Finance • Forensic & Internal Controls ICAI Journal Ref: September 2021 • Vol. 70 • No. 3 • pp. 97–101 (345–349) Special Feature: SSC & BPO Fraud Analytics

Fraud Risk in Technology led Finance Function

AG
CA. Ajay Gupta
Member of the Institute • ajayrgupta121@gmail.com

“In age of technological advancement, every organisation either try to set up their own captive SSC or outsources processes to BPOs to take the benefits of cost savings and process efficiencies. Organisations use cutting-edge technologies to improve the quotient of savings. The evolving technologies coupled with high volume of transactions increases the potential risk of fraud, which occur in almost all organizations. More than half of the frauds occur in operations, accounting, executive/upper management and sales functions. Considering the high volume of transactions, it is not possible to check every transaction and the traditional checker or controls are not adequate in present scenario. This creates the need for an improved controls framework and fraud analytics. From ineffective implementation of policies and procedures to lack of awareness among employees about anti-fraud controls, what can be the major reason behind the frauds and what can be done as a solution. Read on…”

1 Introduction and Depth of Fraud

Fraud is one of the biggest threats to every organisation. The manner, depth and scale of fraud differ according to industry and function. Some of the frauds like duplicate payments, payment to dummy or non-existent employees are common across every organization while revenue related frauds would depend on the type of industry. Every organisation suffers from fraud. Some admit it while others do not admit in order to avoid negative publicity. While the owners and senior management are experts in managing business, they are not aware of the fraud mechanisms. Some even know the mechanisms but still ignore this risk, assuming fraud cannot impact their organisation. Organisations lose significant amounts of money simply because of lack of anti-fraud controls.

The size of the organisation and the complexity of the business are also relevant from a fraud risk perspective. Smaller organisations often lack robust internal controls and segregation of duties. This makes smaller organisations more susceptible to fraud risk.

The Dark Figure of Fraud: It is difficult to measure the exact scale of fraud. Many of the frauds go undetected. In some cases, frauds are not reported even after detection due to fear of negative publicity. Due to this, any study conducted is not able to provide an exact amount of fraud; but can only present an indication to the extent of the problem.

2 Global Empirical Evidence: ACFE Occupational Fraud Study

The Association of Certified Fraud Examiners (ACFE) survey based on 2,504 real cases of occupational fraud investigated between January 2018 and September 2019 across 125 countries and 23 industries revealed total cumulative losses of 3.6 Billion USD. The investigation highlighted critical baseline benchmarks:

Typical Duration & Monthly Burn:

Typical fraud schemes last 14 months before detection and cause an average loss of USD 8,300 per month.

Annual Revenue Loss:

ACFE estimates that organizations lose 5% of revenue to fraud each year, with an average loss per case of 1,509,000 USD.

Primary Detection Mode:

43% of fraud schemes were detected by tips, and half of these whistleblower tips originated directly from employees.

Internal Control Failure:

A lack of internal controls contributed directly to nearly one-third of all frauds.

Key Statistical Findings from the ACFE Study

  • Prevalence of Corruption: Corruption emerged as the most common scheme across every global geographical region.
  • Frequency vs. Cost: Asset misappropriation schemes are the most common but least costly; conversely, fraudulent financial statement schemes are the least common but inflict the most catastrophic financial losses.
  • Small vs. Large Entities: Billing, payroll, and payment tampering fraud risks were significantly more likely in small businesses compared to large corporations due to limited internal resources.
  • Control Effectiveness: The presence of structured anti-fraud controls is directly associated with lower fraud losses and substantially quicker detection intervals.
  • Departmental Origination: More than half of occupational frauds originated from four departments: Operations (15%), Accounting (14%), Executive/Upper Management (12%), and Sales (11%).
  • Executive Impact: Owners and executive management committed only 20% of frauds, yet caused the largest aggregate monetary losses.
  • Law Enforcement Referral: 46% of victim organizations declined to refer cases to external law enforcement authorities because their internal administrative discipline was deemed sufficient.

According to the ACFE, there are three main categories of fraud: asset misappropriation, fraudulent financial statements, and corruption. While a majority of frauds result from inadequate anti-fraud controls, ethics, or governance, it is exceptionally difficult to identify corruption-related frauds because many transactions occur in unrecorded cash outside formal accounting ledgers. Hence, this analysis primarily focuses on asset misappropriation and fraudulent financial statements, examining the root causes and actionable technological remedies.

