A fraud risk assessment is the document that answers a question every board asks after a loss and almost none asks before: where, in this organisation, could someone take money or misstate results, how would they do it, and what stands in the way? The ACFE’s Occupational Fraud 2026: A Report to the Nations gives the arithmetic that makes the question worth answering before rather than after. Across 2,402 cases in 143 countries the median loss was 104,000 dollars and the median scheme ran for twelve months before detection; a third of the cases happened where there was simply no control to stop them, and a further fifth where management overrode the control that existed. Tips found 43 percent of frauds, internal audit 15 percent, management review 13 percent. Organisations with proactive data monitoring saw median losses 53 percent lower, and those that trained both staff and managers lost 84,000 dollars per case against 150,000 for those that trained nobody. None of those defences can be designed without first deciding what they are defending against, which is what the assessment does.
This guide is the practitioner’s method for running one: what the assessment is and is not, who owns it and what internal audit’s role should be, the seven-step method with outputs and hours, the scheme library that seeds the workshops, rating scales that stop everything landing on “medium”, a ninety-minute workshop plan, the register template with every field explained, a worked example from MidState Beverage’s first assessment after a depot theft, the mistakes that make assessments useless, and what an audit function does with the result. It draws on the COSO and ACFE Fraud Risk Management Guide, whose second edition (2023) sets out five principles for a fraud risk management program, the second of which is the assessment itself, and on COSO’s 2013 framework, whose Principle 8 requires an organisation to consider the potential for fraud in assessing risks to its objectives. The scheme catalog it builds on is in the fraud risk management guide; the schemes themselves are organised in the ACFE fraud tree guide.
In this guide
- What a fraud risk assessment is, and what it is not
- Who owns it, and what internal audit’s role should be
- The method in seven steps
- The scheme library that seeds the workshops
- Rating scales that stop everything landing on medium
- The ninety-minute workshop plan
- The register template, field by field
- Worked example: MidState Beverage’s first assessment
- The mistakes that make assessments useless
- What internal audit does with the result
- Where to go next
What a fraud risk assessment is, and what it is not
A fraud risk assessment is a structured identification of the specific ways fraud could occur in an organisation (the schemes), by whom (the perpetrator populations: employees, managers, executives, vendors, customers, outsiders, and combinations), against which assets or statements, with an assessment of likelihood and impact before controls, a mapping of the controls that prevent or detect each scheme, a residual rating, and a decision about each residual risk. Three things distinguish it from documents it is often confused with. It is not the enterprise risk register, which lists “fraud risk” as one line among strategic and operational risks; the fraud assessment is that one line opened up into forty or fifty scenarios, because a scheme-level view is the only level at which a control can be designed. It is not the SOX fraud risk consideration, which is scoped to financial reporting and to the assertions in the financial statements; misappropriation of assets below materiality, corruption that never touches the ledger, and fraud against customers all sit outside it. And it is not an investigation: the assessment asks what could happen, and the discipline of the workshop is that nobody is accused of anything; when a participant describes a scheme in suspiciously precise detail, the facilitator notes it and follows up under the allegation protocol, not in the room.
The theoretical frame is still Cressey’s fraud triangle, extended by later writers into a diamond: a fraud needs pressure or incentive (a debt, a target, a bonus), opportunity (access without effective control), and rationalisation (a story the person tells themselves), and, in the diamond version, capability (the position and skills to do it). The assessment’s practical use of the frame is as a prompt set: for each process, where are the pressures (targets, commissions, personal circumstances the organisation cannot see), where are the opportunities (the controls that are missing, manual, or overridable, and the people who can override them), and what stories would make the scheme feel acceptable (everyone does it; the company owes me; I will pay it back). Opportunity is the leg the organisation controls, which is why the assessment ends in controls and monitoring rather than in psychology.
