For internal audit and assurance professionals. Curated, not algorithmic.

New since July 28

October 2025

linkedin.com ·
Fraud Risk Assessments, Oh Yes there is a Need

In the last article we discussed whether a Fraud Risk Assessment (FRA) was a need or a waste?

My opinion is there is a need, and they are most assuredly a value add. We spend enormous amounts of time and money to hire, train, equip, and retain employees, not to mention the sums spent to advertise and entice customers or the lengths we go to find and groom suppliers and vendors. So why would we not spend a small portion to ensure our controls are sufficient to prevent or detect the tried and true as well as the newest fraud scenarios?

So, what kind of FRAs are available? Many people feel there is only one kind of FRA, a full-fledged assessment covering the entire organization with:
• Surveys to numerous managers and employees
• in-person and virtual interviews and brainstorming sessions involving executive, senior, and mid-level management and selected senior employees
• Scenario development
• Controls analysis across the organization for their consistency or not
• Development of a heat map showing the low to high fraud risks based on their impact and likelihood
Whew, I am tired just thinking and writing about one.
While a full FRA is certainly a great idea and needed at times such as:
• Recent merger or acquisition to determine new additional fraud risks
• Significant fraud loss
• Fraud loss by a senior management official
• Expansion to country that requires an FRA
• Company significantly expands into geographic area with high fraud risk
• Company significantly expands into a service or function they have no prior experience/expertise in

There are other less resource rich and more nimble ways to keep your fingers on historical, current, and future fraud risks in between a full FRA.

I will outline the ones I have used over the years and found them to be helpful and timely in educating the management and employee populations as well as detecting and preventing fraud risks and control gaps and weaknesses.

They are:
• Enhance the current or Add a section on Fraud Risk to the Annual Risk Assessment.
• Include 2 to 4 unscheduled reviews, time, and resources available, in Annual Audit Plan. Quarterly review of management requests, audits from previous 6 to 12 months, and/or Annual Risk Assessment rankings for unscheduled review candidates.
• Include a Fraud Risk Questionnaire in Internal Audit planning and share with the auditee for their input.
• Quarterly meeting with department representatives involved in investigations for fraud, ethics, cyber, and administrative violations. The goal is learning about respective current investigations for crossover, duplications, and department/function process education.
o Example: HR Employee Relations investigating management timecard misuse but felt funny. Internal Audit Investigations follow up review determined manager not misusing from lack of training but colluding with employee and intentionally abusing timecard for kickbacks.
• Form a special committee from selected departments to advise on current/potential fraud risks they are concerned about. Suggested areas are Finance, Accounting, Supply Chain, Sales, Marketing, Security, Ethics, Legal, HR/ER.

What we need to remember for any FRA is the goal is to not only make sure we identify and mitigate known and potential fraud risks, but also to educate our front-line defenders, the managers, and employees. They know the job, the area, and what is and is not suspicious; they just need education, guidance, and an escalation process. They are the tip of the spear to identify anomalies and suspicious activities and understand who to report to, their job is then done, except to provide support during the follow-on investigation.

I hope this provides some ideas on the different kinds of FRAs. In the next two articles I will share examples that have worked for me in various companies, and I hope they will provide templates for your use. Please remember that one size FRA does not fit all entities at any given time.

Other resources to consider on this topic can be found on:
Association of Certified Fraud Examiners - https://www.acfe.com/search?s=ethics
Institute of Internal Auditors - Global Resources in Internal Audit | The IIA

Please let me know if I can help or be a resource for your questions / comments on the content of this article. If you would like clarification on or related articles, please connect with me and I can share any you would like. My fraud risk assessment experiences have included healthcare and manufacturing environments.
George

News & Blogs · Global Read more
linkedin.com ·
Other Ways to Assess Fraud Risk

In my last article we discussed there are various ways to have a Fraud Risk Assessment (FRA) other than a resource intensive one.

