Explain the Academic Research Lifecycle

ZEKEB
The_Effects_of_the_Presence_of.pdf

The Effects of the Presence of Fraud and Auditor Certification Considering Professional

Skepticism on Fraud Risk Assessment Performance

Dissertation Manuscript

Submitted to Northcentral University

School of Business and Technology Management

in Partial Fulfillment of the

Requirements for the Degree of

DOCTOR OF PHILOSOPHY

by

CYNTHIA E. VANCE

San Diego, California

May 2017

ProQuest Number:

All rights reserved

INFORMATION TO ALL USERS The quality of this reproduction is dependent upon the quality of the copy submitted.

In the unlikely event that the author did not send a complete manuscript and there are missing pages, these will be noted. Also, if material had to be removed,

a note will indicate the deletion.

ProQuest

Published by ProQuest LLC ( ). Copyright of the Dissertation is held by the Author.

All rights reserved. This work is protected against unauthorized copying under Title 17, United States Code

Microform Edition © ProQuest LLC.

ProQuest LLC. 789 East Eisenhower Parkway

P.O. Box 1346 Ann Arbor, MI 48106 - 1346

10288565

10288565

2017

Abstract

Financial statement fraud is still prevalent in the United States, even after the enactment

of the Sarbanes-Oxley Act of 2002 and SAS No. 99. Researchers and auditing regulators

report that auditors’ fraud risk assessments are not effectively detecting financial

statement fraud. Both professional skepticism and fraud knowledge are attributes that

may have an effect on auditors’ fraud risk assessment outcomes. The purpose of this

quantitative between-participants research study was to examine the independent

variables of the presence of fraud and auditor certification while controlling for

professional skepticism in relation to the dependent variable, fraud risk assessment

performance, for participants within the U.S., who are certified public accountants

(CPAs) and/or certified fraud examiners (CFEs). The experiment was conducted in the

online environment using Qualtrics online survey software. Participants completed the

Hurtt Professional Skepticism Scale questionnaire to measure professional skepticism

and conducted a fraud risk assessment of a company’s set of financial statements (Form

10-K). Statistical data analysis was performed using both a two-way analysis of variance

(ANOVA) and a two-way analysis of covariance (ANCOVA) in conjunction with

planned comparisons to determine interaction effects of the variables. Results revealed a

significant effect of the presence of fraud on fraud risk assessment performance with and

without the influence of professional skepticism. However, the absence of fraud risk

condition produced a higher fraud risk assessment performance than the presence of fraud

risk condition, which did not support the hypothesis. Moreover, the effect of auditor

certification had an insignificant effect on fraud risk assessment performance with and

without the influence of professional skepticism. Results of this study provide support

that a quantitative review of financial statements does not accurately assess fraud risk,

even if the evaluators possess higher levels of professional skepticism. Further research

should be conducted to evaluate the minimum requirements prescribed by the accounting

profession for effective financial statement fraud detection.

Acknowledgements

I would like to thank my dissertation committee chair, Dr. Vanessa Ann Claus, for

all of her assistance and dedication to my research project. She went over and above to

help me complete the dissertation process on time. Additionally, I am appreciative of the

time commitment and advice from my dissertation reviewers, Dr. Garrett Smiley and Dr.

Stephen Verrill. I am also grateful to Dr. Gail Gessert and the faculty members at

Northcentral University who equipped me with the skills needed to become a scholar

through their valuable feedback and insights during my coursework. I also would like to

thank my wonderful son, Cory, for understanding my time commitment to this project,

and my friends and family for their continued support. I thank God for being with me

during this journey and giving me the strength to persevere.

Table of Contents

Chapter 1: Introduction……………………………………………………………………1

Statement of the Problem ............................................................................................. 5 Purpose of the Study .................................................................................................... 6 Theoretical Framework ................................................................................................ 9 Nature of the Study .................................................................................................... 11 Research Questions .................................................................................................... 13 Significance of the Study ........................................................................................... 15 Definition of Key Terms ............................................................................................ 17 Summary .................................................................................................................... 18

Chapter 2: Literature Review ............................................................................................ 20

Theoretical Framework .............................................................................................. 21 Regulations ................................................................................................................ 24 Risk Assessment Models ........................................................................................... 34 Auditors' Attributes .................................................................................................... 49 Certified Fraud Examiners ......................................................................................... 66 Summary .................................................................................................................... 69

Chapter 3: Research Method ............................................................................................. 71

Research Methodology and Design ........................................................................... 76 Population and Sample .............................................................................................. 80 Materials/Instrumentation .......................................................................................... 82 Operational Definition of Variables .......................................................................... 84 Study Procedures ....................................................................................................... 87 Data Collection and Analysis .................................................................................... 88 Assumptions .............................................................................................................. 91 Limitations ................................................................................................................. 92 Delimitations.............................................................................................................. 93 Ethical Assurances ..................................................................................................... 93 Summary .................................................................................................................... 95

Chapter 4: Findings ........................................................................................................... 97

Trustworthiness of Data ............................................................................................. 98 Results...................................................................................................................... 103 Research Question 1 ................................................................................................ 109 Research Question 2 ................................................................................................ 110 Research Question 3 ................................................................................................ 111 Evaluation of Findings ............................................................................................. 112 Summary .................................................................................................................. 114

Chapter 5: Implications, Recommendations, and Conclusions ...................................... 115 Implications ............................................................................................................. 117 Recommendations for Practice ................................................................................ 128 Recommendations for Future Research ................................................................... 130 Conclusions.............................................................................................................. 132

References ....................................................................................................................... 137 Appendices ...................................................................................................................... 145 Appendix A: Hurtt Professional Skepticism Scale ......................................................... 145 Appendix B: CITI Requirements Report ........................................................................ 146 Appendix C: Internal Review Board Approval .............................................................. 147 Appendix D: Informed Consent Form ............................................................................ 148 Appendix E: Qualtrics Online Survey ............................................................................ 151

List of Tables Table 1 Descriptive Statistics of Age and Years of Experience for Audit and Fraud Risk

Assessment………………………………………………………………………….…..105 Table 2 Descriptive Statistics of Gender and U.S. Geographic Region..………………..106 Table 3 Descriptive Statistics of Fraud Risk Assessment and Professional Skepticism Score ……………………………………..………………………………………..….…107 Table 4 Group Means With and Without the Effect of the Covariate……………….....…109

1

Chapter 1: Introduction

Financial statement fraud is the intentional act of misrepresenting financial

information, which harms the users who rely on the false data (Association of Certified

Fraud Examiners, 2014; George, 2012). The occurrence of financial statement fraud has

a significant impact on economies and stakeholders including employees, investors,

creditors, auditors, regulators, and communities (Beasley, Carcello, Hermanson, & Neal,

2010). In the late 1990s and early 2000s financial statement fraud was discovered in

large United States (U.S.) public companies (e.g., Enron, WorldCom, and Waste

Management), which resulted in the collapse of the respected public accounting firm,

Arthur Andersen (Soltani, 2014). Congress enacted legislation, the Sarbanes-Oxley Act

of 2002 (SOX), in response to the financial scandals (Alleyne & Elson, 2013). SOX

brought significant changes to the public accounting profession, including a change from

self-regulation to regulation by a private board, the Public Company Accounting

Oversight Board (PCAOB).

In accordance with the Statement on Auditing Standard (SAS) No. 99,

Consideration of Fraud in a Financial Statement Audit, auditors of U.S. public

companies are required to perform a fraud risk assessment as part of financial statement

audits to detect material financial misstatements (Kassem & Higson, 2012; Victoravich,

2010). An auditor’s role is to provide reasonable assurance that the financial statements

are free from material misstatements (Buchholz, 2012). However, according to the

PCAOB, “the lack of professional skepticism is a serious problem in auditors’ fraud

investigations” (Trompeter, Carpenter, Desai, Jones, & Riley, 2013, p. 304).

Investigations ensued calling for research to ascertain the influences of fraud training on

2

auditors’ fraud judgments (Carpenter, Durtschi, & Gaynor, 2011a; Hogan, Rezaee, Riley,

& Velury, 2008 as cited in Trompeter et al., 2013). The research study examined

variables that influence auditors’ detection and reporting of financial statement fraud in

the U.S. during the post-SOX period (2005–2014). The research study participants were

CPAs and/or CFEs from the Association of Certified Fraud Examiners (ACFE), the

American Institute of Certified Public Accountants (AICPA), and the Virginia Society of

Certified Public Accountants (VSCPA) populations.

The U.S. Congress responded to financial statement fraud after the stock market

crash of 1929 by enacting two statutory laws – the Securities Act of 1933 and the

Securities Exchange Act of 1934 (Cavaliere, Mulvaney, Swerdlow, & Baldo, 2014). The

Securities Act regulates new public offerings, which requires specific information to be

provided to investors on the securities offered for public sale (Alleyne & Elson, 2013).

The Securities Exchange Act established the Securities and Exchange Commission (SEC)

to regulate the subsequent sales of publicly traded securities on the securities exchanges

(e.g., New York Stock Exchange and NASDAQ; Alleyne & Elson, 2013). The SEC

requires public companies to provide regular reports (e.g., Form 10-K and Form 10-Q) on

business operations, financial conditions, and management, which are maintained in the

SEC’s database that is available to the public (Cavaliere et al., 2014). The Securities Act

of 1933 and the Securities Exchange Act of 1934 did not prevent the major corporate

fraud scandals that occurred during the late 1990s through 2002, which include, but are

not limited to Adelphia, Enron, HealthSouth, Tyco, and WorldCom (Nix & Morgan,

2013; Soltani, 2014). In response to political pressure to prevent financial statement

fraud, Congress enacted SOX in 2002, which established the PCAOB to provide

3

oversight of public accounting firms and publically held corporations (Hulsart, James, &

Cummings, 2012). The PCAOB adopted the American Institute of Certified Public

Accountants (AICPA) Auditing Standards Board’s (ASB) auditing standards as its

interim standards. SOX increased corporate management’s responsibilities by requiring

officer certification of the financial statements and the establishment and reporting of

internal controls over financial reporting (ICFR) to name a few (Victoravich, 2010).

SOX also required auditors to opine on the ICFR, which included the performance of a

fraud risk assessment (Victoravich, 2010).

The ASB also responded to the demand for a reduction in fraudulent financial

reporting in 2002 by issuing SAS No. 99 (later codified as AU Section 316), which

expanded auditors’ responsibilities on fraud assessment during a financial statement audit

(Victoravich, 2010). According to SAS No. 99, auditors must (a) brainstorm and

document potential fraud risks during the audit planning stage, (b) identify potential fraud

risks by making inquiries of management and others, and (c) consider fraud risk factors

and other data to identify risk of material misstatement in the financial statements due to

fraud (Nix & Morgan, 2013, p. 2). SAS No. 99 uses the fraud triangle as the theoretical

framework for auditors to evaluate fraud risk. The fraud triangle, identified in SAS No.

99, defines the elements necessary for fraud to occur as incentives, opportunities, and

attitudes (Nix & Morgan, 2013). SAS No. 99 also emphasizes the importance of

professional skepticism to identify, evaluate, communicate, and document the risks of

material misstatements due to fraud (Nix & Morgan, 2013). The auditing standards

define professional skepticism as “an attitude that includes a questioning mind, being

alert to conditions that may indicate possible misstatement due to fraud or error, and a

4

critical assessment of audit evidence” (Lee, Welker, & Wang, 2013, p. 213). Hence, SAS

No. 99 is a significant regulation for the auditing profession as it provides guidance for

auditors in the detection and reporting of fraudulent financial statements. SAS No. 99

clarifies the responsibilities of auditors in relation to the risk of fraud in financial

statements by using the fraud triangle theoretical framework to assess fraud risks (Nix &

Morgan, 2013).

Even though SAS No. 99 requires a fraud risk assessment, a financial statement

audit does not provide absolute assurance that the financial statements are free from

material misstatement due to fraud. The auditors must demonstrate that the audit

procedures designed and used, including a fraud risk assessment, provide reasonable

assurance that the financial statements are free from material misstatement (Love, 2012).

The purpose of a financial statement audit is to render an opinion on the fair presentation

of the audited entity’s financial statements, not to find fraud (Love, 2012). Love (2012)

identified auditing standards’ testing limitations and the failure of auditors to exercise

professional skepticism, integrity, and objectivity throughout the audit as the reasons that

financial statement audits often fail to detect fraudulent reporting.

SAS No. 99 recommends the use of certified fraud examiners (CFEs) to assist

organizations with fraud prevention and detection (Nix & Morgan, 2013). The CFE

certification was created by the ACFE in 1988 in response to the demand for expertise in

fraud detection and prevention (Nix & Morgan, 2013). ACFE membership requires

passing the CFE “exam which tests knowledge in the areas of criminology, prevention

and deterrence, fraudulent financial transactions, fraud investigation, and legal elements

of fraud” (Nix & Morgan, 2013, p. 3). The ACFE attests that CFEs “have knowledge of

5

fraud assessment, detection, and prevention methods” (Nix & Morgan, 2013, p. 4). Even

with the clarifications of auditors’ responsibilities and defined methodologies in SAS No.

99, to detect and report financial statement fraud, financial statement fraud is still a

problem in the global economy.

Statement of the Problem

Occupational fraud, including financial statement fraud, “is a universal problem

for businesses around the globe” (Association of Certified Fraud Examiners, 2014, p. 5).

PricewaterhouseCoopers reported that 30% of companies worldwide were victims of

fraud in 2009 (Murphy & Dacin, 2011). The ACFE’s Report to the Nations on

Occupational Fraud and Abuse reported that approximately 5% of organizations’ annual

revenues are lost to fraud, which is equivalent to approximately 3.7 trillion dollars

worldwide (Drew, 2014, para. 1). Drew (2014) reported that 48% of the fraud cases were

in the U.S. and that “financial statement frauds were the least common, but most costly,

representing 9% of cases and a median loss of $1 million” (para. 14). Hence, 13 years

after the enactment of SOX, financial statement fraud is still prevalent, not only in the

U.S., but also worldwide (Association of Certified Fraud Examiners, 2014).

Auditors’ fraud risk assessments are not effectively detecting financial statement

fraud. Hopwood, Leiner, and Young (2012) reported that auditors who applied SAS No.

99 detected only “5 to 20 percent of the occupational frauds” (p. 169). Albrecht and

Hoopes (2014) posited the following reasons why auditors are unable to detect fraud (a)

voluminous nature of accounting records, (b) use of outsiders to conceal the fraud, (c)

reluctance of people to disclose information about fraudulent acts, (d) use of forgery and

lying to provide barriers against discovery, and (e) lack of performance of sufficient

6

financial statement audits. Additionally, Albrecht and Hoopes (2014) identified four

factors that prevent auditors from performing sufficient financial statement audits to

detect financial statement fraud, which include (a) inadequate training and experience, (b)

poor audit planning, gathering of evidence, and examining controls, (c) lack of due

professional care, and (d) lack of independence (p. 20). Trompeter, Carpenter, Desai,

Jones, and Riley (2013) stated that the PCAOB inspections found deficiencies in

auditors’ responses to fraud risk. Trompeter et al. (2013) recommended future research

to ascertain if the deficiencies are a result of the auditors’ failure to respond or a result of

the auditors’ inability to respond when appropriate fraud assessment techniques are used.

Hurtt, Brown-Liburd, Earley, and Krishnamoorthy (2013) acknowledged the importance

of professional skepticism in fraud detection, but stated, “research is limited to the

actions that auditors actually take related to their professional skepticism” (p. 72). Due to

the complexity of the interrelationships in conducting a fraud risk assessment and the

importance of fraud detection for the auditing profession and regulators, additional

research is needed to understand fraud risk assessments and the elements influencing

fraud risk assessment performance (Trompeter et al., 2013). Effective fraud risk

assessments identify fraud risk factors (i.e., opportunities, incentives, and pressures),

which may lead auditors to discover of financial statement fraud (Nix & Morgan, 2013).

Purpose of the Study

The purpose of this experimental between-participants quantitative research study

was to examine the theoretical underpinnings of fraud and attribution in relation to the

independent variables of the presence of fraud and auditor certification, the control

variable of professional skepticism, and the dependent variable, fraud risk assessment

7

performance, for participants within the U.S. who are either certified fraud examiners

and/or certified public accountants. The participants were from the population of the

Association of Certified Fraud Examiner’s (ACFE) LinkedIn group and online forum of

certified fraud examiners and associate memberships, the population of the American

Institute of Certified Public Accountants’ (AICPA) LinkedIn group memberships, and the

population of the Virginia Society of Certified Public Accountants’ (VSCPA) LinkedIn

group and online forum memberships. The ACFE is the largest global anti-fraud

organization comprised of certified fraud examiners, associate members, student

members, and educator members (Association of Certified Fraud Examiners, 2014). The

AICPA represents the largest global professional association of accountants comprised of

regular members (i.e., licensed or previously certified/licensed CPAs), associate

members, non-CPA associates, CPA exam candidate affiliate, and student affiliates

(“About the AICPA,” n.d., para. 1). The VSCPA is a professional association of the state

of Virginia comprised of certified public accountants, associate members, and student

members (“About the Virginia Society of CPAs,” n.d.). Auditor certification was

categorized by the self-identification of certification attributes (CFE or CFE/CPA or

CPA). Professional skepticism was measured by using Hurtt’s (2010) six-point Likert

skepticism scale to measure the trait of professional skepticism. Hurtt (2010) validated

the skepticism scale for use in research by using students and professional auditors.

Fraud risk was operationalized by the use of two sets of financial statement data from the

Securities and Exchange Commission’s (SEC) public database for the years 2005–2014

of which one set contained high-fraud risk and one set contained low-fraud risk. Fraud

risk assessment performance measured the auditors’ ability to assess fraud risk. Fraud

8

risk assessment performance was measured on a seven-point Likert scale data using four

Likert-type items combined so that an interval measurement scale could be used for

quantitative analyses. Boone and Boone (2012) illustrated that a composite score (i.e.,

sum or mean) may be calculated from four or more similar Likert-type items, which

allows the use of parametric analysis using the analysis of variance (ANOVA) technique.

NGO Security (2010) combined probability of occurrence and impact of risk to illustrate

the use of a seven-point Likert scale to quantitatively assess risk by multiplying the two

rating values together; the higher number represents higher risk. Jaffar, Haron, Iskandar,

and Salleh (2011) used a seven-point Likert scale ranging from extremely unlikely to

extremely likely to measure auditors’ ability to assess fraud risk with ANOVA as the

statistical method for evaluation. A Likert scale was used as the instrument to measure

fraud risk assessment performance because neither the PCAOB nor the AICPA have a

standardized fraud risk assessment tool that is used by auditors to assess fraud risk

(Albrecht & Hoopes, 2014; Boritz et al., 2015). Generally, auditors measure fraud risk as

high, medium, or low; hence, a numeric value is not traditionally attributed to fraud risk

assessments (Boritz et al., 2015).

The population for this study included U.S. certified fraud examiners (CFEs) and

U.S. certified public accountants (CPAs) that were members of the ACFE, AICPA,

and/or the VSCPA. Members were invited to participate in the experiment using the

ACFE online discussion forum, the ACFE and the AICPA LinkedIn discussion forums,

and the VSCPA online and LinkedIn discussion forums. The experimental construct was

a 2X3 between-participants, which was a design with two levels for one independent

variable and three levels for the second independent variable to test the fraud risk

9

variable. SPSS Statistics version 24 was used to conduct a two-way analysis of variance

(ANOVA) to determine the effect that the categorical independent variables (the presence

of fraud risk and auditor certification) had on the interval dependent variable, fraud risk

assessment performance. Next, SPSS was used to conduct a two-way analysis of

covariance (ANCOVA) to examine the influence of the control variable, professional

skepticism, on the fraud risk assessment performance dependent variable. Planned

contrasts were also conducted in SPSS to determine interaction effects of the auditor

certification variables through the use of the Helmert contrast.

Theoretical Framework

The theoretical framework used to examine the effect of the presence of fraud and

auditor certification, while considering professional skepticism on fraud risk assessment

performance were the fraud theory and attribution theory. Fraud theory is used by

researchers, the accounting profession, and auditing regulators to develop training and

tools for the detection and prevention of financial statement fraud (Boyle et al., 2015).

The fraud triangle serves as the foundation for numerous theories on fraudulent behavior

(Boyle et al., 2015). The fraud triangle was developed by Donald Cressey in the early

1950s to explain the criteria that must be present for fraud to occur, which includes

pressure, opportunity, and rationalization (Dorminey, Fleming, Kranacher, & Riley,

2012). Both the PCAOB and the Auditing Standards Board (ASB) integrate the fraud

triangle in the auditing standards for fraud risk assessment (i.e., AU Section 316 and SAS

No. 99; Dorminey et al., 2012).

Dorminey et al. (2012) developed a meta-model framework that incorporated

various models of fraud theory to expand the fraud triangle concept. Dorminey et al.

10

recommended using the meta-model for future research to examine “interactions among

constructs, mediation and moderation effects of controls, and better tools or approaches

to enhance detection procedures” (p. 576). In comparison to Dorminey et al.’s research,

Kassem and Higson (2012) proposed a new fraud triangle that incorporates components

of fraud models (i.e., M.I.C.E., the fraud triangle, the fraud scale, and the fraud diamond).

Kassem and Higson (2012) refuted the fraud triangle as a model for fraud detection

because the elements of pressure and rationalization are unobservable and other

important elements ignored (e.g., fraudster’s capabilities). Cohen, Ding, Lesage, and

Stolowy (2010) concurred that the fraud triangle is insufficient for fraud detection. By

examining fraud theory, causal relationships or predictive models may be established,

confirmed, or refuted to contribute to the accounting profession’s field of knowledge of

fraud risk assessments to increase the detection of financial statement fraud.

Attribution theory relates the performance of a future task to the causes of prior

successes or failures of the same task based upon internal and/or external attributes

(Jaffar, Haron, Iskandar, & Salleh, 2011). The auditors’ ability to conduct an effective

fraud risk assessment may vary based on internal attributes (i.e., professional skepticism

and fraud knowledge) and/or an external attribute (e.g., fraud risk assessment method).

Fathil and Schmidtke (2010) found that auditors who were moderately suspicious were

more accurate in fraud detection than auditors who were highly suspicious because highly

suspicious auditors overcompensated for their professional skepticism. Kassem and

Higson (2012) recommended that regulators provide more guidance to auditors on fraud

risk assessments and consider “putting the Certified Fraud Examiner (CFE) certificate as

a requirement to get the CPA examination/qualification” (p. 288). By examining

11

attribution theory, the relationships of fraud knowledge, professional skepticism, and

fraud risk assessment method may be better understood to contribute to the knowledge of

how the variables effect the fraud risk assessment performance.

Nature of the Study

The research study used a quantitative between-participants research design to

assess the effect of the presence of fraud risk and auditor certification while considering

professional skepticism on fraud risk assessment performance. The experiment was

conducted in the online environment using Qualtrics online survey software. The

population was U.S. CFEs and U.S. CPAs with a membership in the ACFE, AICPA,

and/or VSCPA. The participants (sample) were those who responded on a volunteer

basis. The ACFE and the AICPA organizations were selected to use as the population

because the ACFE is the largest anti-fraud organization worldwide and the AICPA is the

largest professional accounting association in the U.S. (Association of Certified Fraud

Examiners, 2014; “About the AICPA,” n.d., para. 1). The VSCPA was included in the

population as a representative of a state society of professional accountants. First, three

comparative groups (CFE, CFE/CPA, or CPA) were created by participant self-

identification from the random sample to measure auditor certification. Random

assignment was used to divide the auditor certification groups into comparative groups–

three groups analyzed high-fraud risk data and three groups analyzed low-fraud risk data.

External validity was strengthened from the use of random sampling and the use of

random assignment of participants to test the fraud risk variable.

The SEC database of U.S. publicly traded companies was used to randomly select

a corporation that reported an occurrence of financial statement fraud and restated its

12

financial statements during 2005–2014. Internal validity was strengthened by the use of

an actual set of fraudulent and restated financial statements for the fraud risk variable.

The assessment tool used for the professional skepticism control variable was the

validated Hurtt Professional Skepticism Scale (Hurtt, 2010), which is designed to

measure professional skepticism. The fraud risk assessment performance was measured

using an interval measurement Likert scale. The participants used four similar Likert-

type questions to assess fraud risk (Boone & Boone, 2012), including (a) likelihood of

fraud risk, (b) significance of fraud risks, (c) significance of anti-fraud controls in use,

and (d) likelihood of fraud. A fraud risk assessment composite score was calculated from

the answers to the questions by using MS Excel’s sum function. SPSS was used to

perform statistical data analysis using both a two-way analysis of variance (ANOVA) and

a two-way analysis of covariance (ANCOVA) to ascertain the effect of the independent

variables and the influence of the covariate on the dependent variable.

A quantitative research method was appropriate for this study in that the intent of

the study was to identify and evaluate the variables (i.e., the presence of fraud risk,

auditor certification, and professional skepticism) that influence an outcome (i.e., fraud

risk assessment performance) by developing and testing hypotheses. A between-subjects

experimental design was chosen in that participants were randomly assigned to one of

two conditions (i.e., high-fraud risk and low-fraud risk) to make inferences from the

research findings and achieve generalization. Moreover, a quantitative method provided

for the use of statistical data analysis to conclude causality as the variables was measured

using an interval scale to strengthen validity and reliability.

13

According to Park and Park (2016), a quantitative research method provides for

justification due to reliability and validity testing in a controlled environment, which is in

contrast to a qualitative research method that provides for discovery in natural conditions.

A quantitative study provides for recommendation(s) to research findings by using

structured data collection techniques coupled with statistical analyses compared to the

inconclusive research findings from unstructured or semi-structured data collection

techniques of a qualitative study (Park & Park, 2016). Barnham (2015) emphasized that

the key tenants of quantitative research include controlled conditions, large base sizes,

and the application of statistics to make inferences about the population, which is in

contrast to qualitative research that focuses on perceptions of how incidences occur,

which cannot be generalized to the population. Historically, qualitative studies have

received criticisms of validity and reliability (Barnham, 2015).

A qualitative research method was not appropriate for the research study in that

the variables of the design were identified prior to the collection of data, and data

collection was operationalized to relate the variables to the research questions and

hypotheses for hypothesis testing not hypothesis generation. Instrument-based questions

was utilized instead of open-ended questions as the intent was to provide for

generalizability using statistical interpretations not particularity using emergent

interpretations based on judgment.

Research Questions

The research questions examined the effect of the presence of fraud risk and the

effect of auditor certification while considering professional skepticism on fraud risk

assessment performance by answering the questions: (a) Does the presence of fraud risk

14

have an effect on fraud risk assessment performance? (b) Does a certification in fraud

knowledge have an effect on fraud risk assessment performance? (c) Does professional

skepticism influence fraud risk assessment performance? Gaps in current literature exist

regarding the impact of auditor certification and professional skepticism on fraud risk

assessment performance (Hammersley, 2011; Ray, 2015; Trompeter et al., 2013).

Hammersley (2011) stated that he was not aware of any research that examined “the

impact of auditor knowledge” (p. 111), and Trompeter et al. (2013) called for future

research on fraud training and testing, improvements to auditors’ professional skepticism,

and fraud detection methods (pp. 307-310). Ray (2015) provided examples

demonstrating that professional skepticism is a current challenge for auditors and a

significant concern for the PCAOB, especially after recent inspections of audits

conducted by registered public firms. Ray recommended further studies on the lack of

professional skepticism criticisms found by the regulators and the skeptical mindset of

auditors. The following research questions guided the study to examine the effects of the

presence of fraud risk and the effects of auditor certification while considering

professional skepticism on fraud risk assessment performance.

Q1. Does the presence of fraud risk have an effect on fraud risk assessment

performance?

Q2. Does a certification in fraud knowledge have an effect on fraud risk

assessment performance?

15

Q3. Does professional skepticism influence fraud risk assessment performance?

Hypotheses

H10. The presence of fraud risk does not have a significant effect on fraud risk

assessment performance.

H1a. A high level of fraud risk produces a high-fraud risk assessment

performance.

H20. A certification for fraud knowledge does not have a significant effect on

fraud risk assessment performance.

H2a. Auditors that possess a certification in fraud detection produce more

effective fraud risk assessment performance than auditors without the

certification.

H30. The level of auditor professional skepticism does not have a significant

influence on fraud risk assessment performance.

H3a. Auditors that exhibit professional skepticism produce more effective fraud

risk assessment performance than auditors without this attribute.

Significance of the Study

Financial statement fraud continues to be prevalent regardless of the regulations

imposed for prevention and detection. Based on ACFE’s 2014 Report to the Nations on

Occupational Fraud and Abuse, Verschoor (2014) stated, “fraud continues to be a

significant problem for companies around the world” (p. 11). Verschoor (2014) reported

that external audits were found to be the least effective fraud detection method, which

provides support for the need to assess auditors’ attributes in relation to fraud risk

assessments. Kravitz (2012) quantified the significance of audit failures for fraud

16

detection in excess of 1 trillion dollars, which is indicative that financial statement fraud

is a significant problem for the auditing profession. Boyle, Carpenter, and Hermanson

(2012) discussed the high occurrence of chief executive officers (CEOs) and chief

financial officers (CFOs) involved in financial statement frauds. Even though SOX

requires external auditors to be selected by audit committees, the CEOs and the CFOs

still have a significant influence on the selection of external auditors, which may diminish

auditor objectivity (Boyle et al., 2012). Hence, it is essential that auditors possess both

professional skepticism and fraud knowledge to make effective fraud risk assessments

(Trompeter et al., 2013).

