Internal Controls: Putting Them in Place Is Only Half the Battle
Jan 01, 0001
Jan 01, 0001
According to Connecticut-based forensic accountant and investigator Stephen Pedneault, CPA, CFE, many internal control designers and fraud experts over-think potential fraud scenarios during their risk assessments.
March 2012
By Peter Goldmann, CFE
According to Connecticut-based forensic accountant and investigator Stephen Pedneault, CFE, CPA, many internal control designers and fraud experts over-think potential fraud scenarios during their risk assessments.
In reality, as Pedneault aptly points out, many fraud schemes are not overly complex. He recently told me that more than half of employee thefts and embezzlements he has investigated used very simple schemes that could have been easily prevented or detected with basic, time-tested internal controls.
For example, says Pedneault, a bookkeeper at a church was responsible for collecting, counting, recording and depositing funds for programs run by the church outside of its main offertory program. A separate bank account was established for these programs, and a deposit was supposed to be made each business day. The bookkeeper made these deposits until Dec. 3, the last deposit date identified on the bank statements.
The programs continued through the following June, and the church collected funds as usual. However, despite the lack of deposits on monthly bank statements starting in December, the scheme went undetected until July.
And here’s where Pedneault’s point rings loud and clear: Had the church simply the human and technical resources in place to monitor bank deposits and bank statements on a regular basis the fraud would have been detected in January or February – not July.
The internal controls that Pedneault identified for the church theft are just like countless other operations-level controls that management should have in place to mitigate the risk of fraud. Some others that are probably familiar to you include:
Paying no invoices without a corresponding purchase order
Putting positive pay into place for all disbursement accounts
Segregating employee duties in financial positions to avoid providing the authority to commit embezzlement or other crimes.
Enforcing stringent policies for spending during business trips
Keeping Controls Current
The reason for mentioning these controls is to make the point that putting them into place is a critical “step one.” But it is not the whole story for any organization seeking to maintain long-term fraud risk mitigation. Organizations – even small churches like the one Pedneault describes – need to continuously monitor their controls to assess their effectiveness and make prompt adjustments where controls weaknesses are identified.
This is why anti-fraud practitioners have come up with a bunch of (often confusingly) similar terms, such as: controls self-assessment (CSA), continuous control monitoring (CCM), continuous auditing (CA) and continuous transaction monitoring (CTM). All relate in one way or another to the practice of making sure that anti-fraud controls, once implemented, continue to do what they were designed to do over the long haul. For larger organizations, in fact, compliance with latest COSO guidance requires implementation of some form of controls-monitoring practice.
But what is the difference between the various monitoring processes, and which ones are best for your organization?
CSA is now practiced by many organizations across industries, and more and more are coming on board every year. The broad stroke: According to controls expert Christine Doxey, CAPP, CCSA, CICA, a CSA is best defined by three key points:
The Institute of Internal Auditors (IIA)’s definition of a CSA as a process for examining and assessing internal control effectiveness in order to provide reasonable assurance that all business objectives will be met.
A system for ensuring that controls are embedded in daily business operations. CSA is a preventive tool in the assessment and evaluation of internal controls, and as such an excellent resource for management to validate the “health” of internal controls throughout the company’s operations.
A training program to ensure that employees understand the importance of internal control in general, and the objectives, risks and controls within their organization in particular. It supports quality, reduces unnecessary costs, and allows for quick responses to situations and risks – such as incidents of fraud.
On a more fraud-centric plane, a CSA can be understood as a system for ensuring that the anti-fraud controls in each business process are not only in place, but are also functioning in accordance with their intended purpose of mitigating fraud risk. Example: Regardless of which controls monitoring method or technology you use, the specific anti-fraud controls in the procure-to-pay process should include:
Official written purchasing policies and procedures.
Specific levels of authority identifying who is permitted to approve purchases, for what items, and for what amount.
Establishing an approved-vendor list with a vendor validation process.
Ensuring that people authorized to approve purchases cannot also make changes to the approved vendor list.
Requiring competitive bids for all purchases over a certain amount or type.
Prohibiting purchasing employees from accepting gifts from vendors.
Immediately documenting all purchasing databases and bills of lading.
Reconciling clearing and cash accounts with variance detail.
Implementing disbursement controls such as positive pay, positive payee and ACH debit blocks and filters.
Importantly, while CSA may be effective in accomplishing management’s goal of assessing the effectiveness of these (and other) anti-fraud controls, it may not be the best. The reason is that to achieve long-term control effectiveness, management will need to draw input from employees “in the trenches” who know where controls may be growing slack. A CSA may be conducted through live group facilitation or through a survey. The aim is to elicit specific responses from employees about the weaknesses in anti-fraud controls that they observe on a regular basis.
The IIA points out: “In both the facilitated workshop and survey formats of CSA, the people performing the work assess their own risks and controls, and increase the ability to achieve business objectives. Internal auditors, in a consulting role, often act as facilitators to help work teams in the assessment of risks and controls. Involvement of people performing the work in evaluation of risks and controls uses the expertise of the organization, increases buy-in to any action item, and focuses efforts on important business activities.” The reason: CSA is a low-tech, essentially manual process, requiring a lot of time to set up and execute. This leaves the organization vulnerable to fraud that may already be in progress or that employees believe to hold a minimal risk of detection.
But that is, by no means, the whole story regarding monitoring of anti-fraud control effectiveness. There are numerous other tests, techniques and procedures, each appropriate for specific types of controls. Examples include:
Continuous controls monitoring (CCM). This is a process that, according to Rutgers University professor Miklos A. Vasarhelyi, Ph.D., is interchangeable with “continuous auditing” (CA). The only difference, says Prof. Vasarhelyi, in his co-authored paper, “ Continuous Controls Monitoring: A Case Study with Talecris,” is that the “owner” of the process is different: “Continuous auditing is the responsibility of internal audit and is a method used to perform control and risk assessments automatically on a frequent basis. Continuous auditing changes the audit paradigm from periodic review of selected transactions to ongoing audit testing of 100 percent of transactions.
"Continuous monitoring is owned and performed by management or the business process owner, as part of their responsibility to implement and maintain effective control systems.” If you ask 10 different auditors or forensic accountants to define each of these terms, chances are you’d get 10 different responses." Critical point: Some anti-fraud controls, such as fraud hotlines, for example, are best monitored and assessed for effectiveness by knowledgeable staff members. Others, such as those for accounts payable/disbursements, sales and T&E, are most reliably monitored automatically. Vendors such as ACL, IDEA and a few others offer tools designed to do exactly this.
Continuous auditing (CA). CA is defined by the IIA as the “automatic method used to perform control and risk assessments on a more frequent basis." A rather vague description to be sure, but it may not matter if in practical life, CA is essentially synonymous with CCM.
An executive at one of the main CCM/CA vendors echoed Prof. Vasarhelyi’s definitions of CCM and CA. He pointed out that CA is the responsibility of the internal auditor and is designed to assess the effectiveness of anti-fraud controls, enterprise-wide.
CCM, by contrast, should be performed by the business process “owner” on a transaction-by-transaction basis to flag exceptions or anomalies that might point to an ongoing fraud. Some processes may be monitored, audited and or assessed on a more frequent basis than others, but the bottom line is that the more often a specific business processes’ anti-fraud controls are examined, the better the chances of detecting signs of fraud before serious damage is done.
Regardless of which definition – or monitoring methodology – you prefer, the unavoidable reality is that controls aren’t controls unless they are continuously assessed and, where necessary, replaced, revised or newly introduced.
Peter Goldmann, CFE, is president of White-Collar Crime 101 LLC/FraudAware. Contact Peter at pgoldmann@fraudaware.com.