Guide on fraud

A useful guide on fraud has been produced by accountants Ernst & Young for the CBI.

It notes that fraud is a significant threat facing all businesses. Attempts to quantify the risk are almost impossible as much fraud is undetected, and fraud which has been detected is often unreported. Not only are there financial losses, but fraud can damage reputations, cause markets to lose confidence, undermine staff morale, and consume management time. By far, most fraud is internal, that is, it is committed by employees and others involved in the business, rather than outsiders.

The document looks at the types of fraud, how they are committed, and the risks posed by computers. It gives guidance on how to minimise the risk. The 11 most effective ways of preventing fraud in order are:

1 internal controls (1);

2 internal audit (2);

3 password security (8);

4 management review (3);

5 entry and exit controls (11);

6 external audit (9);

7 management change (5);

8 whistle-blowing (4);

9 outside information (7)

10 anonymous tip-off (6)

11 accident (10).

The 11 most effective ways of detecting fraud are the same 11 items but in the order as indicated by the numbers in brackets.

Examples of effective measures to minimise fraud include:

  • pre-employment screening;
  • physical access controls;
  • employee appraisal and monitoring;
  • having a fraud policy;
  • a corporate culture of openness, transparency and trust;
  • a fraud reporting hotline, going beyond the requirements of Public Interest Disclosure Act 1998;
  • a contingency plan;
  • insurance cover;
  • specific controls on the information technology environment.

The fraud contingency plan should determine priorities. It is too late to wait until a fraud has been committed, for the directors then to argue whether the priority is to recover the money or to bring the perpetrators to justice.

Other requirements of the plan include:

  • identifying who will lead the investigation;
  • conducting the investigation properly;
  • how to deal with suspects;
  • ensuring police involvement and that proper legal advice has been taken, so that (for example) evidence obtained is admissible in court;
  • managing the media while the investigation is in hand;
  • reporting the outcome so that either rumours are scotched or management has demonstrated how it takes effective action.

Warning signs are listed in an appendix under factors regarding people, processes and profits. There is practical guidance on putting the controls in place and in devising a fraud ethics policy and contingency plan.

Fraud: Risk and Prevention is available for £10 from Caspian Publishing Ltd, Millbank Tower, Millbank, London SW1P 4QP.

[2000]

Related Posts

Leave a Reply