11.1 Fraud Prevention & Detection Controls

Key Takeaways

  • Tone at the top from the board and senior management sets the ethical climate that either deters or enables fraud
  • Segregation of duties separates custody, authorization, and recordkeeping so no single person can both commit and conceal fraud
  • Authority levels and approval limits constrain high-risk transactions and create documented accountability trails
  • Detective controls—whistleblower hotlines, reconciliations, and supervisory reviews—surface fraud after it occurs so losses can be limited
  • An effective anti-fraud program blends preventive and detective controls; neither category alone is sufficient
Last updated: July 2026

Anti-fraud controls sit at the heart of Domain IV (Fraud Risks) on the IAP / CIA Part 1 syllabus. Knowing the fraud triangle is not enough—you must also understand how organizations prevent fraud from occurring and detect it when preventive controls fail. Internal auditors evaluate these controls during engagements, recommend improvements, and help management design a balanced control mix.

Why Controls Matter for Fraud Risk

Fraud thrives when three conditions align: pressure (or incentive), opportunity, and rationalization. Controls primarily attack the opportunity leg. Strong ethical culture and clear consequences also weaken rationalization. Preventive controls stop unauthorized acts before they succeed; detective controls identify anomalies after they occur so management can investigate and recover assets.

Control categoryPrimary purposeTypical timingExample
PreventiveStop fraud before it happensBefore the transactionSegregation of duties, approval limits
DetectiveIdentify fraud after it occursAfter the transactionReconciliations, hotlines, reviews
CorrectiveFix root causes and recover lossAfter detectionProcess redesign, recovery actions

For the exam, expect scenario questions that ask which control type is illustrated or which control best addresses a described fraud risk.

Tone at the Top

Tone at the top refers to the ethical climate created by the board of directors and senior management. It is the foundation of an anti-fraud program. If leaders cut corners, override controls, or tolerate questionable results, employees learn that fraud is acceptable—or at least survivable.

Strong tone at the top typically includes:

  • A written code of ethics or code of conduct that is communicated, trained, and enforced
  • Visible board and executive support for integrity, including consequences for violations
  • Realistic performance targets that do not create intolerable pressure to manipulate results
  • Open channels for raising concerns without retaliation
  • Consistent modeling: leaders follow the same rules they expect of others

Exam trap: Tone at the top is not a software control or a checklist item. It is a governance and culture control. When a scenario describes executives ignoring policy or pressuring staff to "make the numbers," the underlying control weakness is often tone at the top—even if technical controls exist on paper.

Internal auditors assess tone through interviews, observation of management behavior, review of ethics complaints, and evaluation of how policy exceptions and violations are handled. A polished code of conduct with zero enforcement is a red flag, not a strength.

Segregation of Duties

Segregation of duties (SoD) is the classic preventive control against occupational fraud. The core idea: no one person should control all steps of a transaction in a way that allows them to both commit and conceal fraud.

The three incompatible functions that should be separated are:

FunctionWhat it meansFraud risk if combined
CustodyPhysical or electronic control of assetsCan steal assets
AuthorizationApproval to initiate or approve transactionsCan approve fictitious or personal transactions
RecordkeepingRecording transactions in the booksCan conceal theft by falsifying records

Practical SoD Examples

  • The employee who receives customer cash should not also post receivables and reconcile the bank account.
  • The purchasing agent who selects vendors should not also approve invoices and issue payments.
  • IT administrators with powerful system access should not also perform business-unit reconciliations without compensating review.

In smaller organizations, perfect SoD may be impossible. Compensating controls—such as owner review of bank statements, dual signatures, or periodic surprise audits—become critical. Exam questions often test whether you recognize when compensating detective controls are needed because SoD cannot be fully achieved.

Authority Levels and Approval Limits

Authority levels (also called approval limits or delegated authorities) define who may authorize transactions of what size and type. They constrain opportunity by ensuring high-risk or high-dollar transactions receive appropriate scrutiny.

Effective authority frameworks usually specify:

  1. Dollar thresholds by role (for example, managers may approve expenses up to $5,000; directors up to $50,000)
  2. Transaction-type restrictions (capital projects, related-party deals, write-offs, and wire transfers may require elevated approval)
  3. Documentation requirements so approvals leave an audit trail
  4. Escalation rules for exceptions, overrides, and emergency approvals

Common weaknesses internal auditors find:

  • Limits that exist in policy but are not enforced in the system
  • Frequent overrides without documented rationale or subsequent review
  • Authority that follows the person rather than the role after transfers or promotions
  • Split transactions ("invoice splitting") designed to stay under approval thresholds

Example: A payables clerk processes five invoices of $4,900 to the same vendor in one week when the manager's approval limit is $5,000. Individually each invoice looks compliant; collectively the pattern may indicate circumvention of authority levels.

Detective Controls: Finding What Prevention Missed

Even strong preventive controls fail. Detective controls provide a second line of defense.

Whistleblower Hotlines

Whistleblower hotlines (and related anonymous reporting channels) are among the most effective fraud-detection tools. Research consistently shows that tips—often from employees—are the leading detection method for occupational fraud.

Key design features of an effective hotline:

  • Anonymous and confidential reporting options
  • Multiple channels (phone, web, mobile) available 24/7 where feasible
  • Clear non-retaliation policy backed by investigation of retaliation claims
  • Independent intake and triage (often outsourced or routed outside the alleged perpetrator's chain of command)
  • Timely follow-up, documented case handling, and reporting to the audit committee for significant matters

Internal auditors evaluate whether the hotline is promoted, trusted, and actually used—and whether trends in complaints feed fraud risk assessments.

Reconciliations

Reconciliations compare two independent sets of records to identify discrepancies. Common fraud-relevant reconciliations include:

  • Bank reconciliations (cash book vs. bank statement)
  • Accounts receivable aging vs. subsidiary ledger totals
  • Inventory counts vs. perpetual records
  • Payroll registers vs. HR headcount and time records

For reconciliations to detect fraud, they must be performed by someone independent of custody and posting, investigated when variances arise, and reviewed by a supervisor. A reconciliation that is rubber-stamped without investigation of reconciling items provides little protection.

Supervisory Reviews

Supervisory reviews are detective (and sometimes preventive) controls in which a manager examines subordinates' work, exception reports, or high-risk transactions. Examples include:

  • Manager review of expense reports and credit-card statements
  • Review of system access logs and override reports
  • Analytical review of margin, scrap, or write-off trends
  • Spot checks of vendor master changes and employee bank-account changes

Supervisory review fails when it is perfunctory, when the supervisor is too busy or too close to the subordinate, or when exception reports are never generated. Auditors look for evidence of actual review—signatures with dates, comments on exceptions, and follow-up on unresolved items—not just a policy that says review should occur.

Building a Balanced Anti-Fraud Control Program

An organization that relies only on prevention may miss fraud that slips through. One that relies only on detection may suffer larger losses before discovery. Best practice combines:

LayerFocusInternal audit's typical focus
CultureTone at the top, ethicsAssess governance messaging and enforcement
PreventiveSoD, authority limits, access controlsTest design and operating effectiveness
DetectiveHotlines, reconciliations, reviews, analyticsEvaluate coverage, independence, and follow-up
ResponseInvestigation and remediationAssess protocols and lessons learned

When evaluating controls, distinguish design effectiveness (is the control properly designed to address the risk?) from operating effectiveness (does it actually operate as designed?). A well-designed SoD matrix that is routinely overridden fails operating effectiveness.

Key Takeaways for the Exam

  • Tone at the top sets the ethical climate that enables or deters fraud
  • Segregation of duties separates custody, authorization, and recordkeeping
  • Authority levels limit who can approve high-risk transactions
  • Whistleblower hotlines, reconciliations, and supervisory reviews are core detective controls
  • Prevention and detection work together; compensating controls matter when SoD is imperfect
Test Your Knowledge

Which control primarily attacks the opportunity element of the fraud triangle by ensuring no single employee can both steal assets and conceal the theft in the accounting records?

A
B
C
D
Test Your Knowledge

A company has a written code of ethics, but executives routinely override purchase approval limits without documentation and employees who raise concerns are transferred to undesirable roles. What is the most significant control weakness illustrated?

A
B
C
D
Test Your Knowledge

Which of the following is BEST classified as a detective anti-fraud control?

A
B
C
D