,

Fraud Risk Management and Internal Audit: Prevention, Detection, and Response

A fraud does not announce itself in the general ledger. It arrives as a customer complaint about a balance that should have cleared months ago, a vendor whose remit-to bank changed nine days before a $240,000 payment, or a depot whose settlement variances are always approved by the person who created them. The ACFE’s Occupational Fraud 2026: A Report to the Nations (2,402 cases across 143 countries) puts the median loss at $104,000 and the median scheme duration at 12 months, and finds that 43 percent of schemes were first detected by a tip against 15 percent by internal audit. Those figures argue for treating fraud risk management as a system to be assessed rather than a hunt to be run: the company that finds a fraud in month four instead of month seventeen has built a reporting channel, an analytic, and a reconciliation that someone independent actually looks at, and internal audit’s leverage lies in testing whether those three things exist and work. MidState Beverage learned this the expensive way in FY26, when a Dayton depot driver diverted $18,400 over five months and the first person to notice was a customer.

This guide gives you the working method: a 26-row fraud scheme catalog by process with the red flag and the detective analytic for each scheme, a scored fraud risk assessment template with a worked assessment of MidState’s $31 million route cash cycle, an investigation protocol table that fixes the boundary between internal audit, legal, and HR, an audit committee reporting outline with a quarterly metrics page, and a failures table drawn from programs that looked complete on paper. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, the second edition of the COSO/ACFE Fraud Risk Management Guide (May 2023), and the 2026 Report to the Nations. It pairs with the site’s fraud red flags reference and the broader fraud risk primer; the analytics in the catalog are built step by step in the accounts payable, payroll, and journal entry analytics guides.

In this guide

What internal audit owns in fraud risk management

The IIA Three Lines Model (2020) settles the ownership question. Management owns fraud risk and the controls over it; the roles that write the anti-fraud policy, run the hotline, and monitor compliance are second-line; internal audit is the third line, giving the board independent assurance that the first two are doing their jobs. The COSO/ACFE Fraud Risk Management Guide, second edition (May 2023), is written for management and the board rather than for auditors. It elaborates COSO 2013 Principle 8, the requirement to consider the potential for fraud when assessing risks to objectives, into five fraud risk management principles with points of focus, and those five principles are the criteria you audit against. When the audit committee asks whether the company manages fraud risk well, the honest answer is a rating against each principle with evidence behind it, not a count of the frauds you personally found.

The Global Internal Audit Standards, effective 9 January 2025, carry fraud in three places. Standard 3.1 (Competency) expects the function collectively to hold competencies for pervasive risks such as fraud. Standard 4.2 (Due Professional Care) and Standard 13.2 (Engagement Risk Assessment) both require internal auditors to consider the probability of significant errors, fraud, noncompliance, and other risks that might affect objectives, operations, or resources, in every engagement rather than only the fraud-themed ones. The glossary defines fraud as any intentional act characterized by deceit, concealment, dishonesty, misappropriation of assets or information, forgery, or violation of trust, perpetrated to secure an unjust or illegal advantage, which covers a driver’s skim and a CFO’s reserve release alike. The IIA’s Global Practice Guide Internal Auditing and Fraud (third edition, 2024) and its 2019 position paper Fraud and Internal Audit hold the older line: you are not expected to have the expertise of someone whose primary job is detecting and investigating fraud, but you must recognize red flags and evaluate how the organization manages the risk. Standard 4.3 (Professional Skepticism) is the disposition that makes the rest work, and the one most often missing when a fraud turns out to have run through three audit cycles.

The 2026 Report to the Nations should shape how you allocate hours. Tips surfaced 43 percent of cases and 55 percent of those tips came from employees; internal audit detected 15 percent and management review 13 percent. Organizations with a formal reporting mechanism showed a median loss of $100,000 and a median duration of 11 months, against $150,000 and 17 months without one. Asset misappropriation appeared in 90 percent of cases (median loss $100,000), corruption in 45 percent (median $150,000), and financial statement fraud in 6 percent but with a median loss of $1 million. Your own detection work matters; the larger lever is assurance over the channel that produces the 43 percent and over the analytics and reconciliations that shorten duration. The table turns the five principles into a program you can run as a standalone review or fold into entity-level controls work.

COSO/ACFE principle (2023 edition)What management should be able to showWhat internal audit testsEvidence to request
1. Fraud risk governanceBoard-approved policy with a named executive owner; code of conduct defining fraud and the duty to report; annual conflict-of-interest and code attestations; board oversight on a calendar.Policy reviewed within 24 months; owner has authority and budget; attestation completion above 98 percent with follow-up; fraud on the committee agenda at least annually.Policy with approval date; ethics committee charter; attestation completion by unit; committee minutes.
2. Fraud risk assessmentScheme-level assessment refreshed annually and on trigger events (acquisition, ERP change, leadership change, layoffs), with likelihood, significance, existing controls, residual risk, and a response per scheme.Schemes rather than categories; process owner participation; management override and third-party collusion covered; cross-references to the RCM; last year’s frauds changed the scores.Assessment workbook; workshop attendance; heat map; change log versus prior year.
3. Fraud control activitiesPreventive and detective controls mapped to every scheme above appetite; segregation of duties enforced in the ERP; analytics run on a cadence with exceptions dispositioned.Mapping completeness; design and operating effectiveness; SoD ruleset coverage; whether detective controls are performed by someone who could not commit the scheme.RCM with fraud-control flag; SoD conflict report; analytics run logs with dispositions; reconciliation sign-offs showing preparer and reviewer.
4. Fraud investigation and corrective actionWritten investigation protocol; case management; defined roles for legal, HR, security, and internal audit; root-cause analysis; corrective action tracking; disclosure decision tree.Protocol followed on a sample of closed cases; intake to triage within two business days; legal holds issued; corrective actions validated; required disclosures made.Case log; sample case files; legal-hold notices; corrective action tracker; disclosure log.
5. Fraud risk management monitoringProgram metrics (report volume, substantiation rate, days to close, analytic hit rates, training completion); periodic scorecard against the five principles; changes after incidents.Metrics produced, reported, and acted on; scorecard completed from evidence rather than self-assessed optimism; post-incident reviews changed something.Quarterly metrics pack; completed COSO/ACFE scorecard; post-incident review memos; training completion by role.

