10.2 Fraud Risks in Engagement Planning

Key Takeaways

  • During engagement planning, internal auditors should deliberately identify and assess fraud risks relevant to the engagement’s objectives and scope—not treat fraud as an afterthought.
  • Fraud risk assessment in planning considers incentives, opportunities created by process design, prior incidents, complexity, and management override potential.
  • Processes with significant fraud exposure commonly include cash handling, procurement and payables, payroll and benefits, revenue recognition and receivables, inventory, and IT access administration.
  • Planning responses may include targeted walkthroughs, data analytics, surprise procedures, extended sampling, or specialist support when fraud risk is elevated.
  • Recognizing fraud risk in planning does not mean every engagement becomes a fraud investigation; it means procedures are risk-based and red flags will not be ignored.
Last updated: July 2026

10.2 Fraud Risks in Engagement Planning

Quick Answer: When planning an engagement, internal auditors must recognize fraud risks tied to objectives and processes in scope, and pay special attention to activities with significant fraud exposure (cash, procurement, payroll, revenue recognition, privileged IT access, and similar). Planning then shapes procedures—analytics, SoD tests, surprise counts—proportionate to that risk.

Syllabus D2 moves from “what is fraud?” (D1) to “how do I build fraud into planning?” Domain IV expects more than a generic sentence in the work program (“consider fraud”). Effective planning identifies where fraud could occur, why it matters to engagement objectives, and what evidence will speak to those risks.

Fraud Risk Belongs in Planning—Not Only in Findings

Engagement planning typically clarifies objectives, scope, criteria, risks, and resource needs. Fraud risk is a subset of engagement risk and process risk, not a separate hobby project. Ask:

  1. What could go wrong intentionally in this process?
  2. Who could benefit, and how would they conceal it?
  3. Which controls should prevent or detect that deception?
  4. How could management override those controls?
  5. What planning decisions (nature, timing, extent of tests) follow?

If planning only lists operational efficiency risks and ignores intentional misstatement or theft, the work program may be incomplete—even if the engagement is not labeled a “fraud audit.”

How to Recognize Fraud Risks While Planning

Use structured inputs, then document conclusions in the planning memo or risk-and-control matrix.

Planning inputFraud-focused questionsExample signal
Objectives & scopeCould fraud prevent achievement of the process objective or corrupt reported results?Revenue engagement: cutoff and fictitious sales risk
Inherent process riskHigh value, high volume, convertible assets, subjective estimates?Cash, inventory, fair-value estimates
IncentivesBonuses, covenants, sales contests, cost-cutting pressure?Quarter-end “must hit” culture
Control designSoD gaps, manual overrides, weak reconciliations, limited monitoring?One person owns vendor master and payment release
HistoryPrior incidents, tips, audit findings, known control failures?Repeat AP duplicate-payment findings
Change & complexityNew systems, reorganizations, remote work, M&A, third parties?New ERP with unfinished access roles
Culture cuesFear of speaking up, exceptions normalized, tone issues?Managers ridicule reporters of bad news

Brainstorming (even a short team huddle) helps surface schemes management might not volunteer. Consider occupational theft, corruption in vendor selection, and financial reporting manipulation when reporting is in scope.

Planning Is Not Investigating

Recognizing elevated fraud risk means you may:

  • Expand testing of high-risk controls.
  • Add data analytics (duplicate vendors, weekend journal entries, round-dollar payments).
  • Use unpredictability (surprise cash counts, unannounced inventory observations).
  • Assign more experienced staff or request forensic/IT specialist support.
  • Clarify escalation paths if indicators appear.

It does not automatically convert the engagement into a full fraud investigation. Investigations often require distinct mandates, legal coordination, evidence handling, and sometimes external specialists. Planning should define what internal audit will do if red flags arise (see D3).

Processes with Significant Fraud Exposure

Certain processes repeatedly appear in fraud case studies and exam scenarios. Memorize the “why exposed” logic, not just the label.

