,

How to Run a Fraud Risk Assessment: Method, Workshop Plan and Register Template

A fraud risk assessment is the document that answers a question every board asks after a loss and almost none asks before: where, in this organisation, could someone take money or misstate results, how would they do it, and what stands in the way? The ACFE’s Occupational Fraud 2026: A Report to the Nations gives the arithmetic that makes the question worth answering before rather than after. Across 2,402 cases in 143 countries the median loss was 104,000 dollars and the median scheme ran for twelve months before detection; a third of the cases happened where there was simply no control to stop them, and a further fifth where management overrode the control that existed. Tips found 43 percent of frauds, internal audit 15 percent, management review 13 percent. Organisations with proactive data monitoring saw median losses 53 percent lower, and those that trained both staff and managers lost 84,000 dollars per case against 150,000 for those that trained nobody. None of those defences can be designed without first deciding what they are defending against, which is what the assessment does.

This guide is the practitioner’s method for running one: what the assessment is and is not, who owns it and what internal audit’s role should be, the seven-step method with outputs and hours, the scheme library that seeds the workshops, rating scales that stop everything landing on “medium”, a ninety-minute workshop plan, the register template with every field explained, a worked example from MidState Beverage’s first assessment after a depot theft, the mistakes that make assessments useless, and what an audit function does with the result. It draws on the COSO and ACFE Fraud Risk Management Guide, whose second edition (2023) sets out five principles for a fraud risk management program, the second of which is the assessment itself, and on COSO’s 2013 framework, whose Principle 8 requires an organisation to consider the potential for fraud in assessing risks to its objectives. The scheme catalog it builds on is in the fraud risk management guide; the schemes themselves are organised in the ACFE fraud tree guide.

In this guide

What a fraud risk assessment is, and what it is not

A fraud risk assessment is a structured identification of the specific ways fraud could occur in an organisation (the schemes), by whom (the perpetrator populations: employees, managers, executives, vendors, customers, outsiders, and combinations), against which assets or statements, with an assessment of likelihood and impact before controls, a mapping of the controls that prevent or detect each scheme, a residual rating, and a decision about each residual risk. Three things distinguish it from documents it is often confused with. It is not the enterprise risk register, which lists “fraud risk” as one line among strategic and operational risks; the fraud assessment is that one line opened up into forty or fifty scenarios, because a scheme-level view is the only level at which a control can be designed. It is not the SOX fraud risk consideration, which is scoped to financial reporting and to the assertions in the financial statements; misappropriation of assets below materiality, corruption that never touches the ledger, and fraud against customers all sit outside it. And it is not an investigation: the assessment asks what could happen, and the discipline of the workshop is that nobody is accused of anything; when a participant describes a scheme in suspiciously precise detail, the facilitator notes it and follows up under the allegation protocol, not in the room.

The theoretical frame is still Cressey’s fraud triangle, extended by later writers into a diamond: a fraud needs pressure or incentive (a debt, a target, a bonus), opportunity (access without effective control), and rationalisation (a story the person tells themselves), and, in the diamond version, capability (the position and skills to do it). The assessment’s practical use of the frame is as a prompt set: for each process, where are the pressures (targets, commissions, personal circumstances the organisation cannot see), where are the opportunities (the controls that are missing, manual, or overridable, and the people who can override them), and what stories would make the scheme feel acceptable (everyone does it; the company owes me; I will pay it back). Opportunity is the leg the organisation controls, which is why the assessment ends in controls and monitoring rather than in psychology.

Who owns it, and what internal audit’s role should be

Management owns the fraud risk assessment, because management owns the controls that answer it, and the COSO and ACFE guide is explicit that the assessment is a management responsibility overseen by the board. In practice ownership sits with a risk, compliance or finance function, or with a named executive in a smaller organisation, and internal audit’s role is to facilitate the method, challenge the results, use the output in its own planning, and test the controls the assessment relies on. The line to hold is the same as in any advisory work: the function can run the workshops, supply the scheme library and the rating scales, and write up the register, but it does not decide which risks management accepts, and it says so in the report. A function that owns the assessment ends up auditing its own judgment a year later. Where there is no second line at all, which is the situation in many mid-sized companies, the CAE facilitates the first assessment, hands the register to a named owner with a refresh date, and records the arrangement in the charter. The Global Internal Audit Standards make the function’s stake plain: Standard 13.2 requires engagement risk assessments to consider the probability of fraud, and the annual plan under Standard 9.4 is expected to be built on a risk assessment that a fraud register directly informs.

The method in seven steps

StepWhat happensOutputWhoEffort (mid-sized company, first time)
1. Scope and universeDecide the entities, processes, locations and perpetrator populations in scope; agree the sponsor, the owner and the refresh cycle; set the rating scalesScoping memo; process list (typically 15 to 25 processes)Sponsor, owner, facilitator2 days
2. Scheme libraryBuild the starting list of schemes per process from the ACFE fraud tree, industry cases, the organisation’s own incidents and hotline history, and the analytics catalogsLibrary of 40 to 80 candidate schemes tagged to processesFacilitator (internal audit or risk)3 days
3. Workshops and interviewsOne workshop per process family with the people who run it, plus interviews with the CFO, HR, legal, IT security and the hotline owner; prompts from the fraud triangleScenarios confirmed, added, discarded; pressures and opportunities notedFacilitator with 4 to 8 participants each6 to 10 workshops of 90 minutes, plus preparation
4. Inherent ratingRate each scenario’s likelihood and impact before controls on the agreed scales; impact includes financial, regulatory and reputational dimensionsInherent heat mapWorkshop participants, moderatedIn the workshops
5. Control mappingFor each scenario, list the preventive and detective controls that address it, whether they are manual or automated, who can override them, and what monitoring exists; note gapsScenario-to-control map with gapsOwner with process owners; internal audit challenges4 days
6. Residual rating and responseRate residual risk; for each above appetite decide: add a control, add monitoring or analytics, accept with a named owner, or investigate (where the workshop surfaced a live concern)Residual heat map; response plan with owners and datesOwner, sponsor; board committee approves acceptances2 days
7. Reporting and refreshReport to the audit or risk committee; feed the audit plan and the analytics program; refresh annually and on triggers (an incident, an acquisition, a new system, a reorganisation)Committee report; refresh calendarOwner; CAE for the audit-plan link2 days, then ongoing

The total for a first assessment at a mid-sized company is about four to six weeks of elapsed time and 150 to 250 hours across the participants, most of it in steps 3 and 5. Later refreshes take a fraction of that, because the library and the register exist and the work is confirming what changed. The step organisations skip is 5, control mapping, and it is the one that makes the assessment useful, because a residual rating without a control map is an opinion, and the audit function cannot test an opinion.

The scheme library that seeds the workshops

A workshop that starts from a blank page produces the three frauds the participants have heard of. A workshop that starts from a library produces a considered view of forty. The library below is organised by the ACFE’s three branches and then by process, with the red flag that usually precedes detection and the analytic that would detect the scheme without waiting for a tip. Use it as a prompt, not a checklist: the value of the workshop is the schemes the library does not contain, which are the ones specific to this business.

Branch and processTypical schemesRed flagsDetective analytic
Asset misappropriation: cash receiptsSkimming of sales or receivables before recording; lapping; cash larceny after recording; unauthorised write-offs and credits to cover diverted receiptsRising unapplied cash; credits issued by the collector; customers complaining of payments not credited; one person opening the mailLapping signature; credit memo concentration; write-off-then-receipt; deposit lag by depositor
Asset misappropriation: disbursementsBilling schemes (shell vendors, pass-through vendors, personal purchases); cheque and payment tampering; expense reimbursement fraud; payroll (ghost employees, falsified hours, commission manipulation); register disbursements (false voids and refunds)Vendors with PO-box addresses and no tax ID; invoices just under approval limits; employees who never take leave; refunds to one cardVendor-employee matches; duplicate and near-duplicate payments; just-below-threshold clustering; payroll-to-HR reconciliation; refund concentration by cashier
Asset misappropriation: inventory and other assetsTheft of stock concealed by adjustments; false shipments; asset requisitions for personal use; scrap sales off the books; misuse of equipment and dataPersistent count variances at one location; adjustments by custodians; scrap revenue falling while volumes riseAdjustment concentration; negative on-hand history; transfer aging; scrap yield trend
Corruption: purchasingKickbacks and invoice-inflation in exchange for orders; bid rigging (specification tailoring, bid rotation, loser as subcontractor); conflicts of interest through undisclosed ownershipSole-source renewals with one buyer; price rising at every renewal; a buyer who will not rotate; vendors sharing addresses or officersPrice creep by buyer-vendor pair; single-requester vendors; bid loser paid by the winner; employee-vendor collisions
Corruption: sales and otherBribes paid to win business (including foreign officials); sales-side kickbacks for discounts, credits or priority; illegal gratuities; economic extortionUnusual discounts to one customer; consultants and agents paid on success; hospitality clustered around tendersDiscount and credit concentration by rep-customer pair; agent payment analytics; expense clusters around award dates
Financial statement fraud: overstatementFictitious revenue; premature recognition and cut-off manipulation; concealed liabilities and expenses; improper asset valuation (inventory, receivables, capitalised costs); improper disclosuresResults that meet targets exactly; period-end manual journals; reserves that move with the quarter; accruals released to hit numbersPeriod-end revenue spikes and reversals; top-side journal analytics; reserve movement against drivers; capitalisation rate trends
Financial statement fraud: understatementUnderstated revenue or assets to reduce tax, royalty or earn-out obligations; cookie-jar reservesResults below plan in a good year; reserves built without a driverReserve build analytics; effective tax rate anomalies
Fraud against the organisation by outsidersBusiness email compromise and payment redirection; customer fraud (chargebacks, refund abuse, credit application fraud); cyber-enabled theft; vendor overbillingBeneficiary change requests by email; refund rates by customer; unusual urgency in payment requestsBank-change-then-payment; refund and chargeback concentration; new-vendor fast-payment
Management overrideAny scheme above, enabled by an executive’s ability to instruct staff, bypass approvals, or adjust the ledgerInstructions that bypass the system; entries posted by senior people; a culture of not questioningJournals by senior users; approvals by delegation outside the matrix; exceptions approved by the same executive

Rating scales that stop everything landing on medium

Most fraud risk assessments fail at the rating step, because the scales are vague and the participants are polite, so every scenario lands on medium and the heat map is a beige rectangle. Two fixes work. Anchor the scales to the organisation’s own numbers: likelihood in terms of how often the scheme would be attempted and succeed given the current controls (rare: less than once in five years; possible: once in one to five years; likely: at least annually; almost certain: happening now or continuously), and impact in terms of the loss or misstatement the scheme could produce before detection, in the organisation’s currency (at MidState the bands were under 25,000 dollars, 25,000 to 100,000, 100,000 to 500,000, and over 500,000, with a regulatory or reputational override that could raise any band). And rate inherent risk honestly, meaning the exposure if the controls that exist were not there, which participants resist because it feels like admitting the process is dangerous; it is, and that is why the controls exist. The table gives the scales and the words to use in the room.

Scale1234
Likelihood (inherent: if no control operated)Rare: would need unusual collusion or circumstances; less than once in five yearsPossible: a motivated individual could do it; once in one to five yearsLikely: the opportunity is routinely available; at least annuallyAlmost certain: the opportunity is continuous and unsupervised; probably happening now
Impact (loss or misstatement before detection)Under 25,000 dollars; no regulatory or reputational consequence25,000 to 100,000 dollars; contained internally100,000 to 500,000 dollars; or a regulatory report or customer harmOver 500,000 dollars; or a restatement, enforcement action or public loss of confidence
Control strength (for the residual step)None, or manual and overridable by the perpetrator populationManual, independent, but infrequent or sample-basedAutomated or independent and frequent, with exceptions reviewedAutomated, segregated, monitored, with analytics over the full population
Residual (likelihood after control strength)Residual likelihood is inherent likelihood reduced by control strengthExample: inherent likelihood 4 with control strength 3 lands at residual 2Impact does not change, because a control that fails does not shrink the lossResidual score is residual likelihood times impact; anything at 8 or above goes to the response plan

The ninety-minute workshop plan

One workshop per process family, four to eight participants who actually run the process (supervisors and senior staff, not only the executive), the facilitator, and a scribe. Send the process’s slice of the library two days before. The plan below has run at MidState, Brightwater and Lakeshore in this site’s examples and survives contact with real people, which is more than most agendas do.

Fraud risk workshop: [process family] — 90 minutes; participants [names and roles]; facilitator [name]; scribe [name]. Ground rules stated at the start: nobody is accused of anything; everything said about how a scheme could work is hypothetical; anything said about a scheme that is actually happening will be taken up separately by the facilitator under the allegation protocol and will not be discussed further in the room.

0 to 10 minutes: the process in one page. Walk the process on a single diagram: who does what, in which system, with what approvals. The facilitator marks the handoffs.

10 to 40 minutes: the schemes. For each library scheme: could it happen here, how, by whom, and what would it look like from inside? Then the question that produces the schemes the library does not have: “If you wanted to take money out of this process and not be caught for a year, how would you do it?” Every answer goes on the board without discussion of whether it is likely.

40 to 60 minutes: pressure, opportunity, rationalisation. For the process as a whole: where are the targets, commissions and personal pressures; which controls are manual, sample-based, or overridable, and by whom; what stories would make it feel acceptable here. This section usually reveals the override paths.

60 to 80 minutes: rating. Each scenario rated for inherent likelihood and impact on the anchored scales, by show of hands, with the facilitator recording the range as well as the consensus; disagreements are recorded, not resolved.

80 to 90 minutes: controls and close. For the five highest-rated scenarios, the participants name the controls they believe prevent or detect them. The facilitator does not evaluate the controls in the room; that is step 5. Close with the follow-up date and the reminder about the protocol.

The register template, field by field

The register is a spreadsheet or a GRC module with one row per scenario. The fields below are the minimum that makes the register usable by the three people who will read it: the owner refreshing it, the auditor planning from it, and the committee member asking what was done about the red ones. Build it in the RCM Workbench if you want the control-mapping columns generated, since a fraud scenario maps to controls in exactly the way a risk does in the risk and control matrix.

1. Scenario ID and process. [F-AP-03; the process and sub-process the scheme lives in.]

2. Scheme. [The ACFE branch and scheme type, then the specific description: “a buyer inflates invoices from a favoured vendor in exchange for a kickback, using the tolerance band on the three-way match to pass the increase”.]

3. Perpetrator population. [Who could do it: role, level, whether collusion is required and with whom (internal-internal, internal-external).]

4. Pressure, opportunity, rationalisation notes. [What the workshop said about each; the opportunity note names the specific control weakness or override path.]

5. Inherent likelihood and impact. [On the anchored scales, with the workshop’s range where there was disagreement.]

6. Preventive controls. [Control IDs from the RCM where one exists; otherwise a five-element description: who, what, when, how, evidence; note manual or automated and who can override.]

7. Detective controls and monitoring. [Reviews, reconciliations, analytics, hotline; frequency; whether the full population is covered.]

8. Control strength and residual rating. [Strength 1 to 4 on the scale; residual likelihood and score.]

9. Response. [Add control / add monitoring or analytic / accept / investigate; owner; date; for acceptances, the committee that approved and when.]

10. Assurance link. [The audit engagement or analytics program that tests the controls in 6 and 7, and when it last did.]

11. History. [Incidents, hotline reports and audit findings against this scenario, with dates.]

12. Last reviewed and by whom. [Date and name; the refresh trigger if one applies.]

Worked example: MidState Beverage’s first assessment

MidState Beverage is the three-state drinks distributor used across this site: twelve depots, three hundred routes, about 31 million dollars a year of driver-collected cash, a 2013 ERP, two acquired distributors integrated for revenue but not for controls, a six-person internal audit function and no compliance function. In FY26 a driver at the Dayton depot diverted 18,400 dollars over five months and was exposed by a customer complaint, and the handling of the discovery went badly enough (the depot manager confronted him alone, the handheld was wiped, HR terminated him before counsel was told) that the audit manager took the CFE and wrote the allegation protocol described in the CFE guide. The company had never had a fraud risk assessment. The audit manager facilitated the first one in the following quarter, with the CFO as sponsor and the controller as the register’s owner, using the twenty-six-scheme catalog from the fraud risk management guide as the library. Eight workshops covered route cash, depot operations, procurement and payables, payroll and HR, sales and pricing, inventory, finance and reporting, and IT; the CFO, the general counsel and the head of HR were interviewed separately. The register ended with 41 scenarios, nine of them at a residual score of 8 or above. The table gives eight of the nine.

ScenarioInherent (L x I)Controls foundResidualResponse
Driver skims route cash and adjusts the customer balance through a self-approved override4 x 3Depot reconciliation (not independent at 9 of 12 depots); override approval (routing rule allowed self-approval)4 x 3 = 12Investigate the override population; route cash audit brought forward to engagement one of FY27; routing rule fixed
Depot manager and driver collude to issue credits to cash customers and split the cash3 x 3Credit approval by depot manager only; no statement to 1,130 of 4,200 cash customers3 x 3 = 9Customer statements extended; credit analytics by depot-driver pair added to the analytics program
Buyer or depot manager takes kickbacks from a local supplier through inflated or split invoices3 x 3Three-way match with a 5 percent or 250-dollar tolerance; approval limit 5,000 dollars at depots3 x 3 = 9Split and below-threshold analytics added; depot approval clustering later found in the AP analytics run
Ghost or terminated employees remain on the payroll of an acquired distributor3 x 2Payroll-to-HR reconciliation not performed at the two acquired entities3 x 2 = 6, raised to 8 by the acquisition triggerMonthly reconciliation implemented; first payroll analytics run later found 11 paid after termination
Stock diverted at a depot and written off as breakage by the depot manager4 x 3Adjustment approval by the same manager; cycle counts not blind4 x 3 = 12Independent adjustment approval above 5,000 dollars; warehouse inventory engagement placed in the FY27 plan
Sales representative grants unauthorised discounts to a customer for a personal payment3 x 2Pricing exceptions approved by the sales manager; no analytic3 x 2 = 6, raised to 8 on the workshop’s evidence that it had happened beforeDiscount analytics by rep-customer pair; pricing exception approval moved to finance
Finance overrides the shrink write-off timing to protect depot bonuses2 x 4CFO review of write-offs; audit committee review of the annual shrink figure2 x 4 = 8Accepted with monitoring: quarterly shrink reporting by depot to the audit committee
Business email compromise redirects a vendor payment3 x 3Call-back verification for bank changes (evidence in mailboxes; not reviewed)3 x 3 = 9Call-back evidence moved to the vendor record; monthly change report signed; bank-change-then-payment analytic

Three things about MidState’s register are worth copying. The nine red scenarios became the spine of the FY27 audit plan, which is why route cash was engagement one, ERP user access engagement three and warehouse inventory engagement four; the assessment did the plan’s risk-ranking work for it, and the plan says so. Four of the nine responses were analytics rather than controls, because at a company with twelve depots and six auditors, a monthly full-population test costs less than a new approval step and catches more; the AP and payroll runs that followed found what the register had predicted. And the one acceptance, the shrink-timing scenario, was written down with the committee’s name on it, which is what turned a suspicion nobody would voice into a reporting requirement nobody could ignore. The register was refreshed the following year in a quarter of the time, after the acquisitions’ integration and the audit management system had changed the control picture.

The mistakes that make assessments useless

Assessing “fraud risk” as one line per process rather than as scenarios, which produces a heat map nobody can act on. Running the workshops with executives only, who describe the process as designed, rather than with the supervisors who know how it is worked around. Rating residual risk directly, without an inherent rating and a control map, so that “we have controls” becomes an unexamined assumption. Letting every scenario land on medium because the scales were not anchored. Treating the assessment as internal audit’s document, so management never owns the responses. Confusing it with the SOX fraud consideration and scoping out everything below financial-statement materiality, which is where most misappropriation lives. Skipping the perpetrator-population column, so collusion and management override are never considered. Ending without responses, owners and dates, so the register is a description rather than a plan. Never linking it to the analytics program, which is the cheapest response to most of the red scenarios. And filing it: an assessment that is not refreshed after an acquisition, a new system, a reorganisation or an incident is a historical document within a year.

What internal audit does with the result

Four things. The register feeds the annual plan: scenarios with high residual scores nominate engagements, and the plan document should trace them, as MidState’s does in the audit plan guide. It feeds engagement planning: Standard 13.2’s requirement to consider fraud in the engagement risk assessment is met by pulling the scenarios for the process into the planning memo and the risk and control matrix, following the planning memo template. It feeds the analytics program: every detective analytic in the response column is a test the function can build once and run monthly, as the AP, payroll and procurement fraud catalogs show. And it defines what the function tests: the controls in column 6 and 7 of the register are the anti-fraud controls the audit committee believes exist, and testing them is how the function tells the committee whether the beliefs are true. The one thing the function should not do with it is hold it, because a fraud risk assessment owned by internal audit is a fraud risk assessment management has been allowed to forget.

Where to go next

Run the first assessment as a project with a sponsor, a library, anchored scales and eight workshops; end it with a register that has owners and dates; and hand it to management with a refresh calendar. The schemes to seed the library are organised in the ACFE fraud tree guide; what to do when a scenario turns out to be live is in the first-48-hours protocol; the purchasing branch of the tree is worked through in the procurement fraud schemes guide and the reporting branch in the financial statement fraud guide; and the program the assessment belongs to is in the fraud risk management guide.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading