Article

Looking Ahead: Are We Focusing on the Right Fraud Issues for 2012?

Jan 01, 0001

In the last month or so, several reports and surveys have been released with predictions about the “fraud outlook” for 2012.

January 2012 

By Peter Goldmann, CFE 

 

In the last month or so, several reports and surveys have been released with predictions about the “fraud outlook” for 2012.

 

For example, Big Four accounting firm KPMG released a survey of companies around the world indicating that “...fraud and misstatement of results continue to be growing problems for companies at a time when budgets are stretched. Defenses, however, seem to be less effective than they used to be.


On the cyber-front, The Green Sheet, a publication for the credit card payments industry, offered its expectations for the top fraud hazards in 2012:


1) Advanced phishing and vishing, SMSishing and whaling. Phishers pretend to be trustworthy entities like major banks or credit card companies and send out E-mails prompting users to send sensitive information confirming that they are the owners of the accounts. Lately, phishers have been migrating to text messaging for these ploys, commonly known as "smishing." Similarly, in voice phishing, or vishing, E-mails ask recipients to make phone calls to dummy numbers where voice prompts ask for credit card numbers.

 

High risk for 2012: In the fraud world, so-called "whaling" or "spear-phishing" attacks target high-net worth individuals on social networking sites such as LinkedIn. Fraudsters search profiles for descriptors such as vice president, chief executive officer and chief financial officer.


2) ATM skimming . Not new, but still growing; skimming devices are placed directly over ATM slots where customers swipe cards, stealing cardholder data off mag stripes. The skimmers are so small, authorities have a hard time finding them. Skimming has been around since the early 1990s. It will be a growing threat in 2012.


Do Anti-Fraud Defenses Need an Overhaul?
These and other recent predictions of the growing threat of fraud and cyber-crime almost sound like a broken record, in that similar predictions have been circulated around this time in each of the past several years. Nonetheless, they are not insignificant and it is never too late to bolster the organization’s anti-fraud controls and defenses.


The bigger problem — at least in the US — is that no anti-fraud policy or procedure, no matter how well-designed, will have meaningful impact unless it has the full and unequivocal backing of top management.


Thus in 2012, as in recent years, "Tone at the Top" has unprecedented urgency. In fact, at no time in recent memory has there been a greater need for no-nonsense top management leadership capable of implementing and enforcing high ethical standards of business conduct and a "zero tolerance" posture vis-à-vis fraud.


Why now? The U.S. economy – along with several others around the world — is still struggling to recover from the devastating fallout of the 2008 financial crisis.

 
According to the FDIC, for example, while a relatively small number of banks (25, to be exact) failed in 2008, that number ballooned to 140 in 2009. It rose further to 152 in 2010. And numerous ones are currently on the brink. Also, the housing market is still stuck in one of the worst slumps in recent history, while major banks fumble through the foreclosure mess that was left in the wake of the housing market collapse.

 

What has this all got to do with fraud prevention? Tone at the Top  (TATT for short) went out the window in the early and mid- 2000’s as mortgage lenders, investment banks, home builders, appraisers, lawyers and brokers all got swept up in the tidal wave of greed that prevailed in those years. Legal and regulatory corners were slashed as financial institutions seeking to capitalize on the seemingly irreversible upward trend in housing prices, lowered their lending standards and pressured their employees and brokers to bring in as many new borrowers as possible.


In the process, a hyperactive subculture of mortgage and securities fraud evolved, ultimately playing a so-far greatly underestimated role in bringing the world financial system to the brink.

 

So in 2012, the key question is: Will financial and corporate executives play their role in accelerating the healing of past fraud-related financial wounds? The hope, of course, is “yes.” The view for now, however, is better summed up as “let’s hope so."


In a recent column, prominent financial writer Francine McKenna (re: The Auditors) wrote: “Corporations, especially global banks, are obviously not learning from past mistakes and failures. There's no money in that. Competition, and desire for windfall profits and rewards, pushes banks to constantly place shareholder capital — and their employees, communities, vendors, and customers — at risk. Some bankers believe failures will never happen at their bank.”


That doesn’t bode well for a meaningful restoration of an ethics-based, anti-fraud and anti-cyber-crime TATT in U.S. and overseas economies.

 

Which brings us to the challenge closer to home. If the big global corporations and banks can’t -- or won’t -- "clean up their act," then it is up to the small and medium-sized entities to do so. The good news is that many if not most business executives are not the greedy, "ethics-be-damned" power mongers willing at the drop of a hat to break business and securities laws.

 

It doesn’t take a Ph.D. to know how to set the right TATT. It takes...

 

1) Continuous communication from top management about the organization’s “zero tolerance” policy toward fraud and cyber crime. This can take the form of regular E-mails to all employees, combined with annual or semi-annual fraud and cyber-crime awareness training and prosecution of fraudsters who are caught.

 

2) Establishment and experienced management of a fraud hotline. This is often best assigned to a dedicated third-party service provider, better able to provide the necessary confidentiality and anonymity to induce whistleblowers to come forward.


3) A formal anti-fraud policy. Most organizations feel that their existing ethics policies or codes of conduct “have them covered”. But too often, these documents don’t even contain the word “fraud.” To bolster TATT, a dedicated anti-fraud policy is essential.

 

Never Too Late 

It may be a few weeks late for New Year’s resolutions. And perhaps that’s a good thing, given the poor record that such commitments have at the personal level.


It is certainly not too late, however, to make 2012 the year of resetting America’s financial ethics standards to the levels previous generations took for granted.