Process / areaWhy fraud exposure is often highIllustrative schemesPlanning emphasis
Cash & treasuryLiquid, portable, immediately valuableSkimming, larceny, fraudulent wires, check tamperingSoD, reconciliations, payment approval, callback verification
Procurement & APLarge disbursements; vendor relationshipsKickbacks, bid rigging, fake vendors, duplicate paymentsVendor master controls, competitive bidding, three-way match, analytics
Payroll & HRRecurring payments; sensitive dataGhost employees, falsified hours, benefit fraudHR–payroll SoD, termination access cutoff, exception reports
Revenue & AREstimates, cutoff, channel pressureFictitious sales, channel stuffing, lapping, credit memo abuseRevenue recognition criteria, period-end entries, confirmations/analytics
Inventory & fixed assetsMovable/high-value items; write-off discretionTheft, scrap schemes, false write-offsCounts, custody, write-off approval, shrink analysis
Expense reimbursementDecentralized; trust-basedPersonal expenses, duplicates, inflated claimsPolicy tests, receipt validity, outlier analytics
IT access & changeKeys to records and concealmentUnauthorized access, log alteration, privileged misuseJoiner-mover-leaver, privileged access reviews, change management
Related parties & estimatesOpacity and judgmentUndisclosed relationships, biased reservesDisclosure completeness, estimate challenge, independence of reviewers

Cash and Liquid Assets

Cash processes deserve automatic fraud consideration in planning. Weak deposit timelines, shared safes, or unreconciled accounts create opportunity. For wires, planning often focuses on initiation vs. approval segregation and out-of-band verification for payee changes.

Procurement and Accounts Payable

Corruption and fraudulent disbursements thrive where vendor setup is loose. Planning should map who can create vendors, who can approve invoices, and whether receiving is independent. Analytics for new vendors, round amounts, and consecutive invoice numbers are common planning additions when risk is high.

Payroll

Ghost employee schemes exploit incomplete HR–payroll handoffs. Planning tests often include comparing payroll registers to HR active-employee lists and reviewing manual payments or terminated employees still paid.

Revenue Recognition

When engagement objectives touch financial reporting or sales processes, plan for management fraud risk: premature revenue, side agreements, and manual overrides. Period-end concentration of entries is a planning red flag that should drive timing of tests.

IT Access

Modern fraud frequently requires or is concealed through system access. Even a “process” audit (for example, AP) should plan to understand who can alter vendor masters, post journals, or disable audit logs. Privileged access without review is both an IT finding and a fraud opportunity.

Translating Fraud Risk into the Work Program

After identifying fraud risks, link each significant risk to:

  1. Controls expected (preventive and detective).
  2. Procedures to evaluate design and operation.
  3. Fraud-oriented procedures if control reliance is low (substantive analytics, detailed tests of transactions, observations).
  4. Documentation of why the extent of work is appropriate.

Example: AP engagement with weak vendor-master SoD → plan tests of new vendor additions, search for employee–vendor address matches, and sample payments to recently created vendors.

Coordination and Independence Notes

If management asks internal audit to “just find fraud” without clear objectives, refine the engagement to risk-based assurance on controls and processes, with a defined protocol for suspicions. If CAE or staff face pressure to ignore high fraud-risk areas in the plan, that is a governance/independence issue to escalate appropriately.

Study Close for D2

Carry a planning checklist:

  • Incentives? Opportunities? Override?
  • Which high-exposure processes are in scope?
  • What unpredictability or analytics will we add?
  • What is our escalation path if indicators appear?
/practice/iia-iapPractice questions with detailed explanations
Test Your Knowledge

During planning for an accounts payable assurance engagement, auditors learn that one clerk can add vendors, enter invoices, and generate the payment file, and that sales leadership is under intense pressure to cut costs through “preferred” suppliers. What is the most appropriate planning response?

A
B
C
D
Test Your Knowledge

Which process set is most consistently cited as carrying significant fraud exposure that internal auditors should explicitly consider when relevant to scope?

A
B
C
D
Test Your Knowledge

An engagement team notes elevated revenue fraud risk due to aggressive bonuses and frequent manual period-end journal entries. Which planning action best reflects D2 principles?

A
B
C
D