Examples to consider include:
1. Include a Fraud Risk Questionnaire in Internal Audit planning and share with the auditee for their input. The questions should cover:
a. Last time they reported suspicious activity and to who?
b. Their knowledge of how and where to report suspicious activity (Hotline, Compliance, Internal Audit, Legal, etc.).
c. Fraud Awareness (aka: Policy Compliance and Employee Poor Choices) training. This is always fun because for the most part they do it, just do not realize they are. An example on timecards/card scan is each employee does their own card/scan. Consequences for punching in or scanning in another employee is generally termination and just like that they realize that is fraud awareness training. You can cover other areas like expense reports, corporate or P-card use, Accounts Payable, asset inventory order/check in/document, etc. This opens up a line of discussion and future education and collaboration.
d. Ethics education, compliance, Hotline use, and who to contact for questions.
e. Offer to share sample questionnaire upon request

2. Quarterly meeting with representatives from some/all for HR/Employee Relations, Cybersecurity, Ethics/Compliance, Security, Legal, and Internal Audit/Suspicious Financial Activity Unit. My luck with these meetings was to share the investigations each was working on, their status, if administrative action(s) planned hearing the allegation and investigation results could also lead to additional investigation from Internal Audit team if possible unrecognized financial fraud potential not part of the initial team’s investigation. Internal Audit would generally work in an advisory capacity with the initial team retaining control. The meeting was an exchange of each team’s work and if assistance or guidance was needed from another team or if the investigation should be transferred or if there were two or more investigations of different allegations involving the same person or department and how best to proceed with just one team taking control or forming a task force.

3. Form a Dirty Dozen Fraud Committee of department subject matter experts and hold periodic (quarterly) discussions/meetings for updates and insights on potential fraud risks in their areas. Additionally use them as a resource as needed for investigations.

4. Other ideas that help spread fraud awareness include:
a. Communication via organization intranet with high level and redacted information on relevant fraud investigations that show the policy(s) violated, if relevant control(s) in place and violated, in some instances how the case was reported, and the consequences to the employee and the control reviewer if they consistently failed to use the control that resulted in the fraud going on more than 2 or 3 review cycles. Z

This lets organization employees know there are policies and controls, and they are expected to be followed, there is a reporting process, and it is acted upon because there is zero tolerance for fraud.

b. Continuous Monitoring is always a great idea. A suggestion is to not label it as Fraud Monitoring, because fraud is determined after an investigation, not before. The monitoring identifies anomalies that need investigation to determine if there is:
i. Poor/Inadequate:
1. communications,
2. policies,
3. controls,
4. training,
ii. Employee arrogance to do it their way and not the policy/control directed way,
iii. Yes there are also intentional acts to circumvent the controls for employee personal gain.
The first 5 are policy non-compliant, but areas for management to address and mitigate. It is the sixth one that is fraud and needs referral to the appropriate investigations team for detailed follow-up.

I hope this provides some background on other ways to assess fraud risk.

Other resources to consider on this topic can be found on:
Association of Certified Fraud Examiners - https://www.acfe.com/search?s=ethics
Institute of Internal Auditors - Global Resources in Internal Audit | The IIA

Please let me know if I can help or be a resource for your questions / comments on the content of this article. If you would like clarification on this or related articles, please connect with me and I can share / comment on any you would like. My fraud risk assessment experiences have included healthcare and manufacturing environments.
George

News & Blogs · Global Read more
auditboard.com ·
How AI provides essential infrastructure for auditors

The article argues that internal audit must treat artificial intelligence as essential infrastructure rather than an optional tool, since AI enables faster risk detection, predictive insights, and connected assurance that manual methods cannot match. However, it stresses that strong governance is critical to manage AI-specific risks such as bias, data privacy, and over-reliance, ensuring audits remain credible, ethical, and forward-looking.

News & Blogs · Global Read more

September 2025

longbridge.com ·
In just a few minutes, AI easily passed the CFA Level 3 exam

Researchers from NYU Stern and GoodFin tested 23 large language models and found that cutting-edge reasoning models like Gemini 2.5 Pro, Claude Opus, and o4-mini successfully passed the notoriously difficult CFA Level III mock exam using chain-of-thought prompting. While these models outperformed traditional ones on complex financial reasoning, experts note AI still falls short of human professionals in contextual understanding and client interaction.