Who owns it, and what internal audit’s role should be
Management owns the fraud risk assessment, because management owns the controls that answer it, and the COSO and ACFE guide is explicit that the assessment is a management responsibility overseen by the board. In practice ownership sits with a risk, compliance or finance function, or with a named executive in a smaller organisation, and internal audit’s role is to facilitate the method, challenge the results, use the output in its own planning, and test the controls the assessment relies on. The line to hold is the same as in any advisory work: the function can run the workshops, supply the scheme library and the rating scales, and write up the register, but it does not decide which risks management accepts, and it says so in the report. A function that owns the assessment ends up auditing its own judgment a year later. Where there is no second line at all, which is the situation in many mid-sized companies, the CAE facilitates the first assessment, hands the register to a named owner with a refresh date, and records the arrangement in the charter. The Global Internal Audit Standards make the function’s stake plain: Standard 13.2 requires engagement risk assessments to consider the probability of fraud, and the annual plan under Standard 9.4 is expected to be built on a risk assessment that a fraud register directly informs.
The method in seven steps
| Step | What happens | Output | Who | Effort (mid-sized company, first time) |
|---|---|---|---|---|
| 1. Scope and universe | Decide the entities, processes, locations and perpetrator populations in scope; agree the sponsor, the owner and the refresh cycle; set the rating scales | Scoping memo; process list (typically 15 to 25 processes) | Sponsor, owner, facilitator | 2 days |
| 2. Scheme library | Build the starting list of schemes per process from the ACFE fraud tree, industry cases, the organisation’s own incidents and hotline history, and the analytics catalogs | Library of 40 to 80 candidate schemes tagged to processes | Facilitator (internal audit or risk) | 3 days |
| 3. Workshops and interviews | One workshop per process family with the people who run it, plus interviews with the CFO, HR, legal, IT security and the hotline owner; prompts from the fraud triangle | Scenarios confirmed, added, discarded; pressures and opportunities noted | Facilitator with 4 to 8 participants each | 6 to 10 workshops of 90 minutes, plus preparation |
| 4. Inherent rating | Rate each scenario’s likelihood and impact before controls on the agreed scales; impact includes financial, regulatory and reputational dimensions | Inherent heat map | Workshop participants, moderated | In the workshops |
| 5. Control mapping | For each scenario, list the preventive and detective controls that address it, whether they are manual or automated, who can override them, and what monitoring exists; note gaps | Scenario-to-control map with gaps | Owner with process owners; internal audit challenges | 4 days |
| 6. Residual rating and response | Rate residual risk; for each above appetite decide: add a control, add monitoring or analytics, accept with a named owner, or investigate (where the workshop surfaced a live concern) | Residual heat map; response plan with owners and dates | Owner, sponsor; board committee approves acceptances | 2 days |
| 7. Reporting and refresh | Report to the audit or risk committee; feed the audit plan and the analytics program; refresh annually and on triggers (an incident, an acquisition, a new system, a reorganisation) | Committee report; refresh calendar | Owner; CAE for the audit-plan link | 2 days, then ongoing |
The total for a first assessment at a mid-sized company is about four to six weeks of elapsed time and 150 to 250 hours across the participants, most of it in steps 3 and 5. Later refreshes take a fraction of that, because the library and the register exist and the work is confirming what changed. The step organisations skip is 5, control mapping, and it is the one that makes the assessment useful, because a residual rating without a control map is an opinion, and the audit function cannot test an opinion.
The scheme library that seeds the workshops
A workshop that starts from a blank page produces the three frauds the participants have heard of. A workshop that starts from a library produces a considered view of forty. The library below is organised by the ACFE’s three branches and then by process, with the red flag that usually precedes detection and the analytic that would detect the scheme without waiting for a tip. Use it as a prompt, not a checklist: the value of the workshop is the schemes the library does not contain, which are the ones specific to this business.