Hurtt et al. (2013) stated that most research on fraud detection focuses on auditor

judgment instead of auditor actions, which is the focus of the PCAOB and the SEC.

Hurtt et al. (2013) claimed that “Academic research indicates that auditors do approach

an audit with the intention of being professionally skeptical and they respond to risk by

changing behaviors; however, the SEC and PCAOB have consistently found a lack of

professional skepticism” (p. 72). Thus, a gap exists between the researchers and the

regulators, which supports the need for future research to aid in the detection of financial

statement fraud. According to PCAOB (2015), the three key areas under review, due to

significant deficiencies found during auditor inspections, are as follows: auditing internal

control over financial reporting, assessing and responding to risks of material

misstatement, and auditing accounting estimates. The PCAOB findings provide support

for ascertaining the value of a CFE certification in comparison to a CPA certification.

Nix and Morgan (2013) encouraged future researchers to reexamine the value of the CFE

certification.

17

The research study targeted auditors, regulators, and academicians. The

participants were CPAs and/or CFEs who were randomly selected and assigned to the

comparative groups to strengthen external validity. An actual set of fraudulent and

restated financial statements were used to strengthen the internal validity of the fraud risk

assessment process. The findings from the research study enhanced the body of

knowledge of the influences of auditor attributes (i.e., certification and professional

skepticism) and the presence of fraud to the outcome of fraud risk assessments.

Definition of Key Terms

The following key terms are used throughout the paper. The definitions include

terms related to the research study that may not be commonly known or understood.

Understanding the key terms provided will offer readers a comprehensive understanding

of the research project.

Financial statement fraud. Financial statement fraud is the false representation

of financial information with knowledge from the presenter that the representation

is false, and there is a financial damage to people receiving the information

resulting from reliance on this information (George, 2012).

Fraud. Fraud is any act, expression, omission, or concealment designed to

deceive and disadvantage another party (Fraud, 2011).

Fraud risk assessment. A fraud risk assessment is the auditors’ judgment

process for assessing the likelihood of financial statement fraud (Kochetova-

Kozloski, Messier, & Eilifsen, 2011).

18

Fraud risk assessment method. The fraud risk assessment method is an audit

procedure or strategy used by auditors to perform fraud risk assessments (Knapp

& Knapp, 2001).

Fraud risk assessment performance. Fraud risk assessment performance is the

auditors’ ability or inability to detect financial statement fraud (Jaffar, Haron,

Iskandar, & Salleh, 2011).

Occupational fraud. Occupational fraud is the use of one’s occupation for

personal enrichment through the deliberate misuse or misapplication of an

organization’s resources or assets (Association of Certified Fraud Examiners,

2014).

Summary

This chapter provided an introduction to the quantitative research study and the

need for effective fraud risk assessments to detect financial statement fraud. Financial

statement fraud continues to negatively affect companies worldwide (Association of

Certified Fraud Examiners, 2014; Drew, 2014; Murphy & Dacin, 2011). Regulators have

sought to minimize financial statement fraud by requiring management and auditors to

conduct fraud risk assessments (Dorminey et al., 2012). The quantitative experimental

between-participants research design examined the influence of two independent

variables (e.g., the presence of fraud risk and auditor certification), while considering

professional skepticism, on the dependent variable, fraud risk assessment performance, to

add to the body of knowledge on auditors’ detection of financial statement fraud. Six

comparison groups – high-fraud risk with CFE; high-fraud risk with CFE and CPA; high-

fraud risk with CPA; low-fraud risk with CFE; low-fraud risk with CFE and CPA; low-

19

fraud risk with CPA – with participants from the population of the ACFE, AICPA, and

VSCPA memberships of certified fraud examiners and certified public accountants were

used to test the hypotheses. Fraud theory and attribution theory was the theoretical

framework used to guide the quantitative research study.

20

Chapter 2: Literature Review

A synthesis of extant literature on fraud and attribution theory was conducted to

find gaps in the current body of knowledge in relation to financial statement fraud. The

literature review was organized into the following categories: regulations, risk assessment

models, auditors’ attributes, and certified fraud examiners. Auditors are bound by

auditing standards when conducting audits; hence, the regulations influence auditors’

conduct (Reffett, 2010). Auditing standards prescribe that auditors must conduct fraud

risk assessments but allow for the performance of auditor judgment for the outcome

assessment (Love, 2012). Auditors’ attributes, specifically knowledge, skills, experience,

and characteristics, are elements used to make fraud risk assessment judgments

(Trompeter et al., 2013). The one characteristic emphasized by the accounting profession

and regulators for auditors to possess is professional skepticism (Ray, 2015). Certified

fraud examiners exhibit specialized knowledge in financial statement fraud detection and

prevention.

Northcentral University Library’s EBSCO database was used to locate the sources

within the literature review. Boolean searches, which combine words and phrases using

operators (i.e., AND, OR, NOT), were conducted (Radecki, 1982). The researcher

utilized various keywords, as deemed appropriate, due to the need to define and limit the

searches. Keywords utilized by the researcher included audit regulation, certified fraud

examiners, financial statement fraud, fraud risk assessment, fraud triangle, and

professional skepticism. The majority of literature mentioned throughout this study

comes from scholarly peer-reviewed journals. The utilization of peer-reviewed journal

articles was due to the need to have accurate and reliable data sources as these articles are

21

written and reviewed by experts in the field. A variety of refereed journals were used

from the areas of accounting, auditing, and ethics, such as Accounting Review, Auditing:

A Journal of Practice & Theory, CPA Journal, and Journal of Business Ethics. There

were a few common findings from the articles reviewed. First, financial statement fraud

is a significant problem even after regulations have been enacted for prevention and

detection. Second, auditors are not finding and/or reporting financial statement fraud

even though fraud risk assessments are performed. Third, the fraud triangle may not be

the most effective framework for financial statement fraud detection even though it is the

prescribed methodology by the auditing regulations (e.g., AU Section 316 and SAS No.

99). Fourth, auditors’ attributes have been found to have an influence on fraud risk

assessments; moreover, the attribute of professional skepticism is emphasized for the

performance of effective fraud risk assessments. Fifth, there is increased support for the

role of CFEs in the fraud risk assessment process.

Theoretical Framework

The theoretical framework used to examine the effect of the presence of fraud and

auditor certification, while considering professional skepticism on fraud risk assessment

performance were the fraud theory and attribution theory. Fraud theory is used by

researchers, the accounting profession, and auditing regulators to develop training and

tools for the detection and prevention of financial statement fraud (Boyle et al., 2015).

The fraud triangle serves as the foundation for numerous theories on fraudulent behavior

(Boyle et al., 2015). The fraud triangle was developed by Donald Cressey in the early

1950s to explain the criteria that must be present for fraud to occur, which includes

pressure, opportunity, and rationalization (Dorminey, Fleming, Kranacher, & Riley,

22

2012). Both the PCAOB and the Auditing Standards Board (ASB) integrate the fraud

triangle in the auditing standards for fraud risk assessment (i.e., AU Section 316 and SAS

No. 99; Dorminey et al., 2012).

Dorminey et al. (2012) developed a meta-model framework that incorporated

various models of fraud theory to expand the fraud triangle concept. Dorminey et al.

recommended using the meta-model for future research to examine “interactions among

constructs, mediation and moderation effects of controls, and better tools or approaches

to enhance detection procedures” (p. 576). In comparison to Dorminey et al.’s research,

Kassem and Higson (2012) proposed a new fraud triangle that incorporates components

of fraud models (i.e., M.I.C.E., the fraud triangle, the fraud scale, and the fraud diamond).

Kassem and Higson (2012) refuted the fraud triangle as a model for fraud detection

because the elements of pressure and rationalization are unobservable and other

important elements ignored (e.g., fraudster’s capabilities). Cohen, Ding, Lesage, and

Stolowy (2010) concurred that the fraud triangle is insufficient for fraud detection. By

examining fraud theory, causal relationships or predictive models may be established,

confirmed, or refuted to contribute to the accounting profession’s field of knowledge of

fraud risk assessments to increase the detection of financial statement fraud.

Attribution theory relates the performance of a future task to the causes of prior

successes or failures of the same task based upon internal and/or external attributes

(Jaffar, Haron, Iskandar, & Salleh, 2011). The auditors’ ability to conduct an effective

fraud risk assessment may vary based on internal attributes (i.e., professional skepticism

and fraud knowledge) and/or an external attribute (e.g., fraud risk assessment method).

Fathil and Schmidtke (2010) found that auditors who were moderately suspicious were

23

more accurate in fraud detection than auditors who were highly suspicious because highly

suspicious auditors overcompensated for their professional skepticism. Kassem and

Higson (2012) recommended that regulators provide more guidance to auditors on fraud

risk assessments and consider “putting the Certified Fraud Examiner (CFE) certificate as

a requirement to get the CPA examination/qualification” (p. 288). By examining

attribution theory, the relationships of fraud knowledge, professional skepticism, and

fraud risk assessment method may be better understood to contribute to the knowledge of

how the variables effect the fraud risk assessment performance.

The research question, “Does the presence of fraud risk have an effect on fraud

risk assessment performance,” and the related hypothesis, “A high level of fraud risk

produces a high-fraud risk assessment performance,” used the fraud theory as the selected

theoretical framework. Since the fraud triangle is the methodology required in current

practice for financial statement fraud risk assessments (Dorminey et al., 2012), fraud

theory was the applicable theory selected to strengthen internal validity. Attribution

theory was the theoretical framework used to answer the research questions, “Does a

certification in fraud knowledge have an effect on fraud risk assessment performance”

and “Does professional skepticism influence fraud risk assessment performance,” along

with the related hypotheses, “Auditors that possess a certification in fraud detection and

exhibit professional skepticism produce more effective fraud risk assessment

performance.” Since professional skepticism and fraud knowledge are internal attributes

(Jaffar et al., 2011), attribution theory was the applicable theory selected to examine the

relationship of the auditors’ attributes on fraud risk assessment performance.

24

Regulations

Auditors are required to follow the Statement on Auditing Standards No. 99 (SAS

No. 99) and Auditing Standard No. 3 (AS3) when conducting fraud risk assessments, as

well as to follow the AICPA Code of Professional Conduct. SAS No. 99 prescribes that

auditors use the fraud triangle to assess financial statement fraud during the planning

stages of an audit (Kassem & Higson, 2012). The fraud triangle examines fraud through

the elements of incentive/pressure, opportunity, and rationalization (Dorminey et al.,

2012). The incentives/pressures to commit financial statement fraud may be caused by

analysts’ expectations, compensation arrangements tied to earnings, debt covenant

requirements, and going-concern issues (Hogan, Rezaee, Riley, & Velury, 2008).

Opportunities for fraud are created by a lack of internal controls over financial reporting,

complex transactions, related party interactions, and ineffective corporate governance

(Hogan et al., 2008; Levy, 2015). Hogan et al. (2008) attributed precise accounting

standards for managers’ rationalization in managing earnings as auditors fail to require

adjustments when precise standards are used in contrast to standards that require

judgment. According to Dorminey et al. (2010), the fraud triangle elements are only

relevant to the accidental fraudster as the predator “requires no pressure and needs no

rationalization” (p. 21). Buchholz (2012) posited that there is “an abundance of corporate

scandals resulting from fraud without detection by the auditor” (p. 109). Buchholz

(2012) recommended that other methods, in addition to the fraud triangle, be utilized in

audit planning to detect financial statement fraud because the auditors become the

opportunity for fraud and the element of rationalization may not be present.

25

According to Hogan et al. (2008), audit firm size, auditor tenure, auditor industry

specialization and experience, time budget pressures, and supervisory style affect

auditors’ roles in fraud detection (p. 236). Hogan et al. (2008) called for further research

in the following areas, which include a) rationalization and attitude component of the

fraud triangle, b) new technology-based tools for fraud detection (e.g., data mining and

pattern-recognition software), c) high-risk areas of auditing fair value estimates, quarterly

financial information, and top-level journal entries, d) auditor communication with audit

committees, and e) mindset of the auditor versus forensic accountants (pp. 246-247).

Levy (2015) also emphasized the significance of professional skepticism and the

importance of the auditors’ responsibility to detect financial statement fraud during

financial statement audits; thus, identifying fraud risk to minimize fraudulent financial

reporting scandals must be a continued focus of the accounting profession.

Similarly, Soltani (2014) and Lokanan (2015) refuted the sole use of the fraud

triangle for fraud detection. Soltani conducted a comparative study of three American

(i.e., Enron, HealthSouth, andWorldCom) and three European (i.e., Parmalat, The Royal

Ahold, and Vivendi Debacle) corporate scandals using ethical climate (i.e., tone at the

top, bubble economy and market pressure, fraudulent financial reporting, accountability,

control, auditing, and governance) and the fraud perspectives of firm-specific

characteristics and environmental context as the theoretical framework. In contrast,

Lokanan (2015) used Fairclough’s critical discourse theory to challenge the validity of

the fraud triangle’s theoretical framework. Lokanan (2015) posited that fraud is a

complex phenomenon that cannot be restricted to only the three components of the fraud

triangle (e.g., incentive/pressure, opportunity, and rationalization).

26

Soltani (2014) used annual reports, regulatory reports, professional and academic

literature, and newspapers for the comparative study. Soltani (2014) found the following

similarities in the organizations: ineffective boards (e.g., insufficient oversight and lack

of independence), inefficient corporate governance and internal control, accounting

irregularities, failure of external auditors, dominant chief executive officers, inappropriate

financial reporting and accounting systems, and ineffective internal audits. The study

examined a variety of causes of corporate fraud including ethics, management behavior,

financial reporting and auditing, control mechanisms, tone at the top, management

incentives, corporate governance, and environmental factors. Soltani (2014) found that

the regulatory, environmental, and ethical climates of corporations “are rarely or not

sufficiently discussed in previous studies” (p. 271). Soltani (2014) recommended future

research to incorporate interviews with the fraudsters to record their perspectives on the

causes of the fraudulent activity.

Lokanan’s (2015) key audience was the AICPA and the ACFE because of their

promotion of the fraud triangle as the recommended framework for fraud detection.

Critical discourse analysis (CDA) was applied to the fraud triangle framework, which

provides that fraud is caused by individual behaviors (i.e., incentive/pressure,

opportunity, and rationalization). Lokanan (2015) used a case study design to conduct a

CDA on three levels (i.e., discourse practice, sociocultural practice, and text) for three

companies: Lehman Brothers, KPMG, and Walmart. Lokanan (2015) posited that fraud

is multifaceted and “consideration of the wider macro social and economic dimensions”

(p. 220) are critical in understanding the causes of fraud.

27

In response to Soltani’s (2014) call for researchers to conduct interviews with

fraudsters, Ferrell and Ferrell (2011) did an interview with Enron’s Chief Executive

Officer, Ken Lay. In May 2006, Ferrell and Ferrell (2011) interviewed Ken Lay after his

criminal conviction for making fraudulent statements about the financial condition of

Enron. Lay stated “he had relied on lawyers, accountants, and senior executives to keep

him informed of such issues of misconduct” (Ferrell & Ferrell, 2011, p. 211). Lay denied

responsibility for Enron’s demise and blamed the lack of internal controls and the lack of

risk management for the company’s failure (Ferrell & Ferrell, 2011, p. 218). Ferrell and

Ferrell’s (2011) interview supported Soltani’s (2014) finding on the importance of the

regulatory, environmental, and ethical climates of corporations.

Using the fraud triangle’s theoretical framework, Schuchter and Levis (2015) also

responded to Soltani’s (2014) recommendation to interview fraudsters. Schuchter and

Levis (2015) applied a qualitative research design to examine the perspectives of

convicted fraudsters from Austria and Switzerland on the causes of fraud. The construct

design, interviews with fraudsters, was “rare in the world of white-collar crime”

(Schuchter & Levis, 2015, p. 179). The period of the investigation was from 1990 to

2010 with interviews conducted in 2010. Twelve of the participants were interviewed

face-to-face and one participant was interviewed by telephone (11 males and 2 females)

using a semi-structured questionnaire with an emphasis on how the fraud occurred versus

why the fraud occurred. Even though the small sample size did not lend itself to “a

defensible universally applicable hypothesis” (Schuchter & Levis, 2015, p. 180) and

contained the risk of respondent bias, the results did not support the fraud triangle theory.

The participants refuted that all of the elements of the fraud triangle were required for

28

fraud to occur. Schuchter and Levis (2015) discovered that the elements of

pressure/incentive and rationalization were not required, but opportunity was required,

for fraud to occur. This finding by Schuchter and Levis (2015) supports Dorminey et al.

(2010) results in relation to predators and accidental fraudsters. Predators do not require

pressure/incentive or rationalization to commit fraud, only opportunity (Dorminey et al.,

2010). Schuchter and Levis (2015) deduced, from the participants’ perceptions that

opportunity triggered by high pressure within an organization provides for the occurrence

of fraudulent behavior.

In contrast to Soltani (2014) and Lokanan (2015), Morales, Gendron, and

Guénin-Paracini (2014) recommended the use of the fraud triangle for financial statement

fraud detection. Morales et al.’s (2014) recommendation for the use of the fraud triangle

was based on a documentary study of 64 articles on organizational fraud from a

genealogy of the fraud triangle. Morales et al. (2014) found recent articles that a)

explained and illustrated the fraud triangle to auditing and accounting professionals, b)

provided case studies for teaching future auditors or managers through the lens of the

fraud triangle, c) used the fraud triangle to elaborate new conceptual frameworks, and d)

posited that the elements of the fraud triangle can predict the presence of fraud (p. 184).

A key finding from Morales et al.’s (2014) literature study was that deviance is not

attributed to complex social factors, but to “failures in individual morality and

breakdowns in the organization’s endeavors to control probity” (p. 191). Hence, this

finding supports that organizations must be attentive to the opportunities and pressures

that exist to prevent the occurrence of fraud. Also, Morales et al. (2014) stated that

“technologies of organizational control and surveillance are influenced by moral

29

judgments about what is normal and what is unacceptable deviance” (p. 192). Morales et

al.’s (2014) point emphasized that the processes that organizations implement for fraud

prevention and detection are influenced by the judgments of the individuals developing

the processes; hence, the processes must be closely monitored by organizations. Thus,

according to Morales et al. (2014), the fraud triangle is an acceptable tool for fraud

prevention and detection since it encompasses both an individual’s character and an

organization’s internal control system.

Auditing standards do not specify a quantitative or qualitative approach to fraud

risk assessment. Piercey (2011) conducted a case study experiment to ascertain whether

the relationship of the methodology chosen by the auditor (quantitative versus

qualitative) influenced the fraud risk assessment. While Piercey (2011) did not find

support for the use of qualitative methodology for fraud risk assessments, Goel and

Gangolly (2012) did provide support for qualitative fraud risk assessment approaches.

Piercey (2011) selected auditors from large accounting firms and senior

accounting students to participate in the case study. The independent variables were

documentation requirements (yes or no) and response mode (qualitative, quantified, and

qualitative-elastic-redefinition) with a PCAOB inspector condition introduced for the

qualitative-elastic-redefinition condition to evaluate changes in risk assessments, and the

dependent variable was the probability of material misstatement. Analysis of covariance

(ANCOVA), analysis of variance (ANOVA), and contrast tests was used to analyze the

data. Piercey (2011) found that more lenient risk assessments occurred when qualitative

approaches were used; hence, further investigation was recommended because lenient

risk assessments lead to fewer audit tests and to the collection of less substantive

30

evidence (p. 243). Piercey (2011) measured only auditors’ perceptions of risk, but not

the planned audit work; additionally, the student participants did not have actual audit

experience (p. 244). Another limitation of the study was that fraud risk was measured

from audit phrases instead of a high-medium-low assessment scale, which is the

measurement used in current practice (p. 243). Piercey’s study created the need to

examine whether the requirement of quantitative fraud risk assessments would aid in

fraud detection. Goel and Gangolly (2012) conducted a study to assess the use of

qualitative content in annual reports instead of quantitative financial information to detect

financial statement fraud. Goel and Gangolly (2012) hypothesized that fraudulent

companies try to misrepresent information and employ different writing techniques in the

annual reports than the companies that do not commit fraud. The following six sub-

hypotheses were tested for increased likelihood of fraud in annual reports: 1) more

difficult to read and understand, 2) greater use of negative words, 3) greater use of

passive voice, 4) greater use of uncertainty markers, 5) greater use of adverbs, and 6)

greater use of formatting styles such as use of caps and use of punctuation. Goel and

Gangolly (2012) used an unmatched sample design to develop a dataset of 126 fraudulent

companies and 622 no-fraud companies from the Compustat, LexisNexis database, and

Wall Street Journal (WSJ) Index, as well as the Accounting and Auditing Enforcement

Releases (AAERs), which was issued by the SEC over the period 1993 to 2006. The

instrument used to examine the data was the companies’ Form 10-K filings. All

hypotheses were tested using a chi-square test of significance and Z-tests to measure

linguistic feature variations in the fraud and no-fraud reports. Goel and Gangolly (2012)

found that the following linguistic cues have been associated with fraudulent financial

31

statements: use of complex sentence structures, difficulty of reading and comprehension,

use of positive tone, use of passive voice, use of uncertainty markers, and use of adverbs

(p. 87). Goel and Gangolly’s (2012) results provide support for the use of qualitative

fraud risk assessment approaches to detect financial statement fraud by examining

writing and presentation styles in annual financial reports in contrast to numeric data,

which is the focus of quantitative fraud risk assessments.

Auditing standard, AS3, emphasizes the importance of proper documentation in

relation to auditors’ effectiveness (Hammersley et al., 2010). Hammersley, Bamber, and

Carpenter (2010) investigated the influence of specific fraud documentation and of

priming the auditor before the evidence evaluation for the fraud risk assessment in

response to auditing regulators’ concerns that auditors are not providing sufficient

documentation in fraud risk assessments. As specific documentation of audit findings

provides evidence that may be used in auditor lawsuits, Reffett (2010) conducted a study

to provide insight into the litigation risks for documented risk assessments. Hammersley

et al. (2010) found that specificity may reduce auditors’ professional skepticism while

Reffett found that auditors may intentionally produce less documentation due to the fear

of lawsuits.

Hammersley, Bamber, and Carpenter (2010) investigated the influence of specific

fraud documentation and of priming the auditor before the evidence evaluation for the

fraud risk assessment in response to auditing regulators’ concerns that auditors are not

providing sufficient documentation in fraud risk assessments. The theoretical framework

for the experiment was support theory, which examined components (e.g., fraud risks) to

assess the likelihood of an event (e.g., fraud). Hammersley et al. (2010) tested the

32

assertion that proper documentation strengthens auditors’ effectiveness by selecting 81

audit seniors from a Big 4 accounting firm of which 57.3 percent were CPAs with an

average of 45.9 months of experience to participate in a two-part experiment. Part one of

the experiment simulated the audit planning stage and part two of the experiment

simulated the audit evaluation stage. The research design was a 2X2 between-

participants design with documentation specificity and fraud risk priming as the

independent variables. Final fraud risk assessments, identification of remaining issues,

and requests of additional evidence were the dependent variables measured. The

documentation variable was manipulated by the use of a summary and a specific fraud

risk memo. Fraud risk priming was assessed by instructing one group of participants to

reconsider the documented fraud risks before evaluation, while the other group was not

instructed to reconsider the documented fraud risks before evaluation. The statistical

analyses used were multivariate analysis of covariates (MANCOVA) and ANCOVA.

Hammersley et al. (2010) found a) for the unprimed condition, documenting the specific

fraud risks in the planning phase increased fraud assessments and evidence requests, b)

for the primed condition, documenting in summary in the planning phase increased fraud

assessments, evidence requests, and issues identified, and c) for the primed condition,

documenting the specific fraud risks in the planning phase decreased fraud assessments,

evidence requests, and issues identified (pp. 549-550); hence, specificity does not always

positively affect auditors’ subsequent judgements. Hammersley et al.’s (2010) study

results support the positive influences of priming before evaluation, but lacks support for

the specific documentation of fraud risks as specificity may reduce auditors’ professional

skepticism.

33

Reffett (2010) used counterfactual reasoning theory to provide support that

auditors are held liable for failure to detect fraud when fraud was identified and

investigated, but not held liable when fraud was not identified and investigated. Reffett

(2010) conducted a between-participants and within-participants experiment with the

participants serving as jurors to evaluate auditors who failed to detect fraud in an audit.

The participants included 229 undergraduate students at two U.S. state universities from a

variety of non-business school courses. For the independent variable, audit procedures

used to investigate fraud, three conditions were tested: no investigation, low

investigation, and high investigation. The dependent variables measured were the

intensity of participants’ counterfactual thoughts and the evaluators’ assessments of

auditor liability for undetected fraud. Reffett (2010) performed independent samples t-

test, paired-samples t-test, planned comparisons of the independent variables, and Chi-

square statistical analyses to evaluate the data. Reffett (2010) found in the between-

participants experiment that the evaluators were “more likely to hold auditors liable for

failing to detect fraud when the auditors performed audit procedures to investigate for the

fraud relative to when the auditors did not investigate for the fraud” (p. 2163), which is

consistent with counterfactual theory. Additionally, the opposite effect occurred with the

within-participants experiment, which “demonstrates that evaluators understand that

higher levels of auditor investigation imply lower levels of auditor liability” (p. 2164).

Future research, according to Reffett (2010), is needed to ascertain if auditors’ fear of

lawsuits create more lenient fraud risk assessments and less specific documentation.

SOX was enacted in 2002 to minimize corporate fraud in the U.S. (Hulsart,

James, & Cummings, 2012). Alleyne and Elson (2013) used the Association of Certified

34

Fraud Examiners’ Report to the Nations for the period 1996-2008 to compare fraud under

the Securities Acts of 1933-1934 regulations to SOX regulations. The researchers

posited that “SOX is more effective in identifying, eliminating, and preventing corporate

fraud” (Alleyne & Elson, 2013, p. 104). However, Alleyne and Elson (2013)

acknowledged that the collection period of the data was limited and the frauds that were

reported to the Association of Certified Fraud Examiners were only those that were

examined throughout the study. Fraudulent financial statement fraud is the most costly

type of occupational fraud as “each scheme results in a median loss of $4.25 million”

(Alleyne & Elson, 2013, p. 94). Hence, future research is needed to expand the collection

period to a more recent period with a focus on auditors’ ability to detect fraudulent

financial statements.

Risk Assessment Models

Researchers, such as Dorminey, Fleming, Kranacher, and Riley (2012), are

continuously developing risk assessment models to improve the fraud risk assessment

process. Dorminey et al. (2012) introduced a meta-model framework and identified

likelihood and magnitude as the primary attributes for risk assessments. Similarly,

Abbasi et al. (2012) developed a metafraud framework using business intelligence. In

contrast, Srivastava et al. (2011) recommended two risk assessment models of which one

would be used to detect irregularities and errors and the other one would be used to assess

management fraud. The aforementioned models are significant to the fraud risk

assessment process as they introduce different methodologies that auditors may use to

produce more effective fraud risk assessments for financial statement fraud detection.

35

Dorminey, Fleming, Kranacher, and Riley (2010) agreed with Soltani (2014) and

Lokanan (2015) that the fraud triangle should not be the only model to assess fraud risk.

Dorminey et al. (2010) suggested the following models be considered in the fraud risk

assessment process: the triangle of fraud action (i.e., the act, concealment, and

conversion), the fraud diamond (i.e., pressure/incentive, opportunity, rationalization, and

capability), the fraud scale (i.e., opportunity, personal integrity, and pressure), and the

MICE (i.e., money, ideology, coercion, and ego) model. Boyle, DeZoort, and

Hermanson (2015) posited the fraud diamond to be more effective for fraud risk

assessments than the fraud triangle.

Dorminey, Fleming, Kranacher, and Riley (2012) introduced a meta-model

framework to provide insights into a fraud “risk assessment approach based on a current

understanding of the antecedents to fraud” (p. 574). The meta-model framework

incorporated not only the fraud triangle elements but also other personality and

behavioral characteristics from other fraud models, which were examined in relation to

the anti-fraud controls of prevention, deterrence, and detection to assess the probability of

fraud. Dorminey et al. (2012) identified likelihood and magnitude as the primary

attributes used by auditors to conduct risk assessments. Likelihood to commit fraud is

evaluated based on the company, industry, and organizational environment, and

magnitude is assessed in relation to the potential financial impact on the company’s

financial condition (Dorminey et al., 2012, p. 574).

