Frauds and Management Overrides as Contributory Causes
Standard on Auditing (SA) 240 – “The Auditor’s Responsibilities Relating to Fraud In An Audit of Financial Statements” deals with a topic that created a chasm between the public at large and the auditing profession. This was caused by the expectations of one group and the refutation of those expectations by the other. While the public at large believes that discovering fraud is part of auditor’s duties, the auditing profession for long refuted the same. SA 240 deals albeit with guidance to the auditors on how to close the window to the occurrence of fraud to the extent possible and reminding auditors that the primary function of auditors is to report whether the financial statements are free from material misstatement either due to fraud or error. SA 240 is a standard that deals with fraud-risk and potential situations that could give rise to situations of fraud, and the manner in which auditors should deal with them.
As a class of frauds involving material misstatement in financial statements, the ones that are more difficult to detect than the others are those that arise on account of management override of internal controls (ICs). The colloquial phrase “fence eating the crop” pithily captures the essence of the problem and the helplessness on the part of the auditors to always deal with these situations. This article tries to capture the issues involved in auditing because of the ever-present possibility of management override of controls and procedures in order to achieve their own goals which run counter to the entity’s goals. This is where the crux of the problem lies since auditors necessarily have to rely on the internal controls and are entitled to rely on them.
If one analyses the recent spate of frauds, there is a preponderance of management inspired frauds. These are usually of a scale that destroys entire organisations. Standards on Auditing (SAs) which are based on the international standards on auditing (ISAs) issued by the International Auditing and Assurance Standards Board (IAASB) of the International Federation of Accountants (IFAC) teach us that ICs are the first line of defense against fraud in any entity. The larger the size of the entity, the greater is the need for ICs. Probably the most important SA on this topic is SA 315 “Identifying And Assessing The Risk of Material Misstatement Through Understanding the Entity and its Environment” which sheds light on the topic although one should not confine oneself to just reading this SA. The topic is spread over several SAs which should be studied for greater enlightenment. Also, a huge amount of published material is available on this topic. Incidentally, the importance of SA 315 lies in the fact that for the purpose of reporting on Internal Financial Controls as required by section 143(3)(i) of the Companies Act, 2013, ICAI has prescribed SA 315 as the Framework for testing internal controls operating in an entity.
Management override and Standards on Auditing
SA 200 - “Overall Objectives of the Independent Auditor and the Conduct of An Audit in Accordance with Standards on Auditing” is the mother standard for all SAs. SA 200 under the topic “Complying with SAs Relevant to the Audit” pronounces in paragraph 20 that the auditor shall not represent compliance with SAs in the auditor’s report unless the auditor has complied with the requirements of this SA and all other SAs relevant to the audit. Compliance with SAs is now not only required under paragraph 20 of SA 200, but has also been made mandatory by section 143(9) of the Companies Act, 2013. The said section states that “Every auditor shall comply with the auditing standards”. Further, an auditor when writing the audit report is required to make the assertion to the effect that the audit was conducted in accordance with Standards on Auditing (Paragraph 28(a) of SA 700(Revised)). Therefore, read together there is an overwhelming need for an auditor to be fully compliant with all the SAs insofar as it affects an auditor’s ability to report on financial statements.
Management’s responsibility
As per paragraph 4 of SA 240, “the primary responsibility for the prevention and detection of fraud rests with both those charged with governance of the entity and management.… In exercising oversight responsibility, those charged with governance consider the potential for override of controls or other inappropriate influence over the financial reporting process, such as efforts by management to manage earnings in order to influence the perceptions of analysts as to the entity’s performance and profitability.”
Continuing with the above paragraphs, paragraph 7 of SA 240 states that “Furthermore, the risk of the auditor not detecting a material misstatement resulting from management fraud is greater than for employee fraud, because management is frequently in a position to directly or indirectly manipulate accounting records, present fraudulent financial information or override control procedures designed to prevent similar frauds by other employees”.
Continuing with the issue of management override, as discussed in SA 200, paragraph A39 of explanatory material to SA 200 states that “…However, internal control, no matter how well designed and operated, can only reduce, but not eliminate, risks of material misstatement in the financial statements, because of the inherent limitations of internal control. These include, for example, the possibility of human errors or mistakes, or of controls being circumvented by collusion or inappropriate management override.”
