudsters might engage in fraudulent activity for years by taking advantage of their “trusted insider” status. Some perform highly complicated accounting schemes that only an expert can detect and understand. Others rely on a lack of visibility within the organization to execute fraudulent behaviors “under the radar.”

Types of Corporate Frauds

There are three primary types of fraud: corruption, asset misappropriation, and financial statement fraud.

Corruption

Corruption schemes usually involve employees misusing their position to influence business transactions for their benefit. Bribery, extortion, and conflicts of interest are the most common types of corporate fraud.

Asset Misappropriation

Also known as insider fraud, asset misappropriation can be committed by an insider such as a company director or employee, or by an outsider such as a third-party vendor.

One common way to perpetrate asset misappropriation fraud is to steal cash before or after it has been recorded in the company’s accounting books. In some fraud cases, fraudsters also steal cash receipt equivalents, such as vouchers or credit notes.

Some other common types of asset misappropriation fraud are:

  • Stealing company data, intellectual property, or business secrets
  • Embezzlement by creating false invoices or by implementing a “ghost employee” scheme
  • Making false expense claims for reimbursement
  • Stealing non-cash assets

Financial Statement Fraud

Employees or senior management create fictitious revenues, understate revenues, hide liabilities, or inflate assets in financial statement fraud. The goal is to paint a false picture of the organization’s financial performance, usually to boost the company’s market value or attract new investors. Improper disclosures are also a type of financial statement fraud.

Financial statement fraud is the least common type of fraud, but it attracts a lot of attention when it occurs. These schemes can take years to detect and can result in battered stock prices, job cuts, and huge losses for investors and shareholders.

For example, the Enron scandal in 2001 involved massive financial misstatement fraud, leading to a collapse in share price and bankruptcy, with shareholders losing over $74 billion. This and other scandals led to the enactment of the Sarbanes-Oxley Act in 2002.

What Is the Cost of Corporate Fraud?

In 2018, the average corporate loss arising from fraud was $2.75 million. Even private companies and small businesses were not exempt, suffering a median annual loss of $164,000 due to fraud. The most common fraud schemes included:

  • Corruption
  • Wire transfer schemes
  • Expense reimbursement schemes
  • Payroll fraud
  • Inventory theft
  • Cash larceny
  • Check tampering
  • Financial statement fraud

ACFE predicted that U.S. businesses would lose around 5 percent of their gross revenues to fraud, with the most significant contributing factor being the lack of strong internal controls.

By 2019, fraud events cost businesses $5.127 trillion each year, representing almost 70 percent of the $7.442 trillion the world spent on annual healthcare costs. In a 2020 PwC survey, respondents reported $42 billion in fraud losses, with 13 percent of victim companies losing $50 million or more.

Fraud costs have also increased in other countries. For example, businesses in Britain now lose £137 billion annually to fraud. In Canada, losses increased from $2.87 per $1 of fraud in 2020 to $3.02 per $1 in 2021.

The Importance of Internal Controls for Preventing Fraud

Most fraud incidents occur due to an outdated or weak internal control system. Without robust controls, fraudsters can exploit weaknesses or take advantage of their position to commit fraud. Effective internal controls minimize the possibility of fraud and its repercussions.

A strong internal controls environment is the bedrock of any corporate fraud prevention program. Your internal control process should include three types of internal controls:

  • Preventive controls to prevent fraud from happening
  • Detective controls to identify and minimize the harm of fraud that has already occurred
  • Corrective controls to address and fix problems that may lead to fraud, cause financial losses, or damage the organization’s reputation

Six Key Controls to Help Protect Against Fraud

Here are six critical internal controls that can help improve fraud detection and protect your organization from fraud losses.

1. A Strong Code of Conduct and Ethics

A robust code of conduct is a valuable anti-fraud control. The code sets the tone from the top and provides a clear roadmap about which behaviors are and are not acceptable. Defining these expectations helps safeguard the company’s reputation, prevent regulatory fines, and avoid legal litigation.

A well-written code of conduct outlines your organization’s mission, vision, values, principles, and commitments, linking them to expected ethical and moral standards. It serves as a benchmark to assess behaviors and hold employees accountable if they are non-compliant.

The code of conduct should include policies such as:

  • Whistleblower policy
  • Incident response plan
  • Executive-specific policies
  • Code of business ethics
  • Anti-fraud policy
  • Conflicts of interest
  • Financial and fiscal policies around:
    • Cash disbursements
    • Expense reimbursements
    • Travel reimbursements
    • Petty cash

2. A Robust Internal Reporting System

Employees detect a large portion of corporate fraud cases. A confidential hotline, internal website or portal, or another reporting mechanism provides employees with the means to report suspected fraudulent activities.

It’s essential to make this system anonymous, as most whistleblowers hesitate to report incidents openly due to fear of reprisals or job loss. The anonymous reporting system and whistleblower policy should be used together to detect and investigate fraud.

3. Segregation of Duties

Segregating duties (separation of duties) is a critical internal control to reduce fraud risk. It means that no single person has multiple duties that could enable them to engage in fraudulent activities.

For example, activities related to financial record-keeping, authorization, reconciliations, and reviews should be divided among different employees. This separation ensures that a single person cannot retain custody of a transaction and manipulate resulting assets, reducing the risk of inappropriate actions.

4. Internal Audits

Solid internal audit procedures limit the risk of fraud. Along with management reviews, internal audits are critical to assess existing anti-fraud controls and assure they remain effective and up-to-date. Internal auditors can also search for fraud and mitigate potential damages. These auditors must know how to assess fraud risk.

To ensure the internal audit system is working well, executive management should:

  • Evaluate the organization’s fraud response plan, including key processes and investigation methodologies
  • Decide who will carry out fraud investigations
  • Clarify how internal audits will investigate fraud and assess any failures of existing controls
  • Check if internal auditors have the required skills to carry out fraud investigations

5. External Audits

While robust internal audits are crucial, working with external auditors is also critical. An independent external auditor can bring objectivity and impartiality to the controls audit process. External audits can also deter employees from indulging in fraudulent behaviors, knowing there’s an additional mechanism to get caught.

External auditors typically work with internal auditors to analyze current anti-fraud controls, recommend changes to policies and procedures, and help with implementation.

6. Up-to-Date Documentation

Accounting records and other documentation can help reduce fraud by increasing visibility and making it easier to audit transactions and activities. It’s imperative to document financial transactions to ensure that no one is manipulating records or affecting the quality and accuracy of financial reporting.

For instance, all sales receipts and bank account deposit preparations should be documented. This allows authorized personnel to perform bank reconciliations and verify that receipts were deposited into the bank, reducing asset misappropriation or other types of fraud.

Other ways to prevent fraud with documentation include:

  • Use “for deposit only” stamps on all incoming checks
  • Avoid using a signature stamp
  • Require two or more signatures on checks above a specified amount
  • List all checks on a log before handing them to an authorized person for depositing receipts
  • Require supervisors to approve employee timesheets before payroll is processed
  • Examine all canceled checks to ensure that third parties are recognized and legitimate

Along with these six controls, you can also hire trustworthy experts like Certified Fraud Examiners (CFE) and Certified Public Accountants (CPA) to help establish anti-fraud policies and controls.