Internal Controls to Prevent Financial Statement Fraud
The article explains that internal controls, guided by the COSO framework's five components—control environment, risk assessment, control activities, information and communication, and monitoring—are essential defenses against financial statement fraud, as exemplified by the Enron scandal and subsequent Sarbanes-Oxley Act, by enhancing transparency, accountability, and reliability in financial reporting to prevent and detect fraudulent manipulation.
“Cooking the books” refers to falsifying financial statements to commit accounting fraud. A landmark example is Enron, whose collapse in 2001 led to the Sarbanes-Oxley Act (SOX) to reduce accounting fraud and unreliable financial reporting among publicly traded companies. Despite SOX, financial fraud can still occur, leading to stock price drops, shareholder losses, and legal trouble for companies.
Can Internal Controls Help to Prevent Fraud?
Yes. Most accounting fraud cases involving financial statement manipulation occur due to weak or absent internal controls. Internal controls are defenses against misstatement of financial results, whether from fraud or mistake. They assure the audit committee, board of directors, and senior management that financial reporting is reliable and compliant with laws and regulations. Implementing various types of internal controls increases transparency and accountability, deterring fraudulent activities and improving fraud detection and prevention.
What Are Internal Controls Over Financial Reporting?
Internal controls are practices used by a firm to ensure its rules are followed. The COSO (Committee on Sponsoring Organizations) framework outlines five interrelated components for effective internal control:
- Control environment: The ethical tone at the top and oversight by the board’s audit committee.
- Risk assessment: Evaluating risks associated with procedures and data sources used in financial reporting.
- Control activities: Addressing identified risks.
- Information and communication: Gathering and disseminating information about risks to responsible parties.
- Monitoring: Ensuring continued vigilance in operations, compliance, and financial reporting as the company evolves.
Internal Controls to Prevent Financial Statement Fraud
Internal controls to address fraud risk begin at the transaction level and can extend beyond accounting to improve oversight and maintain the integrity of financial statements. Basic steps include:
Segregation of Duties
No single person should have multiple responsibilities that could enable fraud. Duties such as record-keeping, authorization, and review should be divided among different employees. At a minimum, segregate duties for:
- Receiving cash or checks
- Preparing deposits
- Handling cash receipts and deposits
- Reconciling deposits and transactions
- Writing checks
- Preparing financial statements
Implement a Reconciliation Process
A formal reconciliation process for all key accounts is critical. For example, reconcile incoming check logs against deposits and regularly examine bank statements and canceled checks. Ensure only authorized personnel sign checks and that all vendors are legitimate. An independent person should handle reconciliation, and the process should be documented. Inform employees that accounts are regularly reviewed to deter manipulation.
Use an External Auditor
Since management often perpetrates financial statement fraud, an external auditor should examine financial statements annually. For publicly traded U.S. companies, this is required by law.
Provide Board of Directors Oversight
The board should:
- Compare actual revenue and spending to budgeted amounts
- Review the check register or general ledger
- Ensure approval of financial and audit procedures is documented
- Evaluate C-suite performance
- Require independent auditors to present annual financial statements
Review Inventory, Journal Entries, and Electronic Transfers
Random inventory counts by unbiased personnel, monthly review of general journal entries, and scrutiny of large or unusual amounts are important. Regularly review wire transfers, especially to offshore accounts, to ensure legitimacy and proper documentation.
Set a Strong Tone at the Top
Management should demonstrate ethical behavior and lead by example. Communicate ethics, values, and procedures through written policies, including:
- Cash disbursements, receipts, and reconciliations
- Expense and travel reimbursements
- Petty cash access and reconciliation
- Voiding checks
- Blank check access and storage
- Purchasing guidelines
- Conflicts of interest
Consequences for policy violations should be clear and approved by the board.
Set Up a Fraud Hotline
A confidential hotline allows employees to report suspected fraud safely. Protecting whistleblowers encourages reporting and helps detect and prevent fraud. SOX requires such hotlines for publicly traded companies, and other laws require protection against retaliation.
Leveraging Technology to Mitigate Fraud Risk
Financial statement fraud, while less common than asset misappropriation, can cause severe problems. Adequate internal controls protect organizations from misstatement frauds. Improving visibility into your risk environment, identifying relevant risks, and enhancing risk assessments can reduce fraud risk. Tools that provide a single source of truth, revision-controlled policies, workflow management, and insightful reporting can help organizations streamline risk management and meet auditing standards.