Fraud Risk in Technology led Finance Function
“In age of technological advancement, every organisation either try to set up their own captive SSC or outsources processes to BPOs to take the benefits of cost savings and process efficiencies. Organisations use cutting-edge technologies to improve the quotient of savings. The evolving technologies coupled with high volume of transactions increases the potential risk of fraud, which occur in almost all organizations. More than half of the frauds occur in operations, accounting, executive/upper management and sales functions. Considering the high volume of transactions, it is not possible to check every transaction and the traditional checker or controls are not adequate in present scenario. This creates the need for an improved controls framework and fraud analytics. From ineffective implementation of policies and procedures to lack of awareness among employees about anti-fraud controls, what can be the major reason behind the frauds and what can be done as a solution. Read on…”
1 Introduction and Depth of Fraud
Fraud is one of the biggest threats to every organisation. The manner, depth and scale of fraud differ according to industry and function. Some of the frauds like duplicate payments, payment to dummy or non-existent employees are common across every organization while revenue related frauds would depend on the type of industry. Every organisation suffers from fraud. Some admit it while others do not admit in order to avoid negative publicity. While the owners and senior management are experts in managing business, they are not aware of the fraud mechanisms. Some even know the mechanisms but still ignore this risk, assuming fraud cannot impact their organisation. Organisations lose significant amounts of money simply because of lack of anti-fraud controls.
The size of the organisation and the complexity of the business are also relevant from a fraud risk perspective. Smaller organisations often lack robust internal controls and segregation of duties. This makes smaller organisations more susceptible to fraud risk.
2 Global Empirical Evidence: ACFE Occupational Fraud Study
The Association of Certified Fraud Examiners (ACFE) survey based on 2,504 real cases of occupational fraud investigated between January 2018 and September 2019 across 125 countries and 23 industries revealed total cumulative losses of 3.6 Billion USD. The investigation highlighted critical baseline benchmarks:
Typical fraud schemes last 14 months before detection and cause an average loss of USD 8,300 per month.
ACFE estimates that organizations lose 5% of revenue to fraud each year, with an average loss per case of 1,509,000 USD.
43% of fraud schemes were detected by tips, and half of these whistleblower tips originated directly from employees.
A lack of internal controls contributed directly to nearly one-third of all frauds.
Key Statistical Findings from the ACFE Study
- Prevalence of Corruption: Corruption emerged as the most common scheme across every global geographical region.
- Frequency vs. Cost: Asset misappropriation schemes are the most common but least costly; conversely, fraudulent financial statement schemes are the least common but inflict the most catastrophic financial losses.
- Small vs. Large Entities: Billing, payroll, and payment tampering fraud risks were significantly more likely in small businesses compared to large corporations due to limited internal resources.
- Control Effectiveness: The presence of structured anti-fraud controls is directly associated with lower fraud losses and substantially quicker detection intervals.
- Departmental Origination: More than half of occupational frauds originated from four departments: Operations (15%), Accounting (14%), Executive/Upper Management (12%), and Sales (11%).
- Executive Impact: Owners and executive management committed only 20% of frauds, yet caused the largest aggregate monetary losses.
- Law Enforcement Referral: 46% of victim organizations declined to refer cases to external law enforcement authorities because their internal administrative discipline was deemed sufficient.
According to the ACFE, there are three main categories of fraud: asset misappropriation, fraudulent financial statements, and corruption. While a majority of frauds result from inadequate anti-fraud controls, ethics, or governance, it is exceptionally difficult to identify corruption-related frauds because many transactions occur in unrecorded cash outside formal accounting ledgers. Hence, this analysis primarily focuses on asset misappropriation and fraudulent financial statements, examining the root causes and actionable technological remedies.
3 Shared Service Centre (SSC) & BPO Environment: Past vs. Present
Today, almost every enterprise either establishes captive Shared Services Centres (SSCs) or outsources routine transactional finance processes to Business Process Outsourcing (BPO) service providers to achieve cost rationalization and operational scale. While cost-effective, these delivery architectures introduce unique vulnerabilities:
- Extreme Transaction Volumes: Millions of entries are processed across multi-client shared platforms, rendering line-by-line manual verification physically impossible.
- Resource Skill Arbitrage: BPOs frequently deploy lower-skilled or entry-level personnel to compress operational costs, leaving front-line processors without adequate training in fraud identification and control mechanics.
| Past Shared Services Environment | Present Shared Services Environment |
|---|---|
| Minimal use of applications. Most of the data in hard copy paper format. | Multiple applications and most of the data are in digital form. |
| Hard copy invoices physically stamped as paid, rejected or amended. | All invoices are digital and controlled on ERP/ Workflow tools. |
| Payments made by cheque and storing cheque book in lock. | Approvals and payments are online with defined role-based access controls. |
| Original receipts / invoices were attached with expense claims. | Scanned images of the expense receipts / invoices are attached with expense claim. |
| Purchase orders were signed and sent to suppliers. | Computer output / scanned image of purchase order sent to suppliers. |
| Hard copy of purchase invoices. | Purchase invoices are booked directly in computer system through Electronic Data Interchange (EDI). |
Modern finance functions are executed using advanced Enterprise Resource Planning (ERP) suites, Robotics Process Automation (RPA) bots, Artificial Intelligence (AI), and other digital interfaces. Due to this, the inherent risk of fraud by manipulating technological layers has multiplied exponentially. Yet, many organizations continue relying on legacy manual controls like maker-checker sign-offs, superficial supervisor spot checks, and periodic sampling audits by internal or statutory teams—mechanisms that are structurally inadequate in automated environments.
4 Fraud Susceptible Processes & Inherent Risk Across Cycles
Fraud can occur in any process, but empirical history demonstrates distinct vulnerability profiles. Executive management, finance & accounting, sales, and operations bear the highest exposures. Billing and payment processing represent far greater systemic fraud risks than payroll or travel reimbursements—while travel expense manipulation is highly prevalent, its fiscal impact is minuscule compared to illicit supplier disbursements or fraudulent top-line revenue inflation.
Procure to Pay (P2P)
- Duplicate or dummy invoice processing and fraudulent disbursement.
- Payments processed exceeding established price variance tolerances.
- Multiple payments routed through one-time vendor master records.
- Unauthorized alteration of payment batch files prior to final bank site release.
- Splitting purchase orders to circumvent delegation of authority limits.
- Creation of post-facto purchase orders after goods or services are received.
Order to Cash (O2C)
- Unrecorded revenue, unbilled deliveries, or suppressed accounts receivable.
- Arbitrary or unauthorized elevation of customer credit limits.
- Generation of invoices against fictitious customer accounts.
- Unusually high price discounts and debt waivers granted to related parties.
- Deliberate overbilling to inflate periodic revenues.
- Issuance of bogus credit notes, false rebates, or unjustified sales refunds.
Travel and Expenses (T&E)
- Submission of expense reimbursement claims on behalf of terminated or non-existent employees.
- Submission of duplicate expense claims for identical expense receipts across altered dates.
Hire to Retire (H2R)
- Disbursement of payroll and bonuses to ghost, terminated, or non-existent workers.
- Systematic fabrication of excessive or unauthorized overtime hours.
- Unexplained variations across gross pay scales, deduction parameters, hourly wage tables, and net pay transfers.
Record to Analyse (R2A)
- Manual journal entries directly overriding supplier and customer subsidiary ledger control accounts.
- Unauthorized or unreviewed top-level journal adjustments at period-end closures.
- Direct manual journal entries impacting core cash and bank ledgers without documentary support.
- Aged, unresolved open items lingering indefinitely in balance sheet reconciliations.
- Substantial legacy balances accumulating in internal clearing, suspense, or wash accounts.
5 Key Reasons Leading to Frauds & Manifestations
| Core Root Cause Category | Specific Examples of Resulting Fraudulent Transactions |
|---|---|
| Absence or Ineffective Implementation of Policies and Procedures |
|
| Lack of Awareness Among Employees About Anti-Fraud Controls |
|
| Lack of Segregation of Duties (SoD) and Excessive User Access |
|
| Inadequate or Ineffective Application and Process Controls |
|
Why Do Frauds Go Undetected?
- Evolving Architectural Complexity: Commercial business models and IT platforms evolve rapidly with minimal manual touchpoints, but control environments lag behind technological shifts.
- Audit Expectation Gap: Management erroneously assumes internal and statutory auditors will detect fraud, whereas audits routinely focus on standard compliance checks and manual controls rather than core IT application logic.
- Absence of Data Analytics: Organizations lack automated, full-population continuous fraud analytics systems.
- Inherent Inadequacy of Sampling: Traditional sample testing covers an infinitesimally small fraction of transactions, inevitably missing deliberate, sophisticated fraud patterns.
- Subjective Supervisory Reviews: A manager reviewing electronic payment batches on banking portals cannot practically cross-verify complex underlying data fields across thousands of records; manual oversight remains person-dependent and error-prone.
6 Framework to Minimise Fraud Risk & Implement Continuous Analytics
It is practically impossible to achieve zero fraud risk. However, enterprises can decisively minimize risk exposure by establishing a robust control environment and enforcing comprehensive prevention policies. Mitigation of technology-driven fraud risks necessitates multi-layered defenses:
Fraud Monitoring and Analytics (CAATs)
While organizational discipline is fundamental, management urgently requires advanced technological solutions capable of providing comprehensive assurance across the entire data population rather than false comfort derived from small sample testing. Continuous monitoring can be realized through bespoke technology architectures or Computer Assisted Audit Techniques (CAAT). Any adopted solution must empower management to:
- Identify Suspicious Patterns: Uncover anomalies, out-of-sequence transactions, unusual velocity spikes, and collusive patterns across 100% of corporate records.
- Test 100% Population: Ensure zero blind spots, as fraudulent and manipulated transactions are deliberately designed to evade random sample selection.
7 Conclusion & Key Takeaways
By adopting these structured technological and governance interventions, organizations can substantially curb fraud vulnerabilities, fortify operational processes, and cultivate a truly resilient control environment.