11.1 Fraud Prevention & Detection Controls
Key Takeaways
- Tone at the top from the board and senior management sets the ethical climate that either deters or enables fraud
- Segregation of duties separates custody, authorization, and recordkeeping so no single person can both commit and conceal fraud
- Authority levels and approval limits constrain high-risk transactions and create documented accountability trails
- Detective controls—whistleblower hotlines, reconciliations, and supervisory reviews—surface fraud after it occurs so losses can be limited
- An effective anti-fraud program blends preventive and detective controls; neither category alone is sufficient
Anti-fraud controls sit at the heart of Domain IV (Fraud Risks) on the IAP / CIA Part 1 syllabus. Knowing the fraud triangle is not enough—you must also understand how organizations prevent fraud from occurring and detect it when preventive controls fail. Internal auditors evaluate these controls during engagements, recommend improvements, and help management design a balanced control mix.
Why Controls Matter for Fraud Risk
Fraud thrives when three conditions align: pressure (or incentive), opportunity, and rationalization. Controls primarily attack the opportunity leg. Strong ethical culture and clear consequences also weaken rationalization. Preventive controls stop unauthorized acts before they succeed; detective controls identify anomalies after they occur so management can investigate and recover assets.
| Control category | Primary purpose | Typical timing | Example |
|---|---|---|---|
| Preventive | Stop fraud before it happens | Before the transaction | Segregation of duties, approval limits |
| Detective | Identify fraud after it occurs | After the transaction | Reconciliations, hotlines, reviews |
| Corrective | Fix root causes and recover loss | After detection | Process redesign, recovery actions |
For the exam, expect scenario questions that ask which control type is illustrated or which control best addresses a described fraud risk.
Tone at the Top
Tone at the top refers to the ethical climate created by the board of directors and senior management. It is the foundation of an anti-fraud program. If leaders cut corners, override controls, or tolerate questionable results, employees learn that fraud is acceptable—or at least survivable.
Strong tone at the top typically includes:
- A written code of ethics or code of conduct that is communicated, trained, and enforced
- Visible board and executive support for integrity, including consequences for violations
- Realistic performance targets that do not create intolerable pressure to manipulate results
- Open channels for raising concerns without retaliation
- Consistent modeling: leaders follow the same rules they expect of others
Exam trap: Tone at the top is not a software control or a checklist item. It is a governance and culture control. When a scenario describes executives ignoring policy or pressuring staff to "make the numbers," the underlying control weakness is often tone at the top—even if technical controls exist on paper.
Internal auditors assess tone through interviews, observation of management behavior, review of ethics complaints, and evaluation of how policy exceptions and violations are handled. A polished code of conduct with zero enforcement is a red flag, not a strength.
Segregation of Duties
Segregation of duties (SoD) is the classic preventive control against occupational fraud. The core idea: no one person should control all steps of a transaction in a way that allows them to both commit and conceal fraud.
The three incompatible functions that should be separated are:
| Function | What it means | Fraud risk if combined |
|---|---|---|
| Custody | Physical or electronic control of assets | Can steal assets |
| Authorization | Approval to initiate or approve transactions | Can approve fictitious or personal transactions |
| Recordkeeping | Recording transactions in the books | Can conceal theft by falsifying records |
Practical SoD Examples
- The employee who receives customer cash should not also post receivables and reconcile the bank account.
- The purchasing agent who selects vendors should not also approve invoices and issue payments.
- IT administrators with powerful system access should not also perform business-unit reconciliations without compensating review.
In smaller organizations, perfect SoD may be impossible. Compensating controls—such as owner review of bank statements, dual signatures, or periodic surprise audits—become critical. Exam questions often test whether you recognize when compensating detective controls are needed because SoD cannot be fully achieved.
Authority Levels and Approval Limits
Authority levels (also called approval limits or delegated authorities) define who may authorize transactions of what size and type. They constrain opportunity by ensuring high-risk or high-dollar transactions receive appropriate scrutiny.
Effective authority frameworks usually specify:
- Dollar thresholds by role (for example, managers may approve expenses up to $5,000; directors up to $50,000)
- Transaction-type restrictions (capital projects, related-party deals, write-offs, and wire transfers may require elevated approval)
- Documentation requirements so approvals leave an audit trail
- Escalation rules for exceptions, overrides, and emergency approvals
Common weaknesses internal auditors find:
- Limits that exist in policy but are not enforced in the system
- Frequent overrides without documented rationale or subsequent review
- Authority that follows the person rather than the role after transfers or promotions
- Split transactions ("invoice splitting") designed to stay under approval thresholds
Example: A payables clerk processes five invoices of $4,900 to the same vendor in one week when the manager's approval limit is $5,000. Individually each invoice looks compliant; collectively the pattern may indicate circumvention of authority levels.
Detective Controls: Finding What Prevention Missed
Even strong preventive controls fail. Detective controls provide a second line of defense.
Whistleblower Hotlines
Whistleblower hotlines (and related anonymous reporting channels) are among the most effective fraud-detection tools. Research consistently shows that tips—often from employees—are the leading detection method for occupational fraud.
Key design features of an effective hotline:
- Anonymous and confidential reporting options
- Multiple channels (phone, web, mobile) available 24/7 where feasible
- Clear non-retaliation policy backed by investigation of retaliation claims
- Independent intake and triage (often outsourced or routed outside the alleged perpetrator's chain of command)
- Timely follow-up, documented case handling, and reporting to the audit committee for significant matters
Internal auditors evaluate whether the hotline is promoted, trusted, and actually used—and whether trends in complaints feed fraud risk assessments.
Reconciliations
Reconciliations compare two independent sets of records to identify discrepancies. Common fraud-relevant reconciliations include:
- Bank reconciliations (cash book vs. bank statement)
- Accounts receivable aging vs. subsidiary ledger totals
- Inventory counts vs. perpetual records
- Payroll registers vs. HR headcount and time records
For reconciliations to detect fraud, they must be performed by someone independent of custody and posting, investigated when variances arise, and reviewed by a supervisor. A reconciliation that is rubber-stamped without investigation of reconciling items provides little protection.
Supervisory Reviews
Supervisory reviews are detective (and sometimes preventive) controls in which a manager examines subordinates' work, exception reports, or high-risk transactions. Examples include:
- Manager review of expense reports and credit-card statements
- Review of system access logs and override reports
- Analytical review of margin, scrap, or write-off trends
- Spot checks of vendor master changes and employee bank-account changes
Supervisory review fails when it is perfunctory, when the supervisor is too busy or too close to the subordinate, or when exception reports are never generated. Auditors look for evidence of actual review—signatures with dates, comments on exceptions, and follow-up on unresolved items—not just a policy that says review should occur.
Building a Balanced Anti-Fraud Control Program
An organization that relies only on prevention may miss fraud that slips through. One that relies only on detection may suffer larger losses before discovery. Best practice combines:
| Layer | Focus | Internal audit's typical focus |
|---|---|---|
| Culture | Tone at the top, ethics | Assess governance messaging and enforcement |
| Preventive | SoD, authority limits, access controls | Test design and operating effectiveness |
| Detective | Hotlines, reconciliations, reviews, analytics | Evaluate coverage, independence, and follow-up |
| Response | Investigation and remediation | Assess protocols and lessons learned |
When evaluating controls, distinguish design effectiveness (is the control properly designed to address the risk?) from operating effectiveness (does it actually operate as designed?). A well-designed SoD matrix that is routinely overridden fails operating effectiveness.
Key Takeaways for the Exam
- Tone at the top sets the ethical climate that enables or deters fraud
- Segregation of duties separates custody, authorization, and recordkeeping
- Authority levels limit who can approve high-risk transactions
- Whistleblower hotlines, reconciliations, and supervisory reviews are core detective controls
- Prevention and detection work together; compensating controls matter when SoD is imperfect
Which control primarily attacks the opportunity element of the fraud triangle by ensuring no single employee can both steal assets and conceal the theft in the accounting records?
A company has a written code of ethics, but executives routinely override purchase approval limits without documentation and employees who raise concerns are transferred to undesirable roles. What is the most significant control weakness illustrated?
Which of the following is BEST classified as a detective anti-fraud control?