10.2 Fraud Risks in Engagement Planning
Key Takeaways
- During engagement planning, internal auditors should deliberately identify and assess fraud risks relevant to the engagement’s objectives and scope—not treat fraud as an afterthought.
- Fraud risk assessment in planning considers incentives, opportunities created by process design, prior incidents, complexity, and management override potential.
- Processes with significant fraud exposure commonly include cash handling, procurement and payables, payroll and benefits, revenue recognition and receivables, inventory, and IT access administration.
- Planning responses may include targeted walkthroughs, data analytics, surprise procedures, extended sampling, or specialist support when fraud risk is elevated.
- Recognizing fraud risk in planning does not mean every engagement becomes a fraud investigation; it means procedures are risk-based and red flags will not be ignored.
10.2 Fraud Risks in Engagement Planning
Quick Answer: When planning an engagement, internal auditors must recognize fraud risks tied to objectives and processes in scope, and pay special attention to activities with significant fraud exposure (cash, procurement, payroll, revenue recognition, privileged IT access, and similar). Planning then shapes procedures—analytics, SoD tests, surprise counts—proportionate to that risk.
Syllabus D2 moves from “what is fraud?” (D1) to “how do I build fraud into planning?” Domain IV expects more than a generic sentence in the work program (“consider fraud”). Effective planning identifies where fraud could occur, why it matters to engagement objectives, and what evidence will speak to those risks.
Fraud Risk Belongs in Planning—Not Only in Findings
Engagement planning typically clarifies objectives, scope, criteria, risks, and resource needs. Fraud risk is a subset of engagement risk and process risk, not a separate hobby project. Ask:
- What could go wrong intentionally in this process?
- Who could benefit, and how would they conceal it?
- Which controls should prevent or detect that deception?
- How could management override those controls?
- What planning decisions (nature, timing, extent of tests) follow?
If planning only lists operational efficiency risks and ignores intentional misstatement or theft, the work program may be incomplete—even if the engagement is not labeled a “fraud audit.”
How to Recognize Fraud Risks While Planning
Use structured inputs, then document conclusions in the planning memo or risk-and-control matrix.
| Planning input | Fraud-focused questions | Example signal |
|---|---|---|
| Objectives & scope | Could fraud prevent achievement of the process objective or corrupt reported results? | Revenue engagement: cutoff and fictitious sales risk |
| Inherent process risk | High value, high volume, convertible assets, subjective estimates? | Cash, inventory, fair-value estimates |
| Incentives | Bonuses, covenants, sales contests, cost-cutting pressure? | Quarter-end “must hit” culture |
| Control design | SoD gaps, manual overrides, weak reconciliations, limited monitoring? | One person owns vendor master and payment release |
| History | Prior incidents, tips, audit findings, known control failures? | Repeat AP duplicate-payment findings |
| Change & complexity | New systems, reorganizations, remote work, M&A, third parties? | New ERP with unfinished access roles |
| Culture cues | Fear of speaking up, exceptions normalized, tone issues? | Managers ridicule reporters of bad news |
Brainstorming (even a short team huddle) helps surface schemes management might not volunteer. Consider occupational theft, corruption in vendor selection, and financial reporting manipulation when reporting is in scope.
Planning Is Not Investigating
Recognizing elevated fraud risk means you may:
- Expand testing of high-risk controls.
- Add data analytics (duplicate vendors, weekend journal entries, round-dollar payments).
- Use unpredictability (surprise cash counts, unannounced inventory observations).
- Assign more experienced staff or request forensic/IT specialist support.
- Clarify escalation paths if indicators appear.
It does not automatically convert the engagement into a full fraud investigation. Investigations often require distinct mandates, legal coordination, evidence handling, and sometimes external specialists. Planning should define what internal audit will do if red flags arise (see D3).
Processes with Significant Fraud Exposure
Certain processes repeatedly appear in fraud case studies and exam scenarios. Memorize the “why exposed” logic, not just the label.
| Process / area | Why fraud exposure is often high | Illustrative schemes | Planning emphasis |
|---|---|---|---|
| Cash & treasury | Liquid, portable, immediately valuable | Skimming, larceny, fraudulent wires, check tampering | SoD, reconciliations, payment approval, callback verification |
| Procurement & AP | Large disbursements; vendor relationships | Kickbacks, bid rigging, fake vendors, duplicate payments | Vendor master controls, competitive bidding, three-way match, analytics |
| Payroll & HR | Recurring payments; sensitive data | Ghost employees, falsified hours, benefit fraud | HR–payroll SoD, termination access cutoff, exception reports |
| Revenue & AR | Estimates, cutoff, channel pressure | Fictitious sales, channel stuffing, lapping, credit memo abuse | Revenue recognition criteria, period-end entries, confirmations/analytics |
| Inventory & fixed assets | Movable/high-value items; write-off discretion | Theft, scrap schemes, false write-offs | Counts, custody, write-off approval, shrink analysis |
| Expense reimbursement | Decentralized; trust-based | Personal expenses, duplicates, inflated claims | Policy tests, receipt validity, outlier analytics |
| IT access & change | Keys to records and concealment | Unauthorized access, log alteration, privileged misuse | Joiner-mover-leaver, privileged access reviews, change management |
| Related parties & estimates | Opacity and judgment | Undisclosed relationships, biased reserves | Disclosure completeness, estimate challenge, independence of reviewers |
Cash and Liquid Assets
Cash processes deserve automatic fraud consideration in planning. Weak deposit timelines, shared safes, or unreconciled accounts create opportunity. For wires, planning often focuses on initiation vs. approval segregation and out-of-band verification for payee changes.
Procurement and Accounts Payable
Corruption and fraudulent disbursements thrive where vendor setup is loose. Planning should map who can create vendors, who can approve invoices, and whether receiving is independent. Analytics for new vendors, round amounts, and consecutive invoice numbers are common planning additions when risk is high.
Payroll
Ghost employee schemes exploit incomplete HR–payroll handoffs. Planning tests often include comparing payroll registers to HR active-employee lists and reviewing manual payments or terminated employees still paid.
Revenue Recognition
When engagement objectives touch financial reporting or sales processes, plan for management fraud risk: premature revenue, side agreements, and manual overrides. Period-end concentration of entries is a planning red flag that should drive timing of tests.
IT Access
Modern fraud frequently requires or is concealed through system access. Even a “process” audit (for example, AP) should plan to understand who can alter vendor masters, post journals, or disable audit logs. Privileged access without review is both an IT finding and a fraud opportunity.
Translating Fraud Risk into the Work Program
After identifying fraud risks, link each significant risk to:
- Controls expected (preventive and detective).
- Procedures to evaluate design and operation.
- Fraud-oriented procedures if control reliance is low (substantive analytics, detailed tests of transactions, observations).
- Documentation of why the extent of work is appropriate.
Example: AP engagement with weak vendor-master SoD → plan tests of new vendor additions, search for employee–vendor address matches, and sample payments to recently created vendors.
Coordination and Independence Notes
If management asks internal audit to “just find fraud” without clear objectives, refine the engagement to risk-based assurance on controls and processes, with a defined protocol for suspicions. If CAE or staff face pressure to ignore high fraud-risk areas in the plan, that is a governance/independence issue to escalate appropriately.
Study Close for D2
Carry a planning checklist:
- Incentives? Opportunities? Override?
- Which high-exposure processes are in scope?
- What unpredictability or analytics will we add?
- What is our escalation path if indicators appear?
/practice/iia-iapPractice questions with detailed explanationsDuring planning for an accounts payable assurance engagement, auditors learn that one clerk can add vendors, enter invoices, and generate the payment file, and that sales leadership is under intense pressure to cut costs through “preferred” suppliers. What is the most appropriate planning response?
Which process set is most consistently cited as carrying significant fraud exposure that internal auditors should explicitly consider when relevant to scope?
An engagement team notes elevated revenue fraud risk due to aggressive bonuses and frequent manual period-end journal entries. Which planning action best reflects D2 principles?