In relation to Dorminey et al.’s (2010) recommendations to broaden the scope of

the fraud triangle to further improve fraud detection, Boyle et al. (2015) compared

auditors’ fraud risk assessments based on the use of the fraud triangle and the fraud

36

diamond to evaluate the effect of the fraud diamond’s capability element. Boyle et al.

conducted a 2X2 between-participants experiment that manipulated the fraud model

practice aids (fraud triangle versus fraud diamond) and the chief executive officer’s

(CEO) risk level (high-risk versus low-risk). The fraud risk assessment research

instrument was adapted from Wilks and Zimbelman and Norman et al. (as cited in Boyle

et al., 2012). The sample consisted of 89 auditors working in two Big 4 and five other

public accounting firms with 71% of the participants completing an online version and 29

percent completing a paper version of the fraud risk assessment research instrument,

which was developed in Qualtrics. The majority of the participants were staff and senior

auditors (only 46% had a CPA license) with less than three years of audit experience,

which limited generalizability. Fraud risk factors for the practice aids, developed from

SAS No. 99 and other fraud studies, for the two experimental conditions, were measured

using a scale ranging from 0 (no fraud risk) to 100 (very high-fraud risk). Additionally,

participants evaluated the overall financial statement fraud risk and confidence level for

the fraud risk assessment using a scale ranging from 0 to 100. Boyle et al. (2015)

controlled for auditors’ differences in professional skepticism by having the participants

complete the Hurtt Professional Skepticism Scale (2010). Statistical analyses were

conducted using an ANCOVA. Boyle et al. (2012) found that the fraud diamond model

produced significantly higher fraud risk assessments than the fraud triangle model and a

higher CEO risk resulted in the fraud diamond group participants identifying capability

items as fraud risk factors (p. 580). Moreover, Boyle et al. (2012) found that professional

skepticism had a significant positive relationship to the fraud risk assessment outcomes.

Boyle et al. (2012) stated that further research is needed to ascertain the “extent that trait

37

skepticism impacts hypothesis generation audit procedure choice, and fraud detection” (p.

592). Boyle et al. recommended the rationalization element of the fraud triangle model

be broadened to include capability items.

Similarly, Kassem and Higson (2012) agreed with Dorminey et al. (2010) on the

use of a variety of models for fraud risk assessment. Kassem and Higson (2012)

proposed a new fraud triangle that integrates all of the fraud models into one model –

motivation from the MICE model, opportunity from the fraud triangle, integrity from the

fraud scale, and fraudster’s capabilities from the fraud diamond (p. 194). The purpose of

Kassem and Higson’s new triangle is to increase auditors’ knowledge of fraud, which

was limited by the fraud triangle because pressure and rationalization are not observable

and the trait of capability is ignored. In contrast to Dorminey et al. (2012), Kassem and

Higson (2012), and Murphy and Dacin (2011) developed a fraud model that used the

fraud triangle framework.

Murphy and Dacin’s (2011) model identified three psychological pathways to

fraud: 1) lack of awareness, 2) intuition coupled with rationalization, and 3) reasoning for

conflicting intuitions. Murphy and Dacin’s (2011) model provides for a theoretical

framework to identify situational factors and methods used to reduce negative affect as

well as narrow the gap in the knowledge of rationalization. Murphy and Dacin (2011)

focused on the variations of rationalization when the elements of pressure and

opportunity were present. The fraud detection model illustrated four levels of behavioral

actions that result from the fraud decision, which include not committing fraud, unlikely

to commit fraud again, likely to continue committing fraud, and commit fraud while

upholding moral values. Murphy and Dacin (2011) posited that understanding

38

“rationalization is useful for predicting the likelihood of fraud … or for detecting it” (p.

613). The limitation of the framework is that it does not distinguish between different

types of fraud. Murphy and Dacin’s (2011) model may be a useful tool for auditors to

better understand the psychological aspects of fraudulent behavior.

Abbasi, Albrecht, Vance, and Hansen (2012) reported that the fraud detection rate

for U.S. firms is less than 70%. Hence, Abbasi et al. (2012) responded to the need for

improved detection tools by developing a metafraud framework that proved to

outperform existing models of financial fraud detection using business intelligence.

Abbasi et al. conducted five experiments to test six hypotheses using a sample of publicly

available quarterly and annual financial statements for the period 1985 to 2008. The SEC

Accounting and Auditing Enforcement Releases (AAERs) were used to identify the

fraudulent financial statements in the sample. Twelve financial ratios were used to derive

industry-level and organizational context features from the quarterly and annual data.

Abbasi et al. (2012) conducted paired t-tests and found a) the incorporation industry-level

and organizational context information improved performance, b) the combination of

quarterly and yearly information yielded the best results, c) the use of quarterly and

yearly context-based features resulted in the stack classifiers outperforming individual

classifiers, d) adaptive learning outperformed its static counterpart, e) a meta-learning

framework that included provisions for improving declarative and procedural bias

outperformed existing methods, and f) a meta-learning framework that included stacked

generalization and adaptive learning provides improved procedural bias over existing

ensemble-based semi-supervised learning methods.

39

Srivastava, Mock, and Gao (2011) concurred with Dorminey et al. (2010) that the

use of a single audit risk model is ineffective. Srivastava et al. (2011) applied Dempster-

Shafer theory to fraud risk assessment and developed a tool “to assess the belief and

plausibility that management has committed financial statement fraud based on

assessments of three ‘fraud triangle’ factors” (pp. 284-285). The revised Dempster-

Shafer differs from the prior model posited by Srivastava et al. (2011), because it

assumes no interrelationships between the fraud triangle factors (incentives, attitude, and

opportunity). Srivastava et al. (2011) argued that probability theory is ineffective in

assessing audit evidence because it does not provide for purely positive or purely

negative evidence as probability theory evidence is always mixed (p. 283). Probability

theory assesses the probability of material misstatement in contrast to the measurement of

the belief and plausibility of misstatement, which are the measures of the Dempster-

Shafer theory (Srivastava et al., 2011). Hence, Srivastava et al. (2011) suggested the use

of two risk assessment models in which one detects irregularities and errors and the other

one assesses management fraud.

Another methodology used to evaluate management fraud is to examine an

organization’s culture, which includes managers’ attributes. Shadnam and Lawrence

(2011) and Campbell and Göritz (2014) examined organizational culture as an element

for fraud risk assessments. Cohen, Ding, Lesage, and Stolowy (2010) combined the

fraud triangle and the theory of planned behavior to examine the personality traits of

managers in relation to unethical behaviors.

Shadnam and Lawrence (2011) used the institutional theory of moral collapse to

link individual morality and institutional behavior. The institutional theory of moral

40

collapse focuses on the interrelationships of individuals, within an organization, with

emphasis on the effect of moral understandings that govern behaviors through the upward

and downward flows of ideology and regulation (Shadnam & Lawrence, 2011).

Shadnam and Lawrence argued that moral collapse is attributable to the breakdown in the

connections among moral communities, organizations, and individuals, and that it is more

common in organizations with conditions that include a lack of leader commitment to the

communication of ideology, high employee turnover, immoral structures and practices,

and accusations of individual misconduct (p. 394). Shadnam and Lawrence’s (2011)

arguments identify fraud risks for auditors to consider when conducting fraud risk

assessments.

Campbell and Göritz (2014) conducted a qualitative research study on the

influence of organizational culture on individual behavior using content analysis to

analyze semi-structured interviews with 14 independent experts who had experience with

corrupt organizations. The experts were primarily German and “former CEOs of corrupt

organizations, ombudsmen, police officers, and investigative journalists” (Campbell &

Göritz, 2014, p. 293). Campbell and Göritz (2014) related the incentive/pressure element

of the fraud triangle to manager behavior and the rationalization element of the fraud

triangle to employee behavior in unethical organizations. Campbell and Göritz (2014)

found that corrupt organizations shared the belief that “the end justifies the means,”

valued job and organizational security, and punished non-corrupt behavior (p. 304).

Campbell and Göritz (2014) also found a difference in the endorsement of values by

managers and employees; managers endorsed high performance values while employees

emphasized security and team spirit values (pp. 305-306). The generalization of the

41

study results were limited as the study focused only on a biased German view of corrupt

organizational cultures with interviewees’ responses based on experiences and

knowledge (Campbell & Göritz, 2014).

Cohen et al. (2010) conducted a literature review of 39 U.S. corporate frauds

during 1992-2005. A content analysis was applied to press articles to examine the

personality traits of managers in relation to the fraud triangle theory and the theory of

planned behavior. The theory of planned behavior postulates that behavioral intentions

can be predicted from a) attitudes toward the behavior, b) subjective norms, and c)

perceived behavioral control (Cohen et al., 2010, p. 274). Cohen et al. (2010) found a

direct correlation between managers’ psychological traits and fraud. Thus, Cohen et al.

(2010) posited the following attributes as fraud-risk factors for assessing managers’

behaviors: high living standard, tyrannical or autocratic-type personality, praised in press

articles, and benefited from a dominant position (p. 287). Cohen et al. posited that

auditors should better integrate the attitudes/rationalization component of the fraud

triangle in relation to managers and the organizational culture when conducting fraud risk

assessments. Limitations of the study included the use of non-scholarly sources, press

articles, and the inherent risk of assessing personality and ethics of individuals (Cohen et

al., 2010).

Research indicates that improvements are needed in auditors’ approaches to fraud

risk assessments to improve auditors’ testing plans to detect financial statement fraud.

The PCAOB has endorsed the use of nonfinancial measures to improve financial

statement fraud detection (Brazel, Jones, & Prawitt, 2014). Brazel et al. (2014)

conducted an experiment to assess auditors’ reactions to inconsistent financial and

42

nonfinancial data in conjunction with a decision prompt during risk assessments. Even

though the PCAOB endorses nonfinancial measures for fraud detection, Brazel et al.

(2014) did not find support for the use of nonfinancial measures. Favere-Marchesi

(2013) investigated another approach to fraud detection and found support for the

decomposition of fraud risk factors in contrast to the categorization of fraud risk factors.

Boritz and Timoshenko (2014) posited that customized fraud checklists may provide for

more effective fraud risk assessments. Trotman and Wright (2012) provided support for

the importance of triangulation of audit evidence and professional skepticism for

effective fraud risk assessments. Similarly, Schmidt (2014) conducted an experiment to

examine the impact of auditors’ mental representations on the auditors’ judgment. Wei et

al. (2015) evaluated sequential unpacking versus simultaneous unpacking of fraud

findings before making fraud risk assessments and found that that even though sequential

unpacking had a positive effect on fraud identification, it reduced the effectiveness of

fraud risk assessments, which implied a decrease in professional skepticism.

Brazel et al. (2014) operationalized the constructs by conducting two between-

participants’ experiments and a within-participants’ manipulation (i.e., decision prompt)

to measure the effects on the auditors’ expectation of fraud. The participants for both

experiments were senior auditors of which 39 and 71 completed experiment 1 and

experiment 2, respectively. Case studies were given to the participants to evaluate

consistent and inconsistent nonfinancial measures of sales growth. The independent

variable manipulated for experiment 1 was the condition of the nonfinancial measures in

relation to sales growth (i.e., consistent versus inconsistent) to determine the participants’

expectation of the sales account. Experiment 2 used a between-participants design to

43

manipulate fraud risk (i.e., high versus low) and a within-in participants design to assess

a pre- and post-prompt expectation of sales. Repeated measures ANOVAs were used for

the statistical analysis of the data collected. Brazel et al. (2014) found that “auditors are

not likely to react to inconsistencies between financial and nonfinancial measures”… and

“a prompt can cause auditors to react to an inconsistency, but the effect of the prompt is

more pronounced when fraud risk is high” (p. 149). Hence, the auditors only used the

nonfinancial data if they were prompted and if the fraud risk was high to examine the

inconsistencies between the nonfinancial data and the financial data.

SAS No. 99 does not require decomposition of the fraud risk factors into the fraud

triangle components of incentive, opportunity, and attitude, but suggests the classification

of the fraud risk factors into the fraud triangle components (Favere-Marchesi, 2013, p.

203). Favere-Marchesi (2013) conducted a 2X2 factorial between-participants

experiment on the effects of fraud judgment decomposition versus fraud-risk factor

categorization using the case study method. The assessment method (i.e., decomposition

versus categorization) and the risk level (i.e., high versus low) were the independent

variables manipulated to evaluate fraud risk. The decomposition group assessed risks

while the categorization group classified risks for attitude, opportunity, and incentive.

The participants consisted of 60 managers, selected by the firms’ partners, from two large

accounting firms in offices throughout Canada and the United States. The case study

simulated the audit managers’ planning phase of the audit for assessing fraud risk with

the inference that management’s attitude was indicative of low-fraud risk. The

decomposition group assessed risks for attitude, opportunity, and incentive, and then

made an overall fraud risk assessment based upon the separate evaluation of the fraud

44

risks components. In contrast, the categorization group classified risks for attitude,

opportunity, and incentive, and then made an overall fraud risk assessment based upon

the categorized fraud risks without making separate component assessments. The fraud

risk assessments were made using a scale from 1 (low) to 10 (high). Various ANOVAs

and univariate tests were used to statistically analyze the data. Favere-Marchesi (2013)

found “auditors who decompose fraud assessments make overall and component fraud-

risk assessments that are more appropriate in response to changes in opportunity and

incentive cues than auditors who only categorize fraud-risk factors” (p. 216).

Auditing standards do not require auditors to use standardized checklists for fraud

risk assessments. Boritz and Timoshenko (2014) conducted a literature review and

posited that customized fraud checklists may increase the effectiveness of fraud risk

assessments. The study design classified checklists at two levels: generic versus

customized and procedural versus judgmental. Boritz and Timoshenko identified “nature

of the task, checklist design, checklist application, and contextual factors” (pp. C4-C7) as

the factors influencing effectiveness for fraud risk assessments checklists. Checklist

design recommendations posited by Boritz and Timoshenko included:

• Focus on items classified as “low risk” to encourage strategic reasoning;

• Customize to the client, client’s industry, and audit team staff mix;

• Include and test red flags between financial and nonfinancial measures;

• Categorize cues into categories (e.g., fraud triangle elements) with

deliberative rather than intuitive cue processing to improve judgments; and

• Consider contextual factors such as auditor experience, performance

pressures, and legal considerations (pp. C15-C16).

45

The auditing profession may want to consider Boritz and Timoshenko’s recommended

framework to provide a tool for conducting more effective fraud risk assessments. A

customized checklist, which considers the client’s business and the fraud risk assessment

factors, would strengthen the standardization of fraud risk assessments and minimize the

reliance on auditors’ judgments for fraud risk assessments.

Auditors must exhibit professional skepticism as “some members of management

may even seek to conceal outright fraud by strategically altering information they expect

the auditor will obtain as evidence” (Bell, Peecher, & Solomon, as cited in Trotman &

Wright, 2012, p. 41). Trotman and Wright (2012) conducted a 2X2X2 between-

participants experiment to ascertain whether external evidence alters fraud risk

assessments as external evidence is more difficult for management to manipulate. The

sources of evidence examined in the experiment were from external sources (EBS),

management information systems (MII), and management business representations

(MBR). A sample of 124 auditors, with an average of 37 months of audit experience,

who attended a national training class of a Big 4 auditing firm, were the participants

involved in this study. Case study materials were given to the participants that described

the client, which included current information on its competitive position, governance

environment and its financial condition. The accounting fraud that was present in the

case study was the inflation of sales revenues by management. The three independent

variables, EBS, MII, and MBR, were manipulated with the condition of either high or

low-fraud risk. The outcome variable was the probability of fraud that was measured by

the participants’ assignment of probabilities to seven potential causes for the higher-than-

expected sales figure in the case study and by the performance of risk assessments on the

46

accounts of sales, cost of goods sold, and selling and administrative expenses. The risk

assessments were evaluated on a continuous scale ranging from 1% (low risk) to 100%

(high risk). The data was evaluated using ANOVA tests. Trotman and Wright found

when MBR and MII evidence was inconsistent unfavorable EBS compared to favorable

EBS resulted in a significant increase in the likelihood for fraud; however, if MBR and

MII were consistent, EBS evidence was limited (pp. 51-52). The key insight from the

study is “if management has committed a fraud and has been strategic enough to alter

evidence that is generally under their control, audit quality would benefit by making use

of external evidence outside management’s control” (Trotman & Wright, 2012, p. 52).

The key limitations of the study include choosing only one type of MBR, MII, and EBS

evidence, as well as not having a measure for auditors’ prior beliefs (Trotman & Wright,

2012). Trotman and Wright’s (2012) study provided support for professional skepticism

and triangulation of audit evidence in fraud risk assessments.

Schmidt (2014) used a 2X1 between-participant design that manipulated retrieval

strategy prior to the fraud risk assessments to examine the impact of auditors’ mental

representations of the clients’ control environment on the auditors’ judgment in fraud

assessments and reliance on management’s explanations. The experimental case study

was adopted from Agoglia (1999) and recruited 156 auditors (91 senior auditors from a

Big 4 firm and 65 practicing auditors attending an academic program at a large

university) to act as auditors in a hypothetical company’s preliminary audit planning

stage. The participants received information on the control environment and after 15

minutes, the subjects were not allowed to reexamine the information. The participants

had to recall the positive and negative “tone at the top” evidence, assess the control

47

environment, react to management’s explanation for discrepancy found from analytical

procedures, and complete a fraud risk assessment. Schmidt (2014) used ANOVA and

ANCOVA statistical analyses to analyze the data and found that the structure of a control

environment decision aid influenced the mental representation of “tone at the top”, and

favorable mental representations resulted in favorable assessments and greater reliance on

management’s explanations (p. 73). The study limitations included the use of exactly 50

items for the evidence, the results were based on a single case with one set of evidence

items, and the requirement of participants to recall evidence was abstract (Schmidt, 2014,

p. 91).

SAS No. 99 requires auditors to conduct team-brainstorming sessions to discuss

the potential for fraud during the planning stages of financial statement audits (Wei,

Khalifa, & Trotman, 2015). Wei et al. examined the impact of individual auditor

brainstorming prior to audit team brainstorming on fraud identification. Wei et al. used

support theory as the theoretical framework to investigate the effects of brainstorming on

auditors’ performance when the potential for fraud exists. Support theory “proposes that

alternative descriptions of the same event will produce different judgments” (Wei et al.,

2015, p. 5). Wei et al. (2015) used a 2X1 between-participants design to manipulate the

brainstorming task for the conditions of simultaneously unpacking and sequentially

unpacking. The dependent variables of the study were a) the quantity and quality of the

potential frauds found in the brainstorming session, b) the distribution of the potential

frauds found across categories, and c) the level of auditors’ fraud risk assessments (Wei

et al., 2015, p. 4). The participants consisted of 38 auditors from a Big 4 audit firm in

Australia with an average of 4.83 years of audit experience; random assignment was used

48

to appoint the participants to one of the two conditions. The research instrument was an

abbreviated international case study used by a Big 4 firm for training auditors on how to

document audit workpapers, including the documentation of fraud risk. Both groups

were instructed to document the potential frauds relating to categories of revenue

recognition, receivables, inventory, noncurrent assets, and management estimates in the

case study; the simultaneous unpacking treatment group listed the potential fraud findings

in any order while the sequential unpacking treatment group listed the potential fraud

findings by category. The participants made a fraud risk assessment using an 11-point

scale ranging from 0 (Extremely Unlikely) to 11 (Extremely Likely). Then the

participants were given two potential frauds (e.g., revenue recognition category and

management estimate category) identified by the management team. The participants had

to list additional potential frauds, excluding the potential frauds listed in phase one of the

experiment. Statistical analyses were conducted using ANCOVA with audit experience

as the covariate. Even though fraud experience for the participants was not measured, the

research findings provide evidence of how the use of different methodologies for fraud

detection may influence auditor behavior. Wei et al. (2015) found the sequential

unpacking approach had a positive effect on potential fraud identification in relation to

the quality and quantity of potential frauds found and the distribution of potential frauds

across categories, but it reduced auditors’ fraud risk assessments. Wei et al. posited that

lower fraud risk assessments may imply lower levels of professional skepticism, which is

a disadvantage to the use of the sequential unpacking methodology at the individual level

(p. 19).

49

Auditors’ Attributes

In addition to fraud risk assessment models, auditor attributes also influence fraud

risk assessments (Fathil & Schmidtke, 2010; Hammersley et al., 2011; Jafar et al., 2011;

Knapp & Knapp, 2001; Rose et al., 2012). Limited research has been conducted to

ascertain the influence of auditors’ characteristics, professional experience, knowledge,

and skills on fraud risk assessments. Fathil and Schmidtke (2010) found positive

correlations of auditor attributes and fraud detection while Jaffar et al. (2011) found no

correlation between auditor personality traits and fraud risk assessment. Hammersley et

al. (2011) provided support for fraud training and experience while Knapp and Knapp

(2001) provided support for audit experience and explicit fraud risk assessment

instructions for effective fraud risk assessments. However, Rose et al. (2012) did not find

support for audit experience but found support for the use of explicit fraud risk

assessment instructions for effective fraud detection.

Fathil and Schmidtke (2010) reported that the relationship between individual

differences and the ability to detect fraud has not been empirically explored. Even

though the pilot study of 25 professional accountants conducted by Fathil and Schmidtke

had limited statistical power and used self-reporting as a measurement device to examine

the auditor attributes of conscientiousness, suspiciousness, integrity, and auditing

knowledge, it provided the support for further study because relationships between

attributes and fraud detection were found. Fathil and Schmidtke (2010) used the theory

of deception to develop a four-stage model for deception detection that integrated the

auditor attributes. The participants had to issue an audit opinion on a financial statement

simulation that contained fraudulent financial information and complete a questionnaire

50

to measure conscientiousness, suspiciousness, and integrity, and auditing knowledge.

Conscientiousness was measured using 12 items from the NEO Personality Inventory-

Five-Factor Inventory, suspiciousness was measured on a paranoia scale with questions

from the Minnesota Multiphasic Personality Inventory, integrity was measured using

eight items from the London House PSI standardized pre-employment integrity test, and

auditing knowledge was measured by the participants’ self-reported auditing grades and

years of accounting experience. Fathil and Schmidtke performed correlation analyses on

the data and found the following:

• Conscientiousness and auditing grades were positively correlated;

• Conscientiousness may be indirectly related to fraud detection from auditing

knowledge;

• Punitiveness, integrity factor, was positively related to fraud detection;

• Moderately suspicious participants were the most accurate in fraud detection;

• Highly suspicious participants overcompensated for suspiciousness resulting

in inaccurate financial statement opinions; and

• Professional accounting experience and fraud detection were not related (pp.

170-171).

One key limitation of Fathil and Schmidtke’s study was the selection of participants with

only professional accounting experience, instead of fraud detection experience. Fathil

and Schmidtke recommended future research to “examine the relation between auditing,

fraud detection and general accounting experience with the ability to detect fraud” and

“whether personality factors influence individuals’ assessment of audit risk” (p. 171).

51

In contrast, Jaffar, Haron, Iskandar, and Salleh (2011) examined personality traits

in relation to fraud assessment and detection in Malaysian audit firms and found no

significant relationship between the personality traits and the auditors’ ability to assess

fraud risk or to detect the likelihood of fraud. The five personality traits tested by Jaffar

et al. included neuroticism, extraversion, conscientiousness, openness to experience, and

agreeableness. Jaffar et al. used attribution theory to examine the effects of fraud risk

assessment on the ability to detect fraud by sending case material and personality

questionnaires to audit partners and managers in 1370 firms in Malaysia. Jaffar et al.

used a 2X2 within-participant factorial experimental design with two levels for fraud risk

assessment (correct versus incorrect) and two levels for the dimension of each personality

factor (high versus low). Goldberg 50 Big-five Factors Makers instrument was used to

measure the results of the personality test for the moderating variables (i.e., neuroticism,

extraversion, conscientiousness, openness to experience, and agreeableness). The

independent variable, ability to assess fraud risk, was measured by a seven-point Likert

scale, which ranged from 1 (Extremely Low) to 7 (Extremely High). The dependent

variable, which was the ability to detect the likelihood of fraud, was measured by a

seven-point Likert scale, which ranged from 1 (Extremely Low) to 7 (Extremely High).

As Jaffer et al. (2011) did not find support for a relationship between the variables, future

research is needed because regulators do assume that a positive relationship exists

between the ability to assess fraud risks and the ability to detect the likelihood of fraud.

As summarized by Hammersley (2011), auditors’ ability to assess fraud risk and

detect the likelihood for fraud is a current topic in auditing literature. Hammersley

(2011) developed a model for fraud risk assessment that incorporated auditor

52

characteristics (i.e., experience, knowledge, ability, and epistemic motivation) and mental

representation development. Hammersley (2011) “expects auditors with sufficient

knowledge gained from ability, experience, and epistemic motivation to be more likely to

detect the presence of fraud risk factors and respond to those risks effectively” (p. 104).

Hammersley’s study supports the importance of fraud training and experience to acquire

the knowledge needed to make accurate fraud risk assessments, which leads to fraud

detection. However, Stephens (2011) found a negative relationship between auditor

tenure and the likelihood of fraud detection in relation to internal control disclosures.

Stephens selected a sample of companies (519) from SEC filings and Audit Analytics

database disclosing material weaknesses from November 15, 2004 through May 30, 2005

of which 147 disclosed control problems and 372 did not disclose control problems.

Stephens (2011) used descriptive statistics, univariate, and logit regressions to analyze

the data. Stephens provided support for auditor tenure to be examined in relation to the

attributes of experience, knowledge, ability, and epistemic motivation in understanding

the influential factors of effective fraud risk assessments.

Knapp and Knapp (2001) examined the effects of audit experience and explicit

fraud risk assessment instructions on the effectiveness of using analytical procedures to

detect financial statement fraud. Knapp and Knapp used a 2X2X2 between-participants

research design of which experience levels (i.e., manager versus senior), financial

statement fraud (i.e., presence versus absence), and explicit fraud risk assessment

instructions (i.e., presence versus absence) were the independent variables manipulated.

The dependent variable, participants’ risk assessment of the presence of fraud in the

financial statements, was measured by a zero-to-ten point scale, with zero being most

53

unlikely and ten being most likely for the presence of fraud. The experimental materials

used in the study were fraudulent financial statements issued by public companies and the

subsequent restated financial statements of the same companies. The experiment

consisted of 119 participants from six different international accounting firms. Fifty-

seven of the participants were audit managers and 62 were senior auditors. To assess the

role of experience, the auditors applied analytical procedures to fraudulent financial

statements and restated financial statements of actual companies. To assess the

effectiveness of fraud risk assessment, some participants received instructions and some

did not. The data was analyzed using ANOVA tests. The results supported Knapp and

Knapp’s (2001) hypotheses that audit managers are more effective than audit seniors in

assessing fraud, and that fraud risk assessment instructions resulted in effective

assessments of fraud; hence, knowledge differences relative to the experience level of

auditors were found to affect fraud risk assessment (p. 35).

In contrast, Rose, McKay, Norman, and Rose (2012) found that when novice

auditors used checklist decision aids, which are designed to represent expert knowledge

structures, without instruction or explanatory feedback, that similar decisions to experts

were made (p. 24). Even though Rose et al.’s (2012) experimental study was limited by

not having an experimental group of experts for comparison, it provided insight into the

effect of new design models versus auditor experience on audit risk assessment

effectiveness. Rose et al.’s laboratory experiments used a 2X2 between-participants

design, which manipulated checklist organization (SAS No. 99 fraud triangle framework

versus an aggregate expert knowledge structure) and the learning requirement

(instructions present versus instructions absent). The dependent variables were decision

54

performance (fraud risk assessment accuracy) and the degree to which the participants’

knowledge matched experts’ knowledge. Experiment one used a sample of 115 senior

accounting students while experiment two used a sample of 79 master of accounting

students who took a pre- and post-knowledge test to verify the significance of the

decision aid on the experiment. The participants used the decision aid to assess fraud risk

for three cases and received outcome feedback before completing a concept pair-rating

task to evaluate the red flags in the decision aid. Pathfinder Network Scaling analysis

was used to compare the participants’ knowledge structure with an expert knowledge

structure. Descriptive statistics and ANOVA models were used to evaluate the data.

Rose et al.’s (2012) study provides support for regulators to examine the fraud risk

assessment framework to enhance the knowledge base for fraud detection.

Auditing standards emphasize the need for auditors to exhibit professional

skepticism during financial statement audits. Beasley et al. (as cited in Carpenter,

Durtschi, & Gaynor, 2011) reported that approximately 60 % of SEC “enforcement

actions against auditors between 1987 and 1997 were directly related to the failure of

auditors’ professional skepticism” (p. 2). The PCAOB cited “the lack of professional

skepticism as a serious problem in auditors’ fraud investigations” (Carpenter & Reimers,

2013, p. 46). Carpenter and Reimers (2013) and Bowlin, Hobson, and Piercey (2015)

provided support for the importance of professional skepticism in achieving high-quality

audits. Hurtt, Eining, and Plumlee et al. (2008) found that professional skepticism caused

auditors to behave differently but “the behavioral differences do not always go in the

direction of higher skepticism being associated with more skeptical behavior” (p. 25).

Rasso (2015) found that abstraction outperformed specificity in relation to achieving a

55

higher-level of professional skepticism when evaluating audit evidence. As different

perspectives of professional skepticism exist, Lee, Welker, and Wang (2013) found that

presumptive trust is more prevalent than presumptive doubt in fraud risk assessments,

while Quadackers, Groot, and Wright (2014) found presumptive doubt to be more

predictive of auditors’ skeptical judgments in high-risk environments. Peytcheva (2014)

provided support for professional skepticism as a personal trait, while Glover and Prawitt

(2014) posited that professional skepticism is influenced by the interrelationship of

structural levels. Ho, Kwock, and James (2015) studied the influence of Chinese culture

on professional skepticism and found a correlation between the cultural beliefs and

behaviors and professional skepticism. Carpenter, Durtschi, and Gaynor (2011)

examined the influence of a forensic accounting course on professional skepticism levels

and found that the course had a positive impact on fraud risk assessment performance.

Carpenter and Reimers (2013) conducted a research experiment to examine the

influence of audit partners’ professional skepticism on fraud risk assessments conducted

by the firms’ auditors. Using only two levels of partners’ professional skepticism

emphasis and one case study, Carpenter and Reimers (2013) found that the firms with

higher professional skepticism resulted in higher risk assessments in cases of both strong

and weak indicators (p. 66). Carpenter and Reimers used a 2X2 between-subjects

research design to manipulate partner emphasis on professional skepticism (high or low)

and the level of fraud indicators (strong or weak) to test fraud risk factors, fraud risk

assessments, and audit procedures for nine hypotheses. The participants in the

experiment consisted of 80 audit managers from Big 4 firms with an average of 8 years of

experience. An actual SEC fraud case using a company’s original financial statements

56

with strong fraud indicators and the same company’s restated financial statements with

weak fraud indicators was the case material utilized in the experiment. The participants

used the case material to assess fraud risk in addition to completing a professional

skepticism questionnaire. Professional skepticism was measured using Hurtt’s (2010)

30-item professional skepticism scale (Hurtt Professional Skepticism Scale). The

statistical analyses used to evaluate the findings were ANOVA and MANOVA.

Carpenter and Reimers’ (2013) findings support the call for auditors to exhibit

professional skepticism when assessing fraud risks.

In addition to the emphasis on maintaining professional skepticism in financial

statement audits, auditor rotation is evaluated as an attribute influencing audit quality.

The SEC requires rotation of audit partners, but not the rotation of audit firms as required

by the European Union (Bowlin, Hobson, & Piercey, 2015). Opponents of audit firm

rotation believe that reducing audit tenure reduces audit quality; however, the PCAOB

posits “that existing rotation requirements in the U.S. are insufficient and that firm

rotation requirements will enhance audit quality and professional skepticism” (Bowlin et

al., 2015, p. 1364). Using support theory as the theoretical framework, Bowlin et al.

conducted an experiment using a 2X2X2 between-participants design to examine the

effects of auditor rotation, professional skepticism, and interactions with managers on

audit quality. The independent variables manipulated to assess the outcome of audit

quality were auditor rotation (e.g., rotation versus no rotation), assessment frame (e.g.,

honesty assessment frame versus dishonesty assessment frame), and availability of

unstructured chat (e.g., chat versus no chat). The participants included 226

undergraduate students from a large university with minimal work experience (74 percent

57

sophomore standing, and 82 percent business students of which 48 percent were

accounting students). Two experimental groups were used (e.g., auditors and managers),

with random assignment of the participants to the groups. The research design was

operationalized as a strategic game where the auditor and manager made decisions.

Auditors chose either high- or low-effort audit while the managers chose either

aggressive or conservative reporting, which led to four possible outcomes. The honesty

and dishonesty probability evaluation of the managers’ representations was measured

using a scale from 0 to 100. The auditor’s highest payoff occurred with the interaction of

low-effort audit and conservative reporting, and the auditor’s lowest payoff occurred with

the interaction of low-effort audit and aggressive reporting. The data was analyzed using

ANOVA and pairwise contrasts. Bowlin et al. (2015) found that when auditors’

judgments were focused on managers’ honesty that auditor rotations increased audit

quality, but when auditor judgments’ were focused on managers’ dishonesty that auditor

rotations decreased audit quality (p. 1388). The aforementioned finding, noted by

Bowlin et al. (2015), provides evidence that audit firm rotation may not provide an

increase in audit quality and professional skepticism as “the benefits of professional

skepticism could be offset under mandatory auditor rotation” (Bowlin et al., 2015, p.

1388). Additionally, Bowlin et al. found that when the auditors interacted informally

with the managers that the assessment of management representations worsened and low-

effort audits were more frequent (p. 1388). Bowlin et al.’s study reinforces the

importance of professional skepticism in achieving high-quality audits.

Hurtt, Eining, and Plumlee (2008) conducted an experimental audit workpaper

review to assess the impact of auditors’ professional skepticism on two behaviors:

58

evidence assessment and generation of alternative explanations. The experimental task

used was a “simulated audit workpaper review adapted from Moeckel” (Hurtt et al.,

2008, p. 13). Eighty-three auditors from a major international accounting firm

participated in the online between-participants research experiment. Half of the

participants performed the workpaper review under a typical audit condition, while the

other half of the participants completed the workpaper review under a skepticism-induced

condition. Hurtt et al. (2008) assigned the participants to the groups based on rank-

ordered skepticism scores. The degree of professional skepticism, in this research, was

measured by the Hurtt Professional Skepticism Scale. The statistical method used to

analyze the data was ANCOVA. Hurtt et al. (2008) found that auditors with higher levels

of skepticism behave differently than auditors with lower levels of skepticism; however,

“the behavioral differences do not always go in the direction of higher skepticism being

associated with more skeptical behavior” (p. 25). Hurtt et al. recommended further

research on the influence of professional skepticism on auditor behaviors.

Evidence collection may also influence professional skepticism as the evidence is

used to make assessments. Rasso (2015) used construal-level theory to examine whether

and how interpretations of evidence affect auditors’ judgments and decisions. Construal-

level theory uses high-level construals (broad and abstract) and low-level construals

(specific and detailed) to evaluate how individuals interpret information to make

decisions (Rasso, 2015). Rasso selected 58 auditors with an average of 5.4 years of audit

experience from six accounting firms to participate in the 1X3 between-participants

experiment. The documentation instructions were manipulated on three levels: high-

level, low-level, and no instructions. The participants were randomly assigned to one of

59

the three conditions. The research instrument was an adapted computerized case study

where accounting estimates were used by the client; the case contained 12 evidence items

suggesting an aggressive estimate, 6 evidence items suggesting a fairly stated estimate,

and 12 neutral evidence items. Additionally, the computerized case study incorporated a

time budget for the participants, emphasizing the cost of evidence collection. The

dependent variables used to evaluate professional skepticism were the participants’

perceived risk that the estimate was materially misstated and the participants’ perceived

likelihood that they would require an adjustment to the estimate. A scale ranging from 1

(Very Unlikely) to 10 (Very Likely) was used to measure the dependent variables.

ANOVA and planned contrasts were used to analyze the data. Rasso found that

participants in the group with the high-level documentation instructions processed

incomplete evidence better and recognized the need for more evidence to make a

judgment; additionally, the high-level participants were more capable of recognizing a

high-risk level for a complex accounting estimate when the majority of the evidence

suggested an overstatement (p. 45). One important finding from Rasso’s study is that

abstraction outperformed specificity in relation to achieving professional skepticism

when evaluating audit evidence. Rasso (2015) also “suggest that auditors in practice

collect and process information with low-level construals” (p. 53), which may be related

to ineffective fraud risk assessments.

Professional skepticism of auditors was examined by Lee, Welker, and Wang

(2013) in relation to deception risk in interviews. In contrast to auditing standards, which

expects auditors to maintain an attitude of presumptive doubt, deception detection

literature presumes an attitude of presumptive trust (Lee et al., 2013). Lee et al.

60

conducted an online experiment with 59 practicing auditors with an average of 4.3 years

of auditing experience. A questionnaire that incorporated seven questions was given to

the participants to measure deception detection after watching an online video between an

interviewer and an interviewee who lied. The construct design used 20 different

interviewees to strengthen the validity of the experiment; hence, all participants did not

have the same interviewee in the video. The experimental design used one independent

variable with three treatment levels (i.e., suspicion-neutral, suspicion-inducing, and

suspicion-neutralizing), which varied based on the manipulation of the pay scheme (i.e.,

incentive to lie versus no incentive to lie) as well as the risk assessment. The risk

categories manipulated were financial pressure, attitude/rationalization, and potential for

discovery. The dependent variable of deception detection was measured by the

frequency of a truth decision in which a frequency exceeding 50 % was indicative of

presumptive trust. Lee et al. (2013) found approximately 70% incorrectly believed the

interviewee, which supports that presumptive trust is more prevalent than presumptive

doubt in conditions of deceptive risks. Notwithstanding the study’s limitations of a short

interview, observation instead of participation by the participants, and no financial risk to

the participants, Lee et al. provided support for future research to ascertain “whether a

trusting attitude deters auditors from perceiving suspicious behavior and whether it has a

detrimental effect on fraud risk assessment” (p. 223).

As professional skepticism does not have a universally accepted definition, two

perspectives have transpired – neutrality and presumptive doubt (Quadackers, Groot, &

Wright, 2014). According to Nelson (as cited in Quadackers et al., 2014), auditing

standards support the neutrality perspective, which supports an unbiased belief in

61

management’s assertions. In contrast, the presumptive doubt perspective supports a

biased belief that dishonesty exists unless evidence proves otherwise (Quadackers et al.,

2014). Quadackers et al. (2014) conducted an experimental study to ascertain the

relationship between the two professional skepticism perspectives and auditor judgments

and decisions using a higher-risk and lower-risk control environment. The independent

variable, control environment risk (high versus low), was manipulated using case

materials of Cohen and Hanno (2000), and the independent variable, professional

skepticism (i.e., neutrality versus presumptive doubt) was measured using two scales.

The Rotter Interpersonal Trust Scale (RIT) was inversed to measure presumptive doubt,

and the Hurtt Professional Skepticism Scale was used to measure neutrality. The

dependent variables were as follows: likelihood that management explanation is correct,

likelihood of fraud, number of alternative explanations, number of total error

explanations, weight of total error explanations, and the number of budgeted hours. The

sample consisted of 96 participants, including partners, managers, and seniors, from one

Big 4 auditing firm with an average of 15.36 years of auditing experience. The

participants were randomly assigned to the two risk conditions to conduct risk assessment

and audit planning tasks and to answer questions on skeptical attributes. Linear

regressions were used to assess the relationship between skeptical attributes and auditing

judgments for the two risk conditions. Quadackers et al. (2014) found the presumptive

doubt perspective to be more predictive of auditors’ skeptical judgments in higher-risk

environments (p. 651). Notwithstanding the limitations of the use of only one accounting

firm and the use of scales that were not designed to specifically measure the neutrality

and presumptive doubt perspectives of professional skepticism, Quadackers et al.

62

provided support for the auditing profession and regulators to reevaluate the emphasis of

a neutrality perspective versus a presumptive doubt perspective in the auditing standards.

Peytcheva (2014) further studied the presumptive doubt view of professional

skepticism. Peytcheva (2014) combined the presumptive doubt view of professional

skepticism (i.e., present versus absent) with a cheater-detection framework (i.e., present

versus absent) from social contracts theory to test auditors’ cognitive performance using a

2X2 between - participants experimental design. The dependent variable was the

participants’ correct response on the audit evidence needed to test the audit hypothesis.

The sample contained 78 senior accounting students enrolled in an auditing class and 85

practicing auditors with an average of 6.5 years of auditing experience from an

international auditing firm. A Wason evidence selection task based on prepositional

logic (i.e., if P then Q) was used by the participants to select the audit evidence

requirements after reading the auditing case. The trait of professional skepticism was

measured by the Hurtt Professional Skepticism Scale, which was modified from a six-

point scale to a seven-point scale. Peytcheva (2014) cautioned the use of a six-point scale

because it does not provide participants with the ability to provide a neutral response (p.

43). Logistic regressions were used to analyze the data. Peytcheva found that the

professional skepticism prompt improved the cognitive performance of the students but

not the auditors, and the cheater-detection prompt did not improve the cognitive

performance of the students or the auditors (p. 42). Additionally, a difference was not

found between the level of professional skepticism between the students and the auditors,

which substantiates the theory that professional skepticism is a personal trait (Peytcheva,

2014, p. 43).

63

Glover and Prawitt (2014) introduced a professional skepticism continuum that

relates the level of professional skepticism (e.g., complete trust to complete doubt) to the

risk characteristics of the account and assertion being audited, which attributes

professional skepticism to situational factors versus a personal trait. Glover and Prawitt

(2014) argued, “that regulation can threaten the appropriate application of auditor

skepticism if regulation and/or inspection focus is not properly aligned with relevant

audit risk” (p. P5). Glover and Prawitt illustrated the interrelationship of structural levels

(i.e., auditor, engagement team, audit firm, and the auditing profession) with the threats

and mitigating factors of each level. Suggestions made for individuals, audit teams, and

audit firms to enhance professional skepticism in the audit process to achieve audit

quality include the following:

• Provide training that uses a common and formal judgment framework;

• Identify and apply different judgment frames to challenge assumptions and

explanations;

• Align performance evaluation and incentives so professional skepticism is

rewarded;

• Create the perspective for the engagement team that an appropriate level of

professional skepticism is expected and valued;

• Structure group decisions to avoid groupthink tendencies; and

• Develop a firm culture of professional skepticism by developing a formal

professional judgment framework and process, and providing tools,

technology, and training to enhance professional skepticism (Glover &

Prawitt, 2014, pp. P8-P10).

64

Professional skepticism may also be influenced by an individual’s culture. Ho,

Kwock, and James (2015) investigated the influences of Chinese culture on the level of

skepticism exhibited by Chinese accounting students without audit experience to assess

only the cultural impact. Ho et al. (2015) developed a theoretical framework to measure

the Chinese students’ level of professional skepticism by using four of Hurtt’s (2010)

professional skepticism trait indicators (i.e., search for knowledge, autonomy, suspension

of judgment, and questioning mind). Hurt (2010) posited that professional skepticism

was not only a personal trait, but also a situational state (Ho et al., 2015, p. 277). A

survey methodology design was used to construct a questionnaire to assess the

relationship between Chinese behaviors and beliefs (guanxi) and professional skepticism.

The participants were 127 fourth year accounting students (73 % female) from a

university in Southern China. The students completed the questionnaire that measured

both guanxi (independent variable) and professional skepticism (dependent variable)

using Ang and Leong’s guanxi scale and Hurtt’s (2010) professional skepticism scale,

respectively. Factor analyses and regression models were used to analyze the data. Ho et

al. found that beliefs only have a significant positive association with search for

knowledge and suspension of judgment, while behaviors do not have a significant

association with neither search for knowledge, autonomy, suspension of judgment, nor a

questioning mind (p. 286). Ho et al. attributed these results to the “Chinese tradition that

advocates academic excellence through attaining knowledge… and not questioning

teachers” (p. 286), and to the acceptance of “the authority and decisions of superiors” (p.

286). Generalization of the study to the Chinese culture was limited by the small sample

65

size and the geographic location selected in China; however, the findings do provide for

further study on the influences of culture on professional skepticism.

Some researchers posit that professional skepticism is a personal trait and/or a

situation state, while other researchers posit that professional skepticism can be learned.

Carpenter, Durtschi, and Gaynor (2011) conducted a seven-month longitudinal study to

examine the influence of a forensic accounting course on fraud risk assessments to

measure professional skepticism levels. An experimental group (37 students) that

completed two courses in auditing and a forensic accounting course, a control group (32

students) that completed only two courses in auditing, and a panel of seven experts

participated in the study. The fraud-related judgments were measured with a case-based

questionnaire that the experimental group participants completed after reviewing a case

study with an unusual bad debt expense on the first day of class, the last day of class, and

seven months after course completion (only 17 of the participants completed). The

control group participants completed the same case-based questionnaire on the last day of

the second auditing course. The case-based questionnaire used an 11-point Likert-type

scale ranging from 0 (Not At All Likely) and 10 (Extremely Likely) to assess the

likelihood of an intentional misstatement in the financial statements of the case study.

The data for this study was analyzed using a repeated-measure ANOVA. Carpenter et al.

(2011) found that the forensic accounting course had a positive impact on fraud risk

assessment performance. The experimental group’s post-training assessment results

provided a higher fraud risk assessment than the results from the control group’s

assessment and the experimental group’s pre-training assessment (Carpenter et al., 2011,

p. 3). Additionally, the experimental group rated the fraud-risk factors as more relevant

66

than the experts and the control group participants; hence, this result emphasized the

importance of fraud education for effective fraud risk assessment performance. More

importantly, Carpenter et al. found that the effects from the forensic accounting course

lasted over time because the test results after seven months were similar to the post-

training assessment results. Carpenter et al.’s study provides support for forensic

accounting training to increase professional skepticism, which leads to improving fraud

risk assessment performance.

Certified Fraud Examiners

The most recognized and respected professional certification of accountants is the

certified public accountant (CPA) designation (Nix & Morgan, 2013). Due to the

occurrence of significant corporate accounting scandals, since the late 1990s, the certified

fraud examiner (CFE) professional certification is attaining the attention of businesses,

the accounting profession and regulators. Nix and Morgan (2013) referenced the ACFE’s

2012 Report to the Nations, which found that fraud remains prevalent despite the passage

of SAS No. 99, as well as SOX in 2002. The CFE certification is indicative of

specialized “knowledge of fraud assessment, detection, and prevention methods” (Nix &

Morgan, 2013, p. 4), which may assist in fraud reduction. Nix and Morgan (2013)

provided support for the value of the CFE certification and Popoola, Che-Ahmad, and

Samsudin (2014) confirmed a positive relationship between fraud knowledge and fraud

risk assessment. However, Boritz, Kochetova-Kozloski, and Robinson (2015) did not

find that fraud specialists were more effective than financial statement auditors in

modifying audit plans when fraud was present.

67

Nix and Morgan (2013) conducted a research survey to ascertain the perceptions

of chief financial officers (CFOs) to provide empirical evidence on the value of the CFE

certification. The sample consisted of 500 CFOs from large public corporations,

commercial banks, and financial institutions. The participants answered survey questions

on perceptions of the CFE certification using a five-point Likert response scale ranging

from -2 (Strongly Disagree) to +2 (Strongly Agree). Nix and Morgan found the CFE

certification to be of value, but the participants’ perceptions of value were directly related

to knowledge of the ACFE’s CFE program. Even though this study was limited to CFO

perceptions, it documented the importance of promoting the CFE professional

certification and conducting future research on the value of the CFE credential (Nix &

Morgan, 2013).

In response to PricewaterhouseCoopers International Limited’s 2011 Global

Economic Crime Survey, which reported a rise in economic crime in Malaysia, Popoola,

Che-Ahmad, and Samsudin (2014) studied the correlation of fraud risk assessments and

auditing knowledge in relation to the auditors in Malaysia. Popoola et al. (2014) posited

that fraud risk assessments performed by individuals with forensic knowledge might

produce higher task performance in fraud detection than auditors without specialized

fraud knowledge. Similarly, Popoola, Che-Ahmad, and Samsudin (2015) conducted a

study of the relationship between fraud knowledge and fraud risk assessment in Nigeria

using a cross-sectional design of auditors and forensic accountants. The 400 participants

completed a 36-item questionnaire, which used a five-point Likert scale ranging from 1

(Strongly Agree) to 5 (Strongly Disagree). Popoola et al. (2015) confirmed a positive

68

relationship between fraud knowledge and fraud risk assessment. These studies support

the important role of certified fraud examiners in fraud detection.

In contrast, Boritz, Kochetova-Kozloski, and Robinson (2015) did not conclude

that fraud specialists are more effective than financial statement auditors in modifying

audit plans when fraud was present. Auditing standards recommend that when there is a

high risk of fraud that financial statement auditors obtain assistance from fraud specialists

to alter audit plans for fraud testing (Boritz, Kochetova-Kozloski, & Robinson, 2015).

Boritz et al. designed an experiment using a one-between participants factor, participant

type (fraud specialists versus financial statement auditors) to test the hypotheses that

fraud specialists increase overall audit effort by proposing greater numbers of audit

procedures, select more effective audit procedures when the risk of fraud is high, and

increase the budgeted hours for the audit procedures (p. 886). The Canadian participants

were 32 fraud specialists (50% Big 4 and 50% medium-size firms with an average of 12

years of fraud experience and 6 years of auditing experience) and 16 financial statement

auditors (60% Big 4 and 40% medium-size firms with an average of 13.25 years of

auditing experience and no fraud-related experience). The research instrument was an

adapted audit case based on an actual company’s fraudulent financial statements in which

the participants selected and proposed audit procedures and modified budget hours for the

audit of the revenue cycle. The quality of the revenue cycle audit program (e.g.,

dependent variable) was tested through the manipulation of the independent variable

(e.g., participant type), and the covariates (e.g., the number of procedures from a standard

audit program and audit experience). The data was analyzed using t-tests, MANOVAs,

and ANCOVAs statistical designs. The results did not provide support for Boritz et al.’s

69

(2015) hypotheses; hence, the regulators’ recommendation to seek assistance from fraud

specialists in the presence of fraud during a financial statement audit may not result in

more effective and efficient audit plans to detect fraud. Due to the study’s construct

limitations, including the lack of a fraud brainstorming session and the use of audit

experts rather than fraud experts to form effectiveness and efficiency judgments for the

audit procedures without knowing that fraud was present (Boritz et al., 2015, p. 899),

additional research is needed to further explore the role of fraud specialists in financial

statement audits when fraud risk is present.

Summary

The purpose of the literature review was to synthesize academic literature to

examine the theoretical underpinnings of fraud and attribution in relation to financial

statement fraud to find gaps in the current body of knowledge. This synthesis should be

relevant to auditors, regulators, researchers, and academicians. This chapter included a

review of literature relevant to regulations pertaining to fraud risk assessment, risk

assessment models used to assess risk, attributes of auditors performing fraud risk

assessments, and perceptions of the certified fraud examiner credential on fraud risk

assessments.

According to the literature, auditors must follow auditing standard, SAS No. 99,

when conducting an audit of a U.S publicly traded company; SAS No. 99 requires that

auditors perform a fraud risk assessment using the fraud triangle to detect financial

statement fraud. Many researchers argue that the fraud triangle is not broad enough to

perform an effective fraud risk assessment (e.g., Boyle et al., 2012; Dorminey et al.,

2010; Lokanan, 2015; Schuchter & Levis, 2015; Soltani, 2014). The literature includes

70

various fraud risk assessment models introduced to improve auditors’ fraud risk

assessment processes.

Researchers disagree on the correlation of auditors’ attributes to fraud risk

assessment outcomes (e.g., Fathil & Schmidtke, 2010; Jaffar et al., 2011). The PCAOB

cited “the lack of professional skepticism as a serious problem in auditors’ fraud

investigations” (Carpenter & Reimers, 2013, p. 46). Researchers were found to have

different beliefs on the role of professional skepticism in relation to fraud risk

assessments (e.g., Bolin et al., 2015; Carpenter & Reimers, 2013; Glover & Prawitt,

2014; Lee et al., 2013; Peytcheva, 2014). The literature also provided mixed perspectives

on the importance of auditors having the certified fraud examiner credential for the

performance of fraud risk assessments (e.g., Boritz et al., 2015; Nix & Morgan, 2013;

Popoola et al., 2014).

Further research is warranted to better understand the complexities of fraud risk

assessments to improve effectiveness in detecting financial statement fraud. Auditing

regulations, fraud risk assessment models, auditor attributes, and fraud knowledge have

been found to have an influence on fraud risk assessment performance. More emphasis

needs to be placed on measuring fraud knowledge and professional skepticism as fraud

risk assessments are based on auditors’ judgments.

71

Chapter 3: Research Method

Occupational fraud overall, including financial statement fraud, is a challenge for

the global business environment. The Association of Certified Fraud Examiners (2014)

posited that, “Occupational fraud is a universal problem for businesses around the globe”

(p. 5). PricewaterhouseCoopers reported that 30% of companies worldwide were victims

of fraud in 2009 (Murphy & Dacin, 2011). The ACFE’s (2014) Report to the Nations on

Occupational Fraud and Abuse reported that approximately 5% of organizations annual

revenues are lost to fraud, which estimates $3.7 trillion worldwide (Drew, 2014, para. 1).

Drew (2014) reported that 48% of the fraud cases were in the U.S. and that “financial

statement frauds were the least common, but most costly, representing 9% of cases and a

median loss of $1 million” (para. 14). Hence, 13 years after the enactment of SOX,

financial statement fraud is still prevalent, not only in the U.S., but also worldwide

(Association of Certified Fraud Examiners, 2014).

Auditors’ fraud risk assessments are not effectively detecting financial statement

fraud. Hopwood, Leiner, and Young (2012) reported that auditors who applied SAS No.

99 detected only “5 to 20 percent of the occupational frauds” (p. 169). Albrecht and

Hoopes (2014) posited the following reasons why auditors are unable to detect fraud,

which include: a) voluminous nature of accounting records, b) use of outsiders to conceal

the fraud, c) reluctance of people to disclose information about fraudulent acts, d) use of

forgery and lying to provide barriers against discovery, and e) lack of performance of

sufficient financial statement audits. Additionally, Albrecht and Hoopes (2014)

identified four factors that prevent auditors from performing sufficient financial statement

audits to detect financial statement fraud, which include a) inadequate training and

72

experience, b) poor audit planning, gathering of evidence, and examining controls, c) lack

of due professional care, and d) lack of independence (p. 20). Trompeter, Carpenter,

Desai, Jones, and Riley (2013) stated that the PCAOB inspections found deficiencies in

auditors’ responses to fraud risk. Trompeter et al. (2013) recommended future research

to ascertain if the deficiencies are a result of the auditors’ failure to respond or a result of

the auditors’ inability to respond when appropriate fraud assessment techniques are used.

Hurtt, Brown-Liburd, Earley, and Krishnamoorthy (2013) acknowledged the importance

of professional skepticism in fraud detection, but stated, “research is limited to the

actions that auditors actually take related to their professional skepticism” (p. 72). Due to

the complexity of the interrelationships in conducting a fraud risk assessment, as well as

the importance of fraud detection for the auditing profession and regulators, additional

research is needed to understand fraud risk assessments and the elements influencing

fraud risk assessment performance. Effective fraud risk assessments identify fraud risk

factors (i.e., opportunities, incentives, and pressures), which may lead auditors to the

discovery of financial statement fraud (Dorminey et al., 2012).

The purpose of this quantitative research study was to examine the theoretical

underpinnings of fraud and attribution as it relates to the independent variables of the

presence of fraud and auditor certification, the control variable of professional

skepticism, and the dependent variable, fraud risk assessment performance, for

participants within the U.S. that are certified fraud examiners and/or certified public

accountants. Auditor certification was categorized by the identification of certification

attributes (CFE, CFE/CPA, or CPA). Professional skepticism was measured by using

Hurtt’s (2010) six-point Likert skepticism scale to classify the trait of professional

73

skepticism into high and low levels. Twenty-five certified public accountants with at

least 15 years of experience, which included working at one or more international

accounting firms, validated Hurtt’s theoretical view of professional skepticism through

the use of an open-ended questionnaire on the traits of professional skepticism. The

content validity of the scale was validated by a pilot test of three faculty members with

professional auditing experience and education, which resulted in the reduction of the

scale items from 170 to 49. Additionally, 89 graduate and undergraduate students

participated in the pretesting of the scale, which resulted in a further reduction of the

scale items to 40. The 40-item scale was administered to 250 undergraduate business

students twice for reliability testing, which resulted in a further reduction of the scale to a

30-item scale; the 30-item scale was successfully tested by the student participants (Hurtt,

2010). The 30-item scale was also tested using a repeated-measures design with

participation from 200 and 88 auditors, respectively, from a major international auditing

firm; Hurtt found a statistically significant correlation of internal consistency between the

two tests. Hurtt (2010) concluded, “These results provide preliminary evidence that the

skepticism scale is a valid instrument with appropriate inter-item and temporal stability”

(p. 164).

Fraud risk was operationalized by the use of two sets of financial statement data

from the Securities and Exchange Commission’s (SEC) public database for the years

2005–2014 of which one set contained high-fraud risk and one set contained low-fraud

risk. Fraud risk assessment performance measured the auditors’ ability to assess fraud

risk. Fraud risk assessment performance was measured as seven-point Likert scale data,

using at least four Likert-type items combined, so that an interval measurement scale

74

could be used for quantitative analyses. Boone and Boone (2012) illustrated that a

composite score (i.e., sum or mean) may be calculated from four or more similar Likert-

type items, which allows the use of parametric analysis using the analysis of variance

(ANOVA) technique. NGO Security (2010) combined probability of occurrence and

impact of risk to illustrate the use of a seven-point Likert scale to quantitatively assess

risk by multiplying the two rating values together; the higher number represents higher

risk. Additionally, NGO Security recommended that the multiplication of the combined

score by two approximate the familiar 100-point scale (i.e., 2 to 98). Jaffar, Haron,

Iskandar, and Salleh (2011) used a seven-point Likert scale ranging from extremely

unlikely to extremely likely to measure auditors’ ability to assess fraud risk with

ANOVA as the statistical method for evaluation. A Likert scale was the instrument

utilized to measure fraud risk assessment performance because neither the PCAOB nor

the AICPA have a standardized fraud risk assessment tool that is used by auditors to

assess fraud risk (Albrecht & Hoopes, 2014; Boritz et al., 2015). Generally, auditors

measure fraud risk as high, medium, or low; hence, a numeric value is not traditionally

attributed to fraud risk assessments (Boritz et al., 2015).

The participants in this study were certified fraud examiners and certified public

accountants from the population of the Association of Certified Fraud Examiner’s

(ACFE) LinkedIn group and online forum of certified fraud examiners and associate

memberships, the population of the American Institute of Certified Public Accountants’

(AICPA) LinkedIn group memberships, and the population of the Virginia Society of

Certified Public Accountants’ (VSCPA) LinkedIn group and online forum memberships.

Members were invited to participate in the experiment using the online forums. The

75

experimental construct was a 2X3 between-participants design with two levels for one

independent variable and three levels for the second independent variable to test the fraud

risk variable. SPSS was used to conduct a two-way analysis of variance (ANOVA) to

determine the effect that the categorical independent variables (the presence of fraud risk

and auditor certification) had on the interval dependent variable (e.g., fraud risk

assessment performance). Next, SPSS was used to conduct a two-way analysis of

covariance (ANCOVA) to examine the influence of the control variable, professional

skepticism, on the fraud risk assessment performance dependent variable. Planned

contrasts were also conducted in SPSS to determine interaction effects of the auditor

certification variables.

The research questions and hypotheses are presented prior to a discussion of the

research methodology, population, and materials/instruments used for the research study.

Operational definitions of the variables are provided along with an elaboration of the data

collection and analyses. Additionally, assumptions, limitations, delimitations, and ethical

assurances of the research project are discussed.

The following research questions and hypotheses guided the study to examine the

effects of the presence of fraud risk and auditor certification while considering

professional skepticism on fraud risk assessment performance.

Q1. Does the presence of fraud risk have an effect on fraud risk assessment

performance?

Q2. Does a certification in fraud knowledge have an effect on fraud risk

assessment performance?

Q3. Does professional skepticism influence fraud risk assessment performance?

76

H10. The presence of fraud risk does not have a significant effect on fraud risk

assessment performance.

H1a. A high level of fraud risk produces a high-fraud risk assessment

performance.

H20. A certification for fraud knowledge does not have a significant effect on

fraud risk assessment performance.

H2a. Auditors that possess a certification in fraud detection produce more

effective fraud risk assessment performance than auditors without the

certification.

H30. The level of auditor professional skepticism does not have a significant

influence on fraud risk assessment performance.

H3a. Auditors that exhibit professional skepticism produce more effective fraud

risk assessment performance than auditors without this attribute.

Research Design

The research study used a quantitative experimental between-participants research

design to assess the effect of the presence of fraud and auditor certification, while

considering professional skepticism, on fraud risk assessment performance. The

experiment was conducted in the online environment using Qualtrics online survey

software. An online research design provided for cost savings of time, postage, and

travel. The population was U.S. CFEs and CPAs that were members of the ACFE,

AICPA, or the VSCPA. The participants (sample) were those who responded on a

volunteer basis. The ACFE and the AICPA were selected as two of the organizations to

use as the population because the ACFE is the largest anti-fraud organization worldwide

77

and the AICPA is the largest global professional association of accountants in the U.S.

(Association of Certified Fraud Examiners, 2014; “About the AICPA,” n.d., para. 1).

The VSCPA was selected as an organization to use as the population for representation of

a state professional association. Members were invited to participate in the online

experiment using the ACFE LinkedIn group and online forum of certified fraud

examiners and associate memberships, the AICPA LinkedIn group memberships, and the

VSCPA LinkedIn group and online forum memberships. The population consisted of

individuals with the following certifications: CFE, CFE/CPA, or CPA. Before the

participant could participate in the online study, a certification question was required to

be answered, which determined participation eligibility. Eligibility was defined by the

participant’s age (i.e., age must be at least 18 years), the possession of the appropriate

professional certification (i.e., CFE, CFE/CPA, or CPA), and the participants’ work

location (i.e., participant must work in the U.S.). Hence, an individual without a CFE

and/or CPA certification was not eligible to participate in the study, which addressed

selection and regression threats. Self-identification of certification was used to categorize

the participants into the three levels for auditor certification (CFE, CFE/CPA, or CPA).

Random assignment was used to divide the three-group random sample into the following

six comparative groups – three groups analyzed high-fraud risk data and three groups

analyzed low-fraud risk data. External validity was strengthened from the use of random

sampling and the use of random assignment of participants to test the fraud risk variable.

The SEC database of U.S. publicly traded companies was used to randomly select

a corporation that reported an occurrence of financial statement fraud during 2005–2014.

The SEC maintains a database of accounting and auditing enforcement releases

78

(AAERs), which is a comprehensive listing of discovered financial statement fraud cases

in the U.S. After the random selection of a U.S. company with financial statement fraud,

the Form 10-K, which contains the company’s financial statements and other financial

and nonfinancial data, was obtained from the SEC database. The Form 10-K, with the

company identifiable information erased, was the instrument used in the high-fraud risk

group for performing the risk assessment. The restated Form 10-K of the same company

(i.e., financial statements without fraud) was the instrument used in the low-risk group for

performing risk assessment. Internal validity was strengthened by the use of an actual set

of fraudulent and restated financial statements for the fraud risk variable.

The assessment tool for the professional skepticism variable was the validated

Hurtt Professional Skepticism Scale (Hurtt, 2010), which is designed to measure

professional skepticism. Hurtt (2010) selected three experts (i.e., faculty members with

auditing experience) for the content validity of the scale (i.e., pretest of the scale), and

selected 247 undergraduate business students and 200 auditors from a major international

auditing firm to validate the scale using a rigorous and iterative process. This is a 30-

item scale with scale scores ranging from 30 to 180 in which higher scores depict a

higher level of professional skepticism. Hurtt (2010) explained that the scale could be

transformed to a 100-point scale by dividing the participant’s score by 180 (p. 168). The

Hurtt Professional Skepticism Scale is a well-recognized instrument used by researchers

to measure professional skepticism. The Hurtt Professional Skepticism Scale has been

used by Boyle et al. (2012), Carpenter and Reimers (2013), Peytcheva (2014), and

Quadackers et al. (2014).

79

The fraud risk assessment performance was measured using an interval

measurement Likert scale. The participants used the following four similar Likert-type

questions to assess fraud risk: a) likelihood of fraud risk, b) significance of fraud risks, c)

significance of anti-fraud controls in use, and d) likelihood of fraud. A fraud risk

assessment composite score was calculated from the answers to the questions. IBM

SPSS Statistics version 24 was used to perform statistical data analyses during ANOVA

and ANCOVA along with planned contrasts for the analysis of variable interactions.

A quantitative research method was appropriate for this research study in that the

intent of the study was to identify and evaluate the variables (i.e., the presence of fraud

risk, auditor certification, and professional skepticism) that influence an outcome (i.e.,

fraud risk assessment performance) by developing and testing hypotheses. A 2X3

between-subjects experimental design was chosen in that participants were divided into

three groups by self-identification of professional certification (i.e., CFE, CFE/CPA, or

CPA) and then randomly assigned by Qualtrics to one of two conditions (i.e., high-fraud

risk and low-fraud risk) to make inferences from the research findings and achieve

generalization. Moreover, a quantitative method provided for the use of statistical data

analysis to conclude causality as the variables were measured using an interval scale.

According to Park and Park (2016), a quantitative research method provides for

justification due to reliability and validity testing, in a controlled environment, which is

in contrast to a qualitative research method, which provides for discovery in natural

conditions. A quantitative study provides for recommendation(s) to research findings by

using structured data collection techniques coupled with statistical analyses compared to

the inconclusive research findings from unstructured or semi-structured data collection

80

techniques of a qualitative study (Park & Park, 2016). Barnham (2015) emphasized that

the key tenants of quantitative research include controlled conditions, large base sizes,

and the application of statistics to make inferences about the population, which is in

contrast to qualitative research that focuses on perceptions of how incidences occur,

which cannot be generalized to the population. Historically, qualitative studies have

received criticisms related to validity and reliability (Barnham, 2015).

A qualitative research method was not appropriate for the research study in that

the variables of the design were identified prior to the collection of data, and data

collection was operationalized to relate the variables to the research questions and

hypotheses for hypothesis testing not hypothesis generation. Instrument-based questions

were utilized, as opposed to open-ended questions, as the intent was to provide for

generalizability using statistical interpretations, as opposed to particularity using

emergent interpretations based on judgment.

Population

The ACFE was selected as one organization to use as the population because it is

the largest anti-fraud organization worldwide, which includes approximately 70,000

members in 150 countries (Association of Certified Fraud Examiners, 2014). The

population of the ACFE online forum was limited to U.S. CFEs and U.S. associate

members of the ACFE, which included approximately 33,500 CFEs and 16,800 associate

members (A. McNeal, personal communication, October 16, 2015). The associate

members of the ACFE are not CFEs, but they may be CPAs so they were included in the

population. The population of LinkedIn ACFE group members approximated 37,500

(LinkedIn, n.d., ACFE group).

81

The AICPA was selected as one organization to use as the population, because it

is the largest global professional association of accountants in the U.S. with

approximately 418,000 members in 143 countries (“About the AICPA,” n.d., para. 1).

AICPA members are required to complete 120 hours of continuing education every three

years to stay current in the accounting field (“About the AICPA,” n.d.). The population

was limited to U.S. CPAs and/or CFEs AICPA LinkedIn group members, which included

approximately 63,500 members (LinkedIn, n.d., AICPA group).

The VSCPA was selected as another organization to use as the population for the

inclusion of a state professional association of which the researcher is a member. The

VSCPA consists of approximately 12,000 members (“About the Virginia Society of

CPAs,” n.d., para. 2). The population was limited to U.S. CPAs and/or CFEs from the

VSCPA LinkedIn group, which included approximately 5,260 members (LinkedIn, n.d.,

VSCPA group), and from the VSCPA Connect online forum, which included

approximately 11,600 members (Connect, n.d.).

The sample represented participants from the ACFE, AICPA, and the VSCPA

populations of CFEs and CPAs, who work in the U.S., and voluntarily decided to

participate in the study. CFEs and CPAs, from the U.S., were invited to participate in the

online between-participants experiment using the ACFE and VSCPA online forums and

the LinkedIn forums of the ACFE, AICPA, and VSCPA. Before the individual could

participate in the online study, a certification question was required to be answered to

determine participation eligibility. Next, the eligible participants were divided into three

groups by the self-identification of professional certification (CFE, CFE/CPA, or CPA).

Qualtrics, online survey software, was designed to apply random assignment to divide the

82

random sample of the three groups into the following comparative groups – three groups

were to analyze high-fraud risk data and three groups were to analyze low-fraud risk data.

The sample size has a direct relationship to the significance of the test statistic

(Field, 2013). According to Field (2013), the p-value is used to signify a statistically

significant result (i.e., p < .05). Using the computer program, G*Power3, the sample size

for this research study needed to include least 100 participants to achieve a 95%

confidence interval and a significance level of .05 (p < .05) for six groups and a large

effect size of .40 for an ANCOVA statistical analysis.

Materials/Instrumentation

The materials used to test the presence of fraud risk variable was a set of

fraudulent financial statements issued by a U.S. public company to represent high-fraud

risk and the subsequent restated financial statements of the same company to represent

low-fraud risk. The SEC database of U.S. publicly traded companies was used to

randomly select a corporation that reported an occurrence of financial statement fraud

during 2005–2014. The time period was selected because it is after the passage of the

Sarbanes-Oxley Act of 2002, which created numerous regulations for both auditors and

corporations (Alleyne & Elson, 2013). The SEC maintains a database of accounting and

auditing enforcement releases (AAERs), which is a comprehensive listing of discovered

financial statement fraud cases in the U.S. After the random selection of a U.S. company,

with financial statement fraud, the Form 10-K, which contains the company’s financial

statements and other financial and nonfinancial data, was obtained from the SEC

database. The Form 10-K, with the company’s identifiable information removed, was the

instrument used in the high-fraud risk group for performing the risk assessment. The

83

restated Form 10-K of the same company, with the company’s identifiable and

restatement inferences removed, was the instrument used in the low-fraud risk group for

performing the risk assessment. Internal validity was strengthened by the use of an actual

set of fraudulent and restated financial statements for the fraud risk variable. The

instrumentation of the original fraudulent Form 10-K and the restated Form 10-K

provided for control to accurately draw conclusions about the effect of the presence of

fraud on fraud risk assessment performance.

Participants in each group completed a questionnaire, designed in Qualtrics, to

capture demographic data, including information about professional certification. The

self-identification of professional certification was used to categorize the participants into

the three levels of auditor certification (CFE, CFE/CPA, or CPA) to measure the auditor

certification variable. The CPA credential was selected as it is the most respected

certification in the accounting profession and represents “knowledge and competence”

(Nix & Morgan, 2013, p. 2). The CFE certification was selected because it was

recognized in SAS No. 99 as beneficial for fraud risk assessments and fraud detection

(Nix & Morgan, 2013).

The Hurtt Professional Skepticism Scale was input into Qualtrics and used to

measure the level of professional skepticism for each participant. The Hurtt Scale is a

30-item scale with scale scores ranging from 30 to 180 in which higher scores depict a

higher level of professional skepticism (See Appendix A). The Hurtt Professional

Skepticism Scale was validated by Hurtt (2010) using a rigorous and iterative process;

moreover, it is used by researchers to measure professional skepticism (Boyle et al.,

2012; Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014).

84

Participants in each group completed a seven-point Likert scale designed in

Qualtrics to perform a fraud risk assessment on the experimental financial statement

materials. The participants used four similar Likert-type questions to assess fraud risk:

(a) likelihood of fraud risk, (b) significance of fraud risks, (c) significance of anti-fraud

controls in use, and (d) likelihood of fraud. A fraud risk assessment composite score was

calculated from the Likert scale ratings, which ranged from 1 (Very

Improbable/Insignificant) to 7 (Very Probable/Significant; See Appendix E).

Operational Definition of Variables

The construct was a 2X3 experimental design using a two-way ANOVA and

ANCOVA for the statistical analyses. Between-participants construct, which utilized

random sampling and random assignment, was used to create six comparison groups

from the ACFE, AICPA, and VSCPA online forums and LinkedIn memberships. Three

comparison groups performed a fraud risk assessment using an instrument that contained

high-fraud risk, and three groups performed a fraud risk assessment using an instrument

that contained low-fraud risk. The instruments used were actual Form 10-Ks from the

SEC database of U.S. publicly traded companies. The participants in each group self-

reported professional certification status as CFE, CFE/CPA, or CPA to create three

groups for the three levels of the auditor certification variable. Additionally, the

participants in each group used the Hurtt Professional Skepticism Scale to assess the level

of professional skepticism. The calculated fraud risk assessment score from the

responses to the seven-point Likert scale, which contained four similar questions, was

used to measure the fraud risk assessment performance.

85

Construct 1- Auditor certification. The auditor certification independent

variable was a nominal variable with three levels – CFE credential, CFE/CPA credential,

and CPA credential. Self-identification by participants for professional certification was

used to categorize the participants into three groups in the Qualtrics application. The

categorization of participants in Qualtrics was exported to SPSS for statistical analyses

purposes.

Construct 2- Fraud risk assessment performance. The dependent variable of

fraud risk assessment performance was an interval variable measured by a seven-point

Likert scale, which ranged from 1 (Very Improbable/Insignificant) to 7 (Very

Probable/Significant; See Appendix E). The participants used four similar Likert-type

questions to assess fraud risk: a) likelihood of fraud risk, b) significance of fraud risks, c)

significance of anti-fraud controls in use, and d) likelihood of fraud. The raw data from

Qualtrics was exported to MS Excel to calculate a fraud risk assessment composite score

from the Likert scale ratings. The Likert scale composite score was the sum of four

similar Likert-type questions to quantify the assessment of financial statement fraud risk.

The fraud risk assessment composite score was exported from MS Excel to SPSS for use

in the statistical analyses.

Construct 3- Presence of fraud risk. The presence of fraud risk independent

variable was a nominal variable with two levels (e.g., high-fraud risk and low-fraud risk).

The source of experimental materials (Form 10-K) used was from the SEC database. The

fraudulent financial statements of a U.S. publicly traded corporation represented high-

fraud risk, and the restated financial statements of the same corporation represented low-

fraud risk. Each participant in the three auditor certification groups was randomly

86

assigned, by Qualtrics, to the high-fraud risk group or the low-fraud risk group, which

created six groups for the research study. Qualtrics used a different question number for

the participants who were randomly assigned to the high-risk condition and to the low-

risk condition (See Appendix E; Question 10 represents the high-risk condition and

Question 11 represents the low-risk condition). MS Excel was used to code the

participants who were assigned to the high-fraud risk condition with a 1) and the

participants who were assigned to the low-fraud risk condition with a 2) to identify the

presence of the fraud condition for each participant. The MS Excel spreadsheet was

exported to SPSS, which was used for statistical analyses.

Construct 4- Professional skepticism. The professional skepticism control

variable was an interval variable measured by the Hurtt (2010) six-point Likert scale,

which ranged from 1 (Strongly Disagree) to 6 (Strongly Agree; See Appendix A). The

Hurtt Professional Skepticism Scale 30-item questionnaire was the instrument selected to

measure the participants’ level of professional skepticism towards financial statement

fraud detection. The participants’ results were exported from Qualtrics to MS Excel to

calculate the participants’ professional skepticism composite score by summing

participant responses. The professional skepticism composite scores were exported from

MS Excel to SPSS for use in the statistical analyses.

Study Procedures

Approval was obtained from Northcentral University’s Institutional Review

Board (IRB) prior to any data collection. The research design met Northcentral

University’s IRB Category 2 criterion for exempt reviews, which indicated that the

ethical issues associated with this research study were minimal. The ethical principles

87

and guidelines applied to this research study relate to plagiarism, risk of harm, informed

consent, privacy and confidentiality, and data collection and reporting. Participants’ risk

of harm was minimized as they only performed a fraud risk assessment on a set of

financial statements and completed a validated professional skepticism questionnaire.

Informed consent was obtained from all of the participants without deception or coercion.

Confidentiality was maintained, even though the research study used the Internet to

obtain data using an online survey. Confidentiality can be viewed as problematic, as

there is a potential risk for a confidentiality breach, though this breach did not occur in

this research study. Privacy and anonymity were provided as participant names were not

collected and a third-party online survey software, Qualtrics, was used, which used a

high-end firewall system to protect the data stored on the Qualtrics website. The data

downloaded from Qualtrics excluded the participants’ IP addresses. Furthermore,

password-protection was used on portable devices that stored the data. All paper files

and portable devices with data information continue to remain stored in a locked cabinet.

In accordance with IRB requirements, the paper and electronic data will be destroyed in

seven years (i.e., after the completion of this dissertation; Northcentral University, 2015).

The construct design of two fraud risk conditions, which were unknown to the

participants, did create a lack of full disclosure because of the need to strengthen the

study’s internal validity. As internal validity is achieved when the results can be

explained by the independent variable, the construct design provided that the participant

was not made aware of the presence of fraud condition since this was the variable tested.

The research study was conducted by obtaining volunteer participants from the

members participating in the online forums of the ACFE and VSCPA and the LinkedIn

88

ACFE and AICPA online forums. Qualtrics software was used to create the

questionnaire for the participants (See Appendix E). The questionnaire included the

informed consent form (See Appendix D), demographic questions (i.e., age, gender, U.S.

geographical location, years of audit experience, and years of fraud risk assessment

experience), the professional certification eligibility question (i.e., CFE, CFE/CPA, or

CPA), and the 30-item Hurtt Professional Skepticism Scale questionnaire. After

completing the skepticism questionnaire (See Appendix A) that was inputted into the

Qualtrics questionnaire, the participants were randomly assigned by the Qualtrics

application to either the high-fraud risk or to the low-fraud risk condition to review the

Form 10-K materials. Next, the participants performed a fraud risk assessment from the

Form 10-K materials using the seven-point Likert scale created in the Qualtrics software.

The survey concluded after the fraud risk assessment was complete.

Data Collection and Analysis

The proposed research study used human subjects to test the hypotheses in the

online environment. Qualtrics was used to collect data from the participants. The

financial data used in the fraud risk assessment process was collected from the Securities

and Exchange Commissions, which is a publicly available Internet database, that has

Form 10-K company filings and Accounting and Auditing Enforcement Releases

(Beasley et al., 2010). The Hurtt Professional Skepticism Scale was the instrument used

to measure professional skepticism. The collected data was processed with SPSS

Statistics version 24 and MS Excel software applications. A two-way ANOVA and

ANCOVA with planned contrasts were used to analyze the data.

89

Data collection. An online survey software tool, Qualtrics, was used to collect

the data from the participants. Qualtrics was designed to randomly assign the volunteer

participants to one of two conditions (e.g., high-fraud risk or low-fraud risk), which

occurred after the self-identification of professional certification (CFE, CFE/CPA, or

CPA). The software was programmed to alternate the assignment of participants with the

same professional certification to a different experimental condition to provide for

diversity of certifications in each group (i.e., CFE, CFE/CPA, or CPA). Once assigned to

a group, each participant completed a set of demographic questions, which included age,

gender, U.S. geographical location, years of audit experience, and years of fraud risk

assessment experience. The aforementioned demographic groups were chosen to

strengthen the external validity of the research study by providing support for the random

selection of the participants so that the findings could be generalized to the population.

As the sample used random selection, it was essential to validate that the participants had

sufficient audit and fraud risk assessment experience. Additionally, the demographics

provided strength to the generalizability of the study to provide the gender and the U.S.

geographical region of the participants. Next, the participants completed the inputted 30-

item six-point Hurtt Professional Skepticism Scale questionnaire, which examined

professional skepticism. This instrument was selected because of its use by researchers

to measure professional skepticism (Boyle et al., 2012; Carpenter & Reimers, 2013;

Peytcheva, 2014; Quadackers et al., 2014). After completing the skepticism

questionnaire, the participants were given the Form 10-K materials to review and to

perform a fraud risk assessment using the seven-point Likert scale created in the

Qualtrics software.

90

Data analysis. Data collected in the Qualtrics survey software program was

imported into MS Excel to prepare the data for importing into the SPSS Statistics version

24 statistical software for analysis. The demographic information of gender and

geographic region was coded by Qualtrics with a (1) for male participants and a (2) for

female participants and with a (1) for Northeast, (2) for Southeast, (3) for Southwest, (4)

for west, and (5) for Midwest. The auditor certification variable was coded by Qualtrics

with a (1) for CFE, (2) CFE/CPA, and (3) for CPA. Participants who performed the

fraud risk assessment on the Form 10-K with fraud were coded with a 1) for the presence

of fraud risk variable, and the participants who performed the fraud risk assessment on

the Form 10-K without fraud were coded with a 2) for the no presence of fraud risk

variable. This coding (e.g., 1 and 2) of the fraud risk variable was performed in MS

Excel. The professional skepticism questionnaire results for questions 1 to 30 were

summed for a composite score in MS Excel, in accordance with the Hurtt Professional

Skepticism Scale administration instructions (Hurtt, 2010, p. 168). The fraud risk

assessment questionnaire results for the four Likert scale questions were summed for a

composite score in MS Excel; the rating for the question “Significance of anti-fraud

controls in use” was reverse scored in summing the total score. The following data

elements for each participant were exported from MS Excel into SPSS for data analysis:

age, gender, U.S. geographic location, years of audit experience, years of fraud risk

assessment experience, professional certification classification, professional skepticism

score, fraud risk presence variable, and the fraud risk assessment score. The statistical

analyses performed in SPSS Statistics version 24, to test the hypotheses, were a two-way

91

ANOVA and an ANCOVA. Planned contrasts were also conducted in SPSS Statistics

version 24 to determine interaction effects of the auditor certification variables.

Assumptions

An experimental research design was assumed to be the appropriate design choice

to ascertain how different groups performed financial statement fraud risk assessments.

A quantitative research method was deemed appropriate for this research study in that the

intent of the study was to identify and evaluate the effect of the presence of fraud risk,

auditor certification, and professional skepticism on fraud risk assessment performance

by testing hypotheses. The selection of the online environment as the construct design

provided for the random selection of participants from online forums to strengthen the

assumption of generalization from the sample to the population. It was assumed by the

researcher that the professional online forums would provide for a higher response rate

and be more cost effective in securing the appropriate number of participants for the

sample, specifically as compared to mailing the research materials to eligible individuals

in the U.S. (Poynter, 2010). Additionally, Qualtrics was selected as the online survey

application as it had the capability to randomly assign participants to the fraud risk

groups. The study’s eligibility requirements, which required a professional certification

(i.e., CFE or CPA), provided for the assumption that the participants had knowledge and

experience in the research topic and financial statement fraud.

The primary assumption for the fraud risk assessment materials was the presence

of financial statement fraud in the Form 10-K selected for the corporation that was listed

in the SEC AAER database and the absence of fraud in the restated Form 10-K of the

same corporation. Additionally, it was assumed that the time period, 2005–2014, was

92

representative of auditors’ compliance with SOX and SAS No. 99. Participant honesty

was the primary assumption for eligibility, auditor certification self-reporting, and

professional skepticism assessment.

Limitations

One limitation of the study was that the research design only included U.S.

publicly traded companies, which limited generalizability to U.S. companies listed on

U.S. stock exchanges, which is not representative of the global environment or non-

publicly traded companies in the U.S. The study was also limited to the assessment of

fraud risk assessment performance as only one corporation’s financial and nonfinancial

data was examined, which reduced external validity. The fraud risk assessment design

was limited due to the exclusion of group interactions, such as brainstorming sessions, as

required by auditing standards for financial statement fraud risk assessment, which

weakened internal validity. Brainstorming is required by SAS No. 99 as part of the audit

team’s fraud risk assessment and audit planning to improve fraud risk performance (Wei

et al., 2015). Another internal validity construct limitation was the exclusion of financial

statement audit experience and/or forensic auditing experience as an independent or

mediating variable, which may have had an effect on the fraud risk assessment

performance outcome; however, this limitation was mitigated by only including

participants with specific auditor certification attributes (i.e., CFE and CPA) in the

sample.

Delimitations

Delimitations, which narrowed the scope of the study, were present in the

research design. The following delimitations applied to the research study: the time

93

period of 2005–2014 was used for the Form 10-K selection from the SEC database, the

selection of participants from only ACFE, AICPA, and VSCPA online group

memberships, the selection of only one U.S. publicly traded company’s financial and

nonfinancial data, and the selection of only three variables (i.e., the presence of fraud,

auditor certification, and professional skepticism), when numerous other variables may

have attributed to auditors’ fraud risk assessment performance.

Ethical Assurances

The proposed between-participants experimental research study was conducted in

accordance with the Belmont Report, the American Psychological Association’s Code of

Conduct, and Northcentral University’s ethical guidelines. Approval from the

Northcentral University Institutional Review Board (IRB) was received prior to any data

collection. The research design met Northcentral University’s IRB Category 2 criterion

for exempt reviews. The Category 2 criterion states:

Research involving the use of educational tests (cognitive, diagnostic, aptitude,

achievement), survey procedures, interview procedures or observation of public

behavior, unless: (i) information obtained is recorded in such a manner that

human participants can be identified, directly or through identifiers linked to the

participants; and (ii) any disclosure of the human participants' responses outside

the research could reasonably place the participants at risk of criminal or civil

liability or be damaging to the participants' financial standing, employability, or

reputation (Northcentral University, 2015, p. 15).

The ethical principles and guidelines applied relate to plagiarism, risk of harm,

informed consent, privacy and confidentiality, and data collection and reporting. The

94

research study presented no more than minimal risk to the participants because they only

performed a fraud risk assessment on a set of financial statements, and completed a

validated professional skepticism questionnaire, which did not provide for physical,

psychological, or social harm (Northcentral University, 2015). Moreover, vulnerable or

disempowered populations were not used in the study. There were not any monetary

costs associated with study involvement, nor was compensation paid to the participants.

Informed consent was obtained from all of the participants without deception or coercion.

Confidentiality was maintained even though the use of the Internet for the online survey

presented a risk for a confidentiality breach. Privacy and anonymity was provided as

participant names were not collected, which also minimized reputational risk. The

construct design of two fraud risk conditions, which were unknown to the participants,

did create a lack of full disclosure because of the need to strengthen the study’s internal

validity. The participants were not made aware that there were two fraud risk conditions

where one Form 10-K represented high-fraud risk and one Form 10-K represented low-

fraud risk. Each participant was randomly assigned one Form 10-K to evaluate fraud

risk.

The online data collection methodology provided for a breach in privacy and

anonymity due to the Internet Protocol (IP) address of a computer accessing the Internet,

even though confidentiality was maintained. The research design employed the use of

third-party online survey software, Qualtrics, to collect the data; hence, to safeguard

participants’ privacy and anonymity, IP addresses were not included in the dataset

downloaded from Qualtrics. In accordance with Northcentral University (2015) research

confidentiality policies, password-protection was used on portable devices that stored the

95

data. All paper files and portable devices of the data are stored in a locked cabinet. In

accordance with IRB requirements, the paper and electronic data will be destroyed in

seven years, which begins upon the completion of this study.

Summary

The purpose of this between-participants 2X3 quantitative research study was to

examine the effects of the presence of fraud and auditor certification while considering

professional skepticism on fraud risk assessment performance. The literature reviewed

indicates that financial statement fraud is a global problem (Association of Fraud

Examiners, 2014; Drew, 2014; Murphy & Dacin, 2011), and regulations have been

enacted to improve auditors’ detection of financial statement fraud, which includes

conducting a fraud risk assessment. This research study determined whether a causal

relationship existed between the independent variables (e.g., the presence of fraud risk

and auditor certification, while controlling for professional skepticism) and the dependent

variable (e.g., fraud risk assessment performance) to fill a gap in the accounting literature

of fraud risk assessment influences.

The participants were randomly selected through volunteer consent from eligible

members of the ACFE, AICPA, and VSCPA online discussion forums to participate in

the online experiment that was administered by the use of Qualtrics survey software.

Qualtrics was designed to randomly assign the participants to either the high-fraud risk or

the low-fraud risk condition to perform a fraud risk assessment on a U.S. publicly traded

corporation’s Form 10-K. All participants used Qualtrics to complete a professional

skepticism questionnaire and self-report auditor certification status. Likert scales were

used to measure the professional skepticism level and the fraud risk assessment outcome.

96

The data collected in Qualtrics was exported to MS Excel to prepare the data for import

into SPSS Statistics version 24 statistical software. A two-way ANOVA and ANCOVA

were used to test the hypotheses and planned contrasts were conducted to determine

interaction effects of the auditor certification variable. Research was conducted and

handled in accordance with the Belmont Report and Northcentral University’s ethical

guidelines.

97

Chapter 4: Findings The purpose of this quantitative research study was to examine the effects of the

presence of fraud risk and auditor certification while considering professional skepticism

on fraud risk assessment performance. As reported by the Association of Certified Fraud

Examiners (2014), occupational fraud is a global problem and external audits are one of

the least effective methods of fraud detection. The auditing profession implemented SAS

No. 99/AU Section 316 to improve the detection of financial statement fraud by requiring

auditors to conduct a fraud risk assessment. Yet, despite the implementation of SAS No.

99/AU Section 316, the PCAOB found that auditors’ lack of professional skepticism

thwarted the detection of fraud (Trompeter et al., 2013). Nix and Morgan (2013)

purported that auditors with the CFE certification, which is indicative of a person having

fraud knowledge, may improve auditors’ fraud detection skills. Popoola et al. (2014)

confirmed a positive relationship between fraud knowledge and fraud risk assessment.

To answer the research questions and test the hypotheses, a 2X3 between-

participants design was constructed to manipulate two variables – presence of fraud and

auditor certification – while controlling for professional skepticism to ascertain the

outcome on the dependent variable, fraud risk assessment performance. Participant self-

identification was used to create three comparative groups (i.e., CFE, CFE/CPA, or CPA)

from the random sample to measure auditor certification. Random assignment was used

to divide the auditor certification groups into the following six comparative groups to

measure the presence of fraud: high-fraud risk with CFE, high-fraud risk with CFE and

CPA, high-fraud risk with CPA, low-fraud risk with CFE, low-fraud risk with CFE and

CPA, and low-fraud risk with CPA. The participants in each group performed a fraud

98

risk assessment on a company’s Form 10-K retrieved from the SEC database of U.S.

publicly traded companies using a seven-point Likert scale, which ranged from 1 (Very

Improbable/Insignificant) to 7 (Very Probable/Significant). The participants used four

similar Likert-type questions to assess fraud risk: a) likelihood of fraud risk, b)

significance of fraud risks, c) significance of anti-fraud controls in use, and d) likelihood

of fraud. Three groups analyzed high-fraud risk data by reviewing the company’s Form

10-K in a year with reported financial statement fraud, and three groups analyzed low-

fraud risk data by reviewing the selected company’s restated financial statements. Each

participant completed the Hurtt Professional Skepticism Scale, a 30-item professional

skepticism questionnaire, to measure professional skepticism using a six-point Likert

scale, which ranged from 1 (Strongly Disagree) to 6 (Strongly Agree).

This chapter presents the means by which the trustworthiness of data in relation to

credibility, transferability, dependability, and confirmability was secured. It provides the

descriptive statistics of the sample demographics and study variables, and the results of

ANOVA and ANCOVA statistical analyses, which were used to ascertain if a significant

relationship existed between the variables. This chapter also includes a brief evaluation

of the research findings.

Trustworthiness of Data

Credibility of the data was achieved by the use of only recognized professional

accounting forums to recruit the participants (i.e., ACFE, AICPA, and VSCPA). Third-

party software, Qualtrics, was used to develop the survey and store the participants’

responses, which provided for a secure and controlled research environment. A validated

instrument was used to measure professional skepticism, the Hurtt Professional

99

Skepticism Scale, which has been used by other researchers (i.e., Boyle et al., 2012;

Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014). The materials

used for the fraud risk assessment were Form 10-Ks retrieved from the SEC online public

database. Moreover, the company selected to represent the presence of fraud for the

Form 10-K material selection was found by a review of the SEC AAER online public

database.

Transferability of the data was achieved by the use of specific detailed

descriptions of the research problem, the purpose of the study, the participants, the

research design and methodology, and the statistical results. Auditors, regulators,

researchers, and academicians may compare other research studies and/or audit findings

to this research study to search for similarities and differences in the research

methodology used and the results found. The use of a third-party survey application,

Qualtrics, in conjunction with MS Excel and SPSS statistical applications, strengthened

the study’s transferability, as most readers of the study are familiar with these research

applications.

Dependability of the data was achieved by the use of instruments and online

forums to provide for the replication of the research study. The instruments used (i.e.,

Form 10-Ks, Hurtt Professional Skepticism Scale) are publicly available for other

researchers to use to duplicate the study design. The accounting and fraud-related

professional online discussion forums (i.e., ACFE and LinkedIn) are available to use to

recruit similar participants once authorization is obtained from the groups/organizations.

Confirmability of the data was achieved by the creation of an audit trail of the

participants’ responses in Qualtrics to the statistical results in SPSS. The survey

100

questionnaire (See Appendix E) was saved in Qualtrics along with the participants’

responses. The calculations performed using MS Excel to prepare the data for SPSS was

saved in MS Excel files that were backed up for future retrieval. Additionally, the SPSS

files generated from the statistical analyses (e.g., ANOVA and ANCOVA) were backed

up for future retrieval. As the original data source was saved in Qualtrics, the MS Excel

and SPSS calculations could be replicated, if needed. Hence, it may be assumed that the

study results were a result of the participants’ responses and not the researcher’s biases.

ANOVA and ANCOVA assumptions. A two-way analysis of variance

(ANOVA) and a two-way analysis of covariance (ANCOVA) were the statistical

analyses selected to ascertain if a significant relationship existed between the variables.

In accordance with Field (2013), the assumptions below (e.g., 1 to 6) were tested to

ascertain if an ANOVA was an appropriate statistical test to conduct for the data set. The

ANOVA assumptions had to pass before the additional ANCOVA assumptions were

tested, as the ANCOVA statistical test required that the ANOVA assumptions were met.

Assumption 1. Field (2013) stated that the dependent variable should be a

continuous variable. Fraud risk assessment performance was the dependent variable.

This variable was measured using a seven-point Likert scale. Data was assessed using

four Likert-type items combined, so that an interval measurement scale could be used for

quantitative analyses.

Assumption 2. Field (2013) stated that the independent variables should be

categorical variables. The presence of fraud and auditor certification were the two

independent variables. The 2X3 construct categorized the presence of fraud variable into

101

high-fraud risk and low-fraud risk levels, and auditor certification variable into CFE, CFE

and CPA, and CPA levels.

Assumption 3. Field (2013) stated that there should be independence of

observations, which means that participants cannot be in more than one group. There

were different participants in each of the six groups: High-fraud risk, CFE; High-fraud

risk, CFE and CPA; High-fraud risk, CPA; Low-fraud risk, CFE; Low-fraud risk, CFE

and CPA; and Low-fraud risk, CPA. The participants were assigned to the groups based

on self-identification of professional certification and then randomly assigned by

Qualtrics to one of the two presences of fraud conditions (e.g., high-fraud risk and low-

fraud risk).

Assumption 4. Field (2013) stated that there should be no significant outliers.

SPSS Statistics version 24 was used to identify outliers using boxplots. One participant

was an outlier in the boxplots of the CFE professional certification variable and the low-

fraud risk presence of fraud variable. This participant exhibited the attributes of an

extreme outlier as the total fraud risk assessment score was observed to be outside of the

fences of the boxplots for these two variables. Three of the other participants’ fraud risk

assessment scores were observable outliers in the boxplot for the CPA professional

certification variable, but were identified as mild compared to the extreme outlier

identified for the CFE professional certification variable. Before removing the outliers

from the data set, assumptions 5 and 6 were examined to see if the outliers were

significant enough to cause the assumptions to fail. One participant, the outlier in the

low-fraud risk, CFE group, did cause assumption 5 to fail, which, if not corrected, would

have violated the assumption for parametric analyses. Given this failure, this participant

102

was removed from the sample. The other outliers did not cause the assumptions to fail.

Therefore, these other participants were kept in the sample.

Assumption 5. The dependent variable should be normally distributed for each

combination of the groups of the two independent variables. SPSS Statistics version 24

was used to test for normality using the Shapiro-Wilk test. A non-significant (p > .05)

test result indicates that the sample is not significantly different from a normal

distribution. The CPE professional certification, W(48) = .969, p = .234, the CFE and

CPA professional certification, W(41) = .982, p = .758, the CPA professional

certification, W(72) = .967, p = .059, the high risk presence of fraud, W(78) = .984, p =

.459, and the low risk presence of fraud, W(83) = .979, p = .203 did not deviate

significantly from a normal distribution, which is identified as a bell-shaped curve where

observations lie within three standard deviations of the mean (Field, 2013).

Assumption 6. In accordance with Field (2013), there must be homogeneity of

variances for each combination of the groups of the two independent variables. SPSS

Statistics version 24 was used to test the homogeneity of variances using Levene’s test.

A non-significant (p > .05) test result indicates that the variance in the dependent variable

is approximately equal across the various combinations of the independent variables. For

the fraud risk assessment performance, the variances were equal, F(5, 155) = .709, p =

.618. Hence, homogeneity of variance was assumed.

As the ANOVA assumptions passed, two additional assumptions are required to

test the appropriateness of using a two-way ANCOVA for statistical analyses. In

accordance with Field (2013), the additional assumptions (e.g., covariate independence

103

and homogeneity of regression slopes) were tested. The assumption test results are

outlined below.

Assumption 7. Field (2013) stated that the covariate must be independent of the

independent variables. SPSS Statistics version 24 was used to test the covariate’s

independence by running a two-way ANOVA with professional skepticism as the

dependent variable and the independent variables, presence of fraud risk and auditor

certification, as the predictors. For the presence of fraud risk variable, F(1, 157) = .000, p

= .988. For the auditor certification variable, F(2, 157) = .402, p = .670. Hence,

professional skepticism was not significantly different in the two groups (p > .05), thus

independence of the covariate was assumed.

Assumption 8. Field (2013) stated that there must be homogeneity of regression

slopes, which means that the relationship between the dependent variable and the

covariate is the same in each of the groups. SPSS Statistics version 24 was used to test

the homogeneity by customizing the model of the two-way ANCOVA for an interaction

between the covariate and the independent variables. The outcome interaction (auditor

certification X presence of fraud X professional skepticism) resulted in F(5, 151) = 1.171,

p = .326, which demonstrated that the homogeneity of regression slopes was not broken

because p < .05.

Results

The sample demographics collected for the research study included age, gender,

U.S. geographical region, years of audit experience, and years of fraud risk assessment

experience. The study variables included the two independent variables, the presence of

fraud and auditor certification, while considering the covariate of professional skepticism,

104

on the dependent variable of fraud risk assessment performance. Three research

questions guided the study: a) Does the presence of fraud risk have an effect on fraud risk

assessment performance?, b) Does a certification in fraud knowledge have an effect on

fraud risk assessment performance?, and c) Does professional skepticism influence fraud

risk assessment performance? To answer the research questions, a two-way ANOVA and

a two-way ANCOVA were performed to determine the effect of the presence of fraud

risk and auditor certification on fraud risk assessment performance. A brief evaluation of

the findings is presented.

Descriptive statistics of the sample demographics and the study variables. Of

the 398 surveys started, 162 surveys were completed, which resulted in a 41% survey

completion rate over a seven-month period. Of the 162 participants, one outlier was

removed because it created violations in normality between the variables in the CFE low-

fraud risk group (Field, 2013). SPSS was used to test for normality between the variables

using the Shapiro-Wilk test, which resulted in a violation of normality as p = .006 for the

combination of the professional skepticism score and the fraud risk assessment

performance score. The resulting normally distributed sample of 161 participants

consisted of 78 participating in the high-fraud risk condition and 83 participating in the

low-fraud risk condition. The percentage of participants possessing the CFE, CPA and

CFE, and CPA certification was 30%, 25%, and 45%, respectively. The majority of the

participants (62%) were representative of the Northeast (29%) and the Southeast (33%)

U.S. geographical regions. More males (67%) than females (33%) participated in the

study. The overall average age was 47 years, the overall years of audit experience was 11

years, and the overall years of fraud risk assessment experience was 9 years. Descriptive

105

analyses were conducted to make comparisons in the age, years of audit experience, years

of fraud risk assessment experience, gender, and U.S. geographic region of the

participants in the six groups to provide support for generalizability of the research

findings.

Table 1 summarizes the mean, number of participants, and standard deviation for

age, years of audit experience, and years of fraud risk assessment experience for the six

groups. Table 2 summarizes the count of participants by gender and geographic region

for the six groups. Table 3 summarizes the mean, number of participants, and standard

deviation for the dependent variable, fraud risk assessment performance, and for the

covariate, professional skepticism, for the six groups.

Table 1

Descriptive Statistics of Age and Years of Experience for Audit and Fraud Risk Assessment

Certification Age

Years of Experience

Audit Fraud High- fraud risk

CFE

M N SD

46.96 28 12.48

10.79 28 11.70

11.57 28 10.13

High- fraud risk

CFE + CPA

M N SD

43.94 18 13.69

14.39 18 12.66

11.11 18 6.69

High- fraud risk

CPA

M N SD

46.59 32 13.10

10.16 32 10.48

6.69 32 9.21

High- fraud risk

Total

M N SD

46.12 78 12.91

11.36 78 11.42

9.46 78 9.61

Low- fraud risk

CFE

M N SD

48.15 20 13.32

6.65 20 5.97

7.45 20 6.79

106

Low- fraud risk

CFE + CPA

M N SD

51.43 23 13.04

19.91 23 10.37

13.91 23 9.07

Low- fraud risk

CPA M N SD

46.33 40 13.54

8.88 40 9.97

6.63 40 8.99

Low- fraud risk

Total M N SD

48.18 83 13.33

11.40 83 10.64

8.84 83 9.01

Total Fraud Risk

Total M N SD

47.18 161 13.13

11.38 161 10.99

9.02 161 9.28

The comparison of the mean and standard deviation, for the six groups, provide support

for the similarity in age, years of audit experience, and years of fraud risk assessment

experience between the groups.

Table 2

Descriptive Statistics of Gender and U.S. Geographic Region

Gender

Geographic Region Certification Male Female NE SE SW W MW

High- fraud risk

CFE 19 9 6 9 5 3 5 CFE+CPA 11 7 5 7 3 1 2

CPA 20 12 7 11 5 5 4

Total 50 28 18 27 13 9 11

Low- fraud risk

CFE 14 6 5 10 2 1 2

CFE+CPA 13 10 6 5 4 3 5

CPA 31 9 17 12 3 2 6

Total 58 25 28 27 9 6 13

Total 108 53 46 54 22 15 24

107

Table 2 illustrates a higher participation rate of males and a higher participation rate of

participants from the Northeast and Southeast U.S. geographic regions. This table also

illustrates the similarity of the gender and geographic region distribution between the six

groups.

Table 3

Descriptive Statistics of Fraud Risk Assessment and Professional Skepticism Score

Certification

Score

Fraud Risk Professional Skepticism

High- fraud risk

CFE

M N SD

19.61 28 3.24

145.11 28 20.84

High- fraud risk

CFE + CPA

M N SD

17.67 18 3.69

144.72 18 16.16

High- fraud risk

CPA

M N SD

18.19 32 3.37

139.25 32 23.54

High- fraud risk

Total

M N SD

18.58 78 3.45

142.62 78 21.00

Low- fraud risk

CFE

M N SD

19.80 20 3.02

139.40 20 26.20

Low- fraud risk

CFE + CPA

M N SD

20.87 23 3.79

145.04 23 25.08

Low- fraud risk

CPA M N SD

20.60 40 3.88

142.92 40 12.15

Low- fraud risk

Total M N SD

20.48 83 3.64

142.66 83 20.06

Total Fraud Risk

Total M N SD

19.56 161 3.67

142.64 161 20.54

108

The mean comparisons of the fraud risk assessment score variable did

demonstrate an observable change in the mean fraud risk assessment score between the

high-fraud risk group and the low-fraud risk group of 18.58 versus 20.48. In the high-

fraud risk group, the CFE certification participants had the highest average fraud risk

assessment score (19.61), and in the low-fraud risk group the CFE certification

participants had the lowest average fraud risk assessment score (19.80). The mean

comparisons of the professional skepticism score did not depict an observable change

between the high-fraud risk and the low-fraud risk groups, which means that it was not

possible to make the determination that the level professional skepticism does or does not

have an impact on fraud risk assessment performance. However, the CPA certification

participants had the lowest average professional skepticism score (139.25) in the high-

fraud risk group and the CFE certification participants had the lowest average

professional skepticism score (139.40) in the low-fraud risk group. CFE certification

participants in the high-fraud risk group and the CFE and CPA certification participants

in the low-fraud risk group, respectively demonstrated the highest average professional

skepticism scores of 145.11 and 145.04.

Adjusted group means. To better understand the effect of the covariate,

professional skepticism, on the group means for fraud risk assessment performance,

SPSS Statistics version 24 was used to adjust the group means for the covariate. Table 4

provides the group means with and without the effect of the covariate. The group means

were similar, which showed no observable influence of professional skepticism on fraud

risk assessment performance.

109

Table 4

Group Means With and Without the Effect of the Covariate

Certification With

Without High- fraud risk

CFE 19.54 19.61 CFE+CPA 17.61 17.67

CPA 18.29 18.19

Low- fraud risk

CFE 19.89 19.80

CFE+CPA 20.81 20.87

CPA 20.59 20.60

Research Question 1

Research Question 1 examined the effect of the presence of fraud risk on fraud

risk assessment performance. The hypothesis tested was that a high level of fraud risk

produced a high fraud risk assessment performance. SPSS version 24 was used to

perform statistical analyses on the data. A two-way ANOVA test was performed with

fraud risk assessment performance score as the dependent variable, and with the presence

of fraud risk and auditor certification as the independent variables. The ANOVA test

yielded a significant main effect of the presence of fraud on fraud risk assessment

performance, F(1, 155) = 11.17, p = .001. The mean fraud risk assessment score was

significantly greater for the low-fraud risk condition (M = 20.48, SD = 3.64) than for the

high-risk fraud condition (M = 18.58, SD = 3.45). Hence, this score resulted in the

rejection of the null and the alternative hypothesis. The alternative hypothesis was

rejected because the low-fraud risk condition produced a higher fraud risk assessment

performance than the high-fraud risk condition.

110

Research Question 2

Research Question 2 examined the effect of auditor certification (CFE, CFE and

CPA, or CPA) on fraud risk assessment performance. The hypothesis tested was that

auditors who possess a certification in fraud detection produce more effective fraud risk

assessment performance than auditors without the certification. SPSS version 24 was

used to perform statistical analyses on the data. A two-way ANOVA test was performed

with fraud risk assessment performance score as the dependent variable, and with the

presence of fraud risk and auditor certification as the independent variables. The

ANOVA test resulted in a non-significant main effect of auditor certification on fraud

risk assessment performance, F(2, 155) = .182, p = .834. Bonferroni post hoc tests

revealed no significant difference between the combinations of auditor certifications, p =

1 for all combinations, which indicated the means for the CPA, CPA/CFE, and CFE

variables were almost identical. Planned contrasts were also performed using a Helmert

contrast, which compared each auditor certification category against all subsequent

categories. Planned contrasts of the auditor certification variable revealed that having a

CFE certification compared to having either a CFE and CPA or a CPA certification, p =

.552, or a having a CFE and CFE certification compared to a CPA certification, p = .857,

did not have a significant effect on the fraud risk assessment performance. Additionally,

there was a non-significant interaction between the presence of fraud and auditor

certification on fraud risk assessment performance, F(2, 155) = 2.22, p = .112. The

aforementioned result indicates that the presence of fraud was not affected differently by

auditor certifications. Hence, these findings resulted in the acceptance of the null

hypothesis.

111

Research Question 3

Research Question 3 examined if professional skepticism influences fraud risk

assessment performance. The hypothesis tested was that auditors who exhibited

professional skepticism produce more effective fraud risk assessment performance than

auditors without professional skepticism. SPSS version 24 was used to perform

statistical analyses on the data. A two-way ANCOVA test was performed with fraud risk

assessment performance score as the dependent variable, the presence of fraud risk and

auditor certification as the independent variables, and professional skepticism as the

covariate. Planned contrasts were also performed using simple contrasts and post hoc

tests using a Sidak correction. Levene’s test was not significant, F(5, 155) = .509, p =

.769, which demonstrated that the group variances were equal and the assumption of

homogeneity of variance was not violated. The ANCOVA test and planned contrasts

resulted in the acceptance of the null hypothesis due to the following results:

• The covariate, professional skepticism, was not significantly related to fraud

risk assessment performance, F(1, 154) = 3.84, p = .052. There was not a

significant effect of professional certification on fraud risk assessment

performance after controlling for the effect of professional skepticism, F(2,

154) = .228, p = .797. There was a significant effect of presence of fraud on

fraud risk assessment performance after controlling for the effect professional

skepticism, F(1, 154) = 11.550, p = .001.

• Planned contrasts of the auditor certification variable revealed that having a

CPA certification compared to having a CFE certification, p = .674, or

compared to having a CFE and CFE certification, p = .743, did not have a

112

significant effect on the fraud risk assessment performance. Additionally, the

contrast of having a CFE certification compared to having a CPA and CFE

certification, p = .504, did not have a significant effect on the fraud risk

assessment performance.

• Planned contrasts revealed that having a CPA certification did not

significantly increase fraud risk assessment performance compared to having

a CFE certification, t(157) = -.733, p = .464 or a CFE and CPA certification,

t(158) = .232, p = .817.

• Planned contrasts revealed that the presence of no fraud significantly

increased the fraud risk assessment performance compared to the presence of

fraud, t(156), = -2.776, p = .006.

Evaluation of Findings

The 2X3 between-participants quantitative research study provided an evaluation

of two independent variables (e.g., the presence of fraud and auditor certification), while

considering a control variable (e.g., professional skepticism) to measure the outcome on

fraud risk assessment performance. The theoretical foundations for this research study

were fraud theory and attribution theory. Fraud theory uses the fraud triangle to explain

the criteria that must be present for fraud to occur (Dorminey et al., 2010). The elements

of the fraud triangle, opportunity, pressure, and rationalization, are used in fraud theory to

explain the presence of fraud (Dorminey et al., 2012). The auditing profession has

integrated the fraud triangle in the auditing standards (i.e., AU Section 316 and SAS No.

99) to assess fraud risk in financial statement audits. Attribution theory relates internal

and/or external attributes to the performance of a task. This research study investigated

113

the effects of the presence of fraud using a company’s fraudulent and restated Form 10-

K. This research study examined the effects of auditor certification through the selection

of participants with CPA and CFE certifications on the participants’ fraud risk assessment

performance of a randomly assigned Form 10-K. Fraud risk assessment performance was

measured by a seven-point Likert scale, which ranged from 1 (Very

Improbable/Insignificant) to 7 (Very Probable/Significant). Consideration was made for

the participants’ level of professional skepticism by the completion of the 30-item Hurtt

Professional Skepticism Scale questionnaire, which was measured using a six-point

Likert scale ranging from 1 (Strongly Disagree) to 6 (Strongly Agree).

Research Question 1. Research Question 1 examined the effect of the presence

of fraud risk on fraud risk assessment performance. The statistical results from a two-

way ANOVA showed a significant effect for the presence of fraud on fraud risk

assessment performance; hence, the null hypothesis was rejected. However, instead of a

direct relationship between the presence of fraud and the fraud risk assessment there was

an inverse relationship as the participants’ average fraud risk assessment score (20.48), in

the low-fraud risk group, was higher than the participants’ average fraud risk assessment

score (18.58) in the high-fraud risk group. Hence, the alternative hypothesis, which

hypothesized that the presence of fraud produces a high-fraud risk assessment, failed

because the experiment results did not support the assumption.

Research Question 2. Research Question 2 examined the effect of auditor

certification (CFE, CFE and CPA, or CPA) on fraud risk assessment performance. The

statistical results from a two-way ANOVA did not show a significant effect for auditor

certification on fraud risk assessment performance; hence, the null hypothesis was

114

accepted. This finding does not support the value of the CFE certification for fraud risk

assessment evaluations, as recommended by SAS No. 99 (Nix & Morgan, 2013).

Research Question 3. Research Question 3 examined if professional skepticism

influences fraud risk assessment performance. The statistical results from a two-way

ANCOVA did not show a significant effect for professional skepticism on fraud risk

assessment performance; hence, the null hypothesis was accepted. This finding is not

only contrary to the majority of past research studies, but to the beliefs of the regulators

(i.e., PCAOB and SEC) that a lack of professional skepticism provides for ineffective

fraud risk assessments (Trompeter et al., 2013).

Summary

The purpose of this research study was to examine the effects of the presence of

fraud risk and auditor certification while considering professional skepticism on fraud

risk assessment performance. The results of the two-way ANOVA and ANCOVA

statistical tests resulted in only one significant finding – the presence of fraud risk had a

significant effect on fraud risk assessment performance, with and without considering the

influence of professional skepticism. However, alternative hypothesis one, for the

presence of fraud risk on fraud risk assessment performance, was rejected because the

low-fraud risk groups produced a higher fraud risk assessment performance than the

high-fraud risk groups even though null hypothesis one was rejected. The test results did

not demonstrate a statistically significant effect of auditor certification or professional

skepticism on fraud risk assessment performance, which led to the acceptance of null

hypothesis two and three.

115

Chapter 5: Implications, Recommendations, and Conclusions

According to the ACFE’s Report to the Nations on Occupational Fraud and

Abuse (2014), occupational fraud continues to be a global problem with organizations

losing approximately 5% of annual revenues to fraud. Drew (2014) reported that

financial statement fraud is the most costly to organizations. The accounting profession

and regulators have enacted auditing standards and regulations (i.e., SAS No. 99 and AU

Section 316) to improve the detection and prevention of financial statement fraud. One

of the techniques that must be performed by external auditors during a financial statement

audit is a fraud risk assessment. However, fraud risk assessments have not produced

effective results in fraud detection (Hopwood et al., 2012). SAS No. 99 emphasizes the

importance of professional skepticism to detect financial statement fraud (Nix & Morgan,

2013). However, the PCAOB found deficiencies in auditors’ responses to fraud risk and

stated, “the lack of professional skepticism is a serious problem in auditors’ fraud

investigations” (Trompeter et al., 2013, p. 304).

The purpose of this experimental between-participants quantitative research study

was to examine the theoretical underpinnings of fraud and attribution in relation to the

independent variables of the presence of fraud and auditor certification, the control

variable of professional skepticism, and the dependent variable, fraud risk assessment

performance, for participants within the U.S., who identified themselves as either

certified fraud examiners and/or certified public accountants. The study was conducted

online by obtaining volunteer participants from professional online forums (i.e., ACFE,

AICPA, and VSCPA) to complete an experimental survey using the Qualtrics

application. Auditor certification was categorized by the participants’ self-identification

116

of professional certification(s) (e.g., CFE, CFE/CPA, or CPA). The participants in each

group completed the 30-item six-point Hurtt Professional Skepticism Scale questionnaire

to measure professional skepticism. After completing the professional skepticism

questionnaire, the participants were given one of two sets of financial statement materials

(e.g., Form 10-K) to review and to perform a fraud risk assessment using a seven-point

Likert scale. One set of materials represented fraudulent financial statements of a U.S.

publicly traded corporation (high-fraud risk), and the other set of materials represented

the restated financial statements of the same corporation (low-fraud risk). SPSS Statistics

version 24 was used to conduct a two-way ANOVA and ANCOVA to answer the

research questions and test the hypotheses.

Several limitations were identified for the current research study. First, the

selection of the experimental materials (i.e., Form 10-Ks) limited generalizability to only

U.S. companies listed on the U.S. stock exchange. Second, the study only used one

corporation’s financial statement and nonfinancial data (i.e., Form 10-Ks) to assess fraud

risk assessment performance, which reduced external validity. Third, the fraud risk

assessment design process excluded participant group interactions, such as brainstorming

sessions, as required by the SAS No. 99 auditing standards for financial statement fraud

risk assessment, which weakened internal validity. Fourth, the study excluded financial

statement audit experience and/or forensic auditing experience as an independent or

mediating variable, which may have had an effect on the fraud risk assessment

performance outcome; hence, this created an internal validity construct limitation.

However, the fourth limitation was mitigated by only including participants with specific

auditor certification attributes (i.e., CFE and CPA) in the study.

117

The research design met Northcentral University’s IRB Category 2 criterion for

exempt reviews, which indicated that the ethical issues associated with this research

study were minimal. Participants’ risk of harm was minimized as they only performed a

fraud risk assessment on a set of financial statements and completed a validated

professional skepticism questionnaire. Informed consent was obtained from all of the

participants without deception or coercion. Furthermore, confidentiality was maintained

through the secure storage of data, even though the use of the Internet for the online

survey presented a risk for a confidentiality breach. Finally, privacy and anonymity were

provided as participant names were not collected and a third-party online survey software

was used.

This chapter discusses the study implications of each research question and

hypothesis. Logical conclusions will be drawn for each research question with a

discussion of any potential limitations that may have affected the interpretation of the

results. Finally, this chapter concludes with recommendations for practice, as well as

recommendations for future research.

Implications

The following research questions guided the study: a) Does the presence of fraud

risk have an effect on fraud risk assessment performance?, b) Does a certification in fraud

knowledge have an effect on fraud risk assessment performance?, and c) Does

professional skepticism influence fraud risk assessment performance? To answer the

research questions, a two-way ANOVA was performed to determine the effect of the

presence of fraud risk and auditor certification on fraud risk assessment performance.

Then, after reviewing the results, a two-way ANCOVA was conducted to examine the

118

variability in the fraud risk assessment performance outcome due to the participants’

professional skepticism measurement. Results from the statistical analyses revealed that

neither auditor certification nor professional skepticism had a significant effect on fraud

risk assessment performance. However, the results did show that the presence of fraud

did have a significant effect on fraud risk assessment performance. Each question, and its

related hypothesis, are discussed below, along with logical conclusions and limitations.

The research implications and recommendations for practical application and future

research are also provided below.

Research Question 1. Does the presence of fraud have an effect on fraud risk

assessment performance?

The hypothesis that was tested to ascertain if the presence of fraud had an effect on fraud

risk assessment performance was as follows:

H10. The presence of fraud risk does not have a significant effect on fraud risk

assessment performance.

H1a. The presence of fraud risk produces a high level of fraud risk assessment

performance.

Financial statement fraud costs companies more financially than any other type of

occupational fraud (Alleyne & Elson, 2013). Auditing regulators have attempted to

minimize the losses from financial statement fraud by implementing fraud detection

auditing standards (e.g., SAS No. 99). Auditing standards require auditors to conduct a

fraud risk assessment during a financial statement audit; however, there is not a standard

fraud risk assessment framework to use for the assessment process. The material used by

the participants in this research study to examine financial statements fraud risk was a

119

company’s Form 10-K filing from the SEC database of U.S. publicly traded companies.

Three groups of participants assessed a U.S. company’s Form 10-K that contained known

fraud to create high-fraud risk groups, and three groups of participants assessed the

company’s restated Form 10-K that did not contain known fraud to create low-fraud risk

groups. The participants’ fraud risk assessment was measured by answering four fraud

assessment questions after reviewing the Form 10-K using a seven-point Likert scale. An

ANOVA statistical analysis revealed a statistically significant relationship between the

presence of fraud and fraud risk assessment performance; hence, the null hypothesis was

rejected. The rejection of the null hypothesis means that the presence of fraud is a

significant predictor of fraud risk assessment performance.

The alternative hypothesis was that the Form 10-K with the high-fraud risk would

produce a higher fraud risk assessment outcome than the Form 10-K with the low-fraud

risk. However, this was not the result. The average fraud risk assessment score was

19.56 for the low-fraud risk groups and 18.58 for the high-fraud risk groups. Therefore,

the alternative hypothesis was rejected. This alternative hypothesis rejection supports

Trotman and Wright’s (2012) beliefs that management’s ability to disguise fraud in

financial statements is a significant risk to fraud risk assessment outcomes. Goel and

Gangolly (2012) also posited that fraudulent companies employ various techniques in

annual financial reports to manipulate financial information, which may prevent auditors

from detecting financial statement fraud. This finding supports Hogan et al. (2008)

discussions that the use of traditional analytical procedures (e.g., ratio analysis,

relationships between financial and nonfinancial measures, and Benford’s Law) using

financial statement data has limited success in fraud detection. Kaminski and Wetzel (as

120

cited in Hogan et al., 2008) did not find any difference in the use of ratios to detect

financial statement fraud between fraudulent and non-fraudulent companies. The

experiment conducted by Kaminski and Wetzel (as cited in Hogan et al., 2008) did not

expose the participants to any conditions that may have influenced the results or require

the participants to use specific methods in performing the fraud risk assessment; hence,

the methodology used by the participants is unknown but the instrument (Form 10-K)

only provided data on business operations, financial condition, and management

discussion and analysis. This experiment provides support for the postulations of other

researchers that auditors need to expand the focus of fraud detection beyond the guidance

issued in AU Section 316 SAS No. 99 (Abbasi et al., 2012; Buchholz, 2012; Dorminey et

al., 2010; Goel & Gangolly, 2012; Kassem & Higson, 2012; Lokanan, 2015; Love, 2012;

Trotman & Wright, 2012).

Because the hypotheses were rejected, the implication is that fraud risk cannot be

effectively predicted. The research results also provide evidence to support that the

current financial statement fraud risk assessment process is not effective in fraud

detection, specifically since the financial statements evaluated in the low-fraud risk

condition produced a more effective fraud risk assessment performance than the financial

statements evaluated in the high-fraud risk condition. As auditing standards do not

require standardized approaches for performing fraud risk assessments, this experiment

allowed the participant to perform a fraud risk assessment of a company’s financial

statements without the use of standardized processes. The participants’ fraud risk

assessment was measured by a scale of four similar Likert-type questions: a) likelihood

of fraud risk, b) significance of fraud risks, c) significance of anti-fraud controls in use,

121

and d) likelihood of fraud. Hence, the fraud risk assessment was based on professional

judgment as it is in current practice. This study contributes to other researchers’

recommendations that the auditing profession should consider other methods for fraud

risk detection as the participants assessed the restated financial statements, assuming low-

fraud risk, higher than the fraudulent financial statements. Boritz and Timoshenko

(2014) recommended a standardized tool for conducting fraud risk assessments to

minimize auditor judgment. A standardized framework for performing fraud risk

assessments may strengthen risk assessment performance, as Hammersley et al. (2010)

found support for the use of priming before risk assessment; hence, a checklist could be

used to prime the auditor for the fraud risk assessment. Abbasi et al. (2012) developed a

metafraud framework using business intelligence for financial fraud risk assessment.

Abbasi et al. (2012) used financial ratios and organizational and industry contextual

information to evaluate companies’ quarterly and annual reports and found the metafraud

framework was effective for financial statement fraud detection. Favere-Marchesi (2013)

found that the use of fraud judgment decomposition was more effective than fraud risk

factor categorization, which is the SAS No. 99 requirement. SAS No. 99 requires the use

of the fraud triangle to evaluate risk by categorizing fraud risk into the elements of

opportunity, pressure/incentive, and rationalization (Nix & Morgan, 2013). Yet, Favere-

Marchesi (2013) found that examining the fraud risks, instead of classifying fraud risks,

resulted in more effective fraud risk assessments.

The results of the study may have implications to the auditing profession and

regulators regarding the development of auditing standards and processes for financial

statement fraud detection. The implication of using the fraud triangle as the theoretical

122

framework for predicting financial statement fraud may be too restrictive, as the lack of

fraud detection in financial statement audits is in excess of one trillion dollars (Kravitz,

2012), which is indicative of a significant problem. Dorminey et al. (2010) and Abbasi et

al. (2012) recommended a meta-fraud framework to broaden the scope of fraud detection.

Hogan et al. (2008) and Abbasi et al. (2012) proposed the use of business intelligence

(e.g., data mining and pattern recognition) for improving fraud assessments. As auditing

standards do not require checklists or models for evaluating fraud risk, the results of this

study provide support for the identification of accurate tools to detect financial statement

fraud and to minimize the costs associated with financial statement fraud. Boritz and

Timoshenko (2014) and Rose et al. (2012) found that the use of fraud checklists

increased the effectiveness of fraud risk assessments. Additionally, Knapp and Knapp

(2001) found that fraud risk assessment instructions resulted in more effective fraud risk

assessments.

This study adds to the existing research that the auditing profession needs to

develop more effective methodologies to evaluate the presence of fraud in financial

statements. It is apparent from the results of this study that more effective tools are

needed to identify warning factors present in financial statements to increase fraud risk

assessment outcomes. This study also provides support for the use of multiple

methodologies to detect fraud as the review of only a Form 10-K was not effective in

detecting fraud.

123

Research Question 2. Does a certification in fraud knowledge have an effect

on fraud risk assessment performance?

The hypothesis that was tested to ascertain if a certification in fraud knowledge

had an effect on fraud risk assessment performance was as follows:

H20. A certification in fraud knowledge does not have a significant effect on fraud

risk assessment performance.

H2a. Auditors that possess a certification in fraud detection produce more

effective fraud risk assessment performance than auditors without the

certification.

According to Nix and Morgan (2013), the CFE certification is indicative of fraud

assessment and detection knowledge. The participants were divided into three groups

based on the following certifications: CFE, CFE and CPA, and CPA. It was

hypothesized that the participants with the CFE certification would perform more

effective fraud risk assessments than the participants without the CFE certification due to

multiple research findings. Nix and Morgan (2013) and Popoola et al. (2014) confirmed

a positive relationship between fraud knowledge and fraud risk assessment. Hammersley

(2011) found support for fraud training, to gain fraud knowledge, which in turn resulted

in more accurate fraud risk assessments.

An ANOVA statistical analysis did not reveal a statistically significant

relationship between auditor certification and fraud risk assessment performance; hence,

the null hypothesis was accepted. This finding means that auditor certification is not a

significant predictor of fraud risk assessment performance. This outcome supported

Boritz et al.’s (2015) finding that fraud specialists were not more effective than financial

124

statement auditors in conducting fraud risk assessments. This research study, as well as

the study conducted by Boritz et al., excluded fraud brainstorming sessions as part of the

construct, which may be seen as a limitation for performing fraud risk assessments, as

required by SAS No. 99.

The results of the study may have implications to the ACFE’s certified fraud

examiner credential and SAS No. 99’s support of CFE certifications in fraud risk

assessment evaluations, since it did not support the belief that the CFE credential

produces more effective fraud risk assessment performance. Hence, regulators may want

to reconsider the recommendation that auditors should seek assistance from fraud

specialists during financial statement audits because the use of fraud specialists may not

result in more effective fraud risk assessment outcomes. The aforementioned finding

contradicted Carpenter, Durtschi, and Gaynor’s (2011) findings that fraud knowledge had

a positive impact on fraud risk assessment performance.

This study adds to the existing research that auditor certifications may not be the

best credential to use to measure fraud knowledge. The insignificant relationship

between the auditor certifications provides evidence that individuals with the CFE

credential do not provide more effective fraud risk assessment outcomes than individuals

with the CPA credential. Thus, this finding challenged Kassem and Higson’s (2012)

recommendation to regulators to consider requiring CPA candidates to obtain a CFE

certification prior to qualifying for a CPA certification.

125

Research Question 3: Does professional skepticism influence fraud risk

assessment performance?

The hypothesis that was tested to ascertain if professional skepticism has an

influence on fraud risk assessment performance was as follows:

H30. The level of auditor professional skepticism does not have a significant

influence on fraud risk assessment performance.

H3a. Auditors that exhibit professional skepticism produce more effective fraud

risk assessment performance than auditors without this attribute.

According to the PCAOB, auditors lack professional skepticism, which results in

ineffective fraud assessments (Trompeter et al., 2013). The instrument used by all of the

participants to measure professional skepticism was the 30-item Hurtt Professional

Skepticism Scale, which used a six-point Likert scale for measurement. The study results

provided evidence that the professional skepticism level of the participants was

negatively skewed, which indicated a higher level of professional skepticism. It was

hypothesized that the participants with a higher level of professional skepticism would

perform more effective fraud risk assessments. An ANCOVA statistical analysis did not

reveal a statistically significant relationship between professional skepticism and fraud

risk assessment performance; hence, the null hypothesis was accepted. Often, the finding

that professional skepticism does not have a significant influence on fraud risk

assessment performance would mean that professional skepticism is not a significant

predictor of fraud risk assessment performance. The negative skew of the professional

skepticism scores and the similarity of the average score between the six groups do not

provide sufficient evidence to make the determination that the level professional

126

skepticism does or does not have an impact on fraud risk assessment performance. As

the professional skepticism scores of all participants are similar, it is not possible to

compare participants with different levels of professional skepticism to evaluate the

influence on fraud risk assessment performance.

The negative skew (-2.341) of the participants’ professional skepticism scores,

which was due to high scores, and the pointy and heavy-tailed distribution demonstrated

by a positive kurtosis (9.130), may be due to the requirement that the participants had to

possess either a CFE and/or a CPA certification. The negative skew may explain the

finding that professional skepticism did not have a significant effect on fraud risk

assessment performance. Moreover, this finding may have implications for the PCAOB,

as the majority of the participants did exhibit high levels of professional skepticism, but

the high level of professional skepticism did not result in a more effective fraud risk

assessment outcome.

Nix and Morgan (2013) reported that SAS No. 99 emphasizes the importance of

professional skepticism in the performance of fraud risk assessment. Furthermore,

Carpenter and Reimers (2013) stated that the PCAOB cited the lack of professional

skepticism as a factor for ineffective fraud risk assessments. Hurtt et al. (2013)

acknowledged the importance of professional skepticism, and other researchers provided

support of a significant positive relationship between professional skepticism and fraud

risk assessment outcomes (Bowlin et al., 2015; Boyle et al., 2015; Carpenter & Reimers,

2013; Trotman & Wright, 2012; Wei et al., 2015). Moreover, Boyle et al.’s experiment

controlled for professional skepticism using the Hurtt Professional Skepticism Scale and

used ANCOVA to conduct statistical analysis, as did this research study. As SAS No. 99

127

emphasizes the importance of professional skepticism to evaluate the risks of financial

statement fraud, auditors must demonstrate appropriate levels of professional skepticism

(Boyle et al., 2015; Nix & Morgan, 2013).

The study results may have been influenced by the construct of the research

design. The participants were required to complete the professional skepticism

questionnaire prior to the fraud risk assessment of the Form 10-K, which may have

primed the participants to be more skeptical for the fraud risk assessment measurement.

Hammersley et al. (2010) investigated the influence of priming participants before

performing a fraud risk assessment and found a positive influence of priming before the

fraud risk assessment, especially when the participants received documented fraud risks

before the fraud risk assessment.

The results of the study may have implications to the auditing profession,

regulators, and researchers in regards to the influence of professional skepticism on fraud

risk assessments. As Hurtt et al. (2008) found, “the behavioral differences do not always

go in the direction of higher skepticism being associated with more skeptical behavior”

(p. 25). This research study provides support for the professional skepticism gap between

researchers and regulators, as posited by Hurtt et al. (2013). Both the SEC and PCAOB

believe that higher levels of professional skepticism result in more effective fraud risk

assessments (Carpenter & Reimers, 2013; Hurt et al., 2013; Trompeter et al., 2013).

While some researchers provide evidence to support that professional skepticism has a

positive influence on fraud risk assessments (Boyle et al., 2015; Wei et al., 2015), other

researchers did not find evidence to support the positive influence of professional

skepticism on fraud risk assessments (Jaffar et al., 2011; Peytcheva, 2014). Rasso (2015)

128

provided evidence to support the influence of behavior on professional skepticism by

comparing high-level versus low-level documentation instructions on fraud risk

assessments; hence, abstraction (low-level) outperformed specificity (high-level).

This study adds to the existing research that participants with higher levels of

professional skepticism did not significantly influence the fraud risk assessment

outcomes. Hence, the study provides support for more research on the influence of

professional skepticism behavior versus the influence of the professional skepticism

attribute on fraud risk assessment performance. Additionally, this study adds to the

existing research that participants that possess the CFE certification did not significantly

produce more effective fraud risk assessment outcomes than the participants that

possessed only the CPA certification. Thus, further research is needed to evaluate

differences in the CFE and CPA certification, specifically in relation to evaluating

financial statement fraud risks.

Recommendations for Practice

To expand the literature with regard to achieving effective fraud risk assessment

outcomes, two research recommendations are proposed for application. First, researchers

and regulators should develop a standard checklist to use for fraud risk assessments that

includes a quantifiable evaluation process. This research study and others (e.g., Favere-

Marchesi, 2013; Jaffar et al., 2011; Popoola et al., 2015; Rasso, 2015; Wei et al., 2015)

used a Likert scale to measure fraud risk assessment performance. Additional data needs

to be captured to better understand the formation of the high-risk versus low-risk

assessments. For example, analytical ratios, data comparisons, management disclosures,

management behaviors, corporate governance, corporate culture (client and audit firm),

129

and auditor attributes and behaviors may be factors affecting these assessments. In order

to understand the difference between effective and ineffective fraud risk assessments,

more detailed fraud risk assessments need to be conducted so that researchers are able to

study the relationships of the various factors that affect auditors’ judgments of fraud risk.

The collection of additional data using a standardized checklist would provide

quantifiable evidence to support the fraud risk assessment outcome, which should reduce

the influence of auditor bias and subjectivity during the fraud risk assessment evaluation.

The lack of a validated instrument for conducting fraud risk assessments provides for the

opportunity of inconsistency and auditor bias in fraud risk assessment outcomes, which

should be a concern for the accounting profession and the regulators.

Second, researchers and regulators need to further evaluate the use of the fraud

triangle as the theoretical framework to perform fraud risk assessments. As required by

SAS No. 99, the fraud triangle is the methodology used to conduct fraud risk assessments

(Dorminey et al., 2012). Numerous researchers have proposed other models to use for

fraud risk assessments (Kassem & Higson, 2012; Lokanan, 2015; Soltani, 2014;

Srivastava et al., 2011). Abbasi et al. (2012) and Dorminey et al. (2012) posited a meta-

model framework that incorporated additional elements for evaluation. Dorminey et al.

(2012) discussed the impact of other fraud models on the fraud triangle (e.g., fraud

diamond, fraud scale, M.I.C.E. model, triangle of fraud action) to provide support for the

weaknesses inherent in the fraud triangle framework for effective fraud detection.

Abbasi et al. (2012) compared the metafraud framework to other fraud detection models

and confirmed that “the viability of using meta-learning methods enhanced financial

statement fraud detection” (p. 1323). Regulators may want to consider the combination

130

of fraud theory with the theory of planned behavior (Cohen et al., 2010) and the

institutional theory of moral collapse (Shadnam & Lawrence, 2011) to strengthen the

theoretical framework used for financial statement fraud detection. As research supports,

a more comprehensive theoretical framework is needed to produce more effective fraud

risk assessment outcomes.

Recommendations for Future Research

To expand the literature, with regard to achieving effective fraud risk assessment

outcomes, several research recommendations are proposed for future research. First,

qualitative or mixed research studies could expand the evaluation of professional

skepticism behaviors on fraud risk assessment outcomes by developing complex practical

applications, which use observations, interviews, and documents to collect data to

increase the internal validity of the study results. Brainstorming, as prescribed in SAS

No. 99, should be incorporated into the qualitative fraud risk assessment construct to

expand upon Wei et al.’s (2015) research, which studied the effects of brainstorming on

auditors’ performance of fraud risk assessments.

Additionally, this research study used only one source of data, Form 10-K, to

measure fraud risk, which is not representative of fraud risk assessments in practice.

Auditors use other qualitative measures to form fraud risk judgments by investigating the

company’s culture, corporate governance, and management’s behaviors and attributes.

Further research is needed to expand upon Campbell and Göritz’s (2014) and Shadnam

and Lawrence’s (2011) examinations of organizational culture to ascertain the influences

of underlying assumptions, regulations, ideologies, values, and norms on financial

statement fraud. Future research is needed to provide more evidence to support Cohen et

131

al.’s (2010) research findings on the relationship between managers’ personality traits

and unethical behaviors. Evidence may support that managers’ behaviors may

significantly influence the occurrence of financial statement fraud.

Second, researchers should develop more instruments to measure professional

skepticism and to test the validity of the Hurtt Professional Skepticism Scale. The Hurtt

Professional Skepticism Scale has been used by many researchers to measure the level of

professional skepticism (e.g., Boyle et al., 2012; Carpenter & Reimers, 2013; Peytcheva,

2014; Quadackers et al., 2014). By combining the other studies that used the Hurtt

Professional Skepticism Scale with this study, researchers could ascertain if the

participants’ average professional skepticism scores varied to evaluate scale limitations.

If the average professional skepticism scores are similar for the participants in other

research studies, there may be reason to question the validity of the Hurtt Professional

Skepticism Scale to measure professional skepticism. To examine the effects of

professional skepticism on variables, researchers must be able to find participants with

both low and high levels of professional skepticism; hence, a validated instrument is

required.

Third, additional research needs to be conducted to better assess the effect of

fraud knowledge on fraud risk assessment performance. This research study measured

fraud knowledge by the presence or absence of the CFE certification for participants

within the U.S., which did not result in a significant effect on fraud risk assessment

performance. This study’s results agreed with Boritz et al. (2015) who used Canadian

participants to examine an actual company’s fraudulent financial statements and found no

significant difference between fraud specialists and financial statement auditors. In

132

contrast, Popoola et al. (2015) evaluated fraud knowledge of auditors and forensic

accountants in Nigeria using a 36-item questionnaire and found a positive relationship

between fraud knowledge and risk assessment. Researchers should not only evaluate the

methodology used to measure fraud knowledge, but also evaluate the cultural influence

on fraud risk assessment outcomes. Different cultures influence the values, norms, and

behaviors of individuals (Hofstede as cited in Ho et al., 2015). Campbell and Göritz

(2014) conducted a study in Germany and found that corrupt organizations shared the

belief that “the end justifies the means,” valued job and organizational security, and

punished non-corrupt behavior (p. 304). Thus, cultural influence may have a significant

effect on the occurrence of financial statement fraud.

Conclusions

The purpose of this quantitative research study was to examine the effect of the

presence of fraud and auditor certification, while controlling for professional skepticism,

on fraud risk assessment performance, for participants within the U.S. who identified as

certified fraud examiners and/or certified public accountants. Financial statement fraud

continues to be challenge for auditors and regulators even after the adoption of fraud

detection and reporting regulations (e.g., Association of Certified Fraud Examiners, 2014;

AU 316 and SAS No. 99). These aforementioned regulations emphasize the use of

professional skepticism when performing the required fraud risk assessment in financial

statement audits. The lack of professional skepticism and ineffective fraud risk

assessment are serious concerns of the PCAOB (Hopwood et al., 2012; Trompeter et al.,

2013). Fraud theory was chosen as one of the theoretical frameworks to guide this study

as SAS No. 99 requires the use of the fraud triangle by auditors to evaluate fraud risk

133

(Nix & Morgan, 2013). Many researchers argue that the fraud triangle is not broad

enough to perform an effective fraud risk assessment (e.g., Boyle et al., 2012; Dorminey

et al., 2010; Lokanan, 2015; Schuchter & Levis, 2015; Soltani, 2014).

The other theoretical framework utilized to ground the study was attribution

theory with a focus on auditors’ internal attributes of professional skepticism and fraud

knowledge in relation to the performance of fraud risk assessments. Fraud knowledge

was examined by comparing the effects of auditor certifications (i.e., CFE, CFE/CPA, or

CPA) on fraud risk assessment performance. Researchers were found to have different

beliefs on the role of professional skepticism in relation to fraud risk assessments (e.g.,

Bolin et al., 2015; Carpenter & Reimers, 2013; Glover & Prawitt, 2014; Lee et al., 2013;

Peytcheva, 2014). The literature also provided mixed perspectives on the importance of

auditors having the certified fraud examiner credential for the performance of fraud risk

assessments (e.g., Boritz et al., 2015; Nix & Morgan, 2013; Popoola et al., 2014).

An experimental 2X3 between-participants research design was assumed to be the

appropriate design choice for this study in order to ascertain how different groups

performed financial statement fraud risk assessments in relation to the presence of fraud

and auditor certification while considering professional skepticism. The participants

were randomly selected through volunteer consent from eligible members of the ACFE,

AICPA, and VSCPA online discussion forums to participate in the online experiment that

was administered by the use of Qualtrics survey software. Participants were randomly

assigned to either the high-fraud risk or the low-fraud risk condition to perform a fraud

risk assessment on a U.S. publicly traded corporation’s Form 10-K. All participants used

Qualtrics to complete a professional skepticism questionnaire and self-report auditor

134

certification status. Likert scales were used to measure the professional skepticism level

and the fraud risk assessment outcome.

The following hypotheses were tested: 1) a high level of fraud risk produces a

high-fraud risk assessment performance, 2) auditors that possess a certification in fraud

detection produce more effective fraud risk assessment performance than auditors

without the certification, and 3) auditors that exhibit professional skepticism produce

more effective fraud risk assessment performance than auditors without this attribute. An

ANOVA statistical analysis revealed a statistically significant relationship between the

presence of fraud and fraud risk assessment performance; however, the high-fraud risk

condition did not produce a higher fraud risk assessment than the low-fraud risk

condition. Therefore, both the null hypothesis and the alternative hypothesis were

rejected for the effect of the presence of fraud on fraud risk assessment performance.

Additionally, an ANOVA statistical analysis did not reveal a statistically significant

relationship between auditor certification and fraud risk assessment performance; hence,

auditor certification was not found to be a significant predictor of fraud risk assessment

performance. An ANCOVA statistical analysis did not reveal a statistically significant

relationship between professional skepticism and fraud risk assessment performance;

however, due to the similarity of the average scores, it was not possible to make the

determination that the level professional skepticism does or does not have an impact on

fraud risk assessment performance.

Several limitations were identified for the research study. First, generalizability

was limited to the U.S. companies listed on the U.S. stock exchanges, as the experimental

materials used were Form 10-Ks of only one company, which was a second limitation.

135

Third, participant group interactions (e.g., brainstorming) as required by SAS No. 99

were excluded from the fraud risk assessment design process. Fourth, financial statement

audit experience and/or forensic auditing experience was excluded as an independent or

mediating variable that may have had an effect on the fraud risk assessment performance

outcome; however, this was mitigated by only including participants with specific auditor

certification attributes (i.e., CFE and CPA) in the experiment.

Due to the multiple influences that effect auditors’ judgment during the

performance of fraud risk assessments, further application and research is needed to

better quantify and understand fraud risk assessments. Prior research studies used a

Likert scale to measure fraud risk assessment performance, as did this study (e.g., Favere-

Marchesi, 2013; Jaffar et al., 2011; Popoola et al., 2015; Rasso, 2015; Wei et al., 2015).

In accordance with Boritz and Timoshenko’s (2014) findings, a customized checklist that

considers the client’s business and the fraud risk assessment factors may strengthen the

standardization of fraud risk assessments and minimize the reliance on auditors’

judgments for fraud risk assessments. Additionally, Rose et al. (2012) reported positive

results from the use of checklists in audit risk assessments. Hence, it is recommended

that fraud risk assessment models should be developed and validated to produce more

effective fraud risk assessments.

Qualitative and/or mixed designs may be more appropriate to examine the

multiple factors influencing the assessment process and to evaluate auditors’ behaviors at

both high and low levels of professional skepticism. Auditors use other qualitative

measures to form fraud risk judgments by investigating the company’s culture, corporate

governance, and management’s behaviors and attributes. Prior research studies (e.g.,

136

Campbell & Göritz, 2014; Cohen et al., 2010; Shadnam & Lawrence, 2011) should be

expanded to better understand the effect of organizational culture and managers’ traits

and behaviors on fraud risk assessment performance. The trait of professional skepticism

may not always exhibit professional skepticism behavior, as posited by Hurtt et al.

(2008), “the behavioral differences do not always go in the direction of higher skepticism

being associated with more skeptical behavior” (p. 25).

Professional skepticism instruments should be developed and validated to

strengthen the validity of research findings for fraud risk assessment effectiveness. The

Hurtt Professional Skepticism Scale has been used by many researchers to measure the

level of professional skepticism, as it was used in this study (e.g., Boyle et al., 2012;

Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014). To examine the

effects of professional skepticism on variables, the researcher must be able to find

participants with both low and high levels of professional skepticism.

As gaps in current literature exist regarding the impact of auditor certification and

professional skepticism on fraud risk assessment performance, additional research needs

to be conducted to better assess the effect of fraud knowledge on fraud risk assessment

performance (Hammersley, 2011; Ray, 2015; Trompeter et al., 2013). This study’s

results agreed with Boritz et al.’s (2015) findings and contradicted Popoola et al.’s (2015)

results that fraud knowledge effects fraud risk assessment performance. Researchers

should evaluate the methodology used to measure fraud knowledge. Hence, further

research is needed to better understand the complexities of fraud risk assessments to

improve effectiveness in detecting financial statement fraud. Auditing regulations, fraud

137

risk assessment models, auditor attributes, and fraud knowledge have been found to

influence fraud risk assessment performance.

138

References

Abbasi, A., Albrecht, C., Vance, A., & Hansen, J. (2012). Metafraud: A meta-learning framework for detecting financial fraud. MIS Quarterly, 36(4), 1293-1327. Retrieved from http://misq.org/metafraud-a-meta-learning-framework-for- detecting-financial-fraud.html?SID=1t981l056pnhbr0h0d6tnel400

About the AICPA. (n.d.). American Institute of CPAs website. Retrieved from

http://www.aicpa.org/About/Pages/About.aspx About the Virginia Society of CPAs. (n.d.). Virginia Society of CPAs website. Retrieved

from https://www.vscpa.com/content/about_vscpa/mission_vision_goals.aspx Albrecht, W. S., & Hoopes, J. L. (2014). Why audits cannot detect all fraud. CPA

Journal, 84(10), 12-21. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11384

Alleyne, B. J., & Elson, R. J. (2013). The impact of federal regulations on identifying,

preventing, and eliminating corporate fraud. Journal of Legal, Ethical & Regulatory Issues, 16(1), 91-106. Retrieved from http://www.alliedacademies.org/legal-ethical-and-regulatory-issues/volume- issue.php?volume=Volume%2016,%20Issue%201&&year=2013

Association of Certified Fraud Examiners. (2014). 2014 Report to the nations: Summary

of findings. Retrieved from http://www.acfe.com/rttn-summary.aspx Barnham, C. (2015). Quantitative and qualitative research. International Journal of

Market Research, 57(6), 837-854. doi:10.2501/IJMR-2015-07 Beasley, M. S., Carcello, J. V., Hermanson, D. R., & Neal, T. L. (2010). Fraudulent

financial reporting 1998-2007: An analysis of U.S. public companies. Retrieved from http://www.coso.org/documents/cosofraudstudy2010.pdf

Boone, H. N., & Boone, D. A. (2012). Analyzing Likert data. Journal of Extension,

50(2). Retrieved from http://www.joe.org/joe/2012april/tt2.php Boritz, J. E., Kochetova-Kozloski, N., & Robinson, L. (2015). Are fraud specialists

relatively more effective than auditors at modifying audit programs in the presence of fraud risk?. Accounting Review, 90(3), 881-915. doi:10.2308/accr-50911

Boritz, J. E., & Timoshenko, L. M. (2014). On the use of checklists in auditing: A

commentary. Current Issues in Auditing, 8(1), C1-C25. doi:10.2308/ciia-50741

139

Bowlin, K. O., Hobson, J. L., & Piercey, M. D. (2015). The effects of auditor rotation, professional skepticism, and interactions with managers on audit quality. Accounting Review, 90(4), 1363-1393. doi:10.2308/accr-51032

Boyle, D. N., Carpenter, B. W., & Hermanson, D. R. (2012). CEOs, CFOs, and

accounting fraud. CPA Journal, 82(1), 62-65. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=10911

Boyle, D. M., DeZoort, F. T., & Hermanson, D. R. (2015). The effect of alternative fraud

model use on auditors’ fraud risk judgments. Journal of Accounting & Public Policy, 34(6), 578-596. doi:10.1016/j.jaccpubpol.2015.05.006

Brazel, J. F., Carpenter, T. D., & Jenkins, J. G. (2010). Auditors’ use of brainstorming in

the consideration of fraud: Reports from the field. Accounting Review, 85(4), 1273-1301. doi:10.2308/accr.2010.85.4.1273

Brazel, J. F., Jones, K. L., & Prawitt, D. F. (2014). Auditors' reactions to inconsistencies

between financial and nonfinancial measures: The interactive effects of fraud risk assessment and a decision prompt. Behavioral Research in Accounting, 26(1), 131- 156. doi:10.2308/bria-50630

Buchholz, A. K. (2012). SAS 99: Deconstructing the fraud triangle and some classroom

suggestions. Journal of Leadership, Accountability & Ethics, 9(2), 109-118. Retrieved from http://www.na-businesspress.com/jlaeopen.html

Campbell, J., & Göritz, A. (2014). Culture corrupts! A qualitative study of organizational

culture in corrupt organizations. Journal of Business Ethics, 120(3), 291-311. doi:10.1007/s10551-013-1665-7

Carpenter, T. D., Durtschi, C., & Gaynor, L. M. (2011). The incremental benefits of a

forensic accounting course on skepticism and fraud-related judgments. Issues in Accounting Education, 26(1), 1-21. doi:10.2308/iace.2011.26.1.1

Carpenter, T. D., & Reimers, J. L. (2013). Professional skepticism: The effects of a

partner's influence and the level of fraud indicators on auditors' fraud judgments and actions. Behavioral Research in Accounting, 25(2), 45-69. doi:10.2308/bria-50468

Cavaliere, F. J., Mulvaney, T., Swerdlow, M., & Baldo, M. (2014). Congress kickstarts

securities laws to jumpstart the economy: The JOBS Act awaits SEC implementation. Southern Law Journal, 24(1), 149-164. Retrieved from http://www.southernlawjournal.com/2014_1/SLJ_Spring_2014_Cavaliere et al.pdf

140

Cohen, J., Ding, Y., Lesage, C., & Stolowy, H. (2010). Corporate fraud and managers' behavior: Evidence from the press. Journal of Business Ethics, 95, 271-315. doi:10.1007/s10551-011-0857-2

Connect. (n.d.). Virginia Society of CPAs website. Retrieved from

http://connect.vscpa.com/home Dorminey, J. W., Fleming, A. S., Kranacher, M., & Riley, R. A. (2010). Beyond the fraud

triangle. CPA Journal, 80(7), 16-23. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=10614

Dorminey, J., Fleming, A. S., Kranacher, M., & Riley, R. A. (2012). The evolution of

fraud theory. Issues in Accounting Education, 27(2), 555-579. doi:10.2308/iace-50131

Drew, J. (2014, May 20). Biennial report details fraud’s impact worldwide. CGMA

Magazine. Retrieved from http://www.cgma.org/magazine/news/pages/201410170.aspx

Fathil, F. M., & Schmidtke, J. M. (2010). The relation between individual differences and

accountants' fraud detection ability. International Journal of Auditing, 14(2), 163- 173. doi:10.1111/j.1099-1123.2009.00412.x

Favere-Marchesi, M. (2013). Effects of decomposition and categorization on fraud-risk

assessments. Auditing: A Journal of Practice & Theory, 32(4), 201-219. doi:10.2308/ajpt-50528

Ferrell, O., & Ferrell, L. (2011). The responsibility and accountability of CEOs: The last

interview with Ken Lay. Journal of Business Ethics, 100(2), 209-219. doi:10.1007/s10551-010-0675-y

Field, A. (2013). Discovering statistics using IBM SPSS Statistics (4th ed.). Thousand

Oaks, CA: Sage Publications. Fraud. (2011). In Merriam-Webster's dictionary of law. Retrieved from

http://search.credoreference.com.proxy1.ncu.edu/content/entry/mwdlaw/fraud/0?id =21348837

George, N. (2012). Financial statement fraud and corporate governance. Review of

Business Research, 12(3), 34-43. Retrieved from http://www.iabe.org/domains/IABE-DOI/Journal.aspx?P=12

Glover, S. M., & Prawitt, D. F. (2014). Enhancing auditor professional skepticism: The

professional skepticism continuum. Current Issues in Auditing, 8(2), P1-P10. doi:10.2308/ciia-50895

141

Goel, S., & Gangolly, J. (2012). Beyond the numbers: Mining the annual reports for hidden cues indicative of financial statement fraud. Intelligent Systems in Accounting, Finance & Management, 19(2), 75-89. doi:10.1002/isaf.1326

Hammersley, J. S., Bamber, E. M., & Carpenter, T. D. (2010). The influence of

documentation specificity and priming on auditors' fraud risk assessments and evidence evaluation decisions. Accounting Review, 85(2), 547-571. doi:10.2308/accr.2010.85.2.547

Hammersley, J. S. (2011). A review and model of auditor judgments in fraud-related

planning tasks. Auditing: A Journal of Practice & Theory, 30(4), 101-128. doi:10.2308/ajpt-10145

Ho, R., Kwock, B., & James, M. (2015). Cultural implications on Chinese accounting

students' professional skepticism. Journal of Business Studies Quarterly, 7(2), 274- 289. Retrieved from http://jbsq.org/wp-content/uploads/2015/12/December_2015_19.pdf

Hogan, C. E., Rezaee, Z., Riley, J. A., & Velury, U. K. (2008). Financial statement fraud: Insights from the academic literature. Auditing: A Journal of Practice & Theory, 27(2), 231-252. doi:10.2308/aud.2008.27.2.231

Hopwood, W. S., Leiner, J. J., & Young, G. R. (2012). Forensic accounting and fraud

examination (2nd ed.). New York, NY: McGraw-Hill Education. Hulsart, R. W., James, K. M., & Cummings, D. M. (2012). Fraud in the lost decade: The

impact of the economic downturn on the prevalence of fraud. Business Studies Journal, 4(1), 9-24. Retrieved from http://www.alliedacademies.org/business- studies-journal/volume-issue.php?volume=Volume 4, Issue 1&&year=2012

Hurtt, K., Eining, M., & Plumlee, D. (2008, May). An experimental examination of

professional skepticism. Social Science Research Network. Retrieved from https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1140267

Hurtt, R. K. (2010). Development of a scale to measure professional skepticism.

Auditing: A Journal of Practice & Theory, 29(1), 149-171. doi:10.2308/aud.2010.29.1.149

Hurtt, R. K., Brown-Liburd, H., Earley, C. E., & Krishnamoorthy, G. (2013). Research

on auditor professional skepticism: Literature synthesis and opportunities for future research. Auditing: A Journal of Practice & Theory, 32(1), 45-97. doi:10.2308/ajpt-50361

Jaffar, N., Haron, H., Iskandar, T., & Salleh, A. (2011). Fraud risk assessment and

detection of fraud: The moderating effect of personality. International Journal of

142

Business & Management, 6(7), 40-50. Retrieved from http://www.ccsenet.org/journal/index.php/ijbm/article/view/9198/7903

Kassem, R., & Higson, A. (2012). Financial reporting fraud: Are standards' setters and

external auditors doing enough?. International Journal of Business & Social Science, 3(19), 283-290. Retrieved from http://ijbssnet.com/journals/Vol_3_No_19_October_2012/32.pdf

Kassem, R., & Higson, A. (2012). The new fraud triangle model. Journal of Emerging

Trends in Economics & Management Sciences, 3(3), 191-195. Retrieved from http://jetems.scholarlinkresearch.com/articlesearch.php

Knapp, C. A., & Knapp, M. C. (2001). The effects of experience and explicit fraud risk

assessment in detecting fraud with analytical procedures. Accounting, Organizations and Society, 26(1), 25-37. doi:10.1016/S0361-3682(00)00005-2

Kochetova-Kozloski, N., Messier, W. F., & Eilifsen, A. (2011). Improving auditors' fraud

judgments using a frequency response mode. Contemporary Accounting Research, 28(3), 837-858. doi:10.1111/j.1911-3846.2011.01067.x

Kravitz, R. H. (2012). Auditors' responsibility for detecting fraud. CPA Journal, 82(6),

24-30. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11056

Lee, C., Welker, R. B., & Wang, T. (2013). An experimental investigation of professional

skepticism in audit interviews. International Journal of Auditing, 17(2), 213-226. doi:10.1111/ijau.12001

LinkedIn. (n.d.). LinkedIn Corp. Retrieved from https://www.linkedin.com/groups/ Lokanan, M. E. (2015). Challenges to the fraud triangle: Questions on its usefulness.

Accounting Forum, 39(3), 201-224. doi:10.1016/j.accfor.2015.05.002 Love, V. J. (2012). Auditors' responsibility for detecting fraud. CPA Journal, 82(6), 32-

38. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11057

Morales, J., Gendron, Y., & Guénin-Paracini, H. (2014). The construction of the risky

individual and vigilant organization: A genealogy of the fraud triangle. Accounting, Organizations & Society, 39(3), 170-194. doi:10.1016/j.aos.2014.01.006

143

Morgan, M., & Nix, W. (2011). CPA perceptions of the marketability, career enhancements and quality of services of certified fraud examiners. Southern Business & Economic Journal, 34(3/4), 31-50. Retrieved from http://www.business.aum.edu/about/southern-business-economic-journal

Murphy, P., & Dacin, M. (2011). Psychological pathways to fraud: Understanding and

preventing fraud in organizations. Journal of Business Ethics, 101(4), 601-618. doi:10.1007/s10551-011-0741-0

NGO Security. (2010, February 14). Using the Likert scale to assess risk [Web log post].

Retrieved from http://ngosecurity.blogspot.com/2010/02/using-likert-scale-to-assess-risk.html

Nix, W., & Morgan, M. (2013). Chief financial officers give credit to certified fraud

examiners' fight against fraud. Academy of Business Journal, 2(1), 1-15. Retrieved from http://www.aobronline.com/#!journals/c5ro

Northcentral University. (2015). Institutional Review Board Handbook. Retrieved from

http://learners.ncu.edu Park, J., & Park, M. (2016). Qualitative versus quantitative research methods: Discovery

or justification?. Journal Of Marketing Thought, 3(1), 1-7. doi:10.15577/jmt.2016.03.01.1

PCAOB focuses on 3 key areas for 2015. (2015, December 1). Retrieved from

http://www.journalofaccountancy.com/issues/2015/dec/pcaob-audit-focus.html Peytcheva, M. (2014). Professional skepticism and auditor cognitive performance in a

hypothesis-testing task. Managerial Auditing Journal, 29(1), 27-49. doi:10.1108/MAJ-04-2013-0852

Piercey, D. M. (2011). Documentation requirements and quantified versus qualitative

audit risk assessments. Auditing: A Journal of Practice & Theory, 30(4), 223-248. doi:10.2308/ajpt-10171

Popoola, O. J., Che-Ahmad, A. B., & Samsudin, R. S. (2014). Fraud and forensic

accounting: Knowledge and risk assessment task performance in Malaysian public sector -- Conceptual study. Annual International Conference on Accounting & Finance, 103-109. doi:10.5176/2251-1997_AF14.55

Popoola, O. J., Che-Ahmad, A. B., & Samsudin, R. S. (2015). An empirical investigation

of fraud risk assessment and knowledge requirement on fraud related problem representation in Nigeria. Accounting Research Journal, 28(1), 78-97. doi:10.1108/ARJ-08-2014-0067

144

Poynter, R. (2010). The handbook of online and social media research: Tools and techniques for market researchers. Hoboken, NJ: Wiley Publishing.

Quadackers, L., Groot, T., & Wright, A. (2014). Auditors' professional skepticism:

Neutrality versus presumptive doubt. Contemporary Accounting Research, 31(3), 639-657. doi:10.1111/1911-3846.12052

Radecki, T. (1982). Similarity measures for Boolean search request formulations. Journal

of the American Society for Information Science, 33(1), 8-17. Retrieved from https://www.asist.org/publications/jasist/

Rasso, J. T. (2015). Construal instructions and professional skepticism in evaluating

complex estimates. Accounting, Organizations & Society, 4(6) 44-55. doi:10.1016/j.aos.2015.03.003

Ray, T. (2015). Auditors still challenged by professional skepticism. CPA Journal, 85(1),

21-27. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=9952

Reffett, A. B. (2010). Can identifying and investigating fraud risks increase auditors'

liability?. Accounting Review, 85(6), 2145-2167. doi:10.2308/accr.2010.85.6.2145 Rose, J. M., McKay, B. A., Norman, C. S., & Rose, A. M. (2012). Designing decision

aids to promote the development of expertise. Journal of Information Systems, 26(1), 7-34. doi:10.2308/isys-10188

Schmidt, R. N. (2014). The effects of auditors' accessibility to “tone at the top”

knowledge on audit judgments. Behavioral Research in Accounting, 26(2), 73-96. doi:10.2308/bria-50824

Schuchter, A., & Levi, M. (2015). Beyond the fraud triangle: Swiss and Austrian elite

fraudsters. Accounting Forum, 39(3), 176-187. doi:10.1016/j.accfor.2014.12.001 Shadnam, M., & Lawrence, T. B. (2011). Understanding widespread misconduct in

organizations: An institutional theory of moral collapse. Business Ethics Quarterly, 21(3), 379-407. Retrieved from https://www.pdcnet.org/pdc/bvdb.nsf/purchase?openform&fp=beq&id=beq_2011_ 0021_0003_0379_0407

Soltani, B. B. (2014). The anatomy of corporate fraud: A comparative analysis of high

profile American and European corporate scandals. Journal of Business Ethics, 120(2), 251-274. Retrieved from http://link.springer.com/article/10.1007%2Fs10551-013-1660-z#/page-1

145

Srivastava, R. P., Mock, T. J., & Gao, L. (2011). The Dempster-Shafer theory: An introduction and fraud risk assessment illustration. Australian Accounting Review, 21(3), 282-291. doi:10.1111/j.1835-2561.2011.00135.x

Stephens, N. M. (2011). External auditor characteristics and internal control reporting

under SOX section 302. Managerial Auditing Journal, 26(2), 114-129. Retrieved from http://dx.doi.org/10.1108/02686901111095001

Trompeter, G. M., Carpenter, T. D., Desai, N., Jones, K. L., & Riley, R. A. (2013). A

synthesis of fraud-related research. Auditing: A Journal of Practice & Theory, 32(S1), 287-321. doi:10.2308/ajpt-50360

Trotman, K. T., & Wright, W. F. (2012). Triangulation of audit evidence in fraud risk

assessments. Accounting, Organizations and Society, 37(1), 41-53. doi:10.1016/j.aos.2011.11.003

Verschoor, C. C. (2014). Fraud continues to cause significant losses. Strategic Finance,

96(8), 11-85. Retrieved from http://www.imanet.org/docs/default-source/sf/08_2014_ethics-pdf.pdf?sfvrsn=0

Victoravich, L. M. (2010). The mediated effect of SAS No. 99 and Sarbanes–Oxley

officer certification on jurors’ evaluation of auditor liability. Journal of Accounting & Public Policy, 29(6), 559-577. doi:10.1016/j.jaccpubpol.2010.09.006

Wei, C., Khalifa, A. S., & Trotman, K. T. (2015). Facilitating brainstorming: Impact of

task representation on auditors' identification of potential frauds. Auditing: A Journal of Practice & Theory, 34(3), 1-22. doi:10.2308/ajpt-50986

146

Appendix A: Hurtt Professional Skepticism Scale

Strongly Disagree

Strongly Agree

I often accept other people’s explanations without further thought. 1 2 3 4 5 6 I feel good about myself. 1 2 3 4 5 6 I wait to decide on issues until I can get more information. 1 2 3 4 5 6 The prospect of learning excites me. 1 2 3 4 5 6 I am interested in what causes people to behave the way that they do. 1 2 3 4 5 6 I am confident of my abilities. 1 2 3 4 5 6 I often reject statements unless I have proof that they are true. 1 2 3 4 5 6 Discovering new information is fun. 1 2 3 4 5 6 I take my time when making decisions. 1 2 3 4 5 6 I tend to immediately accept what other people tell me. 1 2 3 4 5 6 Other people’s behavior does not interest me. 1 2 3 4 5 6 I am self-assured. 1 2 3 4 5 6 My friends tell me that I usually question things that I see or hear. 1 2 3 4 5 6 I like to understand the reason for other people's behavior. 1 2 3 4 5 6 I think that learning is exciting. 1 2 3 4 5 6 I usually accept things I see, read, or hear at face value. 1 2 3 4 5 6 I do not feel sure of myself. 1 2 3 4 5 6 I usually notice inconsistencies in explanations. 1 2 3 4 5 6 Most often I agree with what the others in my group think. 1 2 3 4 5 6 I dislike having to make decisions quickly. 1 2 3 4 5 6 I have confidence in myself. 1 2 3 4 5 6 I do not like to decide until I've looked at all of the readily available information. 1 2 3 4 5 6 I like searching for knowledge. 1 2 3 4 5 6 I frequently question things that I see or hear. 1 2 3 4 5 6 It is easy for other people to convince me. 1 2 3 4 5 6 I seldom consider why people behave in a certain way. 1 2 3 4 5 6 I like to ensure that I’ve considered most available information before making a decision. 1 2 3 4 5 6 I enjoy trying to determine if what I read or hear is true. 1 2 3 4 5 6 I relish learning. 1 2 3 4 5 6 The actions people take and the reasons for those actions are fascinating. 1 2 3 4 5 6

147

Appendix B: CITI Requirements Report

148

Appendix C: Internal Review Board Approval

149

Appendix D: Informed Consent Form

Introduction:

My name is Cynthia Vance. I am a doctoral student at Northcentral University. I am conducting a research study on the effects of auditor certification (i.e., CFE and/or CPA), professional skepticism, and the presence of fraud on fraud risk assessment performance. I am completing this research as part of my doctoral degree. I invite you to participate.

Activities:

If you participate in this research, you will be asked to:

1. Answer demographic questions – 3 minutes 2. Complete a 30-item professional skepticism questionnaire – 7 minutes 3. Review a company’s financial statements and perform a fraud risk assessment

by answering four Likert-type questions – 50 minutes

Eligibility:

You are eligible to participate in this research if you:

1. Are the age of 18 or older 2. Possess either the certified fraud examiner (CFE) and/or the certified public

accountant (CPA) credential 3. Work in the United States

You are not eligible to participate in this research if you:

1. Are not 18 years of age 2. Do not possess the certified fraud examiner (CFE) and/or the certified public

accountant (CPA) credential 3. Do not work in the United States

I hope to include 200 people in this research.

Risks:

There are minimal risks in this study. No identifiable data will be collected from this research. The research design employs the use of third-party online survey software to collect the data; hence, the participants’ privacy and anonymity will be safeguarded.

150

To decrease the impact of these risks, you can stop participation at any time.

Benefits:

If you decide to participate, there are no direct benefits to you.

The others receiving potential benefits are the accounting profession namely, auditors, regulators, and academicians. It will enhance the body of knowledge of the influences of auditor attributes (i.e., certification and professional skepticism) to the outcome of fraud risk assessments, which are used to detect fraudulent financial statements.

Confidentiality:

The information you provide will be kept confidential to the extent allowable by law. Confidentiality will be maintained as no identifiable data will be collected. The use of the Internet for the online survey does present a risk for a confidentiality breach of the IP address. However, IP addresses will not be included in the research dataset used by the researcher to analyze the data.

The people who will have access to your information are: myself, my dissertation chair, and my dissertation committee. The Institutional Review Board may also review my research and view your information.

I will secure your information with these steps: use of a third-party software company that uses high-end firewall systems to protect the data stored on its site, exclude IP addresses from the data downloaded from the third-party software, store all paper files of the downloaded data in a locked cabinet, use a password to lock all downloaded computer files stored on portable devices (i.e., flash drives, external hard drives), which will be stored in a locked cabinet.

I will keep your data for 7 years. Then, I will delete electronic data and destroy paper data.

Contact Information:

If you have questions for me, you can contact me at: C.Vance4867@email.ncu.edu.

My current dissertation chair’s name is Dr. Gail Gessert. She works for Northcentral University and is supervising me on the research. You can contact her at: ggessert@ncu.edu.

If you have questions about your rights in the research, or if a problem has occurred, or if you are injured during your participation, please contact the Institutional Review Board at: irb@ncu.edu or 1-888-327-2877 ext 8014.

151

Voluntary Participation:

Your participation is voluntary. If you decide not to participate, or if you stop participation after you start, there will be no penalty to you. You will not lose any benefit to which you are otherwise entitled.

Signature:

By selecting the “Agree” option, you agree to willfully participate in the research project and you understand this consent form. By selecting the “Decline” option you decline to willfully to participate in the research project.

152

Appendix E: Qualtrics Online Survey Financial Statement Fraud Risk Assessment - Launched Q1. Financial statement fraud is a challenge for the global business environment. The Public Company Accounting Oversight Board (PCAOB) continues to find deficiencies in auditors' responses to fraud risk. This is a research study on financial statement fraud risk in relation to the effects of professional certifications and professional skepticism on the fraud risk assessment process. You may participate in this research study if you are 18 years old or older, have either a certified fraud examiner (CFE) and/or a certified public accountant (CPA) certification, and work in the United States. If you participate in this research, you will answer a few demographic questions, complete a questionnaire on skepticism, and review a company’s financial statements to perform a fraud risk assessment. The three activities should take no longer than an hour. All responses will be kept confidential and no personally recognizable data will be collected. You can stop participation in the study at any time. If you have questions for me, you can contact me at C.Vance4867@email.ncu.edu. Thank you in advance for considering participating in this research study.  Yes, I am eligible to participate in this study. (1)  No, I am not eligible to participate in this study. (2) If No, I am not eligible to part... Is Selected, Then Skip To End of Block Q2. Please read the following consent form IRB Consent Form before you agree to participate in the study. After reading the consent form, click on your decision to participate.  I agree to willfully participate in the research study. (1)  I decline to willfully participate in the research study. (2) If I decline to willfully part... Is Selected, Then Skip To End of Block Q3. Age of participant If Age of participant Is Less Than 18, Then Skip To End of Block Q4. Gender of participant  Male (1)  Female (2) Q5. U.S. Geographic Work Region  Northeast (1)  Southeast (2)  Southwest (3)  West (4)  Midwest (5) Q6. Years of Audit Experience Q7. Years of Fraud Risk Assessment Experience

153

Q8. Professional Certification  Certified Fraud Examiner (1)  Certified Fraud Examiner & Certified Public Accountant (2)  Certified Public Accountant (3)  Neither a Certified Fraud Examiner or Certified Public Accountant (4) If Neither a Certified Fraud E... Is Selected, Then Skip To End of Block

154

Q9. Select the response that indicates how you generally feel. There are no right or wrong answers. Do not spend too much time on any one statement.

Strongly

Agree 1 2 3 4 5

Strongly Disagree

6 I often accept other people’s explanations

without further thought. (1)

     

I feel good about myself.

(2)      

I wait to decide on

issues until I can get more information.

(3)

     

The prospect of learning

excites me. (4)      

I am interested in what causes

people to behave the

way that they do. (5)

     

I am confident of my abilities.

(6)      

I often reject statements

unless I have proof that they

are true. (7)

     

Discovering new

information is fun. (8)

     

I take my time when making decisions. (9)

     

155

I tend to immediately accept what other people tell me. (10)

     

Other people’s behavior does

not interest me. (11)

     

I am self- assured. (12)      

My friends tell me that I usually

question things that I see or hear.

(13)

     

I like to understand the

reason for other people's behavior. (14)

     

I think that learning is

exciting. (15)      

I usually accept things I see, read, or hear at face value. (16)

     

I do not feel sure of myself.

(17)      

I usually notice

inconsistencies in

explanations. (18)

     

Most often I agree with what the

others in my group think.

(19)

     

156

I dislike having to

make decisions

quickly. (20)

     

I have confidence in myself. (21)

     

I do not like to decide until

I've looked at all of the readily

available information.

(22)

     

I like searching for knowledge.

(23)

     

I frequently question

things that I see or hear.

(24)

     

It is easy for other people to convince me.

(25)

     

I seldom consider why people behave

in a certain way. (26)

     

I like to ensure that I’ve

considered most available

information before making

a decision. (27)

     

I enjoy trying to determine if what I read or hear is true.

(28)

     

157

I relish learning. (29)      

The actions people take

and the reasons for

those actions are

fascinating. (30)

     

Q10. Perform a fraud risk assessment for ABC, Inc. for the fiscal year 2006 by responding to the following questions after reviewing the attached 10-K Form ABC Inc_12302006 .

Very improba

ble /insignif icant (1)

Improbable/ insignificant

(2)

Somewhat improbabl

e /insignific

ant (3)

Neith er (4)

Somewh at

probable /

significa nt (5)

Probable /

significa nt (6)

Very probabl

e/ signific ant (7)

Likelihoo d of fraud risks (1)

      

Significan ce of fraud

risks (2)

      

Significan ce of anti-

fraud controls

in use (3)

      

Likelihoo d of fraud

(4)       

158

Q11. Perform a fraud risk assessment for XYZ, Inc. for the fiscal year 2006 by responding to the following questions after reviewing the attached 10-K Form XYZ Inc_12292007.

Very improbable/ insignificant

(1)

Improbable/ insignificant

(2)

Somewhat improbable/ insignificant

(3)

Neither (4)

Somewhat probable/ significant

(5)

Probable/ significant

(6)

Very probable/ significant

(7)

Likelihood of fraud risks (1)

      

Significance of fraud risks (2)

      

Significance of anti- fraud

controls in use (3)

      

Likelihood of fraud

(4)       

  • Chapter 1: Introduction
    • Statement of the Problem
    • Purpose of the Study
    • Theoretical Framework
    • Nature of the Study
    • Research Questions
      • Q3. Does professional skepticism influence fraud risk assessment performance?
    • Hypotheses
    • Significance of the Study
    • Definition of Key Terms
    • Summary
  • Chapter 2: Literature Review
    • A synthesis of extant literature on fraud and attribution theory was conducted to find gaps in the current body of knowledge in relation to financial statement fraud. The literature review was organized into the following categories: regulations, ris...
    • Theoretical Framework
    • Certified Fraud Examiners
    • Summary
  • Chapter 3: Research Method
    • Q1. Does the presence of fraud risk have an effect on fraud risk assessment performance?
    • Q2. Does a certification in fraud knowledge have an effect on fraud risk assessment performance?
    • Research Design
    • Population
    • Materials/Instrumentation
    • Operational Definition of Variables
    • Study Procedures
    • Data Collection and Analysis
    • Assumptions
    • Limitations
    • Delimitations
    • Ethical Assurances
    • Summary
  • Chapter 4: Findings
    • Results
    • Evaluation of Findings
    • Summary
  • Chapter 5: Implications, Recommendations, and Conclusions
    • Implications
  • References
  • Appendix A: Hurtt Professional Skepticism Scale