News & Blogs · Global Read more
auditboard.com ·
Rising risks, shifting priorities: What the IIA’s Risk in Focus 2026 report means for internal audit

The IIA’s 2026 Risk in Focus Report highlights a volatile risk environment for North American organizations, with geopolitical uncertainty, cybersecurity threats, and digital disruption driving major challenges for internal auditors. Chief audit executives are urged to close gaps between top risks and audit priorities by strengthening cyber assurance, engaging in AI governance, and developing agile strategies to address unprecedented volatility.

News & Blogs · Global Read more
linkedin.com ·
The Metrics That Matter: How to Measure Audit, Risk and Control Functions Without Killing the Culture

![beyond_the_lines](https://media.licdn.com/dms/image/v2/D4E12AQFIhXwOZ-7pRA/article-cover_image-shrink_720_1280/B4EZlrwPutKcAI-/0/1758449434850?e=1761782400&v=beta&t=vOXrPBtNmCBOvqImnoHhDH87g4DqFlfr5rzVUyXu2yw)
This article emphasizes that traditional activity-based metrics in audit, risk, and control functions often drive the wrong behaviors, such as prioritizing volume over insight or compliance over trust. Instead, it argues for outcome-focused, strategically relevant, and culture-supportive metrics that balance hard data with soft signals, promote transparency, and foster better decision-making.

News & Blogs · Global Read more
linkedin.com ·
Introducing: Beyond the Lines newsletter

![beyond_the_lines](https://media.licdn.com/dms/image/v2/D4E12AQFIhXwOZ-7pRA/article-cover_image-shrink_720_1280/B4EZlrwPutKcAI-/0/1758449434850?e=1761782400&v=beta&t=vOXrPBtNmCBOvqImnoHhDH87g4DqFlfr5rzVUyXu2yw) An assurance based newsletter to help empower audit, risk, and controls leaders to think differently - and lead with impact. By [Tim Buckley](https://www.linkedin.com/in/tim-buckley-3a5a062a/), CEO of [INTEGRAL Assurance](https://www.integralassurance.com/) | Helping Businesses Build Robust Control Frameworks & Drive Transformation. Published biweekly.

News & Blogs · Global Read more
accountingtoday.com ·
Internal audit and the CFO: 5 safeguards to independence

In this article, Richard Chambers argues that having internal audit report administratively to the CFO, rather than the CEO, risks overemphasizing financial controls and neglecting non-financial risks, thereby compromising organizational oversight and independence. It proposes five safeguards, such as clear charter language and board oversight, to help maintain internal audit's objectivity in this reporting structure.

News & Blogs · Global Read more
podcasts.apple.com ·
Introducing: The Audit - Cybersecurity Podcast

![The_Audit_Podcast](https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/b5/bf/3e/b5bf3ebf-2e3d-d08c-d874-22d820507e92/mza_12379254504281601617.jpg/300x300bb.webp)
Brought to you by IT Audit Labs. Trusted cyber security experts and their guests discuss common security threats, threat actor techniques and other industry topics. IT Audit Labs provides organizations with the leverage of a network of partners and specialists suited for your needs.

​We are experts at assessing security risk and compliance, while providing administrative and technical controls to improve our clients’ data security. Our threat assessments find the soft spots before the bad guys do, identifying likelihood and impact, while our security control assessments rank the level of maturity relative to the size of the organization.

News & Blogs · Global Read more
podcasts.apple.com ·
Introducing: Internal Audit podcast by ACCA

![Internal Audit Podcast](https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/f6/0e/20/f60e2088-e26d-2082-61f9-fd78e5049805/mza_8665497320946256120.jpg/300x300bb.webp)

The ACCA (the Association of Chartered Certified Accountants) is the only truly global professional accountancy body. This podcast is for professionals working in governance, risk, assurance, control and efficiency.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →