A fraud does not announce itself in the general ledger. It arrives as a customer complaint about a balance that should have cleared months ago, a vendor whose remit-to bank changed nine days before a $240,000 payment, or a depot whose settlement variances are always approved by the person who created them. The ACFE’s Occupational Fraud 2026: A Report to the Nations (2,402 cases across 143 countries) puts the median loss at $104,000 and the median scheme duration at 12 months, and finds that 43 percent of schemes were first detected by a tip against 15 percent by internal audit. Those figures argue for treating fraud risk management as a system to be assessed rather than a hunt to be run: the company that finds a fraud in month four instead of month seventeen has built a reporting channel, an analytic, and a reconciliation that someone independent actually looks at, and internal audit’s leverage lies in testing whether those three things exist and work. MidState Beverage learned this the expensive way in FY26, when a Dayton depot driver diverted $18,400 over five months and the first person to notice was a customer.
This guide gives you the working method: a 26-row fraud scheme catalog by process with the red flag and the detective analytic for each scheme, a scored fraud risk assessment template with a worked assessment of MidState’s $31 million route cash cycle, an investigation protocol table that fixes the boundary between internal audit, legal, and HR, an audit committee reporting outline with a quarterly metrics page, and a failures table drawn from programs that looked complete on paper. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, the second edition of the COSO/ACFE Fraud Risk Management Guide (May 2023), and the 2026 Report to the Nations. It pairs with the site’s fraud red flags reference and the broader fraud risk primer; the analytics in the catalog are built step by step in the accounts payable, payroll, and journal entry analytics guides.
In this guide
- What internal audit owns in fraud risk management
- The fraud scheme catalog: 26 schemes, red flags, detective analytics
- The fraud risk assessment method and scoring rubric
- Worked example: scoring MidState Beverage’s route cash cycle
- Turning the catalog into a detection program
- The investigation protocol and the boundary with legal and HR
- Reporting fraud risk to the audit committee
- Testing anti-fraud culture and the whistleblowing channel
- After a fraud: lessons learned and control redesign
- Common failures in fraud risk management programs
- Adapting the approach
What internal audit owns in fraud risk management
The IIA Three Lines Model (2020) settles the ownership question. Management owns fraud risk and the controls over it; the roles that write the anti-fraud policy, run the hotline, and monitor compliance are second-line; internal audit is the third line, giving the board independent assurance that the first two are doing their jobs. The COSO/ACFE Fraud Risk Management Guide, second edition (May 2023), is written for management and the board rather than for auditors. It elaborates COSO 2013 Principle 8, the requirement to consider the potential for fraud when assessing risks to objectives, into five fraud risk management principles with points of focus, and those five principles are the criteria you audit against. When the audit committee asks whether the company manages fraud risk well, the honest answer is a rating against each principle with evidence behind it, not a count of the frauds you personally found.
The Global Internal Audit Standards, effective 9 January 2025, carry fraud in three places. Standard 3.1 (Competency) expects the function collectively to hold competencies for pervasive risks such as fraud. Standard 4.2 (Due Professional Care) and Standard 13.2 (Engagement Risk Assessment) both require internal auditors to consider the probability of significant errors, fraud, noncompliance, and other risks that might affect objectives, operations, or resources, in every engagement rather than only the fraud-themed ones. The glossary defines fraud as any intentional act characterized by deceit, concealment, dishonesty, misappropriation of assets or information, forgery, or violation of trust, perpetrated to secure an unjust or illegal advantage, which covers a driver’s skim and a CFO’s reserve release alike. The IIA’s Global Practice Guide Internal Auditing and Fraud (third edition, 2024) and its 2019 position paper Fraud and Internal Audit hold the older line: you are not expected to have the expertise of someone whose primary job is detecting and investigating fraud, but you must recognize red flags and evaluate how the organization manages the risk. Standard 4.3 (Professional Skepticism) is the disposition that makes the rest work, and the one most often missing when a fraud turns out to have run through three audit cycles.
The 2026 Report to the Nations should shape how you allocate hours. Tips surfaced 43 percent of cases and 55 percent of those tips came from employees; internal audit detected 15 percent and management review 13 percent. Organizations with a formal reporting mechanism showed a median loss of $100,000 and a median duration of 11 months, against $150,000 and 17 months without one. Asset misappropriation appeared in 90 percent of cases (median loss $100,000), corruption in 45 percent (median $150,000), and financial statement fraud in 6 percent but with a median loss of $1 million. Your own detection work matters; the larger lever is assurance over the channel that produces the 43 percent and over the analytics and reconciliations that shorten duration. The table turns the five principles into a program you can run as a standalone review or fold into entity-level controls work.
| COSO/ACFE principle (2023 edition) | What management should be able to show | What internal audit tests | Evidence to request |
|---|---|---|---|
| 1. Fraud risk governance | Board-approved policy with a named executive owner; code of conduct defining fraud and the duty to report; annual conflict-of-interest and code attestations; board oversight on a calendar. | Policy reviewed within 24 months; owner has authority and budget; attestation completion above 98 percent with follow-up; fraud on the committee agenda at least annually. | Policy with approval date; ethics committee charter; attestation completion by unit; committee minutes. |
| 2. Fraud risk assessment | Scheme-level assessment refreshed annually and on trigger events (acquisition, ERP change, leadership change, layoffs), with likelihood, significance, existing controls, residual risk, and a response per scheme. | Schemes rather than categories; process owner participation; management override and third-party collusion covered; cross-references to the RCM; last year’s frauds changed the scores. | Assessment workbook; workshop attendance; heat map; change log versus prior year. |
| 3. Fraud control activities | Preventive and detective controls mapped to every scheme above appetite; segregation of duties enforced in the ERP; analytics run on a cadence with exceptions dispositioned. | Mapping completeness; design and operating effectiveness; SoD ruleset coverage; whether detective controls are performed by someone who could not commit the scheme. | RCM with fraud-control flag; SoD conflict report; analytics run logs with dispositions; reconciliation sign-offs showing preparer and reviewer. |
| 4. Fraud investigation and corrective action | Written investigation protocol; case management; defined roles for legal, HR, security, and internal audit; root-cause analysis; corrective action tracking; disclosure decision tree. | Protocol followed on a sample of closed cases; intake to triage within two business days; legal holds issued; corrective actions validated; required disclosures made. | Case log; sample case files; legal-hold notices; corrective action tracker; disclosure log. |
| 5. Fraud risk management monitoring | Program metrics (report volume, substantiation rate, days to close, analytic hit rates, training completion); periodic scorecard against the five principles; changes after incidents. | Metrics produced, reported, and acted on; scorecard completed from evidence rather than self-assessed optimism; post-incident reviews changed something. | Quarterly metrics pack; completed COSO/ACFE scorecard; post-incident review memos; training completion by role. |
Scope the program review tightly, because the natural drift of any fraud engagement is toward “and also look for fraud.” The model language below goes in the planning memo.