Scope the program review tightly, because the natural drift of any fraud engagement is toward “and also look for fraud.” The model language below goes in the planning memo.

Objective. To assess whether the fraud risk management program is designed and operating in line with the five principles of the COSO/ACFE Fraud Risk Management Guide (second edition, 2023), and whether the FY26 fraud risk assessment identifies the schemes to which the organization is most exposed and maps them to controls that would prevent or detect them within one reporting period.

Scope. The policy, the FY26 fraud risk assessment, the anti-fraud controls mapped to schemes above appetite in procure-to-pay, payroll, cash receipts, and financial close, the reporting channel and case management process, and the metrics reported to the audit committee. The engagement does not investigate any specific allegation; allegations identified during fieldwork are referred under the investigation protocol.

Criteria. COSO/ACFE Fraud Risk Management Guide (2023) principles and points of focus; COSO Internal Control–Integrated Framework (2013) Principle 8; the fraud risk management policy approved 14 March 2025; Global Internal Audit Standards 4.2 and 13.2.

The fraud scheme catalog: 26 schemes, red flags, detective analytics

A fraud risk assessment that lists “procurement fraud” as a risk is a category label, not an assessment. The unit of analysis is the scheme: who does what to which record, and how the money or the asset leaves. The 2023 edition of the COSO/ACFE guide expanded its scheme list considerably, and the ACFE publishes a free “Fraud Risk Exposures” list and a free “Library of Anti-Fraud Data Analytics Tests” alongside it; download both before a scheme workshop. The catalog below is the version I use with process owners: 26 schemes across six processes, each with the red flag you can see in data or documents and the detective analytic that would have found it, meaning the test you can run against the ERP tables rather than a sentiment about vigilance. The preventive control for each row follows from the scheme’s subject: whoever is named cannot be the reviewer, which is why segregation of duties does most of the preventive work and the ERP SoD analysis is the first data set you pull.

ProcessSchemeRed flag (what you see)Detective analytic (what you run)
Procure-to-payShell vendor set up by an employeeHome or mailbox address; no tax ID or one matching an employee; sequential invoice numbers; services only.Vendor master matched to employee master on address, bank account, phone, and tax ID; vendors with under three invoices and no PO.
Procure-to-payPayment diversion through a vendor bank change (email compromise or insider)Remit-to changed shortly before a large payment; request by email; new bank abroad or a consumer bank.Bank changes within 30 days before a payment above $25,000; changes with no logged call-back to the number on file; one bank account on two vendors.
Procure-to-payDuplicate or re-submitted invoicesSame vendor and amount within days; invoice number differs by a suffix, leading zero, or dash.Fuzzy match on vendor, amount, and date within seven days with invoice numbers normalized.
Procure-to-paySplit purchases under the approval thresholdMany POs to one vendor from one requester just under the limit, often the same day.POs at 90 to 99 percent of the requester’s limit by requester and vendor; cumulative 30-day spend per pair against the limit.
Procure-to-payKickbacks and bid riggingSole-source awards concentrated with one buyer; prices drifting above market; the same losing bidders; winner just under the runner-up.Unit price trend by vendor against peers; sole-source rate by buyer; vendor share of spend by buyer; bids within 2 percent of second place; conflict-of-interest declarations matched to vendor ownership.
Procure-to-payPersonal purchases on purchasing cardsWeekend and holiday transactions; consumer retailers; amounts just under the single-transaction limit.Merchant category screening; weekend transactions; transactions at 90 to 100 percent of the limit; same merchant on card and expense claims (see the purchasing card guide).
Procure-to-payInflated or fictitious service invoicesServices vendor with no deliverable on file; approver is the requester; approval within minutes of receipt.Service invoices with no PO or receipt record; approver equals requester; approval minus receipt timestamp under five minutes.
Procure-to-payContractor overbilling on hours or ratesRates above the contract rate card; one named consultant billing over 60 hours a week across invoices.Rate compliance against the contract table; hours per named individual per week summed across all invoices.
PayrollGhost employeesNo benefit elections; no vacation ever taken; bank account or address shared with another employee; no badge or logon activity.Payroll master against HR master against badge and logon logs; duplicate bank accounts and addresses; no timekeeping and no benefits.
PayrollTerminated employees still paidPayments dated after termination, often to an account changed shortly before.Payments after termination date; final-pay lag over one cycle; bank changes within 60 days of termination.
PayrollFalsified hours and overtimeOvertime always at the cap; supervisor approves own time; identical punches across a crew.Overtime by employee against department distribution; approver equals employee; punch edit rate by supervisor.
PayrollUnauthorized rate or bonus changesRate changed by a payroll clerk with no HR action; off-cycle payments created and approved by one user.Rate changes with no matching HR action; off-cycle payments by creator; master change log by user (the payroll audit guide has the full set).
Cash receiptsSkimming (sales never recorded)Cash share of receipts falls at one location or route while peers hold; margin by route below peers; shrink tracks the cash ratio.Cash-to-total-receipts ratio by location or driver over 24 months; margin by route; shrink by route against cash ratio.
Cash receiptsLapping of customer paymentsComplaints about late posting; credits posted to accounts other than the remitter; unapplied cash aging.Days from deposit to customer credit by collector; credits applied to a customer other than the remitter; unapplied cash over seven days.
Cash receiptsFictitious credit memos and write-offs to conceal skimmingCredits issued by the collector; round amounts; clustered near period end on accounts with recent receipts.Credit memos by user against approvals; credits to accounts with a receipt in the prior 30 days; volume per user against the peer median.
Cash receiptsDeposit manipulation (recorded but never fully deposited)Book and bank deposits disagree on date or amount; deposits in transit aged over two business days.Book-to-bank deposit match on date and amount from the bank feed; deposits-in-transit aging.
Travel and expenseFictitious or altered receiptsReceipt-generator templates; the same merchant at the same amount repeatedly; edited PDFs.Duplicate receipt image hash across claims; amounts just under the receipt threshold; merchant frequency by employee; PDF metadata (see the travel and expense guide).
Travel and expenseMileage and per-diem paddingMileage above map distance; per diem on days with hotel-provided meals or no travel.Claimed against calculated route distance; per diem against travel dates and calendar; overlapping trips.
Travel and expenseDouble dipping (card and expense claim for one item)Same amount and merchant in the card feed and in a reimbursed claim.Card transactions cross-matched to claims on merchant, amount, and date within three days.
Financial reportingTop-side entries to inflate revenue or hide expenses (management override)Manual entries at quarter end by senior finance; round amounts; revenue against receivable with no cash; reversals after the period.Manual entries by preparer seniority and timing; round amounts; unusual account pairs; post-period reversals; entries outside business hours (see journal entry testing).
Financial reportingPremature revenue, bill-and-hold, channel stuffingShipments spike in the last three days; credits spike the next month; side letters.Revenue by day of period; next-period credit memos by customer; DSO trend; cut-off tests on the last and first five days.
Financial reportingEstimate and reserve manipulationReserves move opposite to their drivers; releases land in quarters that would otherwise miss.Reserve roll-forward against driver metrics (aging, claims, returns); release timing against targets.
Financial reportingImproper capitalization of expensesRepairs and IT run costs capitalized; additions described as “maintenance”; no project record.Capital additions by account against prior periods; maintenance-type descriptions; additions without a project ID.
Financial reportingConcealed liabilities and held invoicesInvoices received before period end and posted after; accruals fall while spend rises.Subsequent disbursements search; receipt-date to posting-date lag by period; accruals against purchase commitments.
InventoryTheft concealed by count adjustmentsShrink adjustments by the same user within 48 hours of a count; high-value SKUs over-represented.Adjustments by user and reason code; shrink by location against peers; adjustments within 48 hours of a count.
InventoryFictitious inventory to inflate assetsInventory in locations never counted; large aging in-transit balances; turnover far below peers.Book-to-count reconciliation by location; in-transit aging; turnover by location.

Two habits make the catalog useful rather than decorative. Write each scheme in the assessment as a sentence with a subject: “a depot clerk alters the deposit listing” beats “deposit fraud” because the subject tells you which segregation matters and who cannot be the reviewer. And keep the analytic column honest about data: if the handheld sync log does not exist, the analytic on invoice edits is a wish, and the assessment should record that as a control gap. The vendor master audit guide covers the other data set you will need most often once you move from the catalog to testing.

The fraud risk assessment method and scoring rubric

The method is six steps, and the order matters because the common corruption of the process is to score residual risk first and back-fill the rest. Step one is scope: the processes and legal entities in play, including the ones nobody wants to discuss (the acquired subsidiary on its own ledger, the joint venture run by a partner’s finance team). Step two is scheme identification, a 90-minute workshop per process with the process owner, one front-line supervisor, and the auditor, seeded with the catalog; the auditor’s job in the room is to ask “how would you do it if you wanted to” until the list stops growing. Step three scores each scheme’s inherent likelihood and significance before controls, using the anchors below, which forces the conversation about how bad it gets if the one reconciliation stops happening. Step four identifies the existing controls per scheme and rates them from evidence, meaning a walkthrough or a recent test rather than a policy document. Step five computes residual risk. Step six assigns a response, an owner, and a date, which is the step that makes the workbook management’s document rather than internal audit’s.

ScoreLikelihood anchor (inherent, before controls)Financial significance (calibrated to a $220 million revenue company)Non-financial significance
1 RemoteNo known occurrence in the industry in five years; needs collusion among three or more people with different access.Below $10,000 in a year.No impact outside the department.
2 UnlikelyPlausible but not seen here; needs two colluders or privileged system access.$10,000 to $50,000.Internal disruption only.
3 PossibleHas occurred at industry peers; one person with normal access could do it.$50,000 to $250,000.Customer or vendor relationships damaged; local press; lender questions.
4 LikelyHas occurred here within five years, or repeatedly at peers; single actor with weak oversight.$250,000 to $1 million.Regulatory inquiry; covenant reporting; restatement risk at an account level.
5 Almost certainHas occurred here within 12 months or is believed ongoing; the opportunity is open to many people.Above $1 million, or any misstatement requiring a restatement.Enforcement action, license loss, delisting, or executive departures.

Inherent risk is likelihood times significance, a range of 1 to 25. Existing controls are rated on four levels and applied as a multiplier: Strong (designed against this scheme, automated or performed by someone independent of the actor, tested effective within 12 months) at 0.25; Adequate (designed against the scheme, manual, evidence of operation but not tested within 12 months) at 0.50; Weak (a control exists but has known design gaps or an exception rate above 5 percent) at 0.75; Ineffective or none (no control, or the control is performed by the person who could commit the scheme) at 1.00. Residual risk is inherent times the multiplier, rounded. The response follows from the residual score: 12 to 25 is Act (management remediation with a date, an engagement in the current plan, a monthly analytic); 6 to 11 is Monitor (a quarterly analytic and coverage in the next plan cycle); 1 to 5 is Accept (a key risk indicator and the annual refresh). The arithmetic is a ranking device, not a measurement, and the workbook should say so; its value is that two people who disagree about a scheme end up arguing about likelihood, significance, or control evidence rather than the color of a cell. Tie the bands to the risk appetite statement where one exists, and feed the Act rows into the internal audit risk assessment so fraud exposure shapes the plan. The template below is the row structure; management owns the completed workbook, internal audit facilitates and challenges, and the fields export cleanly into the risk and control matrix.