| Branch and process | Typical schemes | Red flags | Detective analytic |
|---|---|---|---|
| Asset misappropriation: cash receipts | Skimming of sales or receivables before recording; lapping; cash larceny after recording; unauthorised write-offs and credits to cover diverted receipts | Rising unapplied cash; credits issued by the collector; customers complaining of payments not credited; one person opening the mail | Lapping signature; credit memo concentration; write-off-then-receipt; deposit lag by depositor |
| Asset misappropriation: disbursements | Billing schemes (shell vendors, pass-through vendors, personal purchases); cheque and payment tampering; expense reimbursement fraud; payroll (ghost employees, falsified hours, commission manipulation); register disbursements (false voids and refunds) | Vendors with PO-box addresses and no tax ID; invoices just under approval limits; employees who never take leave; refunds to one card | Vendor-employee matches; duplicate and near-duplicate payments; just-below-threshold clustering; payroll-to-HR reconciliation; refund concentration by cashier |
| Asset misappropriation: inventory and other assets | Theft of stock concealed by adjustments; false shipments; asset requisitions for personal use; scrap sales off the books; misuse of equipment and data | Persistent count variances at one location; adjustments by custodians; scrap revenue falling while volumes rise | Adjustment concentration; negative on-hand history; transfer aging; scrap yield trend |
| Corruption: purchasing | Kickbacks and invoice-inflation in exchange for orders; bid rigging (specification tailoring, bid rotation, loser as subcontractor); conflicts of interest through undisclosed ownership | Sole-source renewals with one buyer; price rising at every renewal; a buyer who will not rotate; vendors sharing addresses or officers | Price creep by buyer-vendor pair; single-requester vendors; bid loser paid by the winner; employee-vendor collisions |
| Corruption: sales and other | Bribes paid to win business (including foreign officials); sales-side kickbacks for discounts, credits or priority; illegal gratuities; economic extortion | Unusual discounts to one customer; consultants and agents paid on success; hospitality clustered around tenders | Discount and credit concentration by rep-customer pair; agent payment analytics; expense clusters around award dates |
| Financial statement fraud: overstatement | Fictitious revenue; premature recognition and cut-off manipulation; concealed liabilities and expenses; improper asset valuation (inventory, receivables, capitalised costs); improper disclosures | Results that meet targets exactly; period-end manual journals; reserves that move with the quarter; accruals released to hit numbers | Period-end revenue spikes and reversals; top-side journal analytics; reserve movement against drivers; capitalisation rate trends |
| Financial statement fraud: understatement | Understated revenue or assets to reduce tax, royalty or earn-out obligations; cookie-jar reserves | Results below plan in a good year; reserves built without a driver | Reserve build analytics; effective tax rate anomalies |
| Fraud against the organisation by outsiders | Business email compromise and payment redirection; customer fraud (chargebacks, refund abuse, credit application fraud); cyber-enabled theft; vendor overbilling | Beneficiary change requests by email; refund rates by customer; unusual urgency in payment requests | Bank-change-then-payment; refund and chargeback concentration; new-vendor fast-payment |
| Management override | Any scheme above, enabled by an executive’s ability to instruct staff, bypass approvals, or adjust the ledger | Instructions that bypass the system; entries posted by senior people; a culture of not questioning | Journals by senior users; approvals by delegation outside the matrix; exceptions approved by the same executive |
Rating scales that stop everything landing on medium
Most fraud risk assessments fail at the rating step, because the scales are vague and the participants are polite, so every scenario lands on medium and the heat map is a beige rectangle. Two fixes work. Anchor the scales to the organisation’s own numbers: likelihood in terms of how often the scheme would be attempted and succeed given the current controls (rare: less than once in five years; possible: once in one to five years; likely: at least annually; almost certain: happening now or continuously), and impact in terms of the loss or misstatement the scheme could produce before detection, in the organisation’s currency (at MidState the bands were under 25,000 dollars, 25,000 to 100,000, 100,000 to 500,000, and over 500,000, with a regulatory or reputational override that could raise any band). And rate inherent risk honestly, meaning the exposure if the controls that exist were not there, which participants resist because it feels like admitting the process is dangerous; it is, and that is why the controls exist. The table gives the scales and the words to use in the room.
| Scale | 1 | 2 | 3 | 4 |
|---|---|---|---|---|
| Likelihood (inherent: if no control operated) | Rare: would need unusual collusion or circumstances; less than once in five years | Possible: a motivated individual could do it; once in one to five years | Likely: the opportunity is routinely available; at least annually | Almost certain: the opportunity is continuous and unsupervised; probably happening now |
| Impact (loss or misstatement before detection) | Under 25,000 dollars; no regulatory or reputational consequence | 25,000 to 100,000 dollars; contained internally | 100,000 to 500,000 dollars; or a regulatory report or customer harm | Over 500,000 dollars; or a restatement, enforcement action or public loss of confidence |
| Control strength (for the residual step) | None, or manual and overridable by the perpetrator population | Manual, independent, but infrequent or sample-based | Automated or independent and frequent, with exceptions reviewed | Automated, segregated, monitored, with analytics over the full population |
| Residual (likelihood after control strength) | Residual likelihood is inherent likelihood reduced by control strength | Example: inherent likelihood 4 with control strength 3 lands at residual 2 | Impact does not change, because a control that fails does not shrink the loss | Residual score is residual likelihood times impact; anything at 8 or above goes to the response plan |
The ninety-minute workshop plan
One workshop per process family, four to eight participants who actually run the process (supervisors and senior staff, not only the executive), the facilitator, and a scribe. Send the process’s slice of the library two days before. The plan below has run at MidState, Brightwater and Lakeshore in this site’s examples and survives contact with real people, which is more than most agendas do.
Fraud risk workshop: [process family] — 90 minutes; participants [names and roles]; facilitator [name]; scribe [name]. Ground rules stated at the start: nobody is accused of anything; everything said about how a scheme could work is hypothetical; anything said about a scheme that is actually happening will be taken up separately by the facilitator under the allegation protocol and will not be discussed further in the room.
0 to 10 minutes: the process in one page. Walk the process on a single diagram: who does what, in which system, with what approvals. The facilitator marks the handoffs.
10 to 40 minutes: the schemes. For each library scheme: could it happen here, how, by whom, and what would it look like from inside? Then the question that produces the schemes the library does not have: “If you wanted to take money out of this process and not be caught for a year, how would you do it?” Every answer goes on the board without discussion of whether it is likely.
40 to 60 minutes: pressure, opportunity, rationalisation. For the process as a whole: where are the targets, commissions and personal pressures; which controls are manual, sample-based, or overridable, and by whom; what stories would make it feel acceptable here. This section usually reveals the override paths.
60 to 80 minutes: rating. Each scenario rated for inherent likelihood and impact on the anchored scales, by show of hands, with the facilitator recording the range as well as the consensus; disagreements are recorded, not resolved.
80 to 90 minutes: controls and close. For the five highest-rated scenarios, the participants name the controls they believe prevent or detect them. The facilitator does not evaluate the controls in the room; that is step 5. Close with the follow-up date and the reminder about the protocol.
The register template, field by field
The register is a spreadsheet or a GRC module with one row per scenario. The fields below are the minimum that makes the register usable by the three people who will read it: the owner refreshing it, the auditor planning from it, and the committee member asking what was done about the red ones. Build it in the RCM Workbench if you want the control-mapping columns generated, since a fraud scenario maps to controls in exactly the way a risk does in the risk and control matrix.
1. Scenario ID and process. [F-AP-03; the process and sub-process the scheme lives in.]
2. Scheme. [The ACFE branch and scheme type, then the specific description: “a buyer inflates invoices from a favoured vendor in exchange for a kickback, using the tolerance band on the three-way match to pass the increase”.]
3. Perpetrator population. [Who could do it: role, level, whether collusion is required and with whom (internal-internal, internal-external).]
4. Pressure, opportunity, rationalisation notes. [What the workshop said about each; the opportunity note names the specific control weakness or override path.]
5. Inherent likelihood and impact. [On the anchored scales, with the workshop’s range where there was disagreement.]
6. Preventive controls. [Control IDs from the RCM where one exists; otherwise a five-element description: who, what, when, how, evidence; note manual or automated and who can override.]
7. Detective controls and monitoring. [Reviews, reconciliations, analytics, hotline; frequency; whether the full population is covered.]
8. Control strength and residual rating. [Strength 1 to 4 on the scale; residual likelihood and score.]
9. Response. [Add control / add monitoring or analytic / accept / investigate; owner; date; for acceptances, the committee that approved and when.]
10. Assurance link. [The audit engagement or analytics program that tests the controls in 6 and 7, and when it last did.]
11. History. [Incidents, hotline reports and audit findings against this scenario, with dates.]
12. Last reviewed and by whom. [Date and name; the refresh trigger if one applies.]
Worked example: MidState Beverage’s first assessment
MidState Beverage is the three-state drinks distributor used across this site: twelve depots, three hundred routes, about 31 million dollars a year of driver-collected cash, a 2013 ERP, two acquired distributors integrated for revenue but not for controls, a six-person internal audit function and no compliance function. In FY26 a driver at the Dayton depot diverted 18,400 dollars over five months and was exposed by a customer complaint, and the handling of the discovery went badly enough (the depot manager confronted him alone, the handheld was wiped, HR terminated him before counsel was told) that the audit manager took the CFE and wrote the allegation protocol described in the CFE guide. The company had never had a fraud risk assessment. The audit manager facilitated the first one in the following quarter, with the CFO as sponsor and the controller as the register’s owner, using the twenty-six-scheme catalog from the fraud risk management guide as the library. Eight workshops covered route cash, depot operations, procurement and payables, payroll and HR, sales and pricing, inventory, finance and reporting, and IT; the CFO, the general counsel and the head of HR were interviewed separately. The register ended with 41 scenarios, nine of them at a residual score of 8 or above. The table gives eight of the nine.
| Scenario | Inherent (L x I) | Controls found | Residual | Response |
|---|---|---|---|---|
| Driver skims route cash and adjusts the customer balance through a self-approved override | 4 x 3 | Depot reconciliation (not independent at 9 of 12 depots); override approval (routing rule allowed self-approval) | 4 x 3 = 12 | Investigate the override population; route cash audit brought forward to engagement one of FY27; routing rule fixed |
| Depot manager and driver collude to issue credits to cash customers and split the cash | 3 x 3 | Credit approval by depot manager only; no statement to 1,130 of 4,200 cash customers | 3 x 3 = 9 | Customer statements extended; credit analytics by depot-driver pair added to the analytics program |
| Buyer or depot manager takes kickbacks from a local supplier through inflated or split invoices | 3 x 3 | Three-way match with a 5 percent or 250-dollar tolerance; approval limit 5,000 dollars at depots | 3 x 3 = 9 | Split and below-threshold analytics added; depot approval clustering later found in the AP analytics run |
| Ghost or terminated employees remain on the payroll of an acquired distributor | 3 x 2 | Payroll-to-HR reconciliation not performed at the two acquired entities | 3 x 2 = 6, raised to 8 by the acquisition trigger | Monthly reconciliation implemented; first payroll analytics run later found 11 paid after termination |
| Stock diverted at a depot and written off as breakage by the depot manager | 4 x 3 | Adjustment approval by the same manager; cycle counts not blind | 4 x 3 = 12 | Independent adjustment approval above 5,000 dollars; warehouse inventory engagement placed in the FY27 plan |
| Sales representative grants unauthorised discounts to a customer for a personal payment | 3 x 2 | Pricing exceptions approved by the sales manager; no analytic | 3 x 2 = 6, raised to 8 on the workshop’s evidence that it had happened before | Discount analytics by rep-customer pair; pricing exception approval moved to finance |
| Finance overrides the shrink write-off timing to protect depot bonuses | 2 x 4 | CFO review of write-offs; audit committee review of the annual shrink figure | 2 x 4 = 8 | Accepted with monitoring: quarterly shrink reporting by depot to the audit committee |
| Business email compromise redirects a vendor payment | 3 x 3 | Call-back verification for bank changes (evidence in mailboxes; not reviewed) | 3 x 3 = 9 | Call-back evidence moved to the vendor record; monthly change report signed; bank-change-then-payment analytic |
Three things about MidState’s register are worth copying. The nine red scenarios became the spine of the FY27 audit plan, which is why route cash was engagement one, ERP user access engagement three and warehouse inventory engagement four; the assessment did the plan’s risk-ranking work for it, and the plan says so. Four of the nine responses were analytics rather than controls, because at a company with twelve depots and six auditors, a monthly full-population test costs less than a new approval step and catches more; the AP and payroll runs that followed found what the register had predicted. And the one acceptance, the shrink-timing scenario, was written down with the committee’s name on it, which is what turned a suspicion nobody would voice into a reporting requirement nobody could ignore. The register was refreshed the following year in a quarter of the time, after the acquisitions’ integration and the audit management system had changed the control picture.
The mistakes that make assessments useless
Assessing “fraud risk” as one line per process rather than as scenarios, which produces a heat map nobody can act on. Running the workshops with executives only, who describe the process as designed, rather than with the supervisors who know how it is worked around. Rating residual risk directly, without an inherent rating and a control map, so that “we have controls” becomes an unexamined assumption. Letting every scenario land on medium because the scales were not anchored. Treating the assessment as internal audit’s document, so management never owns the responses. Confusing it with the SOX fraud consideration and scoping out everything below financial-statement materiality, which is where most misappropriation lives. Skipping the perpetrator-population column, so collusion and management override are never considered. Ending without responses, owners and dates, so the register is a description rather than a plan. Never linking it to the analytics program, which is the cheapest response to most of the red scenarios. And filing it: an assessment that is not refreshed after an acquisition, a new system, a reorganisation or an incident is a historical document within a year.
What internal audit does with the result
Four things. The register feeds the annual plan: scenarios with high residual scores nominate engagements, and the plan document should trace them, as MidState’s does in the audit plan guide. It feeds engagement planning: Standard 13.2’s requirement to consider fraud in the engagement risk assessment is met by pulling the scenarios for the process into the planning memo and the risk and control matrix, following the planning memo template. It feeds the analytics program: every detective analytic in the response column is a test the function can build once and run monthly, as the AP, payroll and procurement fraud catalogs show. And it defines what the function tests: the controls in column 6 and 7 of the register are the anti-fraud controls the audit committee believes exist, and testing them is how the function tells the committee whether the beliefs are true. The one thing the function should not do with it is hold it, because a fraud risk assessment owned by internal audit is a fraud risk assessment management has been allowed to forget.
Where to go next
Run the first assessment as a project with a sponsor, a library, anchored scales and eight workshops; end it with a register that has owners and dates; and hand it to management with a refresh calendar. The schemes to seed the library are organised in the ACFE fraud tree guide; what to do when a scenario turns out to be live is in the first-48-hours protocol; the purchasing branch of the tree is worked through in the procurement fraud schemes guide and the reporting branch in the financial statement fraud guide; and the program the assessment belongs to is in the fraud risk management guide.
Related guides
- Fraud risk management and internal audit — the program the assessment sits inside, with the scheme catalog
- The ACFE fraud tree explained — every occupational fraud scheme, organised
- When internal audit finds fraud: the first 48 hours — what to do when a scenario is live
- Procurement fraud schemes — the purchasing branch in depth
- Financial statement fraud — the reporting branch in depth
- The CFE for internal auditors — including MidState’s allegation protocol
- Fraud red flags — the behavioural and transactional signals
- Internal audit risk assessment — how the register feeds the plan
- How to build the internal audit plan — MidState’s FY27 plan built on the register
- Risk and control matrix template — mapping scenarios to controls
- The accounts payable analytics catalog — detective analytics as a response
- The payroll analytics catalog — ghost employees and rate changes
- Procurement fraud analytics — collusion tests across P2P
- COSO’s seventeen principles — Principle 8 and the fraud assessment requirement
- All fraud risk guides and all risk management guides
Leave a Reply