Objective. To assess whether the fraud risk management program is designed and operating in line with the five principles of the COSO/ACFE Fraud Risk Management Guide (second edition, 2023), and whether the FY26 fraud risk assessment identifies the schemes to which the organization is most exposed and maps them to controls that would prevent or detect them within one reporting period.
Scope. The policy, the FY26 fraud risk assessment, the anti-fraud controls mapped to schemes above appetite in procure-to-pay, payroll, cash receipts, and financial close, the reporting channel and case management process, and the metrics reported to the audit committee. The engagement does not investigate any specific allegation; allegations identified during fieldwork are referred under the investigation protocol.
Criteria. COSO/ACFE Fraud Risk Management Guide (2023) principles and points of focus; COSO Internal Control–Integrated Framework (2013) Principle 8; the fraud risk management policy approved 14 March 2025; Global Internal Audit Standards 4.2 and 13.2.
The fraud scheme catalog: 26 schemes, red flags, detective analytics
A fraud risk assessment that lists “procurement fraud” as a risk is a category label, not an assessment. The unit of analysis is the scheme: who does what to which record, and how the money or the asset leaves. The 2023 edition of the COSO/ACFE guide expanded its scheme list considerably, and the ACFE publishes a free “Fraud Risk Exposures” list and a free “Library of Anti-Fraud Data Analytics Tests” alongside it; download both before a scheme workshop. The catalog below is the version I use with process owners: 26 schemes across six processes, each with the red flag you can see in data or documents and the detective analytic that would have found it, meaning the test you can run against the ERP tables rather than a sentiment about vigilance. The preventive control for each row follows from the scheme’s subject: whoever is named cannot be the reviewer, which is why segregation of duties does most of the preventive work and the ERP SoD analysis is the first data set you pull.
| Process | Scheme | Red flag (what you see) | Detective analytic (what you run) |
|---|---|---|---|
| Procure-to-pay | Shell vendor set up by an employee | Home or mailbox address; no tax ID or one matching an employee; sequential invoice numbers; services only. | Vendor master matched to employee master on address, bank account, phone, and tax ID; vendors with under three invoices and no PO. |
| Procure-to-pay | Payment diversion through a vendor bank change (email compromise or insider) | Remit-to changed shortly before a large payment; request by email; new bank abroad or a consumer bank. | Bank changes within 30 days before a payment above $25,000; changes with no logged call-back to the number on file; one bank account on two vendors. |
| Procure-to-pay | Duplicate or re-submitted invoices | Same vendor and amount within days; invoice number differs by a suffix, leading zero, or dash. | Fuzzy match on vendor, amount, and date within seven days with invoice numbers normalized. |
| Procure-to-pay | Split purchases under the approval threshold | Many POs to one vendor from one requester just under the limit, often the same day. | POs at 90 to 99 percent of the requester’s limit by requester and vendor; cumulative 30-day spend per pair against the limit. |
| Procure-to-pay | Kickbacks and bid rigging | Sole-source awards concentrated with one buyer; prices drifting above market; the same losing bidders; winner just under the runner-up. | Unit price trend by vendor against peers; sole-source rate by buyer; vendor share of spend by buyer; bids within 2 percent of second place; conflict-of-interest declarations matched to vendor ownership. |
| Procure-to-pay | Personal purchases on purchasing cards | Weekend and holiday transactions; consumer retailers; amounts just under the single-transaction limit. | Merchant category screening; weekend transactions; transactions at 90 to 100 percent of the limit; same merchant on card and expense claims (see the purchasing card guide). |
| Procure-to-pay | Inflated or fictitious service invoices | Services vendor with no deliverable on file; approver is the requester; approval within minutes of receipt. | Service invoices with no PO or receipt record; approver equals requester; approval minus receipt timestamp under five minutes. |
| Procure-to-pay | Contractor overbilling on hours or rates | Rates above the contract rate card; one named consultant billing over 60 hours a week across invoices. | Rate compliance against the contract table; hours per named individual per week summed across all invoices. |
| Payroll | Ghost employees | No benefit elections; no vacation ever taken; bank account or address shared with another employee; no badge or logon activity. | Payroll master against HR master against badge and logon logs; duplicate bank accounts and addresses; no timekeeping and no benefits. |
| Payroll | Terminated employees still paid | Payments dated after termination, often to an account changed shortly before. | Payments after termination date; final-pay lag over one cycle; bank changes within 60 days of termination. |
| Payroll | Falsified hours and overtime | Overtime always at the cap; supervisor approves own time; identical punches across a crew. | Overtime by employee against department distribution; approver equals employee; punch edit rate by supervisor. |
| Payroll | Unauthorized rate or bonus changes | Rate changed by a payroll clerk with no HR action; off-cycle payments created and approved by one user. | Rate changes with no matching HR action; off-cycle payments by creator; master change log by user (the payroll audit guide has the full set). |
| Cash receipts | Skimming (sales never recorded) | Cash share of receipts falls at one location or route while peers hold; margin by route below peers; shrink tracks the cash ratio. | Cash-to-total-receipts ratio by location or driver over 24 months; margin by route; shrink by route against cash ratio. |
| Cash receipts | Lapping of customer payments | Complaints about late posting; credits posted to accounts other than the remitter; unapplied cash aging. | Days from deposit to customer credit by collector; credits applied to a customer other than the remitter; unapplied cash over seven days. |
| Cash receipts | Fictitious credit memos and write-offs to conceal skimming | Credits issued by the collector; round amounts; clustered near period end on accounts with recent receipts. | Credit memos by user against approvals; credits to accounts with a receipt in the prior 30 days; volume per user against the peer median. |
| Cash receipts | Deposit manipulation (recorded but never fully deposited) | Book and bank deposits disagree on date or amount; deposits in transit aged over two business days. | Book-to-bank deposit match on date and amount from the bank feed; deposits-in-transit aging. |
| Travel and expense | Fictitious or altered receipts | Receipt-generator templates; the same merchant at the same amount repeatedly; edited PDFs. | Duplicate receipt image hash across claims; amounts just under the receipt threshold; merchant frequency by employee; PDF metadata (see the travel and expense guide). |
| Travel and expense | Mileage and per-diem padding | Mileage above map distance; per diem on days with hotel-provided meals or no travel. | Claimed against calculated route distance; per diem against travel dates and calendar; overlapping trips. |
| Travel and expense | Double dipping (card and expense claim for one item) | Same amount and merchant in the card feed and in a reimbursed claim. | Card transactions cross-matched to claims on merchant, amount, and date within three days. |
| Financial reporting | Top-side entries to inflate revenue or hide expenses (management override) | Manual entries at quarter end by senior finance; round amounts; revenue against receivable with no cash; reversals after the period. | Manual entries by preparer seniority and timing; round amounts; unusual account pairs; post-period reversals; entries outside business hours (see journal entry testing). |
| Financial reporting | Premature revenue, bill-and-hold, channel stuffing | Shipments spike in the last three days; credits spike the next month; side letters. | Revenue by day of period; next-period credit memos by customer; DSO trend; cut-off tests on the last and first five days. |
| Financial reporting | Estimate and reserve manipulation | Reserves move opposite to their drivers; releases land in quarters that would otherwise miss. | Reserve roll-forward against driver metrics (aging, claims, returns); release timing against targets. |
| Financial reporting | Improper capitalization of expenses | Repairs and IT run costs capitalized; additions described as “maintenance”; no project record. | Capital additions by account against prior periods; maintenance-type descriptions; additions without a project ID. |
| Financial reporting | Concealed liabilities and held invoices | Invoices received before period end and posted after; accruals fall while spend rises. | Subsequent disbursements search; receipt-date to posting-date lag by period; accruals against purchase commitments. |
| Inventory | Theft concealed by count adjustments | Shrink adjustments by the same user within 48 hours of a count; high-value SKUs over-represented. | Adjustments by user and reason code; shrink by location against peers; adjustments within 48 hours of a count. |
| Inventory | Fictitious inventory to inflate assets | Inventory in locations never counted; large aging in-transit balances; turnover far below peers. | Book-to-count reconciliation by location; in-transit aging; turnover by location. |
Two habits make the catalog useful rather than decorative. Write each scheme in the assessment as a sentence with a subject: “a depot clerk alters the deposit listing” beats “deposit fraud” because the subject tells you which segregation matters and who cannot be the reviewer. And keep the analytic column honest about data: if the handheld sync log does not exist, the analytic on invoice edits is a wish, and the assessment should record that as a control gap. The vendor master audit guide covers the other data set you will need most often once you move from the catalog to testing.
The fraud risk assessment method and scoring rubric
The method is six steps, and the order matters because the common corruption of the process is to score residual risk first and back-fill the rest. Step one is scope: the processes and legal entities in play, including the ones nobody wants to discuss (the acquired subsidiary on its own ledger, the joint venture run by a partner’s finance team). Step two is scheme identification, a 90-minute workshop per process with the process owner, one front-line supervisor, and the auditor, seeded with the catalog; the auditor’s job in the room is to ask “how would you do it if you wanted to” until the list stops growing. Step three scores each scheme’s inherent likelihood and significance before controls, using the anchors below, which forces the conversation about how bad it gets if the one reconciliation stops happening. Step four identifies the existing controls per scheme and rates them from evidence, meaning a walkthrough or a recent test rather than a policy document. Step five computes residual risk. Step six assigns a response, an owner, and a date, which is the step that makes the workbook management’s document rather than internal audit’s.
| Score | Likelihood anchor (inherent, before controls) | Financial significance (calibrated to a $220 million revenue company) | Non-financial significance |
|---|---|---|---|
| 1 Remote | No known occurrence in the industry in five years; needs collusion among three or more people with different access. | Below $10,000 in a year. | No impact outside the department. |
| 2 Unlikely | Plausible but not seen here; needs two colluders or privileged system access. | $10,000 to $50,000. | Internal disruption only. |
| 3 Possible | Has occurred at industry peers; one person with normal access could do it. | $50,000 to $250,000. | Customer or vendor relationships damaged; local press; lender questions. |
| 4 Likely | Has occurred here within five years, or repeatedly at peers; single actor with weak oversight. | $250,000 to $1 million. | Regulatory inquiry; covenant reporting; restatement risk at an account level. |
| 5 Almost certain | Has occurred here within 12 months or is believed ongoing; the opportunity is open to many people. | Above $1 million, or any misstatement requiring a restatement. | Enforcement action, license loss, delisting, or executive departures. |
Inherent risk is likelihood times significance, a range of 1 to 25. Existing controls are rated on four levels and applied as a multiplier: Strong (designed against this scheme, automated or performed by someone independent of the actor, tested effective within 12 months) at 0.25; Adequate (designed against the scheme, manual, evidence of operation but not tested within 12 months) at 0.50; Weak (a control exists but has known design gaps or an exception rate above 5 percent) at 0.75; Ineffective or none (no control, or the control is performed by the person who could commit the scheme) at 1.00. Residual risk is inherent times the multiplier, rounded. The response follows from the residual score: 12 to 25 is Act (management remediation with a date, an engagement in the current plan, a monthly analytic); 6 to 11 is Monitor (a quarterly analytic and coverage in the next plan cycle); 1 to 5 is Accept (a key risk indicator and the annual refresh). The arithmetic is a ranking device, not a measurement, and the workbook should say so; its value is that two people who disagree about a scheme end up arguing about likelihood, significance, or control evidence rather than the color of a cell. Tie the bands to the risk appetite statement where one exists, and feed the Act rows into the internal audit risk assessment so fraud exposure shapes the plan. The template below is the row structure; management owns the completed workbook, internal audit facilitates and challenges, and the fields export cleanly into the risk and control matrix.
Process and entity. [Process; legal entity or location; system of record.] Scheme. [Who does what to which record, and how the money or asset leaves. One scheme per row.]
Fraud triangle notes. [Pressure: what would motivate this actor. Opportunity: which access or gap makes it possible. Rationalization: what the actor would tell themselves.]
Inherent likelihood (1–5) and significance (1–5). [Scores with a one-line basis citing the anchor.] Inherent score. [Likelihood × significance.]
Existing controls. [Control ID; preventive or detective; performer; frequency; date last tested and result; evidence reviewed for this assessment.] Control rating and multiplier. [Strong 0.25 / Adequate 0.50 / Weak 0.75 / Ineffective 1.00, with supporting evidence.] Residual score. [Inherent × multiplier, rounded.]
Response, owner, due date. [Act / Monitor / Accept; named owner; date; the specific control change.] Detective analytic. [Test, data source, cadence, who works exceptions.] Last refreshed. [Date and trigger.]
Worked example: scoring MidState Beverage’s route cash cycle
MidState Beverage is a three-state distributor with roughly $220 million in revenue, 12 depots, 300 delivery routes, and about 4,200 smaller customers who pay drivers in cash or checks, about $31 million a year or 14 percent of revenue. Route accounting runs on a 2013 ERP module plus depot spreadsheets, two recently acquired distributors are not yet on the ERP, and internal audit has six people. In FY26 a Dayton driver diverted $18,400 over five months before a customer complaint exposed it. The FY27-01 route cash report was rated Unsatisfactory with five findings: settlement reconciliations not independent at 9 of 12 depots; variance overrides self-approved in 1,412 of 37,400 settlements; handheld sync failures unmonitored; deposit listings re-keyed outside the ERP at 7 depots; and 1,130 of 4,200 customers receiving no monthly statement. The table is the cash receipts section as re-scored at the FY27 plan refresh, using those findings as control evidence; it is management’s document, facilitated by internal audit, and every control rating cites a finding or a walkthrough.
| # | Scheme (who does what) | L | S | Inherent | Existing controls and evidence | Rating | Residual | Response and owner |
|---|---|---|---|---|---|---|---|---|
| 1 | A driver skims cash collections and covers the shortfall by lapping later receipts across route customers. | 5 | 3 | 15 | Settlement reconciliation not independent at 9 of 12 depots; 1,130 customers get no statement; overrides self-approved. | Ineffective 1.00 | 15 | Act. Independent settlement at all depots by Q2 FY27; statements to 100 percent by Q3; weekly days-to-apply analytic by driver. VP Operations with the Controller. |
| 2 | A depot clerk alters the re-keyed deposit listing and keeps the difference between cash counted and cash deposited. | 4 | 4 | 16 | Bank reconciliation prepared by the depot manager who also approves the listing; 7 depots re-key outside the ERP. | Ineffective 1.00 | 16 | Act. Daily bank feed match to ERP deposits by treasury; re-keying eliminated. Controller, Q2 FY27. |
| 3 | A depot manager self-approves variance overrides to hide a personal or a favored driver’s shortage. | 4 | 3 | 12 | Override workflow lets the creator approve (1,412 of 37,400 settlements). | Ineffective 1.00 | 12 | Act. Overrides routed to regional finance; weekly override report by approver. CFO, Q1 FY27. |
| 4 | A driver uses handheld sync failures to void or reduce invoices after delivery and before upload. | 3 | 4 | 12 | None operating; sync failures not logged or reviewed. | Ineffective 1.00 | 12 | Act. Sync exception log reviewed daily; invoice sequence gap and post-sync edit analytic. IT Director, Q2 FY27. |
| 5 | Drivers or clerks skim at the two acquired distributors, which settle manually outside the ERP. | 4 | 4 | 16 | Legacy manual settlement; no internal audit coverage since acquisition; controls unknown. | Ineffective 1.00 | 16 | Act. Acquisition integration engagement in the FY27 plan; quarterly surprise cash counts meanwhile. CFO with the integration lead. |
| 6 | A driver or clerk issues fictitious credit memos to clear balances that were skimmed. | 4 | 3 | 12 | Credits above $500 approved by the depot manager, who is not independent of settlement; credits below $500 unapproved. | Weak 0.75 | 9 | Monitor. Monthly credit memo analytic by user and customer; approval moves to regional finance in Q3. Controller. |
| 7 | A driver swaps customer checks for cash and deposits the checks to a personal account. | 3 | 2 | 6 | Checks restrictively endorsed and imaged at the depot; tested FY26, no exceptions. | Adequate 0.50 | 3 | Accept. Annual re-test. |
| 8 | A sales representative grants unauthorized discounts or free goods in exchange for kickbacks. | 3 | 3 | 9 | Price override report reviewed monthly by the sales manager with sign-off; not tested within 12 months. | Adequate 0.50 | 5 | Accept. Discount rate by representative as a key risk indicator; next order-to-cash audit. |
| 9 | A driver and a customer collude: full delivery, partial invoice, difference split. | 2 | 3 | 6 | Daily route reconciliation of load-out against invoiced and returned product, on spreadsheets at most depots. | Weak 0.75 | 5 | Accept, with a monthly route shrink analytic. VP Operations. |
| 10 | A sales administrator creates fictitious customers to move product off route without a sale. | 2 | 4 | 8 | Customer creation needs a credit check and credit manager approval; change log reviewed quarterly. | Adequate 0.50 | 4 | Accept. Customer master test in the annual data integrity work. |
The scores a process owner will push back on deserve their reasoning. Scheme 1 is a 5 on likelihood because it happened within 12 months, and a 3 rather than a 4 on significance because one route collects roughly $103,000 a year ($31 million across 300 routes), so even a two-year skim on a large route lands in the $50,000 to $250,000 band; it would be a 4 if drivers rotated routes or lapping could spread across depots. Scheme 2 carries the highest residual even though nothing has been found, because a depot handles about $2.6 million in cash a year and the person who re-keys the listing also prepares the reconciliation, which is the configuration that produces multi-year losses. Scheme 5 gets the same treatment on the rule that an acquired business with manual settlement and no coverage is scored as ineffective until someone has looked. Schemes 7, 8, and 10 are accepted not because they are impossible but because a tested or evidenced control exists and the exposure per incident is bounded; recording the accepted schemes means nobody can later say they were never considered.
The “so what” for the committee is arithmetic it can follow. The Dayton driver took about $3,680 a month; if three of 300 routes ran a similar scheme for a year, the loss is about $132,000, above the 2026 median of $104,000 and invisible under FY26 controls. Five of the ten schemes score in the Act band, and all five trace to one root cause: the detective control sits with someone who could commit the scheme. That sentence is the summary the committee needs, and it is why the FY27 plan carries the route cash handling, acquisition integration, and ERP user access engagements rather than three “fraud reviews.” The audit plan template shows how an Act-band scheme becomes a planned engagement with hours attached.
Turning the catalog into a detection program
Every Act and Monitor row names a detective analytic, and the detection program is that set of analytics run on a cadence with a named person working the exceptions. The ownership split matters here more than anywhere: management runs the monitoring because detection is a first-line control, and internal audit periodically re-performs a subset on its own extract to confirm the run is honest, which keeps the function from becoming the company’s fraud detection department and losing the independence it needs to report on the program (the continuous auditing versus continuous monitoring guide sets out the split). MidState’s suite came straight out of the cash receipts assessment: six tests, all runnable from the settlement tables, the AR module, the bank feed, and the handheld logs, each with an expected exception rate so the reviewer knows when the analytic is broken rather than the business.
| Analytic | Cadence | Rule or threshold | Expected exception rate | Who works exceptions |
|---|---|---|---|---|
| Days-to-apply and unapplied cash by driver | Weekly | Receipt applied more than three days after deposit; unapplied cash above $2,000 for one driver. | 2 to 4 percent of drivers; three weeks running is escalated. | Regional finance analyst. |
| Variance overrides by approver | Weekly | Any override approved by its creator; more than two overrides for one driver in a week. | Zero self-approvals after the Q1 workflow change. | Controller. |
| Credit memos by user and customer | Monthly | Credits above $250 to a customer with a receipt in the prior 30 days; any user above three times the peer median. | 1 to 2 percent of credit memos. | AR supervisor. |
| Book-to-bank deposit match | Daily | Any deposit unmatched on date and amount after one business day. | Under 0.5 percent once re-keying ends. | Treasury analyst. |
| Invoice sequence gaps and post-sync edits | Daily | Any sequence gap; any edit or void after sync; any sync failure not cleared in 24 hours. | About 1 percent of invoices at first, falling as devices are replaced. | Depot operations lead; IT for device faults. |
| Statement coverage and dispute aging | Monthly | Any active customer without a statement; any dispute open more than 14 days. | Coverage exceptions to zero by Q3; disputes 3 to 5 percent of statements. | AR supervisor. |
Two design rules keep a suite alive past its first quarter. The exception must go to someone who cannot have caused it, which rules out the depot manager for four of the six tests, and the disposition must be recorded so that internal audit can test it: the exception, the person, the explanation, the evidence, and the date. When you audit the program, sample 25 dispositions per analytic, re-perform the explanation against source, and treat an unsupported “timing difference” as a failure of the control. The sample size guide explains why 25 fits a monthly control with a low expected deviation rate, and the user access review guide covers the companion test: whether the people who can post credit memos, approve overrides, and edit deposits are the people the design says they are.
The investigation protocol and the boundary with legal and HR
The first 72 hours after an allegation decide whether evidence survives, whether the company keeps privilege, and whether the subject is tipped off. In the Dayton case the customer’s complaint went to the depot manager, who confronted the driver that afternoon; the driver resigned, the handheld was reissued the next morning, and the settlement spreadsheets for the prior five months had been overwritten before anyone in finance heard about it. The $18,400 was reconstructed from customer statements and is probably a floor. The protocol below is the one MidState adopted afterward, written for a company without an investigations unit: the General Counsel chairs triage, and internal audit supplies process knowledge and data rather than leading anything that involves management, financial reporting, or a regulator.
| Phase | Trigger or decision | Who does what | Evidence handling | Reporting |
|---|---|---|---|---|
| 1. Intake (day 0) | Hotline report, unexplained analytic exception, auditor observation, customer or vendor complaint, external notice. | Hotline administrator logs a case ID within one business day; General Counsel and CAE notified of anything involving management, financial reporting, a regulator, or more than $10,000. Nobody confronts the subject. | Original report preserved as received; not forwarded beyond the triage panel; reporter identity protected. | Case log entry; committee chair told within 24 hours if senior management is implicated. |
| 2. Triage (within two business days) | Credibility, who is implicated, legal exposure, who investigates. | Panel of General Counsel (chair), CAE, CHRO, and Chief Compliance Officer decides whether internal audit, legal, or an outside forensic firm leads and whether the work is counsel-directed. | Legal hold issued; IT preserves mailboxes, file shares, and logs without reviewing them; physical records secured. | Triage memo, privileged where counsel-directed; a decision not to investigate is documented with reasons. |
| 3. Investigation plan | Hypotheses, data, interviewees, timeline, budget, reporting line. | Lead investigator drafts; General Counsel approves; internal audit supplies walkthroughs, control documentation, and extracts from systems it has already mapped. | Chain-of-custody log opened; devices imaged by IT security or the outside firm; originals sealed, working copies used. | Plan in the privileged file; CAE records audit staff assigned and independence safeguards. |
| 4. Fact-finding | Document review, data analysis, confirmations, bank records. | Investigator leads; internal audit runs targeted analytics on preserved data and records what each test shows and does not show; HR advises on employment law. | Hash values recorded for every extract; bank records by consent or subpoena; originals never annotated. | Weekly status to the General Counsel; no written conclusions until facts are complete. |
| 5. Interviews | Witnesses first; the subject last, once the documentary case is assembled. | Two interviewers, one taking notes; HR present for employee subjects; Upjohn warning where counsel-directed; no promises of confidentiality or immunity. | Contemporaneous notes signed and dated by both interviewers; recording only where law and policy allow. | Interview memoranda in the privileged file. |
| 6. Conclusion | Findings of fact, loss quantification, control failures. | Investigator drafts findings; General Counsel reviews; internal audit quantifies the loss and writes the control failure analysis separately from culpability. | Evidence inventory finalized and retained under the hold. | Report to the CEO and committee as decided at triage; the committee sees every substantiated case involving management or above $10,000. |
| 7. Corrective action | Discipline, recovery, referral, control redesign. | HR handles discipline; General Counsel decides on referral and notifies the crime insurer within the policy window; Controller redesigns the control; CAE validates the fix within 90 days. | Evidence retained until the General Counsel lifts the hold. | Corrective action tracker; committee follow-up at the next meeting. |
| 8. Disclosure decisions | External auditor, regulators, lenders, insurers, law enforcement. | General Counsel decides with the CEO and committee chair; CAE ensures the external auditor is told of any fraud involving management or affecting internal control over financial reporting. | Disclosure packages built from the evidence inventory, not working notes. | Disclosure log with dates, recipients, and what was provided. |
| 9. Lessons learned (within 30 days) | Root cause, horizontal exposure, assessment refresh. | CAE facilitates; process owner presents the redesigned control; assessment re-scored and catalog updated. | Anonymized case summary retained for training. | Summary to the committee with the updated assessment row. |
Write the boundary into the internal audit charter and the fraud policy rather than negotiating it case by case. Standard 2.1 (Individual Objectivity) and Standard 2.2 (Safeguarding Objectivity) require the CAE to identify and manage threats to objectivity, and an auditor who led the investigation of a process is impaired for assurance over its remediation. Standard 5.2 (Protection of Information) is the other constraint: investigation files are the most sensitive records the function will hold, and the conventions in the workpaper example do not apply to them, because privileged material lives in counsel’s file. The model language below has held up in several charters; adapt it with the charter guide before the next allegation rather than during it.
Internal audit’s role in investigations. Internal audit does not lead investigations of allegations involving a member of senior management, the integrity of financial reporting, or a matter reportable to a regulator; such investigations are directed by the General Counsel, who may engage outside counsel or forensic specialists. Internal audit may lead fact-finding into alleged misappropriation of assets where no member of management is implicated and the estimated amount is below $50,000, under the direction of the General Counsel and with the concurrence of the audit committee chair.
Support role and independence safeguards. In all investigations internal audit will, on request, provide process and control documentation, data extracts and analytics, quantification of loss, and an analysis of control failures, reported separately from findings of fact regarding individual culpability. Internal audit staff who perform investigative procedures on a process will not provide assurance over the remediation of that process for 12 months, and the chief audit executive will disclose to the audit committee any investigation in which the function’s objectivity may be impaired and the safeguards applied.
Reporting. The chief audit executive will report to the audit committee at least quarterly the number and nature of matters referred under the investigation protocol, their status, substantiated losses and recoveries, and the control changes made.
Reporting fraud risk to the audit committee
Audit committees hear about fraud in two registers, and mixing them is the reporting failure I see most often. The first is the annual program report: does the company manage fraud risk well, where is it exposed, what changed. The second is the case register: what was alleged, found, lost, and fixed. The annual report belongs on the agenda once a year with an hour attached; the case register belongs on every quarterly agenda as a one-page metrics sheet with a short verbal summary from the General Counsel and the CAE. Standard 11.3 (Communicating Results) obliges the CAE to bring significant matters to the board, and a substantiated fraud involving management is always one. The outline below is the annual report; the table after it is the quarterly page with MidState’s Q1 FY27 numbers, and it fits on one side of a sheet, which is the point.
1. Program status. Rating against each of the five COSO/ACFE principles (effective, partially effective, ineffective) with the evidence basis in one line each and the change from last year.
2. Fraud risk assessment results. The ten highest residual schemes company-wide, the processes with the most Act-band rows, schemes that moved between bands and why, and any process not yet assessed, named.
3. Detection. Reporting channel volume and mix, substantiation rate, median days to close, analytics in production with exception dispositions, and any detection that came from outside the company.
4. Investigations and outcomes. Cases by category (misappropriation, corruption, financial reporting, other), substantiated losses, recoveries and insurance claims, discipline and referrals, and any case involving management.
5. Control failures and remediation. Root cause for each substantiated case, the control redesign, the validation date, and the horizontal check performed.
6. Emerging schemes. Payment diversion through impersonated vendors, synthetic invoices, deepfake voice requests for bank changes, and the control response to each.
7. Internal audit coverage. Which Act-band schemes are covered by planned engagements, which by management monitoring only, and which are uncovered, with hours attached.
8. Decisions requested. Approval of the appetite thresholds, budget for analytics or a forensic retainer, and any policy change such as an investigation protocol amendment.
| Quarterly metric | Q1 FY27 value (MidState) | Trend versus Q4 FY26 | Comment for the committee |
|---|---|---|---|
| Reports received (hotline, web, email, direct) | 11, or 1.2 per 100 employees | Up from 6 | Follows the Dayton communication and driver briefings; a rise after a publicized incident is expected and healthy. |
| Substantiated cases | 3 of 9 closed | Flat | Two policy breaches (expense, conflict of interest); one route shortage under $1,000 resolved as error. |
| Median days from intake to closure | 34 | Down from 51 | Triage within two business days in 10 of 11 matters; the exception waited for outside counsel. |
| Open investigations at quarter end | 2 | Down from 3 | Neither involves management; both under $10,000 estimated. |
| Substantiated losses and recoveries, year to date | $18,400 loss (FY26 Dayton); $6,000 recovered under the crime policy after deductible | n/a | Insurer notified 41 days after discovery, inside the policy window; restitution agreement covers the balance over 24 months. |
| Analytics exceptions raised and dispositioned | 212 raised; 198 closed; 14 open over 30 days | First quarter of the suite | All 14 aged items sit in the credit memo test at two depots; regional finance is clearing them. |
| Self-approved settlement overrides | 0 in the last six weeks (1,412 in the FY27-01 sample period) | Fixed | Workflow change validated by internal audit on 30 overrides. |
| Customers without a monthly statement | 612, from 1,130 | Improving | Remaining customers sit at the two acquired distributors; target zero by Q3. |
| Act-band schemes in the fraud risk assessment | 5 in route cash; 9 company-wide | First full scoring | All 9 have an owner and a date; 4 covered by FY27 engagements, 5 by management monitoring only. |
| Anti-fraud training completion | 91 percent of managers; 78 percent of staff | Up from 64 and 40 | Drivers complete in person at depot meetings; two depots remain. |
Say hard things plainly. A sentence that has worked: “Management’s fraud risk assessment rates route cash as medium; ours rates five schemes in the Act band, and the difference is not judgment but control evidence, because nine of twelve depots have no independent settlement reconciliation.” Another: “We did not find this fraud; a customer did, and 1,130 customers were not receiving the statement that would have let more of them find it sooner.” The finding severity ratings guide sets out how an Unsatisfactory rating is earned, and the report template shows where fraud risk context goes in an engagement report so it reads as assurance rather than accusation.
Testing anti-fraud culture and the whistleblowing channel
The reporting channel is the most valuable detective control in the company on the ACFE’s evidence, and the one internal audit most often leaves untested because it feels like a compliance matter. The 2026 Report to the Nations found that organizations with fraud awareness training for both staff and managers had a median loss of $84,000 against $150,000 without, that 84 percent of perpetrators had displayed at least one behavioral red flag, and that web-based reporting (46 percent of tips) has overtaken telephone hotlines (23 percent) as the channel employees use. For US-listed companies, Sarbanes-Oxley section 301 requires the audit committee to establish procedures for confidential, anonymous submission of concerns about accounting and auditing matters; EU entities with 50 or more employees fall under Directive (EU) 2019/1937 and its national transpositions, which prescribe acknowledgment and feedback deadlines. Culture is harder to test than a channel but not untestable; the tests below produce evidence rather than impressions, and the ethics domain of the Standards gives the function its own footing for reporting uncomfortable results.
| Test | Procedure | Evidence | What a pass looks like |
|---|---|---|---|
| The channel works | Submit a test report through each channel (web, email, telephone, a manager) with a distinctive phrase and trace it to the case log. | Case log entries; acknowledgment timestamps. | Every test report reaches the log within one business day with identity protected as designed. |
| People know it exists | Ask 30 employees across sites during fieldwork how they would report a concern and whether they could do so anonymously. | Interview notes; onboarding checklist; site notices. | At least 25 of 30 name a channel correctly; drivers and warehouse staff score no worse than office staff. |
| Triage is independent and timely | Sample 25 closed matters; check who triaged, whether anyone implicated took part, and the intake-to-triage interval. | Case files; triage memos. | No conflicted triage; 90 percent within two business days; every non-investigation decision has written reasons. |
| Retaliation is watched for | Match known reporters against adverse HR actions in the following 12 months: rating changes, transfers, terminations. | HR action log; case log. | Every adverse action for a known reporter was reviewed by the General Counsel before it took effect. |
| Closures are supported | Re-perform the conclusion on 10 closed cases from the evidence in the file. | Case files; evidence inventories. | All 10 supported; no case closed on the subject’s explanation alone. |
| Attestations mean something | Test conflict-of-interest declarations against vendor ownership records and the employee master for 40 buyers and approvers. | Declarations; vendor master; state business filings. | No undisclosed interests; non-responders followed up within 30 days. |
| The board sees the numbers | Compare the quarterly metrics reported to the committee with the case log for the same period. | Committee packs; case log. | Counts reconcile; every management-implicated matter appears. |
Behavioral red flags belong here rather than in the analytics section because colleagues see them and systems do not. Living beyond means and unusually close relationships with vendors or customers are the two the ACFE reports most consistently, and the company’s only realistic detective control for them is a workforce that knows what to do with the observation. The fraud red flags reference lists the indicators by scheme; the test that matters is whether the manager who notices a driver’s new truck knows the channel is for that kind of concern too.
After a fraud: lessons learned and control redesign
The post-incident review is where a fraud pays for itself, and it should happen within 30 days of closing the case, while the facts are fresh and before the process owner has rewritten the story. Root cause is a choice among five options, and naming the right one determines the fix: the control was missing; the control existed but was not performed; the control was performed by a person who could commit the scheme; the control was designed for a different scheme than the one that ran; or the control was overridden by someone with authority. In the Dayton case the answer was the third option twice (the settlement reconciliation and the variance approval both sat inside the process) plus a missing control (statements to 27 percent of customers). The redesign rules follow from the taxonomy: move the detective control out of the actor’s reach, shorten the detection window (a weekly analytic replaces a monthly reconciliation), and add the specific analytic that would have caught this scheme in month one, which for Dayton was days-to-apply by driver.
The step most often skipped is the horizontal check: was this one route, or every route. MidState ran the days-to-apply and unapplied cash analytics across all 300 routes for the prior 24 months before closing the Dayton case; four routes showed patterns worth a look, two were explained by a depot’s habit of batching applications on Fridays, and two closed as process error once the receipts were traced. That work took a senior auditor nine days, and it is why the committee accepted the FY27-01 rating without arguing that Dayton was an isolated event. The remaining tasks are administrative but consequential: the insurer notice inside the policy window, the restitution agreement drafted by counsel, the anonymized case in next year’s training, and the re-scored assessment row, which is how scheme 1 in the worked example acquired its likelihood of 5. The control deficiency evaluation guide covers the question the external auditor will ask within days: whether the control failure rises to a significant deficiency or material weakness for ICFR purposes.
Common failures in fraud risk management programs
These recur across programs that pass a documentation review, drawn from program assessments and from post-incident reviews where the paperwork looked fine. The table doubles as a self-check before the annual program report goes to the committee.
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Category-level assessment | “Procurement fraud: high” and “payroll fraud: medium” with no schemes. | Nothing maps to a control or an analytic, so the assessment cannot change what anyone does. | Rewrite at scheme level from the catalog; require a subject in every scheme sentence. |
| Residual-first scoring | Every row lands at “low residual” because the scorer started from the belief that controls exist. | Hides the schemes where one control failure produces a large loss. | Score inherent risk first in the workshop; rate controls only from walkthrough or test evidence. |
| Detective control inside the process | The reconciliation, override approval, or credit memo review is performed by someone who handles the cash or the master data. | This configuration produced the longest-running schemes in every program I have reviewed; the control detects nothing the performer chooses to hide. | Move the review to regional or corporate finance; test performer identity, not just the sign-off. |
| Internal audit as the detection department | The plan is a series of “fraud reviews”; management runs no analytics because internal audit does. | Detection becomes a third-line activity that cannot be assured, and management never owns its fraud risk. | Transfer the analytics to management as monitoring controls; audit their operation and re-perform a subset. |
| Hotline untested | The vendor’s annual summary is filed; nobody has submitted a test report or sampled closures. | The channel that produces 43 percent of detections may be broken at intake, triage, or closure without anyone knowing. | Run the seven channel tests annually; report results to the committee. |
| Confrontation before preservation | A manager confronts the suspect on the day of the complaint; devices are reissued; spreadsheets overwritten. | Evidence is lost, the loss cannot be quantified, recovery and prosecution fail. | Protocol step 1: nobody confronts the subject; legal hold and imaging before any interview. |
| No horizontal check | The case closes as an isolated incident without testing whether the same gap exists elsewhere. | The scheme runs at other locations while the committee is told the problem was one person. | Run the detective analytic that would have caught the scheme across every comparable unit for 24 months before closing. |
| Assessment never refreshed after an incident | The process still shows “medium” a year after a substantiated fraud there. | The plan and the monitoring suite rest on scores the facts have overtaken. | Make re-scoring a mandatory close-out step; the committee sees the changed row. |
| Off-system units left out | Entities not on the ERP are scored “not applicable” or omitted. | They carry the weakest controls and the least visibility; MidState’s two acquired distributors score 16. | Score off-system units as ineffective until walked through; schedule integration coverage in the plan. |
| Management override treated as theoretical | No row for top-side entries, reserve manipulation, or an executive approving their own transactions. | Financial statement fraud is 6 percent of cases with a median loss of $1 million, and the perpetrator can disable the controls. | Add the financial reporting schemes from the catalog; run journal entry analytics with the audit committee as the reporting line. |
| Culpability and control failure written together | The investigation report names the driver and the control gap in the same paragraph. | The control analysis gets caught in privilege and employment disputes and never reaches the process owner. | Internal audit writes the control failure analysis as a separate document with its own distribution. |
Adapting the approach
A one- or two-person function cannot run the full method every year and should not try. The version that works at that scale is to facilitate the scheme workshop for the two highest-cash processes, use the ACFE’s free risk assessment and follow-up action templates as the workbook so nothing has to be built, put a forensic firm on a modest retainer before it is needed, and settle the investigation boundary with the General Counsel while nobody is under suspicion. The small-company function guide covers the co-sourcing arithmetic; the fraud-specific point is that the small function’s most valuable output is the assessment and the channel tests, not the analytics, which the controller can run once they exist.
In financial services the fraud program overlaps with the anti-money-laundering and conduct programs, and the assessment should say which regime owns each scheme: internal misappropriation under the fraud program, customer-facing and third-party fraud under fraud operations, laundering under the BSA/AML program, with the overlaps (a banker opening accounts for a scheme, a loan officer’s fictitious borrower) assigned explicitly. Examiners will expect the assessment to reconcile to the operational risk taxonomy, where internal and external fraud are two of the seven Basel event types; the financial services audit guide works through the AML side. In the public sector and not-for-profits the procurement and payroll rows dominate, grant and eligibility schemes need adding, and a management-implicated matter often reports to a governing body or an inspector general rather than an audit committee, which changes protocol steps 1 and 8.
Acquisitions get their own rule, which MidState’s two off-ERP distributors illustrate: an acquired unit is scored as ineffective until someone has walked its controls through, and the integration plan carries a fraud risk assessment as a 90-day deliverable. Third-party schemes (vendor collusion, contractor overbilling, outsourced payroll and collections) come under the IIA’s Third-Party Topical Requirement, effective 15 September 2026, and the assessment should show which third parties handle cash, master data, or payments on the company’s behalf and what the company can see of their controls; the Third-Party Topical Requirement guide covers the mandatory coverage. AI-enabled fraud has changed the payment diversion row of the catalog more than any other: synthetic invoices that pass visual review, cloned executive voices requesting an urgent bank change, and fabricated email threads all attack the same control, and the response is unchanged and non-negotiable. Any change to where money goes is verified by a call to a number already on file, by a person who did not receive the request, with no exception for urgency; if the assessment does not rate that control’s operation from evidence, the row is not finished. The Risk Library holds the risk-by-risk primers, the Topics hub groups the process audit cluster, and the Tools page has the free sampler and RCM workbench that make the testing side of this guide faster.
Related guides
- Fraud red flags — behavioral and transactional indicators by scheme, the companion to the catalog.
- Fraud risk: a comprehensive guide — the risk-library primer on fraud risk and the FRM discipline.
- Journal entry analytics — the management override tests with thresholds and extraction steps.
- Accounts payable analytics — duplicate, split, and vendor-employee match tests built end to end.
- Payroll analytics — ghost employee, termination, and rate change tests.
- Vendor master audit — onboarding, bank change, and duplicate vendor controls that stop payment diversion.
- Segregation of duties — defining incompatible duties and testing them in the ERP.
- How to audit purchasing cards — merchant category screening and personal purchase tests.
- How to audit travel and expense — receipt, mileage, and double-dipping tests with sampling.
- All guides — the full index of the site’s audit guides.
- How to run a fraud risk assessment — the method, workshop plan and register template, with MidState’s first assessment
- The ACFE fraud tree explained — every occupational fraud scheme with the control it defeats and the analytic that finds it
- When internal audit finds fraud: the first 48 hours — the response protocol from detection to referral
- Procurement fraud schemes — bid rigging, kickbacks and phantom vendors, and how to find them
- Financial statement fraud — how the numbers get cooked, and who should catch it
Leave a Reply