Process and entity. [Process; legal entity or location; system of record.] Scheme. [Who does what to which record, and how the money or asset leaves. One scheme per row.]

Fraud triangle notes. [Pressure: what would motivate this actor. Opportunity: which access or gap makes it possible. Rationalization: what the actor would tell themselves.]

Inherent likelihood (1–5) and significance (1–5). [Scores with a one-line basis citing the anchor.] Inherent score. [Likelihood × significance.]

Existing controls. [Control ID; preventive or detective; performer; frequency; date last tested and result; evidence reviewed for this assessment.] Control rating and multiplier. [Strong 0.25 / Adequate 0.50 / Weak 0.75 / Ineffective 1.00, with supporting evidence.] Residual score. [Inherent × multiplier, rounded.]

Response, owner, due date. [Act / Monitor / Accept; named owner; date; the specific control change.] Detective analytic. [Test, data source, cadence, who works exceptions.] Last refreshed. [Date and trigger.]

Worked example: scoring MidState Beverage’s route cash cycle

MidState Beverage is a three-state distributor with roughly $220 million in revenue, 12 depots, 300 delivery routes, and about 4,200 smaller customers who pay drivers in cash or checks, about $31 million a year or 14 percent of revenue. Route accounting runs on a 2013 ERP module plus depot spreadsheets, two recently acquired distributors are not yet on the ERP, and internal audit has six people. In FY26 a Dayton driver diverted $18,400 over five months before a customer complaint exposed it. The FY27-01 route cash report was rated Unsatisfactory with five findings: settlement reconciliations not independent at 9 of 12 depots; variance overrides self-approved in 1,412 of 37,400 settlements; handheld sync failures unmonitored; deposit listings re-keyed outside the ERP at 7 depots; and 1,130 of 4,200 customers receiving no monthly statement. The table is the cash receipts section as re-scored at the FY27 plan refresh, using those findings as control evidence; it is management’s document, facilitated by internal audit, and every control rating cites a finding or a walkthrough.

#Scheme (who does what)LSInherentExisting controls and evidenceRatingResidualResponse and owner
1A driver skims cash collections and covers the shortfall by lapping later receipts across route customers.5315Settlement reconciliation not independent at 9 of 12 depots; 1,130 customers get no statement; overrides self-approved.Ineffective 1.0015Act. Independent settlement at all depots by Q2 FY27; statements to 100 percent by Q3; weekly days-to-apply analytic by driver. VP Operations with the Controller.
2A depot clerk alters the re-keyed deposit listing and keeps the difference between cash counted and cash deposited.4416Bank reconciliation prepared by the depot manager who also approves the listing; 7 depots re-key outside the ERP.Ineffective 1.0016Act. Daily bank feed match to ERP deposits by treasury; re-keying eliminated. Controller, Q2 FY27.
3A depot manager self-approves variance overrides to hide a personal or a favored driver’s shortage.4312Override workflow lets the creator approve (1,412 of 37,400 settlements).Ineffective 1.0012Act. Overrides routed to regional finance; weekly override report by approver. CFO, Q1 FY27.
4A driver uses handheld sync failures to void or reduce invoices after delivery and before upload.3412None operating; sync failures not logged or reviewed.Ineffective 1.0012Act. Sync exception log reviewed daily; invoice sequence gap and post-sync edit analytic. IT Director, Q2 FY27.
5Drivers or clerks skim at the two acquired distributors, which settle manually outside the ERP.4416Legacy manual settlement; no internal audit coverage since acquisition; controls unknown.Ineffective 1.0016Act. Acquisition integration engagement in the FY27 plan; quarterly surprise cash counts meanwhile. CFO with the integration lead.
6A driver or clerk issues fictitious credit memos to clear balances that were skimmed.4312Credits above $500 approved by the depot manager, who is not independent of settlement; credits below $500 unapproved.Weak 0.759Monitor. Monthly credit memo analytic by user and customer; approval moves to regional finance in Q3. Controller.
7A driver swaps customer checks for cash and deposits the checks to a personal account.326Checks restrictively endorsed and imaged at the depot; tested FY26, no exceptions.Adequate 0.503Accept. Annual re-test.
8A sales representative grants unauthorized discounts or free goods in exchange for kickbacks.339Price override report reviewed monthly by the sales manager with sign-off; not tested within 12 months.Adequate 0.505Accept. Discount rate by representative as a key risk indicator; next order-to-cash audit.
9A driver and a customer collude: full delivery, partial invoice, difference split.236Daily route reconciliation of load-out against invoiced and returned product, on spreadsheets at most depots.Weak 0.755Accept, with a monthly route shrink analytic. VP Operations.
10A sales administrator creates fictitious customers to move product off route without a sale.248Customer creation needs a credit check and credit manager approval; change log reviewed quarterly.Adequate 0.504Accept. Customer master test in the annual data integrity work.

The scores a process owner will push back on deserve their reasoning. Scheme 1 is a 5 on likelihood because it happened within 12 months, and a 3 rather than a 4 on significance because one route collects roughly $103,000 a year ($31 million across 300 routes), so even a two-year skim on a large route lands in the $50,000 to $250,000 band; it would be a 4 if drivers rotated routes or lapping could spread across depots. Scheme 2 carries the highest residual even though nothing has been found, because a depot handles about $2.6 million in cash a year and the person who re-keys the listing also prepares the reconciliation, which is the configuration that produces multi-year losses. Scheme 5 gets the same treatment on the rule that an acquired business with manual settlement and no coverage is scored as ineffective until someone has looked. Schemes 7, 8, and 10 are accepted not because they are impossible but because a tested or evidenced control exists and the exposure per incident is bounded; recording the accepted schemes means nobody can later say they were never considered.

The “so what” for the committee is arithmetic it can follow. The Dayton driver took about $3,680 a month; if three of 300 routes ran a similar scheme for a year, the loss is about $132,000, above the 2026 median of $104,000 and invisible under FY26 controls. Five of the ten schemes score in the Act band, and all five trace to one root cause: the detective control sits with someone who could commit the scheme. That sentence is the summary the committee needs, and it is why the FY27 plan carries the route cash handling, acquisition integration, and ERP user access engagements rather than three “fraud reviews.” The audit plan template shows how an Act-band scheme becomes a planned engagement with hours attached.

Turning the catalog into a detection program

Every Act and Monitor row names a detective analytic, and the detection program is that set of analytics run on a cadence with a named person working the exceptions. The ownership split matters here more than anywhere: management runs the monitoring because detection is a first-line control, and internal audit periodically re-performs a subset on its own extract to confirm the run is honest, which keeps the function from becoming the company’s fraud detection department and losing the independence it needs to report on the program (the continuous auditing versus continuous monitoring guide sets out the split). MidState’s suite came straight out of the cash receipts assessment: six tests, all runnable from the settlement tables, the AR module, the bank feed, and the handheld logs, each with an expected exception rate so the reviewer knows when the analytic is broken rather than the business.

AnalyticCadenceRule or thresholdExpected exception rateWho works exceptions
Days-to-apply and unapplied cash by driverWeeklyReceipt applied more than three days after deposit; unapplied cash above $2,000 for one driver.2 to 4 percent of drivers; three weeks running is escalated.Regional finance analyst.
Variance overrides by approverWeeklyAny override approved by its creator; more than two overrides for one driver in a week.Zero self-approvals after the Q1 workflow change.Controller.
Credit memos by user and customerMonthlyCredits above $250 to a customer with a receipt in the prior 30 days; any user above three times the peer median.1 to 2 percent of credit memos.AR supervisor.
Book-to-bank deposit matchDailyAny deposit unmatched on date and amount after one business day.Under 0.5 percent once re-keying ends.Treasury analyst.
Invoice sequence gaps and post-sync editsDailyAny sequence gap; any edit or void after sync; any sync failure not cleared in 24 hours.About 1 percent of invoices at first, falling as devices are replaced.Depot operations lead; IT for device faults.
Statement coverage and dispute agingMonthlyAny active customer without a statement; any dispute open more than 14 days.Coverage exceptions to zero by Q3; disputes 3 to 5 percent of statements.AR supervisor.

Two design rules keep a suite alive past its first quarter. The exception must go to someone who cannot have caused it, which rules out the depot manager for four of the six tests, and the disposition must be recorded so that internal audit can test it: the exception, the person, the explanation, the evidence, and the date. When you audit the program, sample 25 dispositions per analytic, re-perform the explanation against source, and treat an unsupported “timing difference” as a failure of the control. The sample size guide explains why 25 fits a monthly control with a low expected deviation rate, and the user access review guide covers the companion test: whether the people who can post credit memos, approve overrides, and edit deposits are the people the design says they are.

The investigation protocol and the boundary with legal and HR

The first 72 hours after an allegation decide whether evidence survives, whether the company keeps privilege, and whether the subject is tipped off. In the Dayton case the customer’s complaint went to the depot manager, who confronted the driver that afternoon; the driver resigned, the handheld was reissued the next morning, and the settlement spreadsheets for the prior five months had been overwritten before anyone in finance heard about it. The $18,400 was reconstructed from customer statements and is probably a floor. The protocol below is the one MidState adopted afterward, written for a company without an investigations unit: the General Counsel chairs triage, and internal audit supplies process knowledge and data rather than leading anything that involves management, financial reporting, or a regulator.

PhaseTrigger or decisionWho does whatEvidence handlingReporting
1. Intake (day 0)Hotline report, unexplained analytic exception, auditor observation, customer or vendor complaint, external notice.Hotline administrator logs a case ID within one business day; General Counsel and CAE notified of anything involving management, financial reporting, a regulator, or more than $10,000. Nobody confronts the subject.Original report preserved as received; not forwarded beyond the triage panel; reporter identity protected.Case log entry; committee chair told within 24 hours if senior management is implicated.
2. Triage (within two business days)Credibility, who is implicated, legal exposure, who investigates.Panel of General Counsel (chair), CAE, CHRO, and Chief Compliance Officer decides whether internal audit, legal, or an outside forensic firm leads and whether the work is counsel-directed.Legal hold issued; IT preserves mailboxes, file shares, and logs without reviewing them; physical records secured.Triage memo, privileged where counsel-directed; a decision not to investigate is documented with reasons.
3. Investigation planHypotheses, data, interviewees, timeline, budget, reporting line.Lead investigator drafts; General Counsel approves; internal audit supplies walkthroughs, control documentation, and extracts from systems it has already mapped.Chain-of-custody log opened; devices imaged by IT security or the outside firm; originals sealed, working copies used.Plan in the privileged file; CAE records audit staff assigned and independence safeguards.
4. Fact-findingDocument review, data analysis, confirmations, bank records.Investigator leads; internal audit runs targeted analytics on preserved data and records what each test shows and does not show; HR advises on employment law.Hash values recorded for every extract; bank records by consent or subpoena; originals never annotated.Weekly status to the General Counsel; no written conclusions until facts are complete.
5. InterviewsWitnesses first; the subject last, once the documentary case is assembled.Two interviewers, one taking notes; HR present for employee subjects; Upjohn warning where counsel-directed; no promises of confidentiality or immunity.Contemporaneous notes signed and dated by both interviewers; recording only where law and policy allow.Interview memoranda in the privileged file.
6. ConclusionFindings of fact, loss quantification, control failures.Investigator drafts findings; General Counsel reviews; internal audit quantifies the loss and writes the control failure analysis separately from culpability.Evidence inventory finalized and retained under the hold.Report to the CEO and committee as decided at triage; the committee sees every substantiated case involving management or above $10,000.
7. Corrective actionDiscipline, recovery, referral, control redesign.HR handles discipline; General Counsel decides on referral and notifies the crime insurer within the policy window; Controller redesigns the control; CAE validates the fix within 90 days.Evidence retained until the General Counsel lifts the hold.Corrective action tracker; committee follow-up at the next meeting.
8. Disclosure decisionsExternal auditor, regulators, lenders, insurers, law enforcement.General Counsel decides with the CEO and committee chair; CAE ensures the external auditor is told of any fraud involving management or affecting internal control over financial reporting.Disclosure packages built from the evidence inventory, not working notes.Disclosure log with dates, recipients, and what was provided.
9. Lessons learned (within 30 days)Root cause, horizontal exposure, assessment refresh.CAE facilitates; process owner presents the redesigned control; assessment re-scored and catalog updated.Anonymized case summary retained for training.Summary to the committee with the updated assessment row.

Write the boundary into the internal audit charter and the fraud policy rather than negotiating it case by case. Standard 2.1 (Individual Objectivity) and Standard 2.2 (Safeguarding Objectivity) require the CAE to identify and manage threats to objectivity, and an auditor who led the investigation of a process is impaired for assurance over its remediation. Standard 5.2 (Protection of Information) is the other constraint: investigation files are the most sensitive records the function will hold, and the conventions in the workpaper example do not apply to them, because privileged material lives in counsel’s file. The model language below has held up in several charters; adapt it with the charter guide before the next allegation rather than during it.

Internal audit’s role in investigations. Internal audit does not lead investigations of allegations involving a member of senior management, the integrity of financial reporting, or a matter reportable to a regulator; such investigations are directed by the General Counsel, who may engage outside counsel or forensic specialists. Internal audit may lead fact-finding into alleged misappropriation of assets where no member of management is implicated and the estimated amount is below $50,000, under the direction of the General Counsel and with the concurrence of the audit committee chair.

Support role and independence safeguards. In all investigations internal audit will, on request, provide process and control documentation, data extracts and analytics, quantification of loss, and an analysis of control failures, reported separately from findings of fact regarding individual culpability. Internal audit staff who perform investigative procedures on a process will not provide assurance over the remediation of that process for 12 months, and the chief audit executive will disclose to the audit committee any investigation in which the function’s objectivity may be impaired and the safeguards applied.

Reporting. The chief audit executive will report to the audit committee at least quarterly the number and nature of matters referred under the investigation protocol, their status, substantiated losses and recoveries, and the control changes made.

Reporting fraud risk to the audit committee

Audit committees hear about fraud in two registers, and mixing them is the reporting failure I see most often. The first is the annual program report: does the company manage fraud risk well, where is it exposed, what changed. The second is the case register: what was alleged, found, lost, and fixed. The annual report belongs on the agenda once a year with an hour attached; the case register belongs on every quarterly agenda as a one-page metrics sheet with a short verbal summary from the General Counsel and the CAE. Standard 11.3 (Communicating Results) obliges the CAE to bring significant matters to the board, and a substantiated fraud involving management is always one. The outline below is the annual report; the table after it is the quarterly page with MidState’s Q1 FY27 numbers, and it fits on one side of a sheet, which is the point.

1. Program status. Rating against each of the five COSO/ACFE principles (effective, partially effective, ineffective) with the evidence basis in one line each and the change from last year.

2. Fraud risk assessment results. The ten highest residual schemes company-wide, the processes with the most Act-band rows, schemes that moved between bands and why, and any process not yet assessed, named.

3. Detection. Reporting channel volume and mix, substantiation rate, median days to close, analytics in production with exception dispositions, and any detection that came from outside the company.

4. Investigations and outcomes. Cases by category (misappropriation, corruption, financial reporting, other), substantiated losses, recoveries and insurance claims, discipline and referrals, and any case involving management.

5. Control failures and remediation. Root cause for each substantiated case, the control redesign, the validation date, and the horizontal check performed.

6. Emerging schemes. Payment diversion through impersonated vendors, synthetic invoices, deepfake voice requests for bank changes, and the control response to each.

7. Internal audit coverage. Which Act-band schemes are covered by planned engagements, which by management monitoring only, and which are uncovered, with hours attached.

8. Decisions requested. Approval of the appetite thresholds, budget for analytics or a forensic retainer, and any policy change such as an investigation protocol amendment.

Quarterly metricQ1 FY27 value (MidState)Trend versus Q4 FY26Comment for the committee
Reports received (hotline, web, email, direct)11, or 1.2 per 100 employeesUp from 6Follows the Dayton communication and driver briefings; a rise after a publicized incident is expected and healthy.
Substantiated cases3 of 9 closedFlatTwo policy breaches (expense, conflict of interest); one route shortage under $1,000 resolved as error.
Median days from intake to closure34Down from 51Triage within two business days in 10 of 11 matters; the exception waited for outside counsel.
Open investigations at quarter end2Down from 3Neither involves management; both under $10,000 estimated.
Substantiated losses and recoveries, year to date$18,400 loss (FY26 Dayton); $6,000 recovered under the crime policy after deductiblen/aInsurer notified 41 days after discovery, inside the policy window; restitution agreement covers the balance over 24 months.
Analytics exceptions raised and dispositioned212 raised; 198 closed; 14 open over 30 daysFirst quarter of the suiteAll 14 aged items sit in the credit memo test at two depots; regional finance is clearing them.
Self-approved settlement overrides0 in the last six weeks (1,412 in the FY27-01 sample period)FixedWorkflow change validated by internal audit on 30 overrides.
Customers without a monthly statement612, from 1,130ImprovingRemaining customers sit at the two acquired distributors; target zero by Q3.
Act-band schemes in the fraud risk assessment5 in route cash; 9 company-wideFirst full scoringAll 9 have an owner and a date; 4 covered by FY27 engagements, 5 by management monitoring only.
Anti-fraud training completion91 percent of managers; 78 percent of staffUp from 64 and 40Drivers complete in person at depot meetings; two depots remain.

Say hard things plainly. A sentence that has worked: “Management’s fraud risk assessment rates route cash as medium; ours rates five schemes in the Act band, and the difference is not judgment but control evidence, because nine of twelve depots have no independent settlement reconciliation.” Another: “We did not find this fraud; a customer did, and 1,130 customers were not receiving the statement that would have let more of them find it sooner.” The finding severity ratings guide sets out how an Unsatisfactory rating is earned, and the report template shows where fraud risk context goes in an engagement report so it reads as assurance rather than accusation.

Testing anti-fraud culture and the whistleblowing channel

The reporting channel is the most valuable detective control in the company on the ACFE’s evidence, and the one internal audit most often leaves untested because it feels like a compliance matter. The 2026 Report to the Nations found that organizations with fraud awareness training for both staff and managers had a median loss of $84,000 against $150,000 without, that 84 percent of perpetrators had displayed at least one behavioral red flag, and that web-based reporting (46 percent of tips) has overtaken telephone hotlines (23 percent) as the channel employees use. For US-listed companies, Sarbanes-Oxley section 301 requires the audit committee to establish procedures for confidential, anonymous submission of concerns about accounting and auditing matters; EU entities with 50 or more employees fall under Directive (EU) 2019/1937 and its national transpositions, which prescribe acknowledgment and feedback deadlines. Culture is harder to test than a channel but not untestable; the tests below produce evidence rather than impressions, and the ethics domain of the Standards gives the function its own footing for reporting uncomfortable results.

TestProcedureEvidenceWhat a pass looks like
The channel worksSubmit a test report through each channel (web, email, telephone, a manager) with a distinctive phrase and trace it to the case log.Case log entries; acknowledgment timestamps.Every test report reaches the log within one business day with identity protected as designed.
People know it existsAsk 30 employees across sites during fieldwork how they would report a concern and whether they could do so anonymously.Interview notes; onboarding checklist; site notices.At least 25 of 30 name a channel correctly; drivers and warehouse staff score no worse than office staff.
Triage is independent and timelySample 25 closed matters; check who triaged, whether anyone implicated took part, and the intake-to-triage interval.Case files; triage memos.No conflicted triage; 90 percent within two business days; every non-investigation decision has written reasons.
Retaliation is watched forMatch known reporters against adverse HR actions in the following 12 months: rating changes, transfers, terminations.HR action log; case log.Every adverse action for a known reporter was reviewed by the General Counsel before it took effect.
Closures are supportedRe-perform the conclusion on 10 closed cases from the evidence in the file.Case files; evidence inventories.All 10 supported; no case closed on the subject’s explanation alone.
Attestations mean somethingTest conflict-of-interest declarations against vendor ownership records and the employee master for 40 buyers and approvers.Declarations; vendor master; state business filings.No undisclosed interests; non-responders followed up within 30 days.
The board sees the numbersCompare the quarterly metrics reported to the committee with the case log for the same period.Committee packs; case log.Counts reconcile; every management-implicated matter appears.

Behavioral red flags belong here rather than in the analytics section because colleagues see them and systems do not. Living beyond means and unusually close relationships with vendors or customers are the two the ACFE reports most consistently, and the company’s only realistic detective control for them is a workforce that knows what to do with the observation. The fraud red flags reference lists the indicators by scheme; the test that matters is whether the manager who notices a driver’s new truck knows the channel is for that kind of concern too.

After a fraud: lessons learned and control redesign

The post-incident review is where a fraud pays for itself, and it should happen within 30 days of closing the case, while the facts are fresh and before the process owner has rewritten the story. Root cause is a choice among five options, and naming the right one determines the fix: the control was missing; the control existed but was not performed; the control was performed by a person who could commit the scheme; the control was designed for a different scheme than the one that ran; or the control was overridden by someone with authority. In the Dayton case the answer was the third option twice (the settlement reconciliation and the variance approval both sat inside the process) plus a missing control (statements to 27 percent of customers). The redesign rules follow from the taxonomy: move the detective control out of the actor’s reach, shorten the detection window (a weekly analytic replaces a monthly reconciliation), and add the specific analytic that would have caught this scheme in month one, which for Dayton was days-to-apply by driver.

The step most often skipped is the horizontal check: was this one route, or every route. MidState ran the days-to-apply and unapplied cash analytics across all 300 routes for the prior 24 months before closing the Dayton case; four routes showed patterns worth a look, two were explained by a depot’s habit of batching applications on Fridays, and two closed as process error once the receipts were traced. That work took a senior auditor nine days, and it is why the committee accepted the FY27-01 rating without arguing that Dayton was an isolated event. The remaining tasks are administrative but consequential: the insurer notice inside the policy window, the restitution agreement drafted by counsel, the anonymized case in next year’s training, and the re-scored assessment row, which is how scheme 1 in the worked example acquired its likelihood of 5. The control deficiency evaluation guide covers the question the external auditor will ask within days: whether the control failure rises to a significant deficiency or material weakness for ICFR purposes.