Paragraph A117 of SA 315 is of particular relevance and is the central theme of the article. Paragraph A117 states that “Risks of material misstatement at the financial statement level refer to risks that relate pervasively to the financial statements as a whole and potentially affect many assertions. Risks of this nature are not necessarily risks identifiable with specific assertions at the class of transactions, account balance, or disclosure level. Rather, they represent circumstances that may increase the risks of material misstatement at the assertion level, for example, through management override of internal control. Financial statement level risks may be especially relevant to the auditor’s consideration of the risks of material misstatement arising from fraud.”
Thus, what can be observed is that the responsibility for prevention of misstatement of financial statements due to either error or fraud rests with the management and those charged with governance (TCWG) of the entity. There is an overwhelming responsibility on the part of the management and the TCWG to constantly endeavour to ensure that the internal environment in which the entity is operating safeguards the interests of the entity. This is also part of the statute since the Companies Act, 2013 contains requirements for a directors’ responsibility statement to form part of the report of the board of directors. One of the stated responsibilities of the board of directors is safeguarding the assets of the entity.
“There is an overwhelming responsibility on the part of the management and the those charged with governance to constantly endeavour to ensure that the internal environment in which the entity is operating safeguards the interests of the entity.”
The Fraud Triangle & The Fraud Diamond
SA 240 contains in detail the scope for fraud, contributory causes as well as the measures to be taken to counter or reduce the risk of fraud. Paragraph 11 of SA 240 dealing with the definition of fraud and the factors that contribute to fraud-risk states as follows:
“For purposes of the SAs, the following terms have the meanings attributed below:
(a) Fraud - An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.
(b) Fraud risk factors - Events or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud.”
While fraud has been defined in several ways by several authorities, what is at the core of fraud is the intention to obtain an unjust or illegal advantage. Coming to the risk factors, what is interesting is sub-paragraph (b) above talks of “incentive” to commit a fraud, “pressure” to commit a fraud, or an “opportunity” to commit fraud. While individually, none of these factors may cause a fraud to occur, collectively, they may pave the way. Paragraph A25 of SA 240 further elucidates that when dealing with fraud risk factors, in addition to the factors specified in paragraph 11, an ability to rationalize the fraudulent action as an additional factor for an auditor to be watchful about. Thus, the three factors together form what is known as a fraud triangle and where all these factors are present, there is potentially a fraud waiting to occur. Elaborating further on these factors, the following paragraphs offer more in terms of explanations.
1. Incentive or pressure to commit fraud
Incentive or pressure to commit fraudulent financial reporting may exist when management is under pressure to present financial performance of the entity at a certain level to achieve an expected earnings target or financial outcome. This can happen on account of earlier guidance on earnings issued by the management to the market which subsequently proves to be impossible to achieve. As we know, earnings per share (EPS) could be a dominant factor in market expectations and often taken as a sign of successful management. An incentive or pressure can also arise from plans to go public by way of an initial public offer and the need to create a favourable impression particularly since the consequences of failure can be significant. Very often future capital expenditure depends on the public issues.
2. Perceived opportunity
An individual or a group within the entity believes that internal controls can be overridden because of the position that the individual or the group holds. Usually, they are well-versed with the internal control environment and the mechanism and are aware of the deficiencies therein. Probably, in the first place, they are responsible for designing the internal control system.
3. Rationalisation
Rationalization is a state of mind whereby an individual or a group can attribute a higher motive to an act of fraud. This will require adopting an attitude that what they are doing is good for the organisation. This provides them with the justification for otherwise an indefensible act. It is not difficult to imagine situations where in an ever-decreasing working capital situation on account of losses incurred, the management to present a better than the real situation for managing working capital requirements. If one were to ask the management, one would get the reply that it was done for the continued well-being of the entity.
“Rationalization is a state of mind whereby an individual or a group can attribute a higher motive to an act of fraud. This will require adopting an attitude that what they are doing is good for the organisation. This provides them with the justification for otherwise an indefensible act.”
The origins of fraud triangle
Donald R. Cressey, an American sociologist and an expert in criminology first propounded the theory in his book “Other People’s Money” in the following words, “Trusted persons become trust violators when they conceive of themselves as having a financial problem which is non-shareable, are aware this problem can be secretly resolved by violation of the position of financial trust, and are able to apply to their own conduct in that situation verbalizations which enable them to adjust their conceptions of themselves as trusted persons with their conceptions of themselves as users of the entrusted funds or property”. Eventually, this was adopted for Standards on Auditing as it explained criminal behaviour and recognition of which could put auditors on guard.
The fraud diamond
As the theory gained acceptance and began to be followed and adopted widely, a fourth leg emerged. Those with forensic experience began to suggest that in addition to the triangle a fourth factor is required to be added viz. capability [Wolfe, David T., and Dana R. Hermanson. “The Fraud Diamond: Considering the Four Elements of Fraud.” CPA Journal 74.12 (2004): 38-42.] The individual or the group planning a fraudulent act would typically look at risk-assessment and their chances of “getting-away” with it since this would provide a totally risk-free environment wherein the act of fraud could be perpetrated with impunity. While SA 240 does not quite use the word ‘capable’, references are there in SA 240 to words such as “management override of internal controls” and the fact where there is likelihood of management override of internal controls and checks & balances, fraud would be more difficult to discover. Thus ‘capability’ is identified by inference as the fourth factor even if SA 240 does not say so in so many words.
“The individual or the group planning a fraudulent act would typically look at risk-assessment and their chances of ‘getting-away’ with it since this would provide a totally risk-free environment wherein the act of fraud could be perpetrated with impunity.”
Reasons for management override
The reasons for management override are myriad and may include the following:
- Management compensation and remuneration depends on earnings since very often shareholders’ and statutory sanctions require adequate financial performance;
- The need to meet certain covenants in agreement with banks and the need for funding based on adequate financial performance;
- Proposals for mergers etc., or even forming alliances where entities would look at financial health of the potential partners; and
- Threat of bankruptcy that could be postponed by favourable financial statements (this was especially the case in the days of operation of the statute, the Sick Industrial Companies (Special Provisions) Act, 1985 which dealt with sick companies and the need to refer to the Board for Industrial and Financial Reconstruction).
Characteristics and indications of fraud
Paragraph A3 of SA 240 describes how management can accomplish fraudulent financial reporting and suggests that the following are some of the methods:
- Manipulation, falsification (including forgery), or alteration of accounting records or supporting documentation from which the financial statements are prepared;
- Misrepresentation in or intentional omission from, the financial statements of events, transactions or other significant information;
- Intentional misapplication of accounting principles relating to amounts, classification, manner of presentation, or disclosure.
Paragraph A4 of SA 240 lists the following as indicative of the management override of controls that otherwise may appear to be operating effectively. Fraud can be committed by management overriding controls using such techniques as:
- Recording fictitious journal entries, particularly close to the end of an accounting period to manipulate operating results or achieve other objectives;
- Inappropriately adjusting assumptions and changing judgments used to estimate account balances;
- Omitting, advancing or delaying recognition in the financial statements of events and transactions that have occurred during the reporting period;
- Concealing, or not disclosing, facts that could affect the amounts recorded in the financial statements;
- Engaging in complex transactions that are structured to misrepresent the financial position or financial performance of the entity;
- Altering records and terms related to significant and unusual transactions.
Methods of override
The methods dishonest managements have used to create improper financial reporting are numerous including the following:
- Transactions with undisclosed related parties, creating fictitious entries boosting revenue and profit;
- Generate false sales invoices thereby increasing revenue and profit;
- Falsifying inventory records showing more inventory than the actual case which would boost profit;
- Not accounting for invoices for expenses and showing the amounts paid as advance instead of charging to the income statement;
- Capitalizing revenue expenditure; and
- Deliberate misinterpretation of accounting standards supported by “friendly” expert opinions.
Audit procedures responsive to risks related to management override of controls
Having explored the possibilities of management override of ICs and the consequences thereof, the auditor is required to be on guard. Paragraphs 31, 32, and 33 of SA 240 offer defensive steps for the auditor as detailed below:
Paragraph 31: “Management is in a unique position to perpetrate fraud because of management’s ability to manipulate accounting records and prepare fraudulent financial statements by overriding controls that otherwise appear to be operating effectively…………...”
Paragraph 32 Mandatory Procedures (Irrespective of Assessed Risk):
32. Irrespective of the auditor’s assessment of the risks of management override of controls, the auditor shall design and perform audit procedures to:
Test the appropriateness of journal entries recorded in the general ledger and other adjustments made in the preparation of the financial statements. In designing and performing audit procedures for such tests, the auditor shall:
- (i) Make inquiries of individuals involved in the financial reporting process about inappropriate or unusual activity relating to the processing of journal entries and other adjustments;
- (ii) Select journal entries and other adjustments made at the end of a reporting period; and
- (iii) Consider the need to test journal entries and other adjustments throughout the period. (Ref: Para. A41-A44)
Review accounting estimates for biases and evaluate whether the circumstances producing the bias, if any, represent a risk of material misstatement due to fraud. In performing this review, the auditor shall:
- (i) Evaluate whether the judgments and decisions made by management in making the accounting estimates included in the financial statements, even if they are individually reasonable, indicate a possible bias on the part of the entity’s management that may represent a risk of material misstatement due to fraud. If so, the auditor shall re-evaluate the accounting estimates taken as a whole; and
- (ii) Perform a retrospective review of management judgments and assumptions related to significant accounting estimates reflected in the financial statements of the prior year. (Ref: Para. A45- A46)
For significant transactions that are outside the normal course of business for the entity, or that otherwise appear to be unusual given the auditor’s understanding of the entity and its environment and other information obtained during the audit, the auditor shall evaluate whether the business rationale (or the lack thereof) of the transactions suggests that they may have been entered into to engage in fraudulent financial reporting or to conceal misappropriation of assets. (Ref: Para. A47)
33. The auditor shall determine whether, in order to respond to the identified risks of management override of controls, the auditor needs to perform other audit procedures…….”
SA 330, “The Auditor’s Responses To Assessed Risks”
SA 330 deals elaborately with “Substantive Procedures” (paragraphs 18-23 of SA 330). Substantive procedures focus on verification of transactions as opposed to compliance procedures which are ideal in testing control aspects in respect of repetition of transactions. Paragraph A42 of explanatory material to SA 330 talks of the requirement for the auditor to design and perform substantive procedures for each material class of transactions, account balance, and disclosure, irrespective of the assessed risks of material misstatement. This requirement reflects the facts that: (i) the auditor’s assessment of risk is judgmental and so may not identify all risks of material misstatement; and (ii) there are inherent limitations to internal control, including management override.”
Conclusion
It is no coincidence that the formats of audit reports prescribed by standards on auditing contain assertions that reflect the contents of the standards on auditing. While on the one hand, the audit reports precisely state the management’s responsibilities, on the other, the standards on auditing are quite clear what ought to be done. The question that will continue to be asked is whether auditors in their performance of duties have complied with the auditing standards and if so how they are able to demonstrate through proper documentation. Management frauds by their very nature, as dealt with in the preceding paragraphs are very difficult to detect and if detectable whether they can be detectable in time. Unlike other frauds, management frauds can have a devastating effect on the organisations.
“Management frauds by their very nature are very difficult to detect and if detectable whether they can be detectable in time. Unlike other frauds, management frauds can have a devastating effect on the organisations.”
One finds these days a great deal of discussion about professional scepticism in audits or the lack of it in view of the reported management frauds. Although fraud triangle or the diamond sums up the existence of a possibility for fraud to occur and presents a usable template for the auditor, in real life it is not always the case since these factors do not present themselves for a working hypothesis.
Interestingly paragraph 8 of SA 240 contains the statement “when obtaining reasonable assurance, the auditor is responsible for maintaining professional scepticism throughout the audit, considering the potential for management override of controls and recognizing the fact that audit procedures that are effective for detecting error may not be effective in detecting fraud………”.
Therefore, an auditor would do well to remember the various aspects of the matters dealt with above and be on guard.