The Outsourcing Fallacy: Many corporate leaders believe that by outsourcing business processes to third parties, they also outsource the fraud risk. This is a dangerous misconception. The outsourcing partner executes operational routines strictly as per service level agreements (SLAs), but the client organization’s board and executive management remain legally and fiduciary accountable for fraud risk.

3 Shared Service Centre (SSC) & BPO Environment: Past vs. Present

Today, almost every enterprise either establishes captive Shared Services Centres (SSCs) or outsources routine transactional finance processes to Business Process Outsourcing (BPO) service providers to achieve cost rationalization and operational scale. While cost-effective, these delivery architectures introduce unique vulnerabilities:

  • Extreme Transaction Volumes: Millions of entries are processed across multi-client shared platforms, rendering line-by-line manual verification physically impossible.
  • Resource Skill Arbitrage: BPOs frequently deploy lower-skilled or entry-level personnel to compress operational costs, leaving front-line processors without adequate training in fraud identification and control mechanics.
Past Shared Services Environment Present Shared Services Environment
Minimal use of applications. Most of the data in hard copy paper format. Multiple applications and most of the data are in digital form.
Hard copy invoices physically stamped as paid, rejected or amended. All invoices are digital and controlled on ERP/ Workflow tools.
Payments made by cheque and storing cheque book in lock. Approvals and payments are online with defined role-based access controls.
Original receipts / invoices were attached with expense claims. Scanned images of the expense receipts / invoices are attached with expense claim.
Purchase orders were signed and sent to suppliers. Computer output / scanned image of purchase order sent to suppliers.
Hard copy of purchase invoices. Purchase invoices are booked directly in computer system through Electronic Data Interchange (EDI).

Modern finance functions are executed using advanced Enterprise Resource Planning (ERP) suites, Robotics Process Automation (RPA) bots, Artificial Intelligence (AI), and other digital interfaces. Due to this, the inherent risk of fraud by manipulating technological layers has multiplied exponentially. Yet, many organizations continue relying on legacy manual controls like maker-checker sign-offs, superficial supervisor spot checks, and periodic sampling audits by internal or statutory teams—mechanisms that are structurally inadequate in automated environments.

4 Fraud Susceptible Processes & Inherent Risk Across Cycles

Fraud can occur in any process, but empirical history demonstrates distinct vulnerability profiles. Executive management, finance & accounting, sales, and operations bear the highest exposures. Billing and payment processing represent far greater systemic fraud risks than payroll or travel reimbursements—while travel expense manipulation is highly prevalent, its fiscal impact is minuscule compared to illicit supplier disbursements or fraudulent top-line revenue inflation.

Procure to Pay (P2P)

  • Duplicate or dummy invoice processing and fraudulent disbursement.
  • Payments processed exceeding established price variance tolerances.
  • Multiple payments routed through one-time vendor master records.
  • Unauthorized alteration of payment batch files prior to final bank site release.
  • Splitting purchase orders to circumvent delegation of authority limits.
  • Creation of post-facto purchase orders after goods or services are received.

Order to Cash (O2C)

  • Unrecorded revenue, unbilled deliveries, or suppressed accounts receivable.
  • Arbitrary or unauthorized elevation of customer credit limits.
  • Generation of invoices against fictitious customer accounts.
  • Unusually high price discounts and debt waivers granted to related parties.
  • Deliberate overbilling to inflate periodic revenues.
  • Issuance of bogus credit notes, false rebates, or unjustified sales refunds.

Travel and Expenses (T&E)

  • Submission of expense reimbursement claims on behalf of terminated or non-existent employees.
  • Submission of duplicate expense claims for identical expense receipts across altered dates.

Hire to Retire (H2R)

  • Disbursement of payroll and bonuses to ghost, terminated, or non-existent workers.
  • Systematic fabrication of excessive or unauthorized overtime hours.
  • Unexplained variations across gross pay scales, deduction parameters, hourly wage tables, and net pay transfers.

Record to Analyse (R2A)

  • Manual journal entries directly overriding supplier and customer subsidiary ledger control accounts.
  • Unauthorized or unreviewed top-level journal adjustments at period-end closures.
  • Direct manual journal entries impacting core cash and bank ledgers without documentary support.
  • Aged, unresolved open items lingering indefinitely in balance sheet reconciliations.
  • Substantial legacy balances accumulating in internal clearing, suspense, or wash accounts.