Common failures in fraud risk management programs

These recur across programs that pass a documentation review, drawn from program assessments and from post-incident reviews where the paperwork looked fine. The table doubles as a self-check before the annual program report goes to the committee.

FailureWhat it looks likeWhy it mattersFix
Category-level assessment“Procurement fraud: high” and “payroll fraud: medium” with no schemes.Nothing maps to a control or an analytic, so the assessment cannot change what anyone does.Rewrite at scheme level from the catalog; require a subject in every scheme sentence.
Residual-first scoringEvery row lands at “low residual” because the scorer started from the belief that controls exist.Hides the schemes where one control failure produces a large loss.Score inherent risk first in the workshop; rate controls only from walkthrough or test evidence.
Detective control inside the processThe reconciliation, override approval, or credit memo review is performed by someone who handles the cash or the master data.This configuration produced the longest-running schemes in every program I have reviewed; the control detects nothing the performer chooses to hide.Move the review to regional or corporate finance; test performer identity, not just the sign-off.
Internal audit as the detection departmentThe plan is a series of “fraud reviews”; management runs no analytics because internal audit does.Detection becomes a third-line activity that cannot be assured, and management never owns its fraud risk.Transfer the analytics to management as monitoring controls; audit their operation and re-perform a subset.
Hotline untestedThe vendor’s annual summary is filed; nobody has submitted a test report or sampled closures.The channel that produces 43 percent of detections may be broken at intake, triage, or closure without anyone knowing.Run the seven channel tests annually; report results to the committee.
Confrontation before preservationA manager confronts the suspect on the day of the complaint; devices are reissued; spreadsheets overwritten.Evidence is lost, the loss cannot be quantified, recovery and prosecution fail.Protocol step 1: nobody confronts the subject; legal hold and imaging before any interview.
No horizontal checkThe case closes as an isolated incident without testing whether the same gap exists elsewhere.The scheme runs at other locations while the committee is told the problem was one person.Run the detective analytic that would have caught the scheme across every comparable unit for 24 months before closing.
Assessment never refreshed after an incidentThe process still shows “medium” a year after a substantiated fraud there.The plan and the monitoring suite rest on scores the facts have overtaken.Make re-scoring a mandatory close-out step; the committee sees the changed row.
Off-system units left outEntities not on the ERP are scored “not applicable” or omitted.They carry the weakest controls and the least visibility; MidState’s two acquired distributors score 16.Score off-system units as ineffective until walked through; schedule integration coverage in the plan.
Management override treated as theoreticalNo row for top-side entries, reserve manipulation, or an executive approving their own transactions.Financial statement fraud is 6 percent of cases with a median loss of $1 million, and the perpetrator can disable the controls.Add the financial reporting schemes from the catalog; run journal entry analytics with the audit committee as the reporting line.
Culpability and control failure written togetherThe investigation report names the driver and the control gap in the same paragraph.The control analysis gets caught in privilege and employment disputes and never reaches the process owner.Internal audit writes the control failure analysis as a separate document with its own distribution.

Adapting the approach

A one- or two-person function cannot run the full method every year and should not try. The version that works at that scale is to facilitate the scheme workshop for the two highest-cash processes, use the ACFE’s free risk assessment and follow-up action templates as the workbook so nothing has to be built, put a forensic firm on a modest retainer before it is needed, and settle the investigation boundary with the General Counsel while nobody is under suspicion. The small-company function guide covers the co-sourcing arithmetic; the fraud-specific point is that the small function’s most valuable output is the assessment and the channel tests, not the analytics, which the controller can run once they exist.

In financial services the fraud program overlaps with the anti-money-laundering and conduct programs, and the assessment should say which regime owns each scheme: internal misappropriation under the fraud program, customer-facing and third-party fraud under fraud operations, laundering under the BSA/AML program, with the overlaps (a banker opening accounts for a scheme, a loan officer’s fictitious borrower) assigned explicitly. Examiners will expect the assessment to reconcile to the operational risk taxonomy, where internal and external fraud are two of the seven Basel event types; the financial services audit guide works through the AML side. In the public sector and not-for-profits the procurement and payroll rows dominate, grant and eligibility schemes need adding, and a management-implicated matter often reports to a governing body or an inspector general rather than an audit committee, which changes protocol steps 1 and 8.

Acquisitions get their own rule, which MidState’s two off-ERP distributors illustrate: an acquired unit is scored as ineffective until someone has walked its controls through, and the integration plan carries a fraud risk assessment as a 90-day deliverable. Third-party schemes (vendor collusion, contractor overbilling, outsourced payroll and collections) come under the IIA’s Third-Party Topical Requirement, effective 15 September 2026, and the assessment should show which third parties handle cash, master data, or payments on the company’s behalf and what the company can see of their controls; the Third-Party Topical Requirement guide covers the mandatory coverage. AI-enabled fraud has changed the payment diversion row of the catalog more than any other: synthetic invoices that pass visual review, cloned executive voices requesting an urgent bank change, and fabricated email threads all attack the same control, and the response is unchanged and non-negotiable. Any change to where money goes is verified by a call to a number already on file, by a person who did not receive the request, with no exception for urgency; if the assessment does not rate that control’s operation from evidence, the row is not finished. The Risk Library holds the risk-by-risk primers, the Topics hub groups the process audit cluster, and the Tools page has the free sampler and RCM workbench that make the testing side of this guide faster.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading