INTERNAL AUDIT • FRAUD RISK MANAGEMENT & GOVERNANCE The Chartered Accountant • October 2022 • Vol. 71 • pp. 29–33 (Journal pp. 377–381)

Role of internal auditor in fraud detection & mitigation

PD
CA. Prashant Daftary
Author is member of the Institute • Reach at: prashant.daftary@gmail.com & eboard@icai.in

Revisiting the Maxim: “Auditor is Watchdog and Not Bloodhound”

“AUDITOR IS WATCHDOG AND NOT BLOODHOUND” is a well known saying. This is something which is ingrained in the mind of all auditors. Recent events and backlash against the auditing community make us wonder whether this thought is still valid or not.

There seems to be a gap between the expectations of the stakeholders and the regulators and what is being delivered. This may be a perception but as it is famously said that perception is reality. The role of internal auditors has also been under the radar.

1. The Realities of Fraud: Process Breakdown & The Fraud Triangle

A few days back there was a news item as regards a van loaded with cash that was stolen by the driver of the Van. Upon investigation, it was identified that the driver had recently joined the organization and the police verification process was not carried out. This directly indicates a process failure that if detected/controlled could have avoided the fraud. This is just one example and if we do a deep dive into most of the cases, fraud is an outcome of what we call a fraud triangle theory which consists of three elements i.e. incentive, rationalization, and opportunity.

Standard on Internal Audit (SIA-11) – Consideration of Fraud in Internal Audit

The standard though not mandatory especially requires the internal auditor to consider the fraud risk and ensure due care is taken to address the fraud risk during the course of the internal audit. The role of the internal auditor would be to identify potential fraud indicators or red flags and communicate the same to those charged with governance.

Fraud Triangle Pillar Underlying Contributory Factors & Pressures
Opportunity Vulnerabilities in System Architecture
  • Weakness in internal control
  • Concentration of control
  • Lack of segregation of duties
  • Lack of management oversight
  • Lack of documentation
Incentive / Pressure Financial, Operational & Market Drivers
  • Personal incentives
  • Sales/Profit driven incentives (these create immense pressure to report numbers)
  • Expectations from the stock market, investors, analysts, etc.
Rationalization Psychological Self-Justification
  • Personal problems and financial strains
  • Grievances with management or questionable practices followed by senior management
  • Poor tone at the top and cynical corporate culture

2. Changing Expectations: How Internal Auditors Must Prepare

In addition to providing value addition and assurance to the management, the internal auditors are now expected to contribute to identifying fraud risk and helping the organization in mitigating & detecting fraud. The internal auditors are required to be more alert and more conscious efforts are needed in those directions. The regulators and the public have constantly questioned the role of the auditors and their inability to prevent and detect fraud. These changing expectations also result in more opportunities. The internal auditors would have to prepare themselves to face these challenges through the following strategic initiatives:

1. Understanding Technology & Robotic Automation

Technology is changing very rapidly and along with the ease of doing business it also brings about newer risks. Take an example of online payments which are very common now: the auditing procedures and methodology which is required are substantially different as compared to the traditional payment system.

Essential audit steps must evaluate risks from modifying bank account numbers, phishing attacks, compromise of passwords, and use of authorized devices. Many organizations have moved towards robotic process automation (RPA) and AI; internal auditors must upgrade their technical knowledge accordingly.

2. Investing & Auditing “Through the System”

Modern auditing requires auditing through the system and not around the system. Audit firms need to invest substantially in new technologies which provide them with an edge in performing internal audits and meeting stakeholder expectations. The time has come when it will no longer be possible to perform audits in a conventional manner; utilizing data analytic tools and specialized auditing software will become mandatory.

3. Big Data Mastery & Trend Recognition

The buzzword today is big data. Auditors need to develop an eye to understand voluminous data and identify abnormal trends or patterns to draw robust audit conclusions. Audit firms must establish formal training programs to train staff on how to process, sanitize, and analyze large datasets as a specialized core competency.

4. Understanding Cyber Risk in All Entities

Internal auditors need not be technical cybersecurity experts, but they must understand potential threats emanating from digital systems. Internal audit programs and checklists must incorporate cyber risk steps. External expert assistance should be sought where appropriate. Crucially, cyber risks are not confined to large conglomerates; they are equally lethal to small and medium enterprises (SMEs).

5. Heightened Risk Consciousness & Scoping

Being alert and consciously aware of potential threats enables internal auditors to design a sharper audit scope and robust plan. Setting this foundation early ensures that audit engagements focus efforts on vulnerability zones rather than low-impact routines.

6. Regulatory Guidance & International Standards

Auditors must track ICAI auditing standards on auditor’s responsibilities relating to fraud in financial statements (which statutory auditors rely on), ICAI recommendatory Internal Audit Framework on risk management, and international fraud risk management guidance and practice guides issued by The Institute of Internal Auditors (IIA).

3. Fraud Defined & Key Areas Where Internal Auditors Act as Extended Arm of Management

Definition of Fraud: Fraud is generally understood to mean the risk of unexpected financial, material or reputational loss as a result of fraudulent actions of persons internal or external to the organization. This also includes the risk of misstatements in financial statements.

Though the ultimate responsibility of managing the fraud risk is of the management, the internal auditors with their in-depth understanding of the systems, process risk & controls are best suited to support the companies mitigate and detect fraud risk. “A stitch in time saves nine” applies directly to risk management principles. Internal auditors serve as an extended arm of management across six key operational areas:

A. Create a Framework for Fraud Risk Management

Internal auditors can help entities architect a comprehensive fraud risk charter document presented to the Audit Committee and Board for formal approval. Core framework components include:

• Tone at the top and management philosophy
• Guidelines for fraud risk assessment
• Prevention and detection protocols
• Monitoring and incident reporting
• Substantiality thresholds
• Responsibilities and accountability matrix

B. Fraud Risk Assessment – Proactive 4-Step Methodology

Fraud risk assessment proactively addresses vulnerabilities against threats from internal and external sources (embezzlement of funds, misappropriation of assets, theft of proprietary information). It executes across four sequential steps:

  1. Creation of Risk Universe: The internal auditor conducts interactive walkthroughs with senior management, business heads, and process owners to review ERP workflows, standard operating procedures (SOPs), and operational reality to systematically identify and document all possible risk vectors.
  2. Quantify Potential Risk & Rate High/Medium/Low: Detailed evaluation of internal system controls mitigating the identified risk:
    • Maker-checker controls and Segregation of Duties
    • Concentration of power in individual actors
    • Inherent controls vs. residual exposure
    • Classification of controls as manual vs. automated
    • Stress-testing system behaviors under varying scenarios
    Risks with both high frequency and high impact are mapped as High Risk.
  3. Creation of Fraud Risk Register & Risk Treatment: Risks are formally recorded and treated via four standard methodologies:
    • Avoid or Terminate: Eliminating high-risk activities.
    • Transfer: Third-party insurance or indemnification.
    • Treat: Implementing mitigating controls to bring exposure to an acceptable tolerance.
    • Assume: Retaining residual risk within organizational risk appetite.
  4. Integrate Fraud Risk Register with Internal Audit Plan: Audit plan focuses directly on the operating effectiveness of controls mitigating fraud risk.
Function / Activity Identified Risk Risk Rating Mitigating Control Design
Payment Processing Risk of unauthorized payment High • Multiple checks and approval at different hierarchical levels
• Systematic automated linkage between Purchase Order (PO) and payment
• Payments strictly permitted only to pre-authorized vendors
• Online payments restricted to specific whitelisted devices and IP addresses

C. Drafting Code of Conduct & Policies

Supporting the organization in structuring robust governance policies that eliminate ambiguity:

  • Policy on acceptance of gifts from vendors, customers, etc.
  • Anti-Bribery policies and operational guidelines
  • Corporate gifting to customers and dealers
  • Conflict of interest disclosure guidelines

Once documented, compliance is audited systematically during internal audit reviews.

D. Fraud Awareness Training Programs

Heightened awareness creates collective defense. When employees are conscious of fraud risks and red flags, they exercise greater diligence in daily operations.

Internal auditors play a critical proactive role in creating a structured training calendar and conducting interactive fraud awareness training sessions across operational departments.

E. Fraud Risk Detection – Professional Red Flags

Though internal audit is legally distinct from forensic audit, internal auditors are uniquely positioned to spot early red flags and system vulnerabilities.

Key Auditor Tips & Execution Guidance:
  • Planning: Internal audit plans and checklists must embed fraud risk considerations; sample population selection must be guided by fraud risk density.
  • Professional Skepticism: Maintain an inquiring mind and rigorously corroborate assertions.
  • Alertness to Anomalies: Vigilantly track unusual transactions, sudden volume spikes, and disproportionately large expenses.
  • Observation & Inquiry: Keep an open mind and actively observe operational behaviors and office dynamics.
  • Holistic Perspective: Look at the entire organizational architecture rather than getting lost in isolated sample vouchers.
Category of Vulnerability Concrete Red Flags & Field Examples
Deficiencies in System Design (Opportunities to Perpetrate Fraud)
  • The person handling physical cash also has access to write entries into the accounting system
  • Absence of any documented system for price discovery mechanism during procurement
  • Procurement personnel also responsible for bill passing and payment processing approvals
  • No segregation of duties or maker-checker authorization controls
  • Modifications to vendor master files or employee payroll masters made without independent review
Lack of Operating Effectiveness of Controls (Breakdown in Execution)
  • Recurring instances of unapproved payments released outside authorization limits
  • Bank reconciliations not performed on a regular, timely basis
  • Frequent and unexplained deviations from Standard Operating Procedures (SOPs)
  • Recurring data errors in MIS or management reporting submitted to senior leadership
  • Pervasive deficiencies, missing invoices, or alterations in supporting audit documents

F. Setting Up Fraud Prevention & Detection Software Systems

Various automated tools flag unusual transactions and trigger real-time alerts for immediate human verification. A prominent industry benchmark is credit card fraud detection: software systems monitor transaction streams in real-time, flag high-value payments or anomalies occurring during non-business hours, and automatically trigger confirmation calls to account holders.

Internal auditors can play a vital strategic role in assisting corporate management in identifying, evaluating, configuring, and implementing automated fraud detection software.

4. The Horizon: Continuous Upskilling & The Start-up Era Consultative Role

As we conclude, there are numerous opportunities for internal auditors in the mitigation and detection of fraud. However, the auditing fraternity would have to continuously upgrade their skills and make investments in terms of time as well as money in modern technologies.

In a start-up era, the promoters and investors would look upon the internal auditors with greater responsibilities and expect them to play a more consultative role in setting up the systems which pave way for future business growth. ■■■

Virtual Certificate Course on Concurrent Audit of Banks

Internal Audit Standards Board (IASB), ICAI

The concurrent audit system of banks has become very crucial and important for banks. The main objective of the system is to ensure compliance with the audit systems in banks as per the guidelines of the Reserve Bank of India and importantly, to ensure timely detection of lapses/irregularities. In view of the core competence of chartered accountants in finance, accounting, risk management, and banking internal controls, the banking sector relies extensively on them to comply with regulatory requirements.

The Internal Audit Standards Board of ICAI conducts an 11-day Certificate Course on Concurrent Audit of Banks through the Digital Learning Hub. The purpose is to provide members with deep exposure to concurrent audit intricacies, thereby improving audit quality and report coverage.

Course Details: https://www.icai.org/post.html?post_id=15262 Course Fees: Rs. 5,900/- (including GST) Eligibility: Open for Members of ICAI
Batch Scheduled Dates & Timings Course Structure & Details
BATCH 80 October 10–20, 2022 (3:00 to 6:00 PM) Structured_IASB_Certificate Course Concurrent Audit of Banks BATCH - 80
BATCH 81 November 4–15, 2022 (3:00 to 6:00 PM) Structured_IASB_Certificate Course Concurrent Audit of Banks BATCH - 81
BATCH 82 November 18–28, 2022 (3:00 to 6:00 PM) Structured_IASB_Certificate Course Concurrent Audit of Banks BATCH - 82
Authority: Chairman, Internal Audit Standards Board, ICAI Inquiries: cia@icai.in