5 Key Reasons Leading to Frauds & Manifestations

Core Root Cause Category Specific Examples of Resulting Fraudulent Transactions
Absence or Ineffective Implementation of Policies and Procedures
  • Unauthorised approval and processing of commercial transactions.
  • Single-sign-off disbursement approvals in direct breach of mandatory company joint/dual-signatory mandates.
Lack of Awareness Among Employees About Anti-Fraud Controls
  • Unauthorized modification of vendor beneficiary bank master records resulting in misdirected wire transfers.
  • Operational staff routinely ignoring automated system exception warnings regarding duplicate invoice numbers or matching claim amounts.
Lack of Segregation of Duties (SoD) and Excessive User Access
  • Same individual executing both invoice processing and electronic payment release.
  • Same individual executing bank transaction processing and subsequent monthly bank reconciliation.
Inadequate or Ineffective Application and Process Controls
  • Overly wide price tolerance parameters between POs and supplier invoices, creating systematic excess payments.
  • ERP allowing goods issuance in excess of physical warehouse stock (negative inventory states).
  • Disbursement executed without automated deduction and adjustment of historical advance payments.

Why Do Frauds Go Undetected?

  • Evolving Architectural Complexity: Commercial business models and IT platforms evolve rapidly with minimal manual touchpoints, but control environments lag behind technological shifts.
  • Audit Expectation Gap: Management erroneously assumes internal and statutory auditors will detect fraud, whereas audits routinely focus on standard compliance checks and manual controls rather than core IT application logic.
  • Absence of Data Analytics: Organizations lack automated, full-population continuous fraud analytics systems.
  • Inherent Inadequacy of Sampling: Traditional sample testing covers an infinitesimally small fraction of transactions, inevitably missing deliberate, sophisticated fraud patterns.
  • Subjective Supervisory Reviews: A manager reviewing electronic payment batches on banking portals cannot practically cross-verify complex underlying data fields across thousands of records; manual oversight remains person-dependent and error-prone.

6 Framework to Minimise Fraud Risk & Implement Continuous Analytics

It is practically impossible to achieve zero fraud risk. However, enterprises can decisively minimize risk exposure by establishing a robust control environment and enforcing comprehensive prevention policies. Mitigation of technology-driven fraud risks necessitates multi-layered defenses:

Workforce Education: Continuous training of personnel across finance, shared service, and outsourced centers.
Fraud Awareness Culture: Fostering widespread sensitivity toward suspicious transaction indicators and whistleblowing.
Digital Application Controls: Embedding hard validation rules, three-way matching, and tolerance checks directly into ERP systems.
Role-Based Access (RBAC): Enforcing strict least-privilege permissions and active Segregation of Duties (SoD) matrices.

Fraud Monitoring and Analytics (CAATs)

While organizational discipline is fundamental, management urgently requires advanced technological solutions capable of providing comprehensive assurance across the entire data population rather than false comfort derived from small sample testing. Continuous monitoring can be realized through bespoke technology architectures or Computer Assisted Audit Techniques (CAAT). Any adopted solution must empower management to:

  • Identify Suspicious Patterns: Uncover anomalies, out-of-sequence transactions, unusual velocity spikes, and collusive patterns across 100% of corporate records.
  • Test 100% Population: Ensure zero blind spots, as fraudulent and manipulated transactions are deliberately designed to evade random sample selection.

7 Conclusion & Key Takeaways

1. Reliance on Automated Controls: In today’s technology-driven environment, organizations must place paramount reliance on automated, preventive application controls rather than testing and leaning exclusively on post-facto manual checks.
2. Technology-Based Fraud Analytics: Management is strongly advised to deploy enterprise-wide fraud analytics engines that test 100% of transaction populations, replacing the limited assurance provided by conventional sampling.
3. Rigorous Governance & Root Cause Remediation: Implement an enduring governance structure to conduct relentless root cause analyses on detected discrepancies, ensuring system loopholes are rectified to prevent recurring fraud.

By adopting these structured technological and governance interventions, organizations can substantially curb fraud vulnerabilities, fortify operational processes, and cultivate a truly resilient control environment.

About the Author

CA. Ajay Gupta
Member, The Institute of Chartered Accountants of India (ICAI)
Email: ajayrgupta121@gmail.com