Are We Looking Where The Fraud Is?
Jan 01, 0001
Jan 01, 0001
It is a question frequently asked by management, boards of directors and audit committees, but the response given may not necessarily be the same in each organization. Are we looking where the fraud is?
April 2013
By Ryan Hubbs, CFE, CIA, PHR, CCSA
It is a question frequently asked by management, boards of directors and audit committees, but the response given may not necessarily be the same in each organization. Are we looking where the fraud is? Some organizations may decide to dedicate resources to financial statement transactions, others to expense accounts, and yet others still to inventory and assets. However, regardless of the industry, product or service, every entity should be dedicating resources to detect and/or prevent fraud with its vendors and suppliers.
The data are unfortunately very clear. In the ACFE’s 2012 Report to the Nations on Occupational Fraud and Abuse, corruption and billing schemes — the two types of schemes that most typically involve manipulation of vendor transactions — were two of the top three fraud scheme types in all regions of the world. Billing and corruption schemes also account for some of the highest median fraud losses, with billing schemes resulting in a median loss of $100,000 and corruption causing a median loss of $250,000. Further, many vendor fraud schemes involve an insider at the victim organization, typically an employee in the procurement or purchasing function. While most managers do not want to think that they have untrustworthy employees, the data clearly show that corruption exists and is extremely costly. And the costs do not just include the monetary loss of the scheme; the resulting regulatory costs and fines can dwarf the actual fraud loss. The expansion of the Foreign Corrupt Practices Act (FCPA), the UK Bribery Act and other bribery and corruption laws and regulations has put the onus on business leaders to be proactive in identifying and preventing fraud, bribery and corruption, or they will face the consequences. For example, in 2008, German company Siemens paid an $800 million U.S. fine as well as an $800 million German fine to settle bribery and corruption charges; an amount that not does include the costs of the investigation, the ongoing monitoring required by the U.S. government or the loss in stockholder value.
Most organizations rely on vendors to supply the goods and services needed to develop and produce other products or to facilitate business operations. It typically makes good business sense to use contracted vendors and suppliers when they can provide the necessary goods or services at a cheaper price, of better quality, or with more specialized expertise than the purchasing organization has available internally. In a vendor-customer relationship, a contract is usually executed to serve as the formal, documented agreement between the two parties. Unfortunately, simply having a contract in place does not ensure that a vendor will invoice the customer at the agreed-upon rates, deliver the correct quantity or quality of materials, or perform the necessary activities required by procedure or law. The pressures, opportunities and rationalizations that can be catalysts for employee fraud also apply to vendors and suppliers, meaning these organizations cannot always be relied upon to police themselves.
The first response to the suggestion of vendor audits is often that they are unnecessary because contracts are in place to safeguard the organization in the event of fraud. While having a contract in place is good practice, there are opportunities for fraud in the development, issuance and management of contracts, such as:
Management often does not review contracts before they are issued to look for weaknesses that could allow fraud.
Developers might already be corrupt when they begin writing contracts.
Corrupt employees can amend contracts or give verbal exceptions to them.
The vendor/supplier actually builds in overcharging mechanisms into the contract that do not catch the attention of the hiring company.
Unfortunately, once funds have been paid to an unscrupulous vendor, it can be extremely difficult and costly to get them back, even with a contract in place. Further, waiting until an issue materializes can be more costly than the actual errors or fraud. Indirect costs can involve:
Recovery constraints
Operational costs
Audit and investigation costs
Legal costs
Fraud prevention strategies and ongoing, proactive vendor audits can significantly reduce an organization’s fraud risk and general overbilling issues. A continuous, well-communicated program can also improve vendor and supplier relationships, and help them understand what management expects from their billings and supporting documentation.
One of the biggest mistakes management can make is to begin conducting a vendor audit before assessing whether it is even a viable option. Just because a contract exists does not mean that conducting an audit is appropriate. Consider the following to determine the viability of a vendor audit:
Are the signed and executed contracts available?
Are there any change orders or verbal addendums? If so, what do they say?
Does management have its supporting documentation?
Does an adequate audit clause exist?
Unfortunately, not all audit clauses are created equal. And just because a contract contains a few sentences in a section titled “Right to Audit” does not mean that the related vendor audit will be straightforward — or effective. Most vendor/supplier audits fail to start or fail completely based solely on the rights, or lack thereof, that are documented in the audit clause section.
Many factors can affect the success or failure of a vendor audit, and some are entirely out of the control of the auditing organization. But one factor that can be controlled is actually performing vendor audits. As previously mentioned, billing fraud is among the most common schemes noted in the ACFE’s Report to the Nations. Simply having a good contract and an audit clause in place does not prevent billing fraud, nor does it aid in the recovery if vendor audits are never performed. A proactive vendor audit program could also be an additional bullet point to the organization’s anti-fraud program. Management that routinely conducts vendor audits might see a significant reduction in vendor audit costs and overbillings, and experience increased compliance by both its employees and vendors, as:
Organizational policies and procedures are strengthened based on issues occurring with multiple vendors.
Vendors know what to expect from audits, what documentation to keep and where their processes are generating overbillings.
Audit staff is more adept at conducting the audits and knowing what to look for.
Contract and audit clause language is improved based on other vendor audits experiences.
Vendors know that sooner or later the organization will conduct an audit, which might make them less inclined to engage intentionally in unethical conduct due to the increased risk of getting caught.
Company employees are aware that proactive vendor audits can uncover areas where they are not performing their jobs or engaging in conflicts of interests or kickbacks.
Implementing a vendor audit program can be a difficult and daunting task, possibly one of the reasons organizations do not conduct them. Some initial questions and concerns may include:
Where do we start?
Do we have good contracts and audit clause language?
What data and information do we need?
How do we identify the right audit candidates?
What red flags should we look for?
What do we do if we actually find fraud?
These concerns can be properly addressed if the organization makes one important decision: start the vendor audit process. There is a lot of information online that can get you started. There is training offered by professional organizations. There are also many firms that specialize in conducting vendor audits. The data is clear; there is a tremendous amount of fraud and risk with our vendors and suppliers. A comprehensive anti-fraud program must have a robust vendor audit program.
So the question is: are you going to look where the fraud is?
Ryan C. Hubbs CFE, CIA, PHR, CCSA is the Forensic Audit Manager for Halliburton and an ACFE Faculty Member. To learn more about conducting vendor audits, see the ACFE’s training calendar on the ACFE’s Detecting Fraud Through Vendor Audits training program.