Showing posts with label Fraud. Show all posts
Showing posts with label Fraud. Show all posts

Monday, April 4, 2011

An $8 Million Question: Why do auditors test changes to Vendor Master Files?

One of the early audit tests that I was responsible for was to review who had access to change our vendor master file, and to make sure that all those changes were logged, reviewed, and approved. Our audit objective were validity - making sure that all changes to the master file(s) were properly authorized. But even authorized changes to the master file create risk.

Case in point: Conde Nast's $8 million email scam, as reported in this Forbes Magazine blog posting from William Barrett and Janet Novack.

What seems to have happened in the Conde Nast case is that a fraudster sent in a change of address / change of banking information request on behalf of a legitimate vendor. But the bank information provided was not the actual vendor; rather it was an account set up by a fraudster with a similar name and address as the real vendor. So properly authorized payments totaling nearly $8 million were misdirected. The fraud was detected when the real vendor called to ask "where's our money?"

A variety of preventive and detective controls began to visualize in my head when I read this story. How are changes to address and/or bank information communicated from your suppliers? How are these changes corroborated?

How might data analysis be used to identify mis-matches between supplier names and addresses? Seems like a good time to ask at your organization, even if an AP audit is not on the current quarter's schedule.

Joe Oringel
Visual Risk IQ
Charlotte, NC USA


Wednesday, December 2, 2009

IIA Releases new Guidance, including GTAG #13 - Fraud Prevention and Detection in an Automated World

The IIA released its newest Guidance this morning. Both a Practice Guide titled Internal Auditing and Fraud and a Global Technology Audit Guide titled Fraud Prevention and Detection in an Automated World. Contributors include good friends Rich Lanza, Peter Millar (ACL), and Don Sparks (Audimation / IDEA).

I've downloaded both this evening, and look forward to reading each on my Chicago trip this week. We anticipate updating our proprietary QuickStart methodology for Data Analytics to consider the anti-fraud framework in the Guides.

More to follow in the coming week. Any early comments and observations on either document would be welcomed.

Wednesday, July 8, 2009

Observations from Recent, Local Frauds in Charlotte NC

Several folks commented on recent tweets of local fraud and embezzlement, first at UNC-Charlotte and again at Charlotte's Mecklenburg County, specifically within the Department of Social Services. The Fraud Triangle teaches us that as long as there is Pressure / Incentive (I really need the money), Rationalization (e.g. other people do it, I'll pay it back...etc.) and Opportunity (I won't get caught because...) fraud can and will occur and recur.

My own experience is these three elements of the fraud triangle are closely related, and that Opportunity needs to be re-evaluated, especially as Incentive increases. Today's economic times are proving this need most everywhere we look, yet we still see only a few companies who are actively changing and increasing how they monitor for potential fraud, despite the availability of very effective, modern tools for fraud detection. Like CCM-T tools from Oversight and Approva.

A specific example: During my Big 4 Accounting Firm days, I led a team that audited the procedures used to produce scratch-off lottery tickets. When we started, the largest prize awarded was $5,000 or $10,000. While internal controls were always very good (i.e. Opportunity = Low), there were still a number of people at the Ticket Printer and at the Big 4 Firm who had access to information that might help locate a batch of 250 tickets that would likely contain a $5,000 or $10,000 winner.

The likelihood that a person would risk their career to steal $5,000 or $10,000 (two to six months net pay) was pretty low. But when the Ticket Printer and State Lotteries began printing tickets with $100,000 and eventually $1,000,000 tickets. That represented at least a year or even 20 years or more in net pay. What a powerful Incentive!

This change in Incentive was a trigger that we saw to re-evaluate internal controls, because now the temptation needed a corresponding decrease in opportunity. In addition to our agreed-upon procedures to evaluate controls over ticket production, we began a continual security review which included review of other controls that would identify who may be accessing information that might allow a large ticket winner to be located. We publicized the continual security review within the company (and the Big 4 team!), so that the decreased Opportunity was understood by anyone who may have been tempted.

As staffs are cut and monitoring controls become less frequent, what is your organization doing to reduce the Opportunity for Fraud. For a couple of high-profile cases in Charlotte, it's clear that more needs to be done.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Friday, June 12, 2009

Stimulus Fraud Could hit $50 Billion. How could CCM-T help?

MarketWatch article quotes FBI Director Robert Mueller about the potential fraud risks related to Stimulus money. "These funds are inherently vulnerable to bribery, fraud, conflicts of interest and collusion. There is an old adage, that where there is money to be made, fraud is not far behind, like bees to honey," Mueller told an afternoon gathering of business executives.

In reviews of duplicate payments / overpayments, using CCM-T technology from Oversight, Apex Analytix, and/or ACL, we typically find an error rate of 0.1 to 0.5%, or approximately $1,000 to $5,000 for every million in spending.

Fraud statistics from FBI and ACFE suggest higher losses. Often much higher. Our experience is that the fraud losses are harder to detect, especially without more sophisticated automation provided by CCM-T. But the risk is clearly there. And reputation risk may be greater than the financial loss.

Ask your internal audit or general counsel what your firm is doing to proactively find fraud, waste, and errors in your Accounts Payable and P-Card spend. If you don't like the answers - call us. We can help.

Thursday, February 5, 2009

Check out "The Fraudies", Oversight's list of top Corporate Fraudsters

The folks at Oversight Systems have announced The Fraudies, a light-hearted collection of some of the bolder attempts to defraud corporations that have been detected or deterred by continuous auditing and monitoring. My personal favorite is the individual who used their company's P-Card to purchase $3,400 worth of advice from the Psychic Hotline. Let's hope the psychic didn't tell the fraudster to join your firm.

Unfortunately, today's challenging economic times are increasing the pressures and the rationalization behind more potential fraudsters.  We are working with a number of organizations in different industries, to help increase the likelihood of detection by implementing cost-effective monitoring techniques.

Using these techniques as part of regularly scheduled audits of Accounts Payable, Travel & Entertainment or P-Card audits can help organizations achieve compliance objectives while also returning money to the bottom line by reducing overpayments and re-capturing inappropriate disbursements.  Further, like the Fraudies, we hope that by publicizing these instances of fraud, other future fraudsters will be deterred.   

Joe Oringel
Visual Risk IQ
Charlotte NC 28277

Tuesday, February 5, 2008

Back on Line - Continuous Auditing and Fraud Blog

Hi - welcome. You found us.

After a six-month hiatus due to some technical challenges related an Apple iLife '06 to iLife '08 upgrade, our Continuous Auditing blog returns. Now hosted by Google's Blogger, my Visual Risk IQ partner Kim Jones and I will endeavor to keep you posted on interesting (to us) stories in the news related to internal auditing and fraud. We intend to focus on stories which demonstrate the business value of more frequent and more in-depth internal control or risk assessment.

We welcome any comments or suggestions.

Joe Oringel
Visual Risk IQ
Charlotte, North Carolina, USA

www.visualriskiq.com