Explain the Academic Research Lifecycle
The Effects of the Presence of Fraud and Auditor Certification Considering Professional
Skepticism on Fraud Risk Assessment Performance
Dissertation Manuscript
Submitted to Northcentral University
School of Business and Technology Management
in Partial Fulfillment of the
Requirements for the Degree of
DOCTOR OF PHILOSOPHY
by
CYNTHIA E. VANCE
San Diego, California
May 2017
ProQuest Number:
All rights reserved
INFORMATION TO ALL USERS The quality of this reproduction is dependent upon the quality of the copy submitted.
In the unlikely event that the author did not send a complete manuscript and there are missing pages, these will be noted. Also, if material had to be removed,
a note will indicate the deletion.
ProQuest
Published by ProQuest LLC ( ). Copyright of the Dissertation is held by the Author.
All rights reserved. This work is protected against unauthorized copying under Title 17, United States Code
Microform Edition © ProQuest LLC.
ProQuest LLC. 789 East Eisenhower Parkway
P.O. Box 1346 Ann Arbor, MI 48106 - 1346
10288565
10288565
2017
Abstract
Financial statement fraud is still prevalent in the United States, even after the enactment
of the Sarbanes-Oxley Act of 2002 and SAS No. 99. Researchers and auditing regulators
report that auditors’ fraud risk assessments are not effectively detecting financial
statement fraud. Both professional skepticism and fraud knowledge are attributes that
may have an effect on auditors’ fraud risk assessment outcomes. The purpose of this
quantitative between-participants research study was to examine the independent
variables of the presence of fraud and auditor certification while controlling for
professional skepticism in relation to the dependent variable, fraud risk assessment
performance, for participants within the U.S., who are certified public accountants
(CPAs) and/or certified fraud examiners (CFEs). The experiment was conducted in the
online environment using Qualtrics online survey software. Participants completed the
Hurtt Professional Skepticism Scale questionnaire to measure professional skepticism
and conducted a fraud risk assessment of a company’s set of financial statements (Form
10-K). Statistical data analysis was performed using both a two-way analysis of variance
(ANOVA) and a two-way analysis of covariance (ANCOVA) in conjunction with
planned comparisons to determine interaction effects of the variables. Results revealed a
significant effect of the presence of fraud on fraud risk assessment performance with and
without the influence of professional skepticism. However, the absence of fraud risk
condition produced a higher fraud risk assessment performance than the presence of fraud
risk condition, which did not support the hypothesis. Moreover, the effect of auditor
certification had an insignificant effect on fraud risk assessment performance with and
without the influence of professional skepticism. Results of this study provide support
that a quantitative review of financial statements does not accurately assess fraud risk,
even if the evaluators possess higher levels of professional skepticism. Further research
should be conducted to evaluate the minimum requirements prescribed by the accounting
profession for effective financial statement fraud detection.
Acknowledgements
I would like to thank my dissertation committee chair, Dr. Vanessa Ann Claus, for
all of her assistance and dedication to my research project. She went over and above to
help me complete the dissertation process on time. Additionally, I am appreciative of the
time commitment and advice from my dissertation reviewers, Dr. Garrett Smiley and Dr.
Stephen Verrill. I am also grateful to Dr. Gail Gessert and the faculty members at
Northcentral University who equipped me with the skills needed to become a scholar
through their valuable feedback and insights during my coursework. I also would like to
thank my wonderful son, Cory, for understanding my time commitment to this project,
and my friends and family for their continued support. I thank God for being with me
during this journey and giving me the strength to persevere.
Table of Contents
Chapter 1: Introduction……………………………………………………………………1
Statement of the Problem ............................................................................................. 5 Purpose of the Study .................................................................................................... 6 Theoretical Framework ................................................................................................ 9 Nature of the Study .................................................................................................... 11 Research Questions .................................................................................................... 13 Significance of the Study ........................................................................................... 15 Definition of Key Terms ............................................................................................ 17 Summary .................................................................................................................... 18
Chapter 2: Literature Review ............................................................................................ 20
Theoretical Framework .............................................................................................. 21 Regulations ................................................................................................................ 24 Risk Assessment Models ........................................................................................... 34 Auditors' Attributes .................................................................................................... 49 Certified Fraud Examiners ......................................................................................... 66 Summary .................................................................................................................... 69
Chapter 3: Research Method ............................................................................................. 71
Research Methodology and Design ........................................................................... 76 Population and Sample .............................................................................................. 80 Materials/Instrumentation .......................................................................................... 82 Operational Definition of Variables .......................................................................... 84 Study Procedures ....................................................................................................... 87 Data Collection and Analysis .................................................................................... 88 Assumptions .............................................................................................................. 91 Limitations ................................................................................................................. 92 Delimitations.............................................................................................................. 93 Ethical Assurances ..................................................................................................... 93 Summary .................................................................................................................... 95
Chapter 4: Findings ........................................................................................................... 97
Trustworthiness of Data ............................................................................................. 98 Results...................................................................................................................... 103 Research Question 1 ................................................................................................ 109 Research Question 2 ................................................................................................ 110 Research Question 3 ................................................................................................ 111 Evaluation of Findings ............................................................................................. 112 Summary .................................................................................................................. 114
Chapter 5: Implications, Recommendations, and Conclusions ...................................... 115 Implications ............................................................................................................. 117 Recommendations for Practice ................................................................................ 128 Recommendations for Future Research ................................................................... 130 Conclusions.............................................................................................................. 132
References ....................................................................................................................... 137 Appendices ...................................................................................................................... 145 Appendix A: Hurtt Professional Skepticism Scale ......................................................... 145 Appendix B: CITI Requirements Report ........................................................................ 146 Appendix C: Internal Review Board Approval .............................................................. 147 Appendix D: Informed Consent Form ............................................................................ 148 Appendix E: Qualtrics Online Survey ............................................................................ 151
List of Tables Table 1 Descriptive Statistics of Age and Years of Experience for Audit and Fraud Risk
Assessment………………………………………………………………………….…..105 Table 2 Descriptive Statistics of Gender and U.S. Geographic Region..………………..106 Table 3 Descriptive Statistics of Fraud Risk Assessment and Professional Skepticism Score ……………………………………..………………………………………..….…107 Table 4 Group Means With and Without the Effect of the Covariate……………….....…109
1
Chapter 1: Introduction
Financial statement fraud is the intentional act of misrepresenting financial
information, which harms the users who rely on the false data (Association of Certified
Fraud Examiners, 2014; George, 2012). The occurrence of financial statement fraud has
a significant impact on economies and stakeholders including employees, investors,
creditors, auditors, regulators, and communities (Beasley, Carcello, Hermanson, & Neal,
2010). In the late 1990s and early 2000s financial statement fraud was discovered in
large United States (U.S.) public companies (e.g., Enron, WorldCom, and Waste
Management), which resulted in the collapse of the respected public accounting firm,
Arthur Andersen (Soltani, 2014). Congress enacted legislation, the Sarbanes-Oxley Act
of 2002 (SOX), in response to the financial scandals (Alleyne & Elson, 2013). SOX
brought significant changes to the public accounting profession, including a change from
self-regulation to regulation by a private board, the Public Company Accounting
Oversight Board (PCAOB).
In accordance with the Statement on Auditing Standard (SAS) No. 99,
Consideration of Fraud in a Financial Statement Audit, auditors of U.S. public
companies are required to perform a fraud risk assessment as part of financial statement
audits to detect material financial misstatements (Kassem & Higson, 2012; Victoravich,
2010). An auditor’s role is to provide reasonable assurance that the financial statements
are free from material misstatements (Buchholz, 2012). However, according to the
PCAOB, “the lack of professional skepticism is a serious problem in auditors’ fraud
investigations” (Trompeter, Carpenter, Desai, Jones, & Riley, 2013, p. 304).
Investigations ensued calling for research to ascertain the influences of fraud training on
2
auditors’ fraud judgments (Carpenter, Durtschi, & Gaynor, 2011a; Hogan, Rezaee, Riley,
& Velury, 2008 as cited in Trompeter et al., 2013). The research study examined
variables that influence auditors’ detection and reporting of financial statement fraud in
the U.S. during the post-SOX period (2005–2014). The research study participants were
CPAs and/or CFEs from the Association of Certified Fraud Examiners (ACFE), the
American Institute of Certified Public Accountants (AICPA), and the Virginia Society of
Certified Public Accountants (VSCPA) populations.
The U.S. Congress responded to financial statement fraud after the stock market
crash of 1929 by enacting two statutory laws – the Securities Act of 1933 and the
Securities Exchange Act of 1934 (Cavaliere, Mulvaney, Swerdlow, & Baldo, 2014). The
Securities Act regulates new public offerings, which requires specific information to be
provided to investors on the securities offered for public sale (Alleyne & Elson, 2013).
The Securities Exchange Act established the Securities and Exchange Commission (SEC)
to regulate the subsequent sales of publicly traded securities on the securities exchanges
(e.g., New York Stock Exchange and NASDAQ; Alleyne & Elson, 2013). The SEC
requires public companies to provide regular reports (e.g., Form 10-K and Form 10-Q) on
business operations, financial conditions, and management, which are maintained in the
SEC’s database that is available to the public (Cavaliere et al., 2014). The Securities Act
of 1933 and the Securities Exchange Act of 1934 did not prevent the major corporate
fraud scandals that occurred during the late 1990s through 2002, which include, but are
not limited to Adelphia, Enron, HealthSouth, Tyco, and WorldCom (Nix & Morgan,
2013; Soltani, 2014). In response to political pressure to prevent financial statement
fraud, Congress enacted SOX in 2002, which established the PCAOB to provide
3
oversight of public accounting firms and publically held corporations (Hulsart, James, &
Cummings, 2012). The PCAOB adopted the American Institute of Certified Public
Accountants (AICPA) Auditing Standards Board’s (ASB) auditing standards as its
interim standards. SOX increased corporate management’s responsibilities by requiring
officer certification of the financial statements and the establishment and reporting of
internal controls over financial reporting (ICFR) to name a few (Victoravich, 2010).
SOX also required auditors to opine on the ICFR, which included the performance of a
fraud risk assessment (Victoravich, 2010).
The ASB also responded to the demand for a reduction in fraudulent financial
reporting in 2002 by issuing SAS No. 99 (later codified as AU Section 316), which
expanded auditors’ responsibilities on fraud assessment during a financial statement audit
(Victoravich, 2010). According to SAS No. 99, auditors must (a) brainstorm and
document potential fraud risks during the audit planning stage, (b) identify potential fraud
risks by making inquiries of management and others, and (c) consider fraud risk factors
and other data to identify risk of material misstatement in the financial statements due to
fraud (Nix & Morgan, 2013, p. 2). SAS No. 99 uses the fraud triangle as the theoretical
framework for auditors to evaluate fraud risk. The fraud triangle, identified in SAS No.
99, defines the elements necessary for fraud to occur as incentives, opportunities, and
attitudes (Nix & Morgan, 2013). SAS No. 99 also emphasizes the importance of
professional skepticism to identify, evaluate, communicate, and document the risks of
material misstatements due to fraud (Nix & Morgan, 2013). The auditing standards
define professional skepticism as “an attitude that includes a questioning mind, being
alert to conditions that may indicate possible misstatement due to fraud or error, and a
4
critical assessment of audit evidence” (Lee, Welker, & Wang, 2013, p. 213). Hence, SAS
No. 99 is a significant regulation for the auditing profession as it provides guidance for
auditors in the detection and reporting of fraudulent financial statements. SAS No. 99
clarifies the responsibilities of auditors in relation to the risk of fraud in financial
statements by using the fraud triangle theoretical framework to assess fraud risks (Nix &
Morgan, 2013).
Even though SAS No. 99 requires a fraud risk assessment, a financial statement
audit does not provide absolute assurance that the financial statements are free from
material misstatement due to fraud. The auditors must demonstrate that the audit
procedures designed and used, including a fraud risk assessment, provide reasonable
assurance that the financial statements are free from material misstatement (Love, 2012).
The purpose of a financial statement audit is to render an opinion on the fair presentation
of the audited entity’s financial statements, not to find fraud (Love, 2012). Love (2012)
identified auditing standards’ testing limitations and the failure of auditors to exercise
professional skepticism, integrity, and objectivity throughout the audit as the reasons that
financial statement audits often fail to detect fraudulent reporting.
SAS No. 99 recommends the use of certified fraud examiners (CFEs) to assist
organizations with fraud prevention and detection (Nix & Morgan, 2013). The CFE
certification was created by the ACFE in 1988 in response to the demand for expertise in
fraud detection and prevention (Nix & Morgan, 2013). ACFE membership requires
passing the CFE “exam which tests knowledge in the areas of criminology, prevention
and deterrence, fraudulent financial transactions, fraud investigation, and legal elements
of fraud” (Nix & Morgan, 2013, p. 3). The ACFE attests that CFEs “have knowledge of
5
fraud assessment, detection, and prevention methods” (Nix & Morgan, 2013, p. 4). Even
with the clarifications of auditors’ responsibilities and defined methodologies in SAS No.
99, to detect and report financial statement fraud, financial statement fraud is still a
problem in the global economy.
Statement of the Problem
Occupational fraud, including financial statement fraud, “is a universal problem
for businesses around the globe” (Association of Certified Fraud Examiners, 2014, p. 5).
PricewaterhouseCoopers reported that 30% of companies worldwide were victims of
fraud in 2009 (Murphy & Dacin, 2011). The ACFE’s Report to the Nations on
Occupational Fraud and Abuse reported that approximately 5% of organizations’ annual
revenues are lost to fraud, which is equivalent to approximately 3.7 trillion dollars
worldwide (Drew, 2014, para. 1). Drew (2014) reported that 48% of the fraud cases were
in the U.S. and that “financial statement frauds were the least common, but most costly,
representing 9% of cases and a median loss of $1 million” (para. 14). Hence, 13 years
after the enactment of SOX, financial statement fraud is still prevalent, not only in the
U.S., but also worldwide (Association of Certified Fraud Examiners, 2014).
Auditors’ fraud risk assessments are not effectively detecting financial statement
fraud. Hopwood, Leiner, and Young (2012) reported that auditors who applied SAS No.
99 detected only “5 to 20 percent of the occupational frauds” (p. 169). Albrecht and
Hoopes (2014) posited the following reasons why auditors are unable to detect fraud (a)
voluminous nature of accounting records, (b) use of outsiders to conceal the fraud, (c)
reluctance of people to disclose information about fraudulent acts, (d) use of forgery and
lying to provide barriers against discovery, and (e) lack of performance of sufficient
6
financial statement audits. Additionally, Albrecht and Hoopes (2014) identified four
factors that prevent auditors from performing sufficient financial statement audits to
detect financial statement fraud, which include (a) inadequate training and experience, (b)
poor audit planning, gathering of evidence, and examining controls, (c) lack of due
professional care, and (d) lack of independence (p. 20). Trompeter, Carpenter, Desai,
Jones, and Riley (2013) stated that the PCAOB inspections found deficiencies in
auditors’ responses to fraud risk. Trompeter et al. (2013) recommended future research
to ascertain if the deficiencies are a result of the auditors’ failure to respond or a result of
the auditors’ inability to respond when appropriate fraud assessment techniques are used.
Hurtt, Brown-Liburd, Earley, and Krishnamoorthy (2013) acknowledged the importance
of professional skepticism in fraud detection, but stated, “research is limited to the
actions that auditors actually take related to their professional skepticism” (p. 72). Due to
the complexity of the interrelationships in conducting a fraud risk assessment and the
importance of fraud detection for the auditing profession and regulators, additional
research is needed to understand fraud risk assessments and the elements influencing
fraud risk assessment performance (Trompeter et al., 2013). Effective fraud risk
assessments identify fraud risk factors (i.e., opportunities, incentives, and pressures),
which may lead auditors to discover of financial statement fraud (Nix & Morgan, 2013).
Purpose of the Study
The purpose of this experimental between-participants quantitative research study
was to examine the theoretical underpinnings of fraud and attribution in relation to the
independent variables of the presence of fraud and auditor certification, the control
variable of professional skepticism, and the dependent variable, fraud risk assessment
7
performance, for participants within the U.S. who are either certified fraud examiners
and/or certified public accountants. The participants were from the population of the
Association of Certified Fraud Examiner’s (ACFE) LinkedIn group and online forum of
certified fraud examiners and associate memberships, the population of the American
Institute of Certified Public Accountants’ (AICPA) LinkedIn group memberships, and the
population of the Virginia Society of Certified Public Accountants’ (VSCPA) LinkedIn
group and online forum memberships. The ACFE is the largest global anti-fraud
organization comprised of certified fraud examiners, associate members, student
members, and educator members (Association of Certified Fraud Examiners, 2014). The
AICPA represents the largest global professional association of accountants comprised of
regular members (i.e., licensed or previously certified/licensed CPAs), associate
members, non-CPA associates, CPA exam candidate affiliate, and student affiliates
(“About the AICPA,” n.d., para. 1). The VSCPA is a professional association of the state
of Virginia comprised of certified public accountants, associate members, and student
members (“About the Virginia Society of CPAs,” n.d.). Auditor certification was
categorized by the self-identification of certification attributes (CFE or CFE/CPA or
CPA). Professional skepticism was measured by using Hurtt’s (2010) six-point Likert
skepticism scale to measure the trait of professional skepticism. Hurtt (2010) validated
the skepticism scale for use in research by using students and professional auditors.
Fraud risk was operationalized by the use of two sets of financial statement data from the
Securities and Exchange Commission’s (SEC) public database for the years 2005–2014
of which one set contained high-fraud risk and one set contained low-fraud risk. Fraud
risk assessment performance measured the auditors’ ability to assess fraud risk. Fraud
8
risk assessment performance was measured on a seven-point Likert scale data using four
Likert-type items combined so that an interval measurement scale could be used for
quantitative analyses. Boone and Boone (2012) illustrated that a composite score (i.e.,
sum or mean) may be calculated from four or more similar Likert-type items, which
allows the use of parametric analysis using the analysis of variance (ANOVA) technique.
NGO Security (2010) combined probability of occurrence and impact of risk to illustrate
the use of a seven-point Likert scale to quantitatively assess risk by multiplying the two
rating values together; the higher number represents higher risk. Jaffar, Haron, Iskandar,
and Salleh (2011) used a seven-point Likert scale ranging from extremely unlikely to
extremely likely to measure auditors’ ability to assess fraud risk with ANOVA as the
statistical method for evaluation. A Likert scale was used as the instrument to measure
fraud risk assessment performance because neither the PCAOB nor the AICPA have a
standardized fraud risk assessment tool that is used by auditors to assess fraud risk
(Albrecht & Hoopes, 2014; Boritz et al., 2015). Generally, auditors measure fraud risk as
high, medium, or low; hence, a numeric value is not traditionally attributed to fraud risk
assessments (Boritz et al., 2015).
The population for this study included U.S. certified fraud examiners (CFEs) and
U.S. certified public accountants (CPAs) that were members of the ACFE, AICPA,
and/or the VSCPA. Members were invited to participate in the experiment using the
ACFE online discussion forum, the ACFE and the AICPA LinkedIn discussion forums,
and the VSCPA online and LinkedIn discussion forums. The experimental construct was
a 2X3 between-participants, which was a design with two levels for one independent
variable and three levels for the second independent variable to test the fraud risk
9
variable. SPSS Statistics version 24 was used to conduct a two-way analysis of variance
(ANOVA) to determine the effect that the categorical independent variables (the presence
of fraud risk and auditor certification) had on the interval dependent variable, fraud risk
assessment performance. Next, SPSS was used to conduct a two-way analysis of
covariance (ANCOVA) to examine the influence of the control variable, professional
skepticism, on the fraud risk assessment performance dependent variable. Planned
contrasts were also conducted in SPSS to determine interaction effects of the auditor
certification variables through the use of the Helmert contrast.
Theoretical Framework
The theoretical framework used to examine the effect of the presence of fraud and
auditor certification, while considering professional skepticism on fraud risk assessment
performance were the fraud theory and attribution theory. Fraud theory is used by
researchers, the accounting profession, and auditing regulators to develop training and
tools for the detection and prevention of financial statement fraud (Boyle et al., 2015).
The fraud triangle serves as the foundation for numerous theories on fraudulent behavior
(Boyle et al., 2015). The fraud triangle was developed by Donald Cressey in the early
1950s to explain the criteria that must be present for fraud to occur, which includes
pressure, opportunity, and rationalization (Dorminey, Fleming, Kranacher, & Riley,
2012). Both the PCAOB and the Auditing Standards Board (ASB) integrate the fraud
triangle in the auditing standards for fraud risk assessment (i.e., AU Section 316 and SAS
No. 99; Dorminey et al., 2012).
Dorminey et al. (2012) developed a meta-model framework that incorporated
various models of fraud theory to expand the fraud triangle concept. Dorminey et al.
10
recommended using the meta-model for future research to examine “interactions among
constructs, mediation and moderation effects of controls, and better tools or approaches
to enhance detection procedures” (p. 576). In comparison to Dorminey et al.’s research,
Kassem and Higson (2012) proposed a new fraud triangle that incorporates components
of fraud models (i.e., M.I.C.E., the fraud triangle, the fraud scale, and the fraud diamond).
Kassem and Higson (2012) refuted the fraud triangle as a model for fraud detection
because the elements of pressure and rationalization are unobservable and other
important elements ignored (e.g., fraudster’s capabilities). Cohen, Ding, Lesage, and
Stolowy (2010) concurred that the fraud triangle is insufficient for fraud detection. By
examining fraud theory, causal relationships or predictive models may be established,
confirmed, or refuted to contribute to the accounting profession’s field of knowledge of
fraud risk assessments to increase the detection of financial statement fraud.
Attribution theory relates the performance of a future task to the causes of prior
successes or failures of the same task based upon internal and/or external attributes
(Jaffar, Haron, Iskandar, & Salleh, 2011). The auditors’ ability to conduct an effective
fraud risk assessment may vary based on internal attributes (i.e., professional skepticism
and fraud knowledge) and/or an external attribute (e.g., fraud risk assessment method).
Fathil and Schmidtke (2010) found that auditors who were moderately suspicious were
more accurate in fraud detection than auditors who were highly suspicious because highly
suspicious auditors overcompensated for their professional skepticism. Kassem and
Higson (2012) recommended that regulators provide more guidance to auditors on fraud
risk assessments and consider “putting the Certified Fraud Examiner (CFE) certificate as
a requirement to get the CPA examination/qualification” (p. 288). By examining
11
attribution theory, the relationships of fraud knowledge, professional skepticism, and
fraud risk assessment method may be better understood to contribute to the knowledge of
how the variables effect the fraud risk assessment performance.
Nature of the Study
The research study used a quantitative between-participants research design to
assess the effect of the presence of fraud risk and auditor certification while considering
professional skepticism on fraud risk assessment performance. The experiment was
conducted in the online environment using Qualtrics online survey software. The
population was U.S. CFEs and U.S. CPAs with a membership in the ACFE, AICPA,
and/or VSCPA. The participants (sample) were those who responded on a volunteer
basis. The ACFE and the AICPA organizations were selected to use as the population
because the ACFE is the largest anti-fraud organization worldwide and the AICPA is the
largest professional accounting association in the U.S. (Association of Certified Fraud
Examiners, 2014; “About the AICPA,” n.d., para. 1). The VSCPA was included in the
population as a representative of a state society of professional accountants. First, three
comparative groups (CFE, CFE/CPA, or CPA) were created by participant self-
identification from the random sample to measure auditor certification. Random
assignment was used to divide the auditor certification groups into comparative groups–
three groups analyzed high-fraud risk data and three groups analyzed low-fraud risk data.
External validity was strengthened from the use of random sampling and the use of
random assignment of participants to test the fraud risk variable.
The SEC database of U.S. publicly traded companies was used to randomly select
a corporation that reported an occurrence of financial statement fraud and restated its
12
financial statements during 2005–2014. Internal validity was strengthened by the use of
an actual set of fraudulent and restated financial statements for the fraud risk variable.
The assessment tool used for the professional skepticism control variable was the
validated Hurtt Professional Skepticism Scale (Hurtt, 2010), which is designed to
measure professional skepticism. The fraud risk assessment performance was measured
using an interval measurement Likert scale. The participants used four similar Likert-
type questions to assess fraud risk (Boone & Boone, 2012), including (a) likelihood of
fraud risk, (b) significance of fraud risks, (c) significance of anti-fraud controls in use,
and (d) likelihood of fraud. A fraud risk assessment composite score was calculated from
the answers to the questions by using MS Excel’s sum function. SPSS was used to
perform statistical data analysis using both a two-way analysis of variance (ANOVA) and
a two-way analysis of covariance (ANCOVA) to ascertain the effect of the independent
variables and the influence of the covariate on the dependent variable.
A quantitative research method was appropriate for this study in that the intent of
the study was to identify and evaluate the variables (i.e., the presence of fraud risk,
auditor certification, and professional skepticism) that influence an outcome (i.e., fraud
risk assessment performance) by developing and testing hypotheses. A between-subjects
experimental design was chosen in that participants were randomly assigned to one of
two conditions (i.e., high-fraud risk and low-fraud risk) to make inferences from the
research findings and achieve generalization. Moreover, a quantitative method provided
for the use of statistical data analysis to conclude causality as the variables was measured
using an interval scale to strengthen validity and reliability.
13
According to Park and Park (2016), a quantitative research method provides for
justification due to reliability and validity testing in a controlled environment, which is in
contrast to a qualitative research method that provides for discovery in natural conditions.
A quantitative study provides for recommendation(s) to research findings by using
structured data collection techniques coupled with statistical analyses compared to the
inconclusive research findings from unstructured or semi-structured data collection
techniques of a qualitative study (Park & Park, 2016). Barnham (2015) emphasized that
the key tenants of quantitative research include controlled conditions, large base sizes,
and the application of statistics to make inferences about the population, which is in
contrast to qualitative research that focuses on perceptions of how incidences occur,
which cannot be generalized to the population. Historically, qualitative studies have
received criticisms of validity and reliability (Barnham, 2015).
A qualitative research method was not appropriate for the research study in that
the variables of the design were identified prior to the collection of data, and data
collection was operationalized to relate the variables to the research questions and
hypotheses for hypothesis testing not hypothesis generation. Instrument-based questions
was utilized instead of open-ended questions as the intent was to provide for
generalizability using statistical interpretations not particularity using emergent
interpretations based on judgment.
Research Questions
The research questions examined the effect of the presence of fraud risk and the
effect of auditor certification while considering professional skepticism on fraud risk
assessment performance by answering the questions: (a) Does the presence of fraud risk
14
have an effect on fraud risk assessment performance? (b) Does a certification in fraud
knowledge have an effect on fraud risk assessment performance? (c) Does professional
skepticism influence fraud risk assessment performance? Gaps in current literature exist
regarding the impact of auditor certification and professional skepticism on fraud risk
assessment performance (Hammersley, 2011; Ray, 2015; Trompeter et al., 2013).
Hammersley (2011) stated that he was not aware of any research that examined “the
impact of auditor knowledge” (p. 111), and Trompeter et al. (2013) called for future
research on fraud training and testing, improvements to auditors’ professional skepticism,
and fraud detection methods (pp. 307-310). Ray (2015) provided examples
demonstrating that professional skepticism is a current challenge for auditors and a
significant concern for the PCAOB, especially after recent inspections of audits
conducted by registered public firms. Ray recommended further studies on the lack of
professional skepticism criticisms found by the regulators and the skeptical mindset of
auditors. The following research questions guided the study to examine the effects of the
presence of fraud risk and the effects of auditor certification while considering
professional skepticism on fraud risk assessment performance.
Q1. Does the presence of fraud risk have an effect on fraud risk assessment
performance?
Q2. Does a certification in fraud knowledge have an effect on fraud risk
assessment performance?
15
Q3. Does professional skepticism influence fraud risk assessment performance?
Hypotheses
H10. The presence of fraud risk does not have a significant effect on fraud risk
assessment performance.
H1a. A high level of fraud risk produces a high-fraud risk assessment
performance.
H20. A certification for fraud knowledge does not have a significant effect on
fraud risk assessment performance.
H2a. Auditors that possess a certification in fraud detection produce more
effective fraud risk assessment performance than auditors without the
certification.
H30. The level of auditor professional skepticism does not have a significant
influence on fraud risk assessment performance.
H3a. Auditors that exhibit professional skepticism produce more effective fraud
risk assessment performance than auditors without this attribute.
Significance of the Study
Financial statement fraud continues to be prevalent regardless of the regulations
imposed for prevention and detection. Based on ACFE’s 2014 Report to the Nations on
Occupational Fraud and Abuse, Verschoor (2014) stated, “fraud continues to be a
significant problem for companies around the world” (p. 11). Verschoor (2014) reported
that external audits were found to be the least effective fraud detection method, which
provides support for the need to assess auditors’ attributes in relation to fraud risk
assessments. Kravitz (2012) quantified the significance of audit failures for fraud
16
detection in excess of 1 trillion dollars, which is indicative that financial statement fraud
is a significant problem for the auditing profession. Boyle, Carpenter, and Hermanson
(2012) discussed the high occurrence of chief executive officers (CEOs) and chief
financial officers (CFOs) involved in financial statement frauds. Even though SOX
requires external auditors to be selected by audit committees, the CEOs and the CFOs
still have a significant influence on the selection of external auditors, which may diminish
auditor objectivity (Boyle et al., 2012). Hence, it is essential that auditors possess both
professional skepticism and fraud knowledge to make effective fraud risk assessments
(Trompeter et al., 2013).
Hurtt et al. (2013) stated that most research on fraud detection focuses on auditor
judgment instead of auditor actions, which is the focus of the PCAOB and the SEC.
Hurtt et al. (2013) claimed that “Academic research indicates that auditors do approach
an audit with the intention of being professionally skeptical and they respond to risk by
changing behaviors; however, the SEC and PCAOB have consistently found a lack of
professional skepticism” (p. 72). Thus, a gap exists between the researchers and the
regulators, which supports the need for future research to aid in the detection of financial
statement fraud. According to PCAOB (2015), the three key areas under review, due to
significant deficiencies found during auditor inspections, are as follows: auditing internal
control over financial reporting, assessing and responding to risks of material
misstatement, and auditing accounting estimates. The PCAOB findings provide support
for ascertaining the value of a CFE certification in comparison to a CPA certification.
Nix and Morgan (2013) encouraged future researchers to reexamine the value of the CFE
certification.
17
The research study targeted auditors, regulators, and academicians. The
participants were CPAs and/or CFEs who were randomly selected and assigned to the
comparative groups to strengthen external validity. An actual set of fraudulent and
restated financial statements were used to strengthen the internal validity of the fraud risk
assessment process. The findings from the research study enhanced the body of
knowledge of the influences of auditor attributes (i.e., certification and professional
skepticism) and the presence of fraud to the outcome of fraud risk assessments.
Definition of Key Terms
The following key terms are used throughout the paper. The definitions include
terms related to the research study that may not be commonly known or understood.
Understanding the key terms provided will offer readers a comprehensive understanding
of the research project.
Financial statement fraud. Financial statement fraud is the false representation
of financial information with knowledge from the presenter that the representation
is false, and there is a financial damage to people receiving the information
resulting from reliance on this information (George, 2012).
Fraud. Fraud is any act, expression, omission, or concealment designed to
deceive and disadvantage another party (Fraud, 2011).
Fraud risk assessment. A fraud risk assessment is the auditors’ judgment
process for assessing the likelihood of financial statement fraud (Kochetova-
Kozloski, Messier, & Eilifsen, 2011).
18
Fraud risk assessment method. The fraud risk assessment method is an audit
procedure or strategy used by auditors to perform fraud risk assessments (Knapp
& Knapp, 2001).
Fraud risk assessment performance. Fraud risk assessment performance is the
auditors’ ability or inability to detect financial statement fraud (Jaffar, Haron,
Iskandar, & Salleh, 2011).
Occupational fraud. Occupational fraud is the use of one’s occupation for
personal enrichment through the deliberate misuse or misapplication of an
organization’s resources or assets (Association of Certified Fraud Examiners,
2014).
Summary
This chapter provided an introduction to the quantitative research study and the
need for effective fraud risk assessments to detect financial statement fraud. Financial
statement fraud continues to negatively affect companies worldwide (Association of
Certified Fraud Examiners, 2014; Drew, 2014; Murphy & Dacin, 2011). Regulators have
sought to minimize financial statement fraud by requiring management and auditors to
conduct fraud risk assessments (Dorminey et al., 2012). The quantitative experimental
between-participants research design examined the influence of two independent
variables (e.g., the presence of fraud risk and auditor certification), while considering
professional skepticism, on the dependent variable, fraud risk assessment performance, to
add to the body of knowledge on auditors’ detection of financial statement fraud. Six
comparison groups – high-fraud risk with CFE; high-fraud risk with CFE and CPA; high-
fraud risk with CPA; low-fraud risk with CFE; low-fraud risk with CFE and CPA; low-
19
fraud risk with CPA – with participants from the population of the ACFE, AICPA, and
VSCPA memberships of certified fraud examiners and certified public accountants were
used to test the hypotheses. Fraud theory and attribution theory was the theoretical
framework used to guide the quantitative research study.
20
Chapter 2: Literature Review
A synthesis of extant literature on fraud and attribution theory was conducted to
find gaps in the current body of knowledge in relation to financial statement fraud. The
literature review was organized into the following categories: regulations, risk assessment
models, auditors’ attributes, and certified fraud examiners. Auditors are bound by
auditing standards when conducting audits; hence, the regulations influence auditors’
conduct (Reffett, 2010). Auditing standards prescribe that auditors must conduct fraud
risk assessments but allow for the performance of auditor judgment for the outcome
assessment (Love, 2012). Auditors’ attributes, specifically knowledge, skills, experience,
and characteristics, are elements used to make fraud risk assessment judgments
(Trompeter et al., 2013). The one characteristic emphasized by the accounting profession
and regulators for auditors to possess is professional skepticism (Ray, 2015). Certified
fraud examiners exhibit specialized knowledge in financial statement fraud detection and
prevention.
Northcentral University Library’s EBSCO database was used to locate the sources
within the literature review. Boolean searches, which combine words and phrases using
operators (i.e., AND, OR, NOT), were conducted (Radecki, 1982). The researcher
utilized various keywords, as deemed appropriate, due to the need to define and limit the
searches. Keywords utilized by the researcher included audit regulation, certified fraud
examiners, financial statement fraud, fraud risk assessment, fraud triangle, and
professional skepticism. The majority of literature mentioned throughout this study
comes from scholarly peer-reviewed journals. The utilization of peer-reviewed journal
articles was due to the need to have accurate and reliable data sources as these articles are
21
written and reviewed by experts in the field. A variety of refereed journals were used
from the areas of accounting, auditing, and ethics, such as Accounting Review, Auditing:
A Journal of Practice & Theory, CPA Journal, and Journal of Business Ethics. There
were a few common findings from the articles reviewed. First, financial statement fraud
is a significant problem even after regulations have been enacted for prevention and
detection. Second, auditors are not finding and/or reporting financial statement fraud
even though fraud risk assessments are performed. Third, the fraud triangle may not be
the most effective framework for financial statement fraud detection even though it is the
prescribed methodology by the auditing regulations (e.g., AU Section 316 and SAS No.
99). Fourth, auditors’ attributes have been found to have an influence on fraud risk
assessments; moreover, the attribute of professional skepticism is emphasized for the
performance of effective fraud risk assessments. Fifth, there is increased support for the
role of CFEs in the fraud risk assessment process.
Theoretical Framework
The theoretical framework used to examine the effect of the presence of fraud and
auditor certification, while considering professional skepticism on fraud risk assessment
performance were the fraud theory and attribution theory. Fraud theory is used by
researchers, the accounting profession, and auditing regulators to develop training and
tools for the detection and prevention of financial statement fraud (Boyle et al., 2015).
The fraud triangle serves as the foundation for numerous theories on fraudulent behavior
(Boyle et al., 2015). The fraud triangle was developed by Donald Cressey in the early
1950s to explain the criteria that must be present for fraud to occur, which includes
pressure, opportunity, and rationalization (Dorminey, Fleming, Kranacher, & Riley,
22
2012). Both the PCAOB and the Auditing Standards Board (ASB) integrate the fraud
triangle in the auditing standards for fraud risk assessment (i.e., AU Section 316 and SAS
No. 99; Dorminey et al., 2012).
Dorminey et al. (2012) developed a meta-model framework that incorporated
various models of fraud theory to expand the fraud triangle concept. Dorminey et al.
recommended using the meta-model for future research to examine “interactions among
constructs, mediation and moderation effects of controls, and better tools or approaches
to enhance detection procedures” (p. 576). In comparison to Dorminey et al.’s research,
Kassem and Higson (2012) proposed a new fraud triangle that incorporates components
of fraud models (i.e., M.I.C.E., the fraud triangle, the fraud scale, and the fraud diamond).
Kassem and Higson (2012) refuted the fraud triangle as a model for fraud detection
because the elements of pressure and rationalization are unobservable and other
important elements ignored (e.g., fraudster’s capabilities). Cohen, Ding, Lesage, and
Stolowy (2010) concurred that the fraud triangle is insufficient for fraud detection. By
examining fraud theory, causal relationships or predictive models may be established,
confirmed, or refuted to contribute to the accounting profession’s field of knowledge of
fraud risk assessments to increase the detection of financial statement fraud.
Attribution theory relates the performance of a future task to the causes of prior
successes or failures of the same task based upon internal and/or external attributes
(Jaffar, Haron, Iskandar, & Salleh, 2011). The auditors’ ability to conduct an effective
fraud risk assessment may vary based on internal attributes (i.e., professional skepticism
and fraud knowledge) and/or an external attribute (e.g., fraud risk assessment method).
Fathil and Schmidtke (2010) found that auditors who were moderately suspicious were
23
more accurate in fraud detection than auditors who were highly suspicious because highly
suspicious auditors overcompensated for their professional skepticism. Kassem and
Higson (2012) recommended that regulators provide more guidance to auditors on fraud
risk assessments and consider “putting the Certified Fraud Examiner (CFE) certificate as
a requirement to get the CPA examination/qualification” (p. 288). By examining
attribution theory, the relationships of fraud knowledge, professional skepticism, and
fraud risk assessment method may be better understood to contribute to the knowledge of
how the variables effect the fraud risk assessment performance.
The research question, “Does the presence of fraud risk have an effect on fraud
risk assessment performance,” and the related hypothesis, “A high level of fraud risk
produces a high-fraud risk assessment performance,” used the fraud theory as the selected
theoretical framework. Since the fraud triangle is the methodology required in current
practice for financial statement fraud risk assessments (Dorminey et al., 2012), fraud
theory was the applicable theory selected to strengthen internal validity. Attribution
theory was the theoretical framework used to answer the research questions, “Does a
certification in fraud knowledge have an effect on fraud risk assessment performance”
and “Does professional skepticism influence fraud risk assessment performance,” along
with the related hypotheses, “Auditors that possess a certification in fraud detection and
exhibit professional skepticism produce more effective fraud risk assessment
performance.” Since professional skepticism and fraud knowledge are internal attributes
(Jaffar et al., 2011), attribution theory was the applicable theory selected to examine the
relationship of the auditors’ attributes on fraud risk assessment performance.
24
Regulations
Auditors are required to follow the Statement on Auditing Standards No. 99 (SAS
No. 99) and Auditing Standard No. 3 (AS3) when conducting fraud risk assessments, as
well as to follow the AICPA Code of Professional Conduct. SAS No. 99 prescribes that
auditors use the fraud triangle to assess financial statement fraud during the planning
stages of an audit (Kassem & Higson, 2012). The fraud triangle examines fraud through
the elements of incentive/pressure, opportunity, and rationalization (Dorminey et al.,
2012). The incentives/pressures to commit financial statement fraud may be caused by
analysts’ expectations, compensation arrangements tied to earnings, debt covenant
requirements, and going-concern issues (Hogan, Rezaee, Riley, & Velury, 2008).
Opportunities for fraud are created by a lack of internal controls over financial reporting,
complex transactions, related party interactions, and ineffective corporate governance
(Hogan et al., 2008; Levy, 2015). Hogan et al. (2008) attributed precise accounting
standards for managers’ rationalization in managing earnings as auditors fail to require
adjustments when precise standards are used in contrast to standards that require
judgment. According to Dorminey et al. (2010), the fraud triangle elements are only
relevant to the accidental fraudster as the predator “requires no pressure and needs no
rationalization” (p. 21). Buchholz (2012) posited that there is “an abundance of corporate
scandals resulting from fraud without detection by the auditor” (p. 109). Buchholz
(2012) recommended that other methods, in addition to the fraud triangle, be utilized in
audit planning to detect financial statement fraud because the auditors become the
opportunity for fraud and the element of rationalization may not be present.
25
According to Hogan et al. (2008), audit firm size, auditor tenure, auditor industry
specialization and experience, time budget pressures, and supervisory style affect
auditors’ roles in fraud detection (p. 236). Hogan et al. (2008) called for further research
in the following areas, which include a) rationalization and attitude component of the
fraud triangle, b) new technology-based tools for fraud detection (e.g., data mining and
pattern-recognition software), c) high-risk areas of auditing fair value estimates, quarterly
financial information, and top-level journal entries, d) auditor communication with audit
committees, and e) mindset of the auditor versus forensic accountants (pp. 246-247).
Levy (2015) also emphasized the significance of professional skepticism and the
importance of the auditors’ responsibility to detect financial statement fraud during
financial statement audits; thus, identifying fraud risk to minimize fraudulent financial
reporting scandals must be a continued focus of the accounting profession.
Similarly, Soltani (2014) and Lokanan (2015) refuted the sole use of the fraud
triangle for fraud detection. Soltani conducted a comparative study of three American
(i.e., Enron, HealthSouth, andWorldCom) and three European (i.e., Parmalat, The Royal
Ahold, and Vivendi Debacle) corporate scandals using ethical climate (i.e., tone at the
top, bubble economy and market pressure, fraudulent financial reporting, accountability,
control, auditing, and governance) and the fraud perspectives of firm-specific
characteristics and environmental context as the theoretical framework. In contrast,
Lokanan (2015) used Fairclough’s critical discourse theory to challenge the validity of
the fraud triangle’s theoretical framework. Lokanan (2015) posited that fraud is a
complex phenomenon that cannot be restricted to only the three components of the fraud
triangle (e.g., incentive/pressure, opportunity, and rationalization).
26
Soltani (2014) used annual reports, regulatory reports, professional and academic
literature, and newspapers for the comparative study. Soltani (2014) found the following
similarities in the organizations: ineffective boards (e.g., insufficient oversight and lack
of independence), inefficient corporate governance and internal control, accounting
irregularities, failure of external auditors, dominant chief executive officers, inappropriate
financial reporting and accounting systems, and ineffective internal audits. The study
examined a variety of causes of corporate fraud including ethics, management behavior,
financial reporting and auditing, control mechanisms, tone at the top, management
incentives, corporate governance, and environmental factors. Soltani (2014) found that
the regulatory, environmental, and ethical climates of corporations “are rarely or not
sufficiently discussed in previous studies” (p. 271). Soltani (2014) recommended future
research to incorporate interviews with the fraudsters to record their perspectives on the
causes of the fraudulent activity.
Lokanan’s (2015) key audience was the AICPA and the ACFE because of their
promotion of the fraud triangle as the recommended framework for fraud detection.
Critical discourse analysis (CDA) was applied to the fraud triangle framework, which
provides that fraud is caused by individual behaviors (i.e., incentive/pressure,
opportunity, and rationalization). Lokanan (2015) used a case study design to conduct a
CDA on three levels (i.e., discourse practice, sociocultural practice, and text) for three
companies: Lehman Brothers, KPMG, and Walmart. Lokanan (2015) posited that fraud
is multifaceted and “consideration of the wider macro social and economic dimensions”
(p. 220) are critical in understanding the causes of fraud.
27
In response to Soltani’s (2014) call for researchers to conduct interviews with
fraudsters, Ferrell and Ferrell (2011) did an interview with Enron’s Chief Executive
Officer, Ken Lay. In May 2006, Ferrell and Ferrell (2011) interviewed Ken Lay after his
criminal conviction for making fraudulent statements about the financial condition of
Enron. Lay stated “he had relied on lawyers, accountants, and senior executives to keep
him informed of such issues of misconduct” (Ferrell & Ferrell, 2011, p. 211). Lay denied
responsibility for Enron’s demise and blamed the lack of internal controls and the lack of
risk management for the company’s failure (Ferrell & Ferrell, 2011, p. 218). Ferrell and
Ferrell’s (2011) interview supported Soltani’s (2014) finding on the importance of the
regulatory, environmental, and ethical climates of corporations.
Using the fraud triangle’s theoretical framework, Schuchter and Levis (2015) also
responded to Soltani’s (2014) recommendation to interview fraudsters. Schuchter and
Levis (2015) applied a qualitative research design to examine the perspectives of
convicted fraudsters from Austria and Switzerland on the causes of fraud. The construct
design, interviews with fraudsters, was “rare in the world of white-collar crime”
(Schuchter & Levis, 2015, p. 179). The period of the investigation was from 1990 to
2010 with interviews conducted in 2010. Twelve of the participants were interviewed
face-to-face and one participant was interviewed by telephone (11 males and 2 females)
using a semi-structured questionnaire with an emphasis on how the fraud occurred versus
why the fraud occurred. Even though the small sample size did not lend itself to “a
defensible universally applicable hypothesis” (Schuchter & Levis, 2015, p. 180) and
contained the risk of respondent bias, the results did not support the fraud triangle theory.
The participants refuted that all of the elements of the fraud triangle were required for
28
fraud to occur. Schuchter and Levis (2015) discovered that the elements of
pressure/incentive and rationalization were not required, but opportunity was required,
for fraud to occur. This finding by Schuchter and Levis (2015) supports Dorminey et al.
(2010) results in relation to predators and accidental fraudsters. Predators do not require
pressure/incentive or rationalization to commit fraud, only opportunity (Dorminey et al.,
2010). Schuchter and Levis (2015) deduced, from the participants’ perceptions that
opportunity triggered by high pressure within an organization provides for the occurrence
of fraudulent behavior.
In contrast to Soltani (2014) and Lokanan (2015), Morales, Gendron, and
Guénin-Paracini (2014) recommended the use of the fraud triangle for financial statement
fraud detection. Morales et al.’s (2014) recommendation for the use of the fraud triangle
was based on a documentary study of 64 articles on organizational fraud from a
genealogy of the fraud triangle. Morales et al. (2014) found recent articles that a)
explained and illustrated the fraud triangle to auditing and accounting professionals, b)
provided case studies for teaching future auditors or managers through the lens of the
fraud triangle, c) used the fraud triangle to elaborate new conceptual frameworks, and d)
posited that the elements of the fraud triangle can predict the presence of fraud (p. 184).
A key finding from Morales et al.’s (2014) literature study was that deviance is not
attributed to complex social factors, but to “failures in individual morality and
breakdowns in the organization’s endeavors to control probity” (p. 191). Hence, this
finding supports that organizations must be attentive to the opportunities and pressures
that exist to prevent the occurrence of fraud. Also, Morales et al. (2014) stated that
“technologies of organizational control and surveillance are influenced by moral
29
judgments about what is normal and what is unacceptable deviance” (p. 192). Morales et
al.’s (2014) point emphasized that the processes that organizations implement for fraud
prevention and detection are influenced by the judgments of the individuals developing
the processes; hence, the processes must be closely monitored by organizations. Thus,
according to Morales et al. (2014), the fraud triangle is an acceptable tool for fraud
prevention and detection since it encompasses both an individual’s character and an
organization’s internal control system.
Auditing standards do not specify a quantitative or qualitative approach to fraud
risk assessment. Piercey (2011) conducted a case study experiment to ascertain whether
the relationship of the methodology chosen by the auditor (quantitative versus
qualitative) influenced the fraud risk assessment. While Piercey (2011) did not find
support for the use of qualitative methodology for fraud risk assessments, Goel and
Gangolly (2012) did provide support for qualitative fraud risk assessment approaches.
Piercey (2011) selected auditors from large accounting firms and senior
accounting students to participate in the case study. The independent variables were
documentation requirements (yes or no) and response mode (qualitative, quantified, and
qualitative-elastic-redefinition) with a PCAOB inspector condition introduced for the
qualitative-elastic-redefinition condition to evaluate changes in risk assessments, and the
dependent variable was the probability of material misstatement. Analysis of covariance
(ANCOVA), analysis of variance (ANOVA), and contrast tests was used to analyze the
data. Piercey (2011) found that more lenient risk assessments occurred when qualitative
approaches were used; hence, further investigation was recommended because lenient
risk assessments lead to fewer audit tests and to the collection of less substantive
30
evidence (p. 243). Piercey (2011) measured only auditors’ perceptions of risk, but not
the planned audit work; additionally, the student participants did not have actual audit
experience (p. 244). Another limitation of the study was that fraud risk was measured
from audit phrases instead of a high-medium-low assessment scale, which is the
measurement used in current practice (p. 243). Piercey’s study created the need to
examine whether the requirement of quantitative fraud risk assessments would aid in
fraud detection. Goel and Gangolly (2012) conducted a study to assess the use of
qualitative content in annual reports instead of quantitative financial information to detect
financial statement fraud. Goel and Gangolly (2012) hypothesized that fraudulent
companies try to misrepresent information and employ different writing techniques in the
annual reports than the companies that do not commit fraud. The following six sub-
hypotheses were tested for increased likelihood of fraud in annual reports: 1) more
difficult to read and understand, 2) greater use of negative words, 3) greater use of
passive voice, 4) greater use of uncertainty markers, 5) greater use of adverbs, and 6)
greater use of formatting styles such as use of caps and use of punctuation. Goel and
Gangolly (2012) used an unmatched sample design to develop a dataset of 126 fraudulent
companies and 622 no-fraud companies from the Compustat, LexisNexis database, and
Wall Street Journal (WSJ) Index, as well as the Accounting and Auditing Enforcement
Releases (AAERs), which was issued by the SEC over the period 1993 to 2006. The
instrument used to examine the data was the companies’ Form 10-K filings. All
hypotheses were tested using a chi-square test of significance and Z-tests to measure
linguistic feature variations in the fraud and no-fraud reports. Goel and Gangolly (2012)
found that the following linguistic cues have been associated with fraudulent financial
31
statements: use of complex sentence structures, difficulty of reading and comprehension,
use of positive tone, use of passive voice, use of uncertainty markers, and use of adverbs
(p. 87). Goel and Gangolly’s (2012) results provide support for the use of qualitative
fraud risk assessment approaches to detect financial statement fraud by examining
writing and presentation styles in annual financial reports in contrast to numeric data,
which is the focus of quantitative fraud risk assessments.
Auditing standard, AS3, emphasizes the importance of proper documentation in
relation to auditors’ effectiveness (Hammersley et al., 2010). Hammersley, Bamber, and
Carpenter (2010) investigated the influence of specific fraud documentation and of
priming the auditor before the evidence evaluation for the fraud risk assessment in
response to auditing regulators’ concerns that auditors are not providing sufficient
documentation in fraud risk assessments. As specific documentation of audit findings
provides evidence that may be used in auditor lawsuits, Reffett (2010) conducted a study
to provide insight into the litigation risks for documented risk assessments. Hammersley
et al. (2010) found that specificity may reduce auditors’ professional skepticism while
Reffett found that auditors may intentionally produce less documentation due to the fear
of lawsuits.
Hammersley, Bamber, and Carpenter (2010) investigated the influence of specific
fraud documentation and of priming the auditor before the evidence evaluation for the
fraud risk assessment in response to auditing regulators’ concerns that auditors are not
providing sufficient documentation in fraud risk assessments. The theoretical framework
for the experiment was support theory, which examined components (e.g., fraud risks) to
assess the likelihood of an event (e.g., fraud). Hammersley et al. (2010) tested the
32
assertion that proper documentation strengthens auditors’ effectiveness by selecting 81
audit seniors from a Big 4 accounting firm of which 57.3 percent were CPAs with an
average of 45.9 months of experience to participate in a two-part experiment. Part one of
the experiment simulated the audit planning stage and part two of the experiment
simulated the audit evaluation stage. The research design was a 2X2 between-
participants design with documentation specificity and fraud risk priming as the
independent variables. Final fraud risk assessments, identification of remaining issues,
and requests of additional evidence were the dependent variables measured. The
documentation variable was manipulated by the use of a summary and a specific fraud
risk memo. Fraud risk priming was assessed by instructing one group of participants to
reconsider the documented fraud risks before evaluation, while the other group was not
instructed to reconsider the documented fraud risks before evaluation. The statistical
analyses used were multivariate analysis of covariates (MANCOVA) and ANCOVA.
Hammersley et al. (2010) found a) for the unprimed condition, documenting the specific
fraud risks in the planning phase increased fraud assessments and evidence requests, b)
for the primed condition, documenting in summary in the planning phase increased fraud
assessments, evidence requests, and issues identified, and c) for the primed condition,
documenting the specific fraud risks in the planning phase decreased fraud assessments,
evidence requests, and issues identified (pp. 549-550); hence, specificity does not always
positively affect auditors’ subsequent judgements. Hammersley et al.’s (2010) study
results support the positive influences of priming before evaluation, but lacks support for
the specific documentation of fraud risks as specificity may reduce auditors’ professional
skepticism.
33
Reffett (2010) used counterfactual reasoning theory to provide support that
auditors are held liable for failure to detect fraud when fraud was identified and
investigated, but not held liable when fraud was not identified and investigated. Reffett
(2010) conducted a between-participants and within-participants experiment with the
participants serving as jurors to evaluate auditors who failed to detect fraud in an audit.
The participants included 229 undergraduate students at two U.S. state universities from a
variety of non-business school courses. For the independent variable, audit procedures
used to investigate fraud, three conditions were tested: no investigation, low
investigation, and high investigation. The dependent variables measured were the
intensity of participants’ counterfactual thoughts and the evaluators’ assessments of
auditor liability for undetected fraud. Reffett (2010) performed independent samples t-
test, paired-samples t-test, planned comparisons of the independent variables, and Chi-
square statistical analyses to evaluate the data. Reffett (2010) found in the between-
participants experiment that the evaluators were “more likely to hold auditors liable for
failing to detect fraud when the auditors performed audit procedures to investigate for the
fraud relative to when the auditors did not investigate for the fraud” (p. 2163), which is
consistent with counterfactual theory. Additionally, the opposite effect occurred with the
within-participants experiment, which “demonstrates that evaluators understand that
higher levels of auditor investigation imply lower levels of auditor liability” (p. 2164).
Future research, according to Reffett (2010), is needed to ascertain if auditors’ fear of
lawsuits create more lenient fraud risk assessments and less specific documentation.
SOX was enacted in 2002 to minimize corporate fraud in the U.S. (Hulsart,
James, & Cummings, 2012). Alleyne and Elson (2013) used the Association of Certified
34
Fraud Examiners’ Report to the Nations for the period 1996-2008 to compare fraud under
the Securities Acts of 1933-1934 regulations to SOX regulations. The researchers
posited that “SOX is more effective in identifying, eliminating, and preventing corporate
fraud” (Alleyne & Elson, 2013, p. 104). However, Alleyne and Elson (2013)
acknowledged that the collection period of the data was limited and the frauds that were
reported to the Association of Certified Fraud Examiners were only those that were
examined throughout the study. Fraudulent financial statement fraud is the most costly
type of occupational fraud as “each scheme results in a median loss of $4.25 million”
(Alleyne & Elson, 2013, p. 94). Hence, future research is needed to expand the collection
period to a more recent period with a focus on auditors’ ability to detect fraudulent
financial statements.
Risk Assessment Models
Researchers, such as Dorminey, Fleming, Kranacher, and Riley (2012), are
continuously developing risk assessment models to improve the fraud risk assessment
process. Dorminey et al. (2012) introduced a meta-model framework and identified
likelihood and magnitude as the primary attributes for risk assessments. Similarly,
Abbasi et al. (2012) developed a metafraud framework using business intelligence. In
contrast, Srivastava et al. (2011) recommended two risk assessment models of which one
would be used to detect irregularities and errors and the other one would be used to assess
management fraud. The aforementioned models are significant to the fraud risk
assessment process as they introduce different methodologies that auditors may use to
produce more effective fraud risk assessments for financial statement fraud detection.
35
Dorminey, Fleming, Kranacher, and Riley (2010) agreed with Soltani (2014) and
Lokanan (2015) that the fraud triangle should not be the only model to assess fraud risk.
Dorminey et al. (2010) suggested the following models be considered in the fraud risk
assessment process: the triangle of fraud action (i.e., the act, concealment, and
conversion), the fraud diamond (i.e., pressure/incentive, opportunity, rationalization, and
capability), the fraud scale (i.e., opportunity, personal integrity, and pressure), and the
MICE (i.e., money, ideology, coercion, and ego) model. Boyle, DeZoort, and
Hermanson (2015) posited the fraud diamond to be more effective for fraud risk
assessments than the fraud triangle.
Dorminey, Fleming, Kranacher, and Riley (2012) introduced a meta-model
framework to provide insights into a fraud “risk assessment approach based on a current
understanding of the antecedents to fraud” (p. 574). The meta-model framework
incorporated not only the fraud triangle elements but also other personality and
behavioral characteristics from other fraud models, which were examined in relation to
the anti-fraud controls of prevention, deterrence, and detection to assess the probability of
fraud. Dorminey et al. (2012) identified likelihood and magnitude as the primary
attributes used by auditors to conduct risk assessments. Likelihood to commit fraud is
evaluated based on the company, industry, and organizational environment, and
magnitude is assessed in relation to the potential financial impact on the company’s
financial condition (Dorminey et al., 2012, p. 574).
In relation to Dorminey et al.’s (2010) recommendations to broaden the scope of
the fraud triangle to further improve fraud detection, Boyle et al. (2015) compared
auditors’ fraud risk assessments based on the use of the fraud triangle and the fraud
36
diamond to evaluate the effect of the fraud diamond’s capability element. Boyle et al.
conducted a 2X2 between-participants experiment that manipulated the fraud model
practice aids (fraud triangle versus fraud diamond) and the chief executive officer’s
(CEO) risk level (high-risk versus low-risk). The fraud risk assessment research
instrument was adapted from Wilks and Zimbelman and Norman et al. (as cited in Boyle
et al., 2012). The sample consisted of 89 auditors working in two Big 4 and five other
public accounting firms with 71% of the participants completing an online version and 29
percent completing a paper version of the fraud risk assessment research instrument,
which was developed in Qualtrics. The majority of the participants were staff and senior
auditors (only 46% had a CPA license) with less than three years of audit experience,
which limited generalizability. Fraud risk factors for the practice aids, developed from
SAS No. 99 and other fraud studies, for the two experimental conditions, were measured
using a scale ranging from 0 (no fraud risk) to 100 (very high-fraud risk). Additionally,
participants evaluated the overall financial statement fraud risk and confidence level for
the fraud risk assessment using a scale ranging from 0 to 100. Boyle et al. (2015)
controlled for auditors’ differences in professional skepticism by having the participants
complete the Hurtt Professional Skepticism Scale (2010). Statistical analyses were
conducted using an ANCOVA. Boyle et al. (2012) found that the fraud diamond model
produced significantly higher fraud risk assessments than the fraud triangle model and a
higher CEO risk resulted in the fraud diamond group participants identifying capability
items as fraud risk factors (p. 580). Moreover, Boyle et al. (2012) found that professional
skepticism had a significant positive relationship to the fraud risk assessment outcomes.
Boyle et al. (2012) stated that further research is needed to ascertain the “extent that trait
37
skepticism impacts hypothesis generation audit procedure choice, and fraud detection” (p.
592). Boyle et al. recommended the rationalization element of the fraud triangle model
be broadened to include capability items.
Similarly, Kassem and Higson (2012) agreed with Dorminey et al. (2010) on the
use of a variety of models for fraud risk assessment. Kassem and Higson (2012)
proposed a new fraud triangle that integrates all of the fraud models into one model –
motivation from the MICE model, opportunity from the fraud triangle, integrity from the
fraud scale, and fraudster’s capabilities from the fraud diamond (p. 194). The purpose of
Kassem and Higson’s new triangle is to increase auditors’ knowledge of fraud, which
was limited by the fraud triangle because pressure and rationalization are not observable
and the trait of capability is ignored. In contrast to Dorminey et al. (2012), Kassem and
Higson (2012), and Murphy and Dacin (2011) developed a fraud model that used the
fraud triangle framework.
Murphy and Dacin’s (2011) model identified three psychological pathways to
fraud: 1) lack of awareness, 2) intuition coupled with rationalization, and 3) reasoning for
conflicting intuitions. Murphy and Dacin’s (2011) model provides for a theoretical
framework to identify situational factors and methods used to reduce negative affect as
well as narrow the gap in the knowledge of rationalization. Murphy and Dacin (2011)
focused on the variations of rationalization when the elements of pressure and
opportunity were present. The fraud detection model illustrated four levels of behavioral
actions that result from the fraud decision, which include not committing fraud, unlikely
to commit fraud again, likely to continue committing fraud, and commit fraud while
upholding moral values. Murphy and Dacin (2011) posited that understanding
38
“rationalization is useful for predicting the likelihood of fraud … or for detecting it” (p.
613). The limitation of the framework is that it does not distinguish between different
types of fraud. Murphy and Dacin’s (2011) model may be a useful tool for auditors to
better understand the psychological aspects of fraudulent behavior.
Abbasi, Albrecht, Vance, and Hansen (2012) reported that the fraud detection rate
for U.S. firms is less than 70%. Hence, Abbasi et al. (2012) responded to the need for
improved detection tools by developing a metafraud framework that proved to
outperform existing models of financial fraud detection using business intelligence.
Abbasi et al. conducted five experiments to test six hypotheses using a sample of publicly
available quarterly and annual financial statements for the period 1985 to 2008. The SEC
Accounting and Auditing Enforcement Releases (AAERs) were used to identify the
fraudulent financial statements in the sample. Twelve financial ratios were used to derive
industry-level and organizational context features from the quarterly and annual data.
Abbasi et al. (2012) conducted paired t-tests and found a) the incorporation industry-level
and organizational context information improved performance, b) the combination of
quarterly and yearly information yielded the best results, c) the use of quarterly and
yearly context-based features resulted in the stack classifiers outperforming individual
classifiers, d) adaptive learning outperformed its static counterpart, e) a meta-learning
framework that included provisions for improving declarative and procedural bias
outperformed existing methods, and f) a meta-learning framework that included stacked
generalization and adaptive learning provides improved procedural bias over existing
ensemble-based semi-supervised learning methods.
39
Srivastava, Mock, and Gao (2011) concurred with Dorminey et al. (2010) that the
use of a single audit risk model is ineffective. Srivastava et al. (2011) applied Dempster-
Shafer theory to fraud risk assessment and developed a tool “to assess the belief and
plausibility that management has committed financial statement fraud based on
assessments of three ‘fraud triangle’ factors” (pp. 284-285). The revised Dempster-
Shafer differs from the prior model posited by Srivastava et al. (2011), because it
assumes no interrelationships between the fraud triangle factors (incentives, attitude, and
opportunity). Srivastava et al. (2011) argued that probability theory is ineffective in
assessing audit evidence because it does not provide for purely positive or purely
negative evidence as probability theory evidence is always mixed (p. 283). Probability
theory assesses the probability of material misstatement in contrast to the measurement of
the belief and plausibility of misstatement, which are the measures of the Dempster-
Shafer theory (Srivastava et al., 2011). Hence, Srivastava et al. (2011) suggested the use
of two risk assessment models in which one detects irregularities and errors and the other
one assesses management fraud.
Another methodology used to evaluate management fraud is to examine an
organization’s culture, which includes managers’ attributes. Shadnam and Lawrence
(2011) and Campbell and Göritz (2014) examined organizational culture as an element
for fraud risk assessments. Cohen, Ding, Lesage, and Stolowy (2010) combined the
fraud triangle and the theory of planned behavior to examine the personality traits of
managers in relation to unethical behaviors.
Shadnam and Lawrence (2011) used the institutional theory of moral collapse to
link individual morality and institutional behavior. The institutional theory of moral
40
collapse focuses on the interrelationships of individuals, within an organization, with
emphasis on the effect of moral understandings that govern behaviors through the upward
and downward flows of ideology and regulation (Shadnam & Lawrence, 2011).
Shadnam and Lawrence argued that moral collapse is attributable to the breakdown in the
connections among moral communities, organizations, and individuals, and that it is more
common in organizations with conditions that include a lack of leader commitment to the
communication of ideology, high employee turnover, immoral structures and practices,
and accusations of individual misconduct (p. 394). Shadnam and Lawrence’s (2011)
arguments identify fraud risks for auditors to consider when conducting fraud risk
assessments.
Campbell and Göritz (2014) conducted a qualitative research study on the
influence of organizational culture on individual behavior using content analysis to
analyze semi-structured interviews with 14 independent experts who had experience with
corrupt organizations. The experts were primarily German and “former CEOs of corrupt
organizations, ombudsmen, police officers, and investigative journalists” (Campbell &
Göritz, 2014, p. 293). Campbell and Göritz (2014) related the incentive/pressure element
of the fraud triangle to manager behavior and the rationalization element of the fraud
triangle to employee behavior in unethical organizations. Campbell and Göritz (2014)
found that corrupt organizations shared the belief that “the end justifies the means,”
valued job and organizational security, and punished non-corrupt behavior (p. 304).
Campbell and Göritz (2014) also found a difference in the endorsement of values by
managers and employees; managers endorsed high performance values while employees
emphasized security and team spirit values (pp. 305-306). The generalization of the
41
study results were limited as the study focused only on a biased German view of corrupt
organizational cultures with interviewees’ responses based on experiences and
knowledge (Campbell & Göritz, 2014).
Cohen et al. (2010) conducted a literature review of 39 U.S. corporate frauds
during 1992-2005. A content analysis was applied to press articles to examine the
personality traits of managers in relation to the fraud triangle theory and the theory of
planned behavior. The theory of planned behavior postulates that behavioral intentions
can be predicted from a) attitudes toward the behavior, b) subjective norms, and c)
perceived behavioral control (Cohen et al., 2010, p. 274). Cohen et al. (2010) found a
direct correlation between managers’ psychological traits and fraud. Thus, Cohen et al.
(2010) posited the following attributes as fraud-risk factors for assessing managers’
behaviors: high living standard, tyrannical or autocratic-type personality, praised in press
articles, and benefited from a dominant position (p. 287). Cohen et al. posited that
auditors should better integrate the attitudes/rationalization component of the fraud
triangle in relation to managers and the organizational culture when conducting fraud risk
assessments. Limitations of the study included the use of non-scholarly sources, press
articles, and the inherent risk of assessing personality and ethics of individuals (Cohen et
al., 2010).
Research indicates that improvements are needed in auditors’ approaches to fraud
risk assessments to improve auditors’ testing plans to detect financial statement fraud.
The PCAOB has endorsed the use of nonfinancial measures to improve financial
statement fraud detection (Brazel, Jones, & Prawitt, 2014). Brazel et al. (2014)
conducted an experiment to assess auditors’ reactions to inconsistent financial and
42
nonfinancial data in conjunction with a decision prompt during risk assessments. Even
though the PCAOB endorses nonfinancial measures for fraud detection, Brazel et al.
(2014) did not find support for the use of nonfinancial measures. Favere-Marchesi
(2013) investigated another approach to fraud detection and found support for the
decomposition of fraud risk factors in contrast to the categorization of fraud risk factors.
Boritz and Timoshenko (2014) posited that customized fraud checklists may provide for
more effective fraud risk assessments. Trotman and Wright (2012) provided support for
the importance of triangulation of audit evidence and professional skepticism for
effective fraud risk assessments. Similarly, Schmidt (2014) conducted an experiment to
examine the impact of auditors’ mental representations on the auditors’ judgment. Wei et
al. (2015) evaluated sequential unpacking versus simultaneous unpacking of fraud
findings before making fraud risk assessments and found that that even though sequential
unpacking had a positive effect on fraud identification, it reduced the effectiveness of
fraud risk assessments, which implied a decrease in professional skepticism.
Brazel et al. (2014) operationalized the constructs by conducting two between-
participants’ experiments and a within-participants’ manipulation (i.e., decision prompt)
to measure the effects on the auditors’ expectation of fraud. The participants for both
experiments were senior auditors of which 39 and 71 completed experiment 1 and
experiment 2, respectively. Case studies were given to the participants to evaluate
consistent and inconsistent nonfinancial measures of sales growth. The independent
variable manipulated for experiment 1 was the condition of the nonfinancial measures in
relation to sales growth (i.e., consistent versus inconsistent) to determine the participants’
expectation of the sales account. Experiment 2 used a between-participants design to
43
manipulate fraud risk (i.e., high versus low) and a within-in participants design to assess
a pre- and post-prompt expectation of sales. Repeated measures ANOVAs were used for
the statistical analysis of the data collected. Brazel et al. (2014) found that “auditors are
not likely to react to inconsistencies between financial and nonfinancial measures”… and
“a prompt can cause auditors to react to an inconsistency, but the effect of the prompt is
more pronounced when fraud risk is high” (p. 149). Hence, the auditors only used the
nonfinancial data if they were prompted and if the fraud risk was high to examine the
inconsistencies between the nonfinancial data and the financial data.
SAS No. 99 does not require decomposition of the fraud risk factors into the fraud
triangle components of incentive, opportunity, and attitude, but suggests the classification
of the fraud risk factors into the fraud triangle components (Favere-Marchesi, 2013, p.
203). Favere-Marchesi (2013) conducted a 2X2 factorial between-participants
experiment on the effects of fraud judgment decomposition versus fraud-risk factor
categorization using the case study method. The assessment method (i.e., decomposition
versus categorization) and the risk level (i.e., high versus low) were the independent
variables manipulated to evaluate fraud risk. The decomposition group assessed risks
while the categorization group classified risks for attitude, opportunity, and incentive.
The participants consisted of 60 managers, selected by the firms’ partners, from two large
accounting firms in offices throughout Canada and the United States. The case study
simulated the audit managers’ planning phase of the audit for assessing fraud risk with
the inference that management’s attitude was indicative of low-fraud risk. The
decomposition group assessed risks for attitude, opportunity, and incentive, and then
made an overall fraud risk assessment based upon the separate evaluation of the fraud
44
risks components. In contrast, the categorization group classified risks for attitude,
opportunity, and incentive, and then made an overall fraud risk assessment based upon
the categorized fraud risks without making separate component assessments. The fraud
risk assessments were made using a scale from 1 (low) to 10 (high). Various ANOVAs
and univariate tests were used to statistically analyze the data. Favere-Marchesi (2013)
found “auditors who decompose fraud assessments make overall and component fraud-
risk assessments that are more appropriate in response to changes in opportunity and
incentive cues than auditors who only categorize fraud-risk factors” (p. 216).
Auditing standards do not require auditors to use standardized checklists for fraud
risk assessments. Boritz and Timoshenko (2014) conducted a literature review and
posited that customized fraud checklists may increase the effectiveness of fraud risk
assessments. The study design classified checklists at two levels: generic versus
customized and procedural versus judgmental. Boritz and Timoshenko identified “nature
of the task, checklist design, checklist application, and contextual factors” (pp. C4-C7) as
the factors influencing effectiveness for fraud risk assessments checklists. Checklist
design recommendations posited by Boritz and Timoshenko included:
• Focus on items classified as “low risk” to encourage strategic reasoning;
• Customize to the client, client’s industry, and audit team staff mix;
• Include and test red flags between financial and nonfinancial measures;
• Categorize cues into categories (e.g., fraud triangle elements) with
deliberative rather than intuitive cue processing to improve judgments; and
• Consider contextual factors such as auditor experience, performance
pressures, and legal considerations (pp. C15-C16).
45
The auditing profession may want to consider Boritz and Timoshenko’s recommended
framework to provide a tool for conducting more effective fraud risk assessments. A
customized checklist, which considers the client’s business and the fraud risk assessment
factors, would strengthen the standardization of fraud risk assessments and minimize the
reliance on auditors’ judgments for fraud risk assessments.
Auditors must exhibit professional skepticism as “some members of management
may even seek to conceal outright fraud by strategically altering information they expect
the auditor will obtain as evidence” (Bell, Peecher, & Solomon, as cited in Trotman &
Wright, 2012, p. 41). Trotman and Wright (2012) conducted a 2X2X2 between-
participants experiment to ascertain whether external evidence alters fraud risk
assessments as external evidence is more difficult for management to manipulate. The
sources of evidence examined in the experiment were from external sources (EBS),
management information systems (MII), and management business representations
(MBR). A sample of 124 auditors, with an average of 37 months of audit experience,
who attended a national training class of a Big 4 auditing firm, were the participants
involved in this study. Case study materials were given to the participants that described
the client, which included current information on its competitive position, governance
environment and its financial condition. The accounting fraud that was present in the
case study was the inflation of sales revenues by management. The three independent
variables, EBS, MII, and MBR, were manipulated with the condition of either high or
low-fraud risk. The outcome variable was the probability of fraud that was measured by
the participants’ assignment of probabilities to seven potential causes for the higher-than-
expected sales figure in the case study and by the performance of risk assessments on the
46
accounts of sales, cost of goods sold, and selling and administrative expenses. The risk
assessments were evaluated on a continuous scale ranging from 1% (low risk) to 100%
(high risk). The data was evaluated using ANOVA tests. Trotman and Wright found
when MBR and MII evidence was inconsistent unfavorable EBS compared to favorable
EBS resulted in a significant increase in the likelihood for fraud; however, if MBR and
MII were consistent, EBS evidence was limited (pp. 51-52). The key insight from the
study is “if management has committed a fraud and has been strategic enough to alter
evidence that is generally under their control, audit quality would benefit by making use
of external evidence outside management’s control” (Trotman & Wright, 2012, p. 52).
The key limitations of the study include choosing only one type of MBR, MII, and EBS
evidence, as well as not having a measure for auditors’ prior beliefs (Trotman & Wright,
2012). Trotman and Wright’s (2012) study provided support for professional skepticism
and triangulation of audit evidence in fraud risk assessments.
Schmidt (2014) used a 2X1 between-participant design that manipulated retrieval
strategy prior to the fraud risk assessments to examine the impact of auditors’ mental
representations of the clients’ control environment on the auditors’ judgment in fraud
assessments and reliance on management’s explanations. The experimental case study
was adopted from Agoglia (1999) and recruited 156 auditors (91 senior auditors from a
Big 4 firm and 65 practicing auditors attending an academic program at a large
university) to act as auditors in a hypothetical company’s preliminary audit planning
stage. The participants received information on the control environment and after 15
minutes, the subjects were not allowed to reexamine the information. The participants
had to recall the positive and negative “tone at the top” evidence, assess the control
47
environment, react to management’s explanation for discrepancy found from analytical
procedures, and complete a fraud risk assessment. Schmidt (2014) used ANOVA and
ANCOVA statistical analyses to analyze the data and found that the structure of a control
environment decision aid influenced the mental representation of “tone at the top”, and
favorable mental representations resulted in favorable assessments and greater reliance on
management’s explanations (p. 73). The study limitations included the use of exactly 50
items for the evidence, the results were based on a single case with one set of evidence
items, and the requirement of participants to recall evidence was abstract (Schmidt, 2014,
p. 91).
SAS No. 99 requires auditors to conduct team-brainstorming sessions to discuss
the potential for fraud during the planning stages of financial statement audits (Wei,
Khalifa, & Trotman, 2015). Wei et al. examined the impact of individual auditor
brainstorming prior to audit team brainstorming on fraud identification. Wei et al. used
support theory as the theoretical framework to investigate the effects of brainstorming on
auditors’ performance when the potential for fraud exists. Support theory “proposes that
alternative descriptions of the same event will produce different judgments” (Wei et al.,
2015, p. 5). Wei et al. (2015) used a 2X1 between-participants design to manipulate the
brainstorming task for the conditions of simultaneously unpacking and sequentially
unpacking. The dependent variables of the study were a) the quantity and quality of the
potential frauds found in the brainstorming session, b) the distribution of the potential
frauds found across categories, and c) the level of auditors’ fraud risk assessments (Wei
et al., 2015, p. 4). The participants consisted of 38 auditors from a Big 4 audit firm in
Australia with an average of 4.83 years of audit experience; random assignment was used
48
to appoint the participants to one of the two conditions. The research instrument was an
abbreviated international case study used by a Big 4 firm for training auditors on how to
document audit workpapers, including the documentation of fraud risk. Both groups
were instructed to document the potential frauds relating to categories of revenue
recognition, receivables, inventory, noncurrent assets, and management estimates in the
case study; the simultaneous unpacking treatment group listed the potential fraud findings
in any order while the sequential unpacking treatment group listed the potential fraud
findings by category. The participants made a fraud risk assessment using an 11-point
scale ranging from 0 (Extremely Unlikely) to 11 (Extremely Likely). Then the
participants were given two potential frauds (e.g., revenue recognition category and
management estimate category) identified by the management team. The participants had
to list additional potential frauds, excluding the potential frauds listed in phase one of the
experiment. Statistical analyses were conducted using ANCOVA with audit experience
as the covariate. Even though fraud experience for the participants was not measured, the
research findings provide evidence of how the use of different methodologies for fraud
detection may influence auditor behavior. Wei et al. (2015) found the sequential
unpacking approach had a positive effect on potential fraud identification in relation to
the quality and quantity of potential frauds found and the distribution of potential frauds
across categories, but it reduced auditors’ fraud risk assessments. Wei et al. posited that
lower fraud risk assessments may imply lower levels of professional skepticism, which is
a disadvantage to the use of the sequential unpacking methodology at the individual level
(p. 19).
49
Auditors’ Attributes
In addition to fraud risk assessment models, auditor attributes also influence fraud
risk assessments (Fathil & Schmidtke, 2010; Hammersley et al., 2011; Jafar et al., 2011;
Knapp & Knapp, 2001; Rose et al., 2012). Limited research has been conducted to
ascertain the influence of auditors’ characteristics, professional experience, knowledge,
and skills on fraud risk assessments. Fathil and Schmidtke (2010) found positive
correlations of auditor attributes and fraud detection while Jaffar et al. (2011) found no
correlation between auditor personality traits and fraud risk assessment. Hammersley et
al. (2011) provided support for fraud training and experience while Knapp and Knapp
(2001) provided support for audit experience and explicit fraud risk assessment
instructions for effective fraud risk assessments. However, Rose et al. (2012) did not find
support for audit experience but found support for the use of explicit fraud risk
assessment instructions for effective fraud detection.
Fathil and Schmidtke (2010) reported that the relationship between individual
differences and the ability to detect fraud has not been empirically explored. Even
though the pilot study of 25 professional accountants conducted by Fathil and Schmidtke
had limited statistical power and used self-reporting as a measurement device to examine
the auditor attributes of conscientiousness, suspiciousness, integrity, and auditing
knowledge, it provided the support for further study because relationships between
attributes and fraud detection were found. Fathil and Schmidtke (2010) used the theory
of deception to develop a four-stage model for deception detection that integrated the
auditor attributes. The participants had to issue an audit opinion on a financial statement
simulation that contained fraudulent financial information and complete a questionnaire
50
to measure conscientiousness, suspiciousness, and integrity, and auditing knowledge.
Conscientiousness was measured using 12 items from the NEO Personality Inventory-
Five-Factor Inventory, suspiciousness was measured on a paranoia scale with questions
from the Minnesota Multiphasic Personality Inventory, integrity was measured using
eight items from the London House PSI standardized pre-employment integrity test, and
auditing knowledge was measured by the participants’ self-reported auditing grades and
years of accounting experience. Fathil and Schmidtke performed correlation analyses on
the data and found the following:
• Conscientiousness and auditing grades were positively correlated;
• Conscientiousness may be indirectly related to fraud detection from auditing
knowledge;
• Punitiveness, integrity factor, was positively related to fraud detection;
• Moderately suspicious participants were the most accurate in fraud detection;
• Highly suspicious participants overcompensated for suspiciousness resulting
in inaccurate financial statement opinions; and
• Professional accounting experience and fraud detection were not related (pp.
170-171).
One key limitation of Fathil and Schmidtke’s study was the selection of participants with
only professional accounting experience, instead of fraud detection experience. Fathil
and Schmidtke recommended future research to “examine the relation between auditing,
fraud detection and general accounting experience with the ability to detect fraud” and
“whether personality factors influence individuals’ assessment of audit risk” (p. 171).
51
In contrast, Jaffar, Haron, Iskandar, and Salleh (2011) examined personality traits
in relation to fraud assessment and detection in Malaysian audit firms and found no
significant relationship between the personality traits and the auditors’ ability to assess
fraud risk or to detect the likelihood of fraud. The five personality traits tested by Jaffar
et al. included neuroticism, extraversion, conscientiousness, openness to experience, and
agreeableness. Jaffar et al. used attribution theory to examine the effects of fraud risk
assessment on the ability to detect fraud by sending case material and personality
questionnaires to audit partners and managers in 1370 firms in Malaysia. Jaffar et al.
used a 2X2 within-participant factorial experimental design with two levels for fraud risk
assessment (correct versus incorrect) and two levels for the dimension of each personality
factor (high versus low). Goldberg 50 Big-five Factors Makers instrument was used to
measure the results of the personality test for the moderating variables (i.e., neuroticism,
extraversion, conscientiousness, openness to experience, and agreeableness). The
independent variable, ability to assess fraud risk, was measured by a seven-point Likert
scale, which ranged from 1 (Extremely Low) to 7 (Extremely High). The dependent
variable, which was the ability to detect the likelihood of fraud, was measured by a
seven-point Likert scale, which ranged from 1 (Extremely Low) to 7 (Extremely High).
As Jaffer et al. (2011) did not find support for a relationship between the variables, future
research is needed because regulators do assume that a positive relationship exists
between the ability to assess fraud risks and the ability to detect the likelihood of fraud.
As summarized by Hammersley (2011), auditors’ ability to assess fraud risk and
detect the likelihood for fraud is a current topic in auditing literature. Hammersley
(2011) developed a model for fraud risk assessment that incorporated auditor
52
characteristics (i.e., experience, knowledge, ability, and epistemic motivation) and mental
representation development. Hammersley (2011) “expects auditors with sufficient
knowledge gained from ability, experience, and epistemic motivation to be more likely to
detect the presence of fraud risk factors and respond to those risks effectively” (p. 104).
Hammersley’s study supports the importance of fraud training and experience to acquire
the knowledge needed to make accurate fraud risk assessments, which leads to fraud
detection. However, Stephens (2011) found a negative relationship between auditor
tenure and the likelihood of fraud detection in relation to internal control disclosures.
Stephens selected a sample of companies (519) from SEC filings and Audit Analytics
database disclosing material weaknesses from November 15, 2004 through May 30, 2005
of which 147 disclosed control problems and 372 did not disclose control problems.
Stephens (2011) used descriptive statistics, univariate, and logit regressions to analyze
the data. Stephens provided support for auditor tenure to be examined in relation to the
attributes of experience, knowledge, ability, and epistemic motivation in understanding
the influential factors of effective fraud risk assessments.
Knapp and Knapp (2001) examined the effects of audit experience and explicit
fraud risk assessment instructions on the effectiveness of using analytical procedures to
detect financial statement fraud. Knapp and Knapp used a 2X2X2 between-participants
research design of which experience levels (i.e., manager versus senior), financial
statement fraud (i.e., presence versus absence), and explicit fraud risk assessment
instructions (i.e., presence versus absence) were the independent variables manipulated.
The dependent variable, participants’ risk assessment of the presence of fraud in the
financial statements, was measured by a zero-to-ten point scale, with zero being most
53
unlikely and ten being most likely for the presence of fraud. The experimental materials
used in the study were fraudulent financial statements issued by public companies and the
subsequent restated financial statements of the same companies. The experiment
consisted of 119 participants from six different international accounting firms. Fifty-
seven of the participants were audit managers and 62 were senior auditors. To assess the
role of experience, the auditors applied analytical procedures to fraudulent financial
statements and restated financial statements of actual companies. To assess the
effectiveness of fraud risk assessment, some participants received instructions and some
did not. The data was analyzed using ANOVA tests. The results supported Knapp and
Knapp’s (2001) hypotheses that audit managers are more effective than audit seniors in
assessing fraud, and that fraud risk assessment instructions resulted in effective
assessments of fraud; hence, knowledge differences relative to the experience level of
auditors were found to affect fraud risk assessment (p. 35).
In contrast, Rose, McKay, Norman, and Rose (2012) found that when novice
auditors used checklist decision aids, which are designed to represent expert knowledge
structures, without instruction or explanatory feedback, that similar decisions to experts
were made (p. 24). Even though Rose et al.’s (2012) experimental study was limited by
not having an experimental group of experts for comparison, it provided insight into the
effect of new design models versus auditor experience on audit risk assessment
effectiveness. Rose et al.’s laboratory experiments used a 2X2 between-participants
design, which manipulated checklist organization (SAS No. 99 fraud triangle framework
versus an aggregate expert knowledge structure) and the learning requirement
(instructions present versus instructions absent). The dependent variables were decision
54
performance (fraud risk assessment accuracy) and the degree to which the participants’
knowledge matched experts’ knowledge. Experiment one used a sample of 115 senior
accounting students while experiment two used a sample of 79 master of accounting
students who took a pre- and post-knowledge test to verify the significance of the
decision aid on the experiment. The participants used the decision aid to assess fraud risk
for three cases and received outcome feedback before completing a concept pair-rating
task to evaluate the red flags in the decision aid. Pathfinder Network Scaling analysis
was used to compare the participants’ knowledge structure with an expert knowledge
structure. Descriptive statistics and ANOVA models were used to evaluate the data.
Rose et al.’s (2012) study provides support for regulators to examine the fraud risk
assessment framework to enhance the knowledge base for fraud detection.
Auditing standards emphasize the need for auditors to exhibit professional
skepticism during financial statement audits. Beasley et al. (as cited in Carpenter,
Durtschi, & Gaynor, 2011) reported that approximately 60 % of SEC “enforcement
actions against auditors between 1987 and 1997 were directly related to the failure of
auditors’ professional skepticism” (p. 2). The PCAOB cited “the lack of professional
skepticism as a serious problem in auditors’ fraud investigations” (Carpenter & Reimers,
2013, p. 46). Carpenter and Reimers (2013) and Bowlin, Hobson, and Piercey (2015)
provided support for the importance of professional skepticism in achieving high-quality
audits. Hurtt, Eining, and Plumlee et al. (2008) found that professional skepticism caused
auditors to behave differently but “the behavioral differences do not always go in the
direction of higher skepticism being associated with more skeptical behavior” (p. 25).
Rasso (2015) found that abstraction outperformed specificity in relation to achieving a
55
higher-level of professional skepticism when evaluating audit evidence. As different
perspectives of professional skepticism exist, Lee, Welker, and Wang (2013) found that
presumptive trust is more prevalent than presumptive doubt in fraud risk assessments,
while Quadackers, Groot, and Wright (2014) found presumptive doubt to be more
predictive of auditors’ skeptical judgments in high-risk environments. Peytcheva (2014)
provided support for professional skepticism as a personal trait, while Glover and Prawitt
(2014) posited that professional skepticism is influenced by the interrelationship of
structural levels. Ho, Kwock, and James (2015) studied the influence of Chinese culture
on professional skepticism and found a correlation between the cultural beliefs and
behaviors and professional skepticism. Carpenter, Durtschi, and Gaynor (2011)
examined the influence of a forensic accounting course on professional skepticism levels
and found that the course had a positive impact on fraud risk assessment performance.
Carpenter and Reimers (2013) conducted a research experiment to examine the
influence of audit partners’ professional skepticism on fraud risk assessments conducted
by the firms’ auditors. Using only two levels of partners’ professional skepticism
emphasis and one case study, Carpenter and Reimers (2013) found that the firms with
higher professional skepticism resulted in higher risk assessments in cases of both strong
and weak indicators (p. 66). Carpenter and Reimers used a 2X2 between-subjects
research design to manipulate partner emphasis on professional skepticism (high or low)
and the level of fraud indicators (strong or weak) to test fraud risk factors, fraud risk
assessments, and audit procedures for nine hypotheses. The participants in the
experiment consisted of 80 audit managers from Big 4 firms with an average of 8 years of
experience. An actual SEC fraud case using a company’s original financial statements
56
with strong fraud indicators and the same company’s restated financial statements with
weak fraud indicators was the case material utilized in the experiment. The participants
used the case material to assess fraud risk in addition to completing a professional
skepticism questionnaire. Professional skepticism was measured using Hurtt’s (2010)
30-item professional skepticism scale (Hurtt Professional Skepticism Scale). The
statistical analyses used to evaluate the findings were ANOVA and MANOVA.
Carpenter and Reimers’ (2013) findings support the call for auditors to exhibit
professional skepticism when assessing fraud risks.
In addition to the emphasis on maintaining professional skepticism in financial
statement audits, auditor rotation is evaluated as an attribute influencing audit quality.
The SEC requires rotation of audit partners, but not the rotation of audit firms as required
by the European Union (Bowlin, Hobson, & Piercey, 2015). Opponents of audit firm
rotation believe that reducing audit tenure reduces audit quality; however, the PCAOB
posits “that existing rotation requirements in the U.S. are insufficient and that firm
rotation requirements will enhance audit quality and professional skepticism” (Bowlin et
al., 2015, p. 1364). Using support theory as the theoretical framework, Bowlin et al.
conducted an experiment using a 2X2X2 between-participants design to examine the
effects of auditor rotation, professional skepticism, and interactions with managers on
audit quality. The independent variables manipulated to assess the outcome of audit
quality were auditor rotation (e.g., rotation versus no rotation), assessment frame (e.g.,
honesty assessment frame versus dishonesty assessment frame), and availability of
unstructured chat (e.g., chat versus no chat). The participants included 226
undergraduate students from a large university with minimal work experience (74 percent
57
sophomore standing, and 82 percent business students of which 48 percent were
accounting students). Two experimental groups were used (e.g., auditors and managers),
with random assignment of the participants to the groups. The research design was
operationalized as a strategic game where the auditor and manager made decisions.
Auditors chose either high- or low-effort audit while the managers chose either
aggressive or conservative reporting, which led to four possible outcomes. The honesty
and dishonesty probability evaluation of the managers’ representations was measured
using a scale from 0 to 100. The auditor’s highest payoff occurred with the interaction of
low-effort audit and conservative reporting, and the auditor’s lowest payoff occurred with
the interaction of low-effort audit and aggressive reporting. The data was analyzed using
ANOVA and pairwise contrasts. Bowlin et al. (2015) found that when auditors’
judgments were focused on managers’ honesty that auditor rotations increased audit
quality, but when auditor judgments’ were focused on managers’ dishonesty that auditor
rotations decreased audit quality (p. 1388). The aforementioned finding, noted by
Bowlin et al. (2015), provides evidence that audit firm rotation may not provide an
increase in audit quality and professional skepticism as “the benefits of professional
skepticism could be offset under mandatory auditor rotation” (Bowlin et al., 2015, p.
1388). Additionally, Bowlin et al. found that when the auditors interacted informally
with the managers that the assessment of management representations worsened and low-
effort audits were more frequent (p. 1388). Bowlin et al.’s study reinforces the
importance of professional skepticism in achieving high-quality audits.
Hurtt, Eining, and Plumlee (2008) conducted an experimental audit workpaper
review to assess the impact of auditors’ professional skepticism on two behaviors:
58
evidence assessment and generation of alternative explanations. The experimental task
used was a “simulated audit workpaper review adapted from Moeckel” (Hurtt et al.,
2008, p. 13). Eighty-three auditors from a major international accounting firm
participated in the online between-participants research experiment. Half of the
participants performed the workpaper review under a typical audit condition, while the
other half of the participants completed the workpaper review under a skepticism-induced
condition. Hurtt et al. (2008) assigned the participants to the groups based on rank-
ordered skepticism scores. The degree of professional skepticism, in this research, was
measured by the Hurtt Professional Skepticism Scale. The statistical method used to
analyze the data was ANCOVA. Hurtt et al. (2008) found that auditors with higher levels
of skepticism behave differently than auditors with lower levels of skepticism; however,
“the behavioral differences do not always go in the direction of higher skepticism being
associated with more skeptical behavior” (p. 25). Hurtt et al. recommended further
research on the influence of professional skepticism on auditor behaviors.
Evidence collection may also influence professional skepticism as the evidence is
used to make assessments. Rasso (2015) used construal-level theory to examine whether
and how interpretations of evidence affect auditors’ judgments and decisions. Construal-
level theory uses high-level construals (broad and abstract) and low-level construals
(specific and detailed) to evaluate how individuals interpret information to make
decisions (Rasso, 2015). Rasso selected 58 auditors with an average of 5.4 years of audit
experience from six accounting firms to participate in the 1X3 between-participants
experiment. The documentation instructions were manipulated on three levels: high-
level, low-level, and no instructions. The participants were randomly assigned to one of
59
the three conditions. The research instrument was an adapted computerized case study
where accounting estimates were used by the client; the case contained 12 evidence items
suggesting an aggressive estimate, 6 evidence items suggesting a fairly stated estimate,
and 12 neutral evidence items. Additionally, the computerized case study incorporated a
time budget for the participants, emphasizing the cost of evidence collection. The
dependent variables used to evaluate professional skepticism were the participants’
perceived risk that the estimate was materially misstated and the participants’ perceived
likelihood that they would require an adjustment to the estimate. A scale ranging from 1
(Very Unlikely) to 10 (Very Likely) was used to measure the dependent variables.
ANOVA and planned contrasts were used to analyze the data. Rasso found that
participants in the group with the high-level documentation instructions processed
incomplete evidence better and recognized the need for more evidence to make a
judgment; additionally, the high-level participants were more capable of recognizing a
high-risk level for a complex accounting estimate when the majority of the evidence
suggested an overstatement (p. 45). One important finding from Rasso’s study is that
abstraction outperformed specificity in relation to achieving professional skepticism
when evaluating audit evidence. Rasso (2015) also “suggest that auditors in practice
collect and process information with low-level construals” (p. 53), which may be related
to ineffective fraud risk assessments.
Professional skepticism of auditors was examined by Lee, Welker, and Wang
(2013) in relation to deception risk in interviews. In contrast to auditing standards, which
expects auditors to maintain an attitude of presumptive doubt, deception detection
literature presumes an attitude of presumptive trust (Lee et al., 2013). Lee et al.
60
conducted an online experiment with 59 practicing auditors with an average of 4.3 years
of auditing experience. A questionnaire that incorporated seven questions was given to
the participants to measure deception detection after watching an online video between an
interviewer and an interviewee who lied. The construct design used 20 different
interviewees to strengthen the validity of the experiment; hence, all participants did not
have the same interviewee in the video. The experimental design used one independent
variable with three treatment levels (i.e., suspicion-neutral, suspicion-inducing, and
suspicion-neutralizing), which varied based on the manipulation of the pay scheme (i.e.,
incentive to lie versus no incentive to lie) as well as the risk assessment. The risk
categories manipulated were financial pressure, attitude/rationalization, and potential for
discovery. The dependent variable of deception detection was measured by the
frequency of a truth decision in which a frequency exceeding 50 % was indicative of
presumptive trust. Lee et al. (2013) found approximately 70% incorrectly believed the
interviewee, which supports that presumptive trust is more prevalent than presumptive
doubt in conditions of deceptive risks. Notwithstanding the study’s limitations of a short
interview, observation instead of participation by the participants, and no financial risk to
the participants, Lee et al. provided support for future research to ascertain “whether a
trusting attitude deters auditors from perceiving suspicious behavior and whether it has a
detrimental effect on fraud risk assessment” (p. 223).
As professional skepticism does not have a universally accepted definition, two
perspectives have transpired – neutrality and presumptive doubt (Quadackers, Groot, &
Wright, 2014). According to Nelson (as cited in Quadackers et al., 2014), auditing
standards support the neutrality perspective, which supports an unbiased belief in
61
management’s assertions. In contrast, the presumptive doubt perspective supports a
biased belief that dishonesty exists unless evidence proves otherwise (Quadackers et al.,
2014). Quadackers et al. (2014) conducted an experimental study to ascertain the
relationship between the two professional skepticism perspectives and auditor judgments
and decisions using a higher-risk and lower-risk control environment. The independent
variable, control environment risk (high versus low), was manipulated using case
materials of Cohen and Hanno (2000), and the independent variable, professional
skepticism (i.e., neutrality versus presumptive doubt) was measured using two scales.
The Rotter Interpersonal Trust Scale (RIT) was inversed to measure presumptive doubt,
and the Hurtt Professional Skepticism Scale was used to measure neutrality. The
dependent variables were as follows: likelihood that management explanation is correct,
likelihood of fraud, number of alternative explanations, number of total error
explanations, weight of total error explanations, and the number of budgeted hours. The
sample consisted of 96 participants, including partners, managers, and seniors, from one
Big 4 auditing firm with an average of 15.36 years of auditing experience. The
participants were randomly assigned to the two risk conditions to conduct risk assessment
and audit planning tasks and to answer questions on skeptical attributes. Linear
regressions were used to assess the relationship between skeptical attributes and auditing
judgments for the two risk conditions. Quadackers et al. (2014) found the presumptive
doubt perspective to be more predictive of auditors’ skeptical judgments in higher-risk
environments (p. 651). Notwithstanding the limitations of the use of only one accounting
firm and the use of scales that were not designed to specifically measure the neutrality
and presumptive doubt perspectives of professional skepticism, Quadackers et al.
62
provided support for the auditing profession and regulators to reevaluate the emphasis of
a neutrality perspective versus a presumptive doubt perspective in the auditing standards.
Peytcheva (2014) further studied the presumptive doubt view of professional
skepticism. Peytcheva (2014) combined the presumptive doubt view of professional
skepticism (i.e., present versus absent) with a cheater-detection framework (i.e., present
versus absent) from social contracts theory to test auditors’ cognitive performance using a
2X2 between - participants experimental design. The dependent variable was the
participants’ correct response on the audit evidence needed to test the audit hypothesis.
The sample contained 78 senior accounting students enrolled in an auditing class and 85
practicing auditors with an average of 6.5 years of auditing experience from an
international auditing firm. A Wason evidence selection task based on prepositional
logic (i.e., if P then Q) was used by the participants to select the audit evidence
requirements after reading the auditing case. The trait of professional skepticism was
measured by the Hurtt Professional Skepticism Scale, which was modified from a six-
point scale to a seven-point scale. Peytcheva (2014) cautioned the use of a six-point scale
because it does not provide participants with the ability to provide a neutral response (p.
43). Logistic regressions were used to analyze the data. Peytcheva found that the
professional skepticism prompt improved the cognitive performance of the students but
not the auditors, and the cheater-detection prompt did not improve the cognitive
performance of the students or the auditors (p. 42). Additionally, a difference was not
found between the level of professional skepticism between the students and the auditors,
which substantiates the theory that professional skepticism is a personal trait (Peytcheva,
2014, p. 43).
63
Glover and Prawitt (2014) introduced a professional skepticism continuum that
relates the level of professional skepticism (e.g., complete trust to complete doubt) to the
risk characteristics of the account and assertion being audited, which attributes
professional skepticism to situational factors versus a personal trait. Glover and Prawitt
(2014) argued, “that regulation can threaten the appropriate application of auditor
skepticism if regulation and/or inspection focus is not properly aligned with relevant
audit risk” (p. P5). Glover and Prawitt illustrated the interrelationship of structural levels
(i.e., auditor, engagement team, audit firm, and the auditing profession) with the threats
and mitigating factors of each level. Suggestions made for individuals, audit teams, and
audit firms to enhance professional skepticism in the audit process to achieve audit
quality include the following:
• Provide training that uses a common and formal judgment framework;
• Identify and apply different judgment frames to challenge assumptions and
explanations;
• Align performance evaluation and incentives so professional skepticism is
rewarded;
• Create the perspective for the engagement team that an appropriate level of
professional skepticism is expected and valued;
• Structure group decisions to avoid groupthink tendencies; and
• Develop a firm culture of professional skepticism by developing a formal
professional judgment framework and process, and providing tools,
technology, and training to enhance professional skepticism (Glover &
Prawitt, 2014, pp. P8-P10).
64
Professional skepticism may also be influenced by an individual’s culture. Ho,
Kwock, and James (2015) investigated the influences of Chinese culture on the level of
skepticism exhibited by Chinese accounting students without audit experience to assess
only the cultural impact. Ho et al. (2015) developed a theoretical framework to measure
the Chinese students’ level of professional skepticism by using four of Hurtt’s (2010)
professional skepticism trait indicators (i.e., search for knowledge, autonomy, suspension
of judgment, and questioning mind). Hurt (2010) posited that professional skepticism
was not only a personal trait, but also a situational state (Ho et al., 2015, p. 277). A
survey methodology design was used to construct a questionnaire to assess the
relationship between Chinese behaviors and beliefs (guanxi) and professional skepticism.
The participants were 127 fourth year accounting students (73 % female) from a
university in Southern China. The students completed the questionnaire that measured
both guanxi (independent variable) and professional skepticism (dependent variable)
using Ang and Leong’s guanxi scale and Hurtt’s (2010) professional skepticism scale,
respectively. Factor analyses and regression models were used to analyze the data. Ho et
al. found that beliefs only have a significant positive association with search for
knowledge and suspension of judgment, while behaviors do not have a significant
association with neither search for knowledge, autonomy, suspension of judgment, nor a
questioning mind (p. 286). Ho et al. attributed these results to the “Chinese tradition that
advocates academic excellence through attaining knowledge… and not questioning
teachers” (p. 286), and to the acceptance of “the authority and decisions of superiors” (p.
286). Generalization of the study to the Chinese culture was limited by the small sample
65
size and the geographic location selected in China; however, the findings do provide for
further study on the influences of culture on professional skepticism.
Some researchers posit that professional skepticism is a personal trait and/or a
situation state, while other researchers posit that professional skepticism can be learned.
Carpenter, Durtschi, and Gaynor (2011) conducted a seven-month longitudinal study to
examine the influence of a forensic accounting course on fraud risk assessments to
measure professional skepticism levels. An experimental group (37 students) that
completed two courses in auditing and a forensic accounting course, a control group (32
students) that completed only two courses in auditing, and a panel of seven experts
participated in the study. The fraud-related judgments were measured with a case-based
questionnaire that the experimental group participants completed after reviewing a case
study with an unusual bad debt expense on the first day of class, the last day of class, and
seven months after course completion (only 17 of the participants completed). The
control group participants completed the same case-based questionnaire on the last day of
the second auditing course. The case-based questionnaire used an 11-point Likert-type
scale ranging from 0 (Not At All Likely) and 10 (Extremely Likely) to assess the
likelihood of an intentional misstatement in the financial statements of the case study.
The data for this study was analyzed using a repeated-measure ANOVA. Carpenter et al.
(2011) found that the forensic accounting course had a positive impact on fraud risk
assessment performance. The experimental group’s post-training assessment results
provided a higher fraud risk assessment than the results from the control group’s
assessment and the experimental group’s pre-training assessment (Carpenter et al., 2011,
p. 3). Additionally, the experimental group rated the fraud-risk factors as more relevant
66
than the experts and the control group participants; hence, this result emphasized the
importance of fraud education for effective fraud risk assessment performance. More
importantly, Carpenter et al. found that the effects from the forensic accounting course
lasted over time because the test results after seven months were similar to the post-
training assessment results. Carpenter et al.’s study provides support for forensic
accounting training to increase professional skepticism, which leads to improving fraud
risk assessment performance.
Certified Fraud Examiners
The most recognized and respected professional certification of accountants is the
certified public accountant (CPA) designation (Nix & Morgan, 2013). Due to the
occurrence of significant corporate accounting scandals, since the late 1990s, the certified
fraud examiner (CFE) professional certification is attaining the attention of businesses,
the accounting profession and regulators. Nix and Morgan (2013) referenced the ACFE’s
2012 Report to the Nations, which found that fraud remains prevalent despite the passage
of SAS No. 99, as well as SOX in 2002. The CFE certification is indicative of
specialized “knowledge of fraud assessment, detection, and prevention methods” (Nix &
Morgan, 2013, p. 4), which may assist in fraud reduction. Nix and Morgan (2013)
provided support for the value of the CFE certification and Popoola, Che-Ahmad, and
Samsudin (2014) confirmed a positive relationship between fraud knowledge and fraud
risk assessment. However, Boritz, Kochetova-Kozloski, and Robinson (2015) did not
find that fraud specialists were more effective than financial statement auditors in
modifying audit plans when fraud was present.
67
Nix and Morgan (2013) conducted a research survey to ascertain the perceptions
of chief financial officers (CFOs) to provide empirical evidence on the value of the CFE
certification. The sample consisted of 500 CFOs from large public corporations,
commercial banks, and financial institutions. The participants answered survey questions
on perceptions of the CFE certification using a five-point Likert response scale ranging
from -2 (Strongly Disagree) to +2 (Strongly Agree). Nix and Morgan found the CFE
certification to be of value, but the participants’ perceptions of value were directly related
to knowledge of the ACFE’s CFE program. Even though this study was limited to CFO
perceptions, it documented the importance of promoting the CFE professional
certification and conducting future research on the value of the CFE credential (Nix &
Morgan, 2013).
In response to PricewaterhouseCoopers International Limited’s 2011 Global
Economic Crime Survey, which reported a rise in economic crime in Malaysia, Popoola,
Che-Ahmad, and Samsudin (2014) studied the correlation of fraud risk assessments and
auditing knowledge in relation to the auditors in Malaysia. Popoola et al. (2014) posited
that fraud risk assessments performed by individuals with forensic knowledge might
produce higher task performance in fraud detection than auditors without specialized
fraud knowledge. Similarly, Popoola, Che-Ahmad, and Samsudin (2015) conducted a
study of the relationship between fraud knowledge and fraud risk assessment in Nigeria
using a cross-sectional design of auditors and forensic accountants. The 400 participants
completed a 36-item questionnaire, which used a five-point Likert scale ranging from 1
(Strongly Agree) to 5 (Strongly Disagree). Popoola et al. (2015) confirmed a positive
68
relationship between fraud knowledge and fraud risk assessment. These studies support
the important role of certified fraud examiners in fraud detection.
In contrast, Boritz, Kochetova-Kozloski, and Robinson (2015) did not conclude
that fraud specialists are more effective than financial statement auditors in modifying
audit plans when fraud was present. Auditing standards recommend that when there is a
high risk of fraud that financial statement auditors obtain assistance from fraud specialists
to alter audit plans for fraud testing (Boritz, Kochetova-Kozloski, & Robinson, 2015).
Boritz et al. designed an experiment using a one-between participants factor, participant
type (fraud specialists versus financial statement auditors) to test the hypotheses that
fraud specialists increase overall audit effort by proposing greater numbers of audit
procedures, select more effective audit procedures when the risk of fraud is high, and
increase the budgeted hours for the audit procedures (p. 886). The Canadian participants
were 32 fraud specialists (50% Big 4 and 50% medium-size firms with an average of 12
years of fraud experience and 6 years of auditing experience) and 16 financial statement
auditors (60% Big 4 and 40% medium-size firms with an average of 13.25 years of
auditing experience and no fraud-related experience). The research instrument was an
adapted audit case based on an actual company’s fraudulent financial statements in which
the participants selected and proposed audit procedures and modified budget hours for the
audit of the revenue cycle. The quality of the revenue cycle audit program (e.g.,
dependent variable) was tested through the manipulation of the independent variable
(e.g., participant type), and the covariates (e.g., the number of procedures from a standard
audit program and audit experience). The data was analyzed using t-tests, MANOVAs,
and ANCOVAs statistical designs. The results did not provide support for Boritz et al.’s
69
(2015) hypotheses; hence, the regulators’ recommendation to seek assistance from fraud
specialists in the presence of fraud during a financial statement audit may not result in
more effective and efficient audit plans to detect fraud. Due to the study’s construct
limitations, including the lack of a fraud brainstorming session and the use of audit
experts rather than fraud experts to form effectiveness and efficiency judgments for the
audit procedures without knowing that fraud was present (Boritz et al., 2015, p. 899),
additional research is needed to further explore the role of fraud specialists in financial
statement audits when fraud risk is present.
Summary
The purpose of the literature review was to synthesize academic literature to
examine the theoretical underpinnings of fraud and attribution in relation to financial
statement fraud to find gaps in the current body of knowledge. This synthesis should be
relevant to auditors, regulators, researchers, and academicians. This chapter included a
review of literature relevant to regulations pertaining to fraud risk assessment, risk
assessment models used to assess risk, attributes of auditors performing fraud risk
assessments, and perceptions of the certified fraud examiner credential on fraud risk
assessments.
According to the literature, auditors must follow auditing standard, SAS No. 99,
when conducting an audit of a U.S publicly traded company; SAS No. 99 requires that
auditors perform a fraud risk assessment using the fraud triangle to detect financial
statement fraud. Many researchers argue that the fraud triangle is not broad enough to
perform an effective fraud risk assessment (e.g., Boyle et al., 2012; Dorminey et al.,
2010; Lokanan, 2015; Schuchter & Levis, 2015; Soltani, 2014). The literature includes
70
various fraud risk assessment models introduced to improve auditors’ fraud risk
assessment processes.
Researchers disagree on the correlation of auditors’ attributes to fraud risk
assessment outcomes (e.g., Fathil & Schmidtke, 2010; Jaffar et al., 2011). The PCAOB
cited “the lack of professional skepticism as a serious problem in auditors’ fraud
investigations” (Carpenter & Reimers, 2013, p. 46). Researchers were found to have
different beliefs on the role of professional skepticism in relation to fraud risk
assessments (e.g., Bolin et al., 2015; Carpenter & Reimers, 2013; Glover & Prawitt,
2014; Lee et al., 2013; Peytcheva, 2014). The literature also provided mixed perspectives
on the importance of auditors having the certified fraud examiner credential for the
performance of fraud risk assessments (e.g., Boritz et al., 2015; Nix & Morgan, 2013;
Popoola et al., 2014).
Further research is warranted to better understand the complexities of fraud risk
assessments to improve effectiveness in detecting financial statement fraud. Auditing
regulations, fraud risk assessment models, auditor attributes, and fraud knowledge have
been found to have an influence on fraud risk assessment performance. More emphasis
needs to be placed on measuring fraud knowledge and professional skepticism as fraud
risk assessments are based on auditors’ judgments.
71
Chapter 3: Research Method
Occupational fraud overall, including financial statement fraud, is a challenge for
the global business environment. The Association of Certified Fraud Examiners (2014)
posited that, “Occupational fraud is a universal problem for businesses around the globe”
(p. 5). PricewaterhouseCoopers reported that 30% of companies worldwide were victims
of fraud in 2009 (Murphy & Dacin, 2011). The ACFE’s (2014) Report to the Nations on
Occupational Fraud and Abuse reported that approximately 5% of organizations annual
revenues are lost to fraud, which estimates $3.7 trillion worldwide (Drew, 2014, para. 1).
Drew (2014) reported that 48% of the fraud cases were in the U.S. and that “financial
statement frauds were the least common, but most costly, representing 9% of cases and a
median loss of $1 million” (para. 14). Hence, 13 years after the enactment of SOX,
financial statement fraud is still prevalent, not only in the U.S., but also worldwide
(Association of Certified Fraud Examiners, 2014).
Auditors’ fraud risk assessments are not effectively detecting financial statement
fraud. Hopwood, Leiner, and Young (2012) reported that auditors who applied SAS No.
99 detected only “5 to 20 percent of the occupational frauds” (p. 169). Albrecht and
Hoopes (2014) posited the following reasons why auditors are unable to detect fraud,
which include: a) voluminous nature of accounting records, b) use of outsiders to conceal
the fraud, c) reluctance of people to disclose information about fraudulent acts, d) use of
forgery and lying to provide barriers against discovery, and e) lack of performance of
sufficient financial statement audits. Additionally, Albrecht and Hoopes (2014)
identified four factors that prevent auditors from performing sufficient financial statement
audits to detect financial statement fraud, which include a) inadequate training and
72
experience, b) poor audit planning, gathering of evidence, and examining controls, c) lack
of due professional care, and d) lack of independence (p. 20). Trompeter, Carpenter,
Desai, Jones, and Riley (2013) stated that the PCAOB inspections found deficiencies in
auditors’ responses to fraud risk. Trompeter et al. (2013) recommended future research
to ascertain if the deficiencies are a result of the auditors’ failure to respond or a result of
the auditors’ inability to respond when appropriate fraud assessment techniques are used.
Hurtt, Brown-Liburd, Earley, and Krishnamoorthy (2013) acknowledged the importance
of professional skepticism in fraud detection, but stated, “research is limited to the
actions that auditors actually take related to their professional skepticism” (p. 72). Due to
the complexity of the interrelationships in conducting a fraud risk assessment, as well as
the importance of fraud detection for the auditing profession and regulators, additional
research is needed to understand fraud risk assessments and the elements influencing
fraud risk assessment performance. Effective fraud risk assessments identify fraud risk
factors (i.e., opportunities, incentives, and pressures), which may lead auditors to the
discovery of financial statement fraud (Dorminey et al., 2012).
The purpose of this quantitative research study was to examine the theoretical
underpinnings of fraud and attribution as it relates to the independent variables of the
presence of fraud and auditor certification, the control variable of professional
skepticism, and the dependent variable, fraud risk assessment performance, for
participants within the U.S. that are certified fraud examiners and/or certified public
accountants. Auditor certification was categorized by the identification of certification
attributes (CFE, CFE/CPA, or CPA). Professional skepticism was measured by using
Hurtt’s (2010) six-point Likert skepticism scale to classify the trait of professional
73
skepticism into high and low levels. Twenty-five certified public accountants with at
least 15 years of experience, which included working at one or more international
accounting firms, validated Hurtt’s theoretical view of professional skepticism through
the use of an open-ended questionnaire on the traits of professional skepticism. The
content validity of the scale was validated by a pilot test of three faculty members with
professional auditing experience and education, which resulted in the reduction of the
scale items from 170 to 49. Additionally, 89 graduate and undergraduate students
participated in the pretesting of the scale, which resulted in a further reduction of the
scale items to 40. The 40-item scale was administered to 250 undergraduate business
students twice for reliability testing, which resulted in a further reduction of the scale to a
30-item scale; the 30-item scale was successfully tested by the student participants (Hurtt,
2010). The 30-item scale was also tested using a repeated-measures design with
participation from 200 and 88 auditors, respectively, from a major international auditing
firm; Hurtt found a statistically significant correlation of internal consistency between the
two tests. Hurtt (2010) concluded, “These results provide preliminary evidence that the
skepticism scale is a valid instrument with appropriate inter-item and temporal stability”
(p. 164).
Fraud risk was operationalized by the use of two sets of financial statement data
from the Securities and Exchange Commission’s (SEC) public database for the years
2005–2014 of which one set contained high-fraud risk and one set contained low-fraud
risk. Fraud risk assessment performance measured the auditors’ ability to assess fraud
risk. Fraud risk assessment performance was measured as seven-point Likert scale data,
using at least four Likert-type items combined, so that an interval measurement scale
74
could be used for quantitative analyses. Boone and Boone (2012) illustrated that a
composite score (i.e., sum or mean) may be calculated from four or more similar Likert-
type items, which allows the use of parametric analysis using the analysis of variance
(ANOVA) technique. NGO Security (2010) combined probability of occurrence and
impact of risk to illustrate the use of a seven-point Likert scale to quantitatively assess
risk by multiplying the two rating values together; the higher number represents higher
risk. Additionally, NGO Security recommended that the multiplication of the combined
score by two approximate the familiar 100-point scale (i.e., 2 to 98). Jaffar, Haron,
Iskandar, and Salleh (2011) used a seven-point Likert scale ranging from extremely
unlikely to extremely likely to measure auditors’ ability to assess fraud risk with
ANOVA as the statistical method for evaluation. A Likert scale was the instrument
utilized to measure fraud risk assessment performance because neither the PCAOB nor
the AICPA have a standardized fraud risk assessment tool that is used by auditors to
assess fraud risk (Albrecht & Hoopes, 2014; Boritz et al., 2015). Generally, auditors
measure fraud risk as high, medium, or low; hence, a numeric value is not traditionally
attributed to fraud risk assessments (Boritz et al., 2015).
The participants in this study were certified fraud examiners and certified public
accountants from the population of the Association of Certified Fraud Examiner’s
(ACFE) LinkedIn group and online forum of certified fraud examiners and associate
memberships, the population of the American Institute of Certified Public Accountants’
(AICPA) LinkedIn group memberships, and the population of the Virginia Society of
Certified Public Accountants’ (VSCPA) LinkedIn group and online forum memberships.
Members were invited to participate in the experiment using the online forums. The
75
experimental construct was a 2X3 between-participants design with two levels for one
independent variable and three levels for the second independent variable to test the fraud
risk variable. SPSS was used to conduct a two-way analysis of variance (ANOVA) to
determine the effect that the categorical independent variables (the presence of fraud risk
and auditor certification) had on the interval dependent variable (e.g., fraud risk
assessment performance). Next, SPSS was used to conduct a two-way analysis of
covariance (ANCOVA) to examine the influence of the control variable, professional
skepticism, on the fraud risk assessment performance dependent variable. Planned
contrasts were also conducted in SPSS to determine interaction effects of the auditor
certification variables.
The research questions and hypotheses are presented prior to a discussion of the
research methodology, population, and materials/instruments used for the research study.
Operational definitions of the variables are provided along with an elaboration of the data
collection and analyses. Additionally, assumptions, limitations, delimitations, and ethical
assurances of the research project are discussed.
The following research questions and hypotheses guided the study to examine the
effects of the presence of fraud risk and auditor certification while considering
professional skepticism on fraud risk assessment performance.
Q1. Does the presence of fraud risk have an effect on fraud risk assessment
performance?
Q2. Does a certification in fraud knowledge have an effect on fraud risk
assessment performance?
Q3. Does professional skepticism influence fraud risk assessment performance?
76
H10. The presence of fraud risk does not have a significant effect on fraud risk
assessment performance.
H1a. A high level of fraud risk produces a high-fraud risk assessment
performance.
H20. A certification for fraud knowledge does not have a significant effect on
fraud risk assessment performance.
H2a. Auditors that possess a certification in fraud detection produce more
effective fraud risk assessment performance than auditors without the
certification.
H30. The level of auditor professional skepticism does not have a significant
influence on fraud risk assessment performance.
H3a. Auditors that exhibit professional skepticism produce more effective fraud
risk assessment performance than auditors without this attribute.
Research Design
The research study used a quantitative experimental between-participants research
design to assess the effect of the presence of fraud and auditor certification, while
considering professional skepticism, on fraud risk assessment performance. The
experiment was conducted in the online environment using Qualtrics online survey
software. An online research design provided for cost savings of time, postage, and
travel. The population was U.S. CFEs and CPAs that were members of the ACFE,
AICPA, or the VSCPA. The participants (sample) were those who responded on a
volunteer basis. The ACFE and the AICPA were selected as two of the organizations to
use as the population because the ACFE is the largest anti-fraud organization worldwide
77
and the AICPA is the largest global professional association of accountants in the U.S.
(Association of Certified Fraud Examiners, 2014; “About the AICPA,” n.d., para. 1).
The VSCPA was selected as an organization to use as the population for representation of
a state professional association. Members were invited to participate in the online
experiment using the ACFE LinkedIn group and online forum of certified fraud
examiners and associate memberships, the AICPA LinkedIn group memberships, and the
VSCPA LinkedIn group and online forum memberships. The population consisted of
individuals with the following certifications: CFE, CFE/CPA, or CPA. Before the
participant could participate in the online study, a certification question was required to
be answered, which determined participation eligibility. Eligibility was defined by the
participant’s age (i.e., age must be at least 18 years), the possession of the appropriate
professional certification (i.e., CFE, CFE/CPA, or CPA), and the participants’ work
location (i.e., participant must work in the U.S.). Hence, an individual without a CFE
and/or CPA certification was not eligible to participate in the study, which addressed
selection and regression threats. Self-identification of certification was used to categorize
the participants into the three levels for auditor certification (CFE, CFE/CPA, or CPA).
Random assignment was used to divide the three-group random sample into the following
six comparative groups – three groups analyzed high-fraud risk data and three groups
analyzed low-fraud risk data. External validity was strengthened from the use of random
sampling and the use of random assignment of participants to test the fraud risk variable.
The SEC database of U.S. publicly traded companies was used to randomly select
a corporation that reported an occurrence of financial statement fraud during 2005–2014.
The SEC maintains a database of accounting and auditing enforcement releases
78
(AAERs), which is a comprehensive listing of discovered financial statement fraud cases
in the U.S. After the random selection of a U.S. company with financial statement fraud,
the Form 10-K, which contains the company’s financial statements and other financial
and nonfinancial data, was obtained from the SEC database. The Form 10-K, with the
company identifiable information erased, was the instrument used in the high-fraud risk
group for performing the risk assessment. The restated Form 10-K of the same company
(i.e., financial statements without fraud) was the instrument used in the low-risk group for
performing risk assessment. Internal validity was strengthened by the use of an actual set
of fraudulent and restated financial statements for the fraud risk variable.
The assessment tool for the professional skepticism variable was the validated
Hurtt Professional Skepticism Scale (Hurtt, 2010), which is designed to measure
professional skepticism. Hurtt (2010) selected three experts (i.e., faculty members with
auditing experience) for the content validity of the scale (i.e., pretest of the scale), and
selected 247 undergraduate business students and 200 auditors from a major international
auditing firm to validate the scale using a rigorous and iterative process. This is a 30-
item scale with scale scores ranging from 30 to 180 in which higher scores depict a
higher level of professional skepticism. Hurtt (2010) explained that the scale could be
transformed to a 100-point scale by dividing the participant’s score by 180 (p. 168). The
Hurtt Professional Skepticism Scale is a well-recognized instrument used by researchers
to measure professional skepticism. The Hurtt Professional Skepticism Scale has been
used by Boyle et al. (2012), Carpenter and Reimers (2013), Peytcheva (2014), and
Quadackers et al. (2014).
79
The fraud risk assessment performance was measured using an interval
measurement Likert scale. The participants used the following four similar Likert-type
questions to assess fraud risk: a) likelihood of fraud risk, b) significance of fraud risks, c)
significance of anti-fraud controls in use, and d) likelihood of fraud. A fraud risk
assessment composite score was calculated from the answers to the questions. IBM
SPSS Statistics version 24 was used to perform statistical data analyses during ANOVA
and ANCOVA along with planned contrasts for the analysis of variable interactions.
A quantitative research method was appropriate for this research study in that the
intent of the study was to identify and evaluate the variables (i.e., the presence of fraud
risk, auditor certification, and professional skepticism) that influence an outcome (i.e.,
fraud risk assessment performance) by developing and testing hypotheses. A 2X3
between-subjects experimental design was chosen in that participants were divided into
three groups by self-identification of professional certification (i.e., CFE, CFE/CPA, or
CPA) and then randomly assigned by Qualtrics to one of two conditions (i.e., high-fraud
risk and low-fraud risk) to make inferences from the research findings and achieve
generalization. Moreover, a quantitative method provided for the use of statistical data
analysis to conclude causality as the variables were measured using an interval scale.
According to Park and Park (2016), a quantitative research method provides for
justification due to reliability and validity testing, in a controlled environment, which is
in contrast to a qualitative research method, which provides for discovery in natural
conditions. A quantitative study provides for recommendation(s) to research findings by
using structured data collection techniques coupled with statistical analyses compared to
the inconclusive research findings from unstructured or semi-structured data collection
80
techniques of a qualitative study (Park & Park, 2016). Barnham (2015) emphasized that
the key tenants of quantitative research include controlled conditions, large base sizes,
and the application of statistics to make inferences about the population, which is in
contrast to qualitative research that focuses on perceptions of how incidences occur,
which cannot be generalized to the population. Historically, qualitative studies have
received criticisms related to validity and reliability (Barnham, 2015).
A qualitative research method was not appropriate for the research study in that
the variables of the design were identified prior to the collection of data, and data
collection was operationalized to relate the variables to the research questions and
hypotheses for hypothesis testing not hypothesis generation. Instrument-based questions
were utilized, as opposed to open-ended questions, as the intent was to provide for
generalizability using statistical interpretations, as opposed to particularity using
emergent interpretations based on judgment.
Population
The ACFE was selected as one organization to use as the population because it is
the largest anti-fraud organization worldwide, which includes approximately 70,000
members in 150 countries (Association of Certified Fraud Examiners, 2014). The
population of the ACFE online forum was limited to U.S. CFEs and U.S. associate
members of the ACFE, which included approximately 33,500 CFEs and 16,800 associate
members (A. McNeal, personal communication, October 16, 2015). The associate
members of the ACFE are not CFEs, but they may be CPAs so they were included in the
population. The population of LinkedIn ACFE group members approximated 37,500
(LinkedIn, n.d., ACFE group).
81
The AICPA was selected as one organization to use as the population, because it
is the largest global professional association of accountants in the U.S. with
approximately 418,000 members in 143 countries (“About the AICPA,” n.d., para. 1).
AICPA members are required to complete 120 hours of continuing education every three
years to stay current in the accounting field (“About the AICPA,” n.d.). The population
was limited to U.S. CPAs and/or CFEs AICPA LinkedIn group members, which included
approximately 63,500 members (LinkedIn, n.d., AICPA group).
The VSCPA was selected as another organization to use as the population for the
inclusion of a state professional association of which the researcher is a member. The
VSCPA consists of approximately 12,000 members (“About the Virginia Society of
CPAs,” n.d., para. 2). The population was limited to U.S. CPAs and/or CFEs from the
VSCPA LinkedIn group, which included approximately 5,260 members (LinkedIn, n.d.,
VSCPA group), and from the VSCPA Connect online forum, which included
approximately 11,600 members (Connect, n.d.).
The sample represented participants from the ACFE, AICPA, and the VSCPA
populations of CFEs and CPAs, who work in the U.S., and voluntarily decided to
participate in the study. CFEs and CPAs, from the U.S., were invited to participate in the
online between-participants experiment using the ACFE and VSCPA online forums and
the LinkedIn forums of the ACFE, AICPA, and VSCPA. Before the individual could
participate in the online study, a certification question was required to be answered to
determine participation eligibility. Next, the eligible participants were divided into three
groups by the self-identification of professional certification (CFE, CFE/CPA, or CPA).
Qualtrics, online survey software, was designed to apply random assignment to divide the
82
random sample of the three groups into the following comparative groups – three groups
were to analyze high-fraud risk data and three groups were to analyze low-fraud risk data.
The sample size has a direct relationship to the significance of the test statistic
(Field, 2013). According to Field (2013), the p-value is used to signify a statistically
significant result (i.e., p < .05). Using the computer program, G*Power3, the sample size
for this research study needed to include least 100 participants to achieve a 95%
confidence interval and a significance level of .05 (p < .05) for six groups and a large
effect size of .40 for an ANCOVA statistical analysis.
Materials/Instrumentation
The materials used to test the presence of fraud risk variable was a set of
fraudulent financial statements issued by a U.S. public company to represent high-fraud
risk and the subsequent restated financial statements of the same company to represent
low-fraud risk. The SEC database of U.S. publicly traded companies was used to
randomly select a corporation that reported an occurrence of financial statement fraud
during 2005–2014. The time period was selected because it is after the passage of the
Sarbanes-Oxley Act of 2002, which created numerous regulations for both auditors and
corporations (Alleyne & Elson, 2013). The SEC maintains a database of accounting and
auditing enforcement releases (AAERs), which is a comprehensive listing of discovered
financial statement fraud cases in the U.S. After the random selection of a U.S. company,
with financial statement fraud, the Form 10-K, which contains the company’s financial
statements and other financial and nonfinancial data, was obtained from the SEC
database. The Form 10-K, with the company’s identifiable information removed, was the
instrument used in the high-fraud risk group for performing the risk assessment. The
83
restated Form 10-K of the same company, with the company’s identifiable and
restatement inferences removed, was the instrument used in the low-fraud risk group for
performing the risk assessment. Internal validity was strengthened by the use of an actual
set of fraudulent and restated financial statements for the fraud risk variable. The
instrumentation of the original fraudulent Form 10-K and the restated Form 10-K
provided for control to accurately draw conclusions about the effect of the presence of
fraud on fraud risk assessment performance.
Participants in each group completed a questionnaire, designed in Qualtrics, to
capture demographic data, including information about professional certification. The
self-identification of professional certification was used to categorize the participants into
the three levels of auditor certification (CFE, CFE/CPA, or CPA) to measure the auditor
certification variable. The CPA credential was selected as it is the most respected
certification in the accounting profession and represents “knowledge and competence”
(Nix & Morgan, 2013, p. 2). The CFE certification was selected because it was
recognized in SAS No. 99 as beneficial for fraud risk assessments and fraud detection
(Nix & Morgan, 2013).
The Hurtt Professional Skepticism Scale was input into Qualtrics and used to
measure the level of professional skepticism for each participant. The Hurtt Scale is a
30-item scale with scale scores ranging from 30 to 180 in which higher scores depict a
higher level of professional skepticism (See Appendix A). The Hurtt Professional
Skepticism Scale was validated by Hurtt (2010) using a rigorous and iterative process;
moreover, it is used by researchers to measure professional skepticism (Boyle et al.,
2012; Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014).
84
Participants in each group completed a seven-point Likert scale designed in
Qualtrics to perform a fraud risk assessment on the experimental financial statement
materials. The participants used four similar Likert-type questions to assess fraud risk:
(a) likelihood of fraud risk, (b) significance of fraud risks, (c) significance of anti-fraud
controls in use, and (d) likelihood of fraud. A fraud risk assessment composite score was
calculated from the Likert scale ratings, which ranged from 1 (Very
Improbable/Insignificant) to 7 (Very Probable/Significant; See Appendix E).
Operational Definition of Variables
The construct was a 2X3 experimental design using a two-way ANOVA and
ANCOVA for the statistical analyses. Between-participants construct, which utilized
random sampling and random assignment, was used to create six comparison groups
from the ACFE, AICPA, and VSCPA online forums and LinkedIn memberships. Three
comparison groups performed a fraud risk assessment using an instrument that contained
high-fraud risk, and three groups performed a fraud risk assessment using an instrument
that contained low-fraud risk. The instruments used were actual Form 10-Ks from the
SEC database of U.S. publicly traded companies. The participants in each group self-
reported professional certification status as CFE, CFE/CPA, or CPA to create three
groups for the three levels of the auditor certification variable. Additionally, the
participants in each group used the Hurtt Professional Skepticism Scale to assess the level
of professional skepticism. The calculated fraud risk assessment score from the
responses to the seven-point Likert scale, which contained four similar questions, was
used to measure the fraud risk assessment performance.
85
Construct 1- Auditor certification. The auditor certification independent
variable was a nominal variable with three levels – CFE credential, CFE/CPA credential,
and CPA credential. Self-identification by participants for professional certification was
used to categorize the participants into three groups in the Qualtrics application. The
categorization of participants in Qualtrics was exported to SPSS for statistical analyses
purposes.
Construct 2- Fraud risk assessment performance. The dependent variable of
fraud risk assessment performance was an interval variable measured by a seven-point
Likert scale, which ranged from 1 (Very Improbable/Insignificant) to 7 (Very
Probable/Significant; See Appendix E). The participants used four similar Likert-type
questions to assess fraud risk: a) likelihood of fraud risk, b) significance of fraud risks, c)
significance of anti-fraud controls in use, and d) likelihood of fraud. The raw data from
Qualtrics was exported to MS Excel to calculate a fraud risk assessment composite score
from the Likert scale ratings. The Likert scale composite score was the sum of four
similar Likert-type questions to quantify the assessment of financial statement fraud risk.
The fraud risk assessment composite score was exported from MS Excel to SPSS for use
in the statistical analyses.
Construct 3- Presence of fraud risk. The presence of fraud risk independent
variable was a nominal variable with two levels (e.g., high-fraud risk and low-fraud risk).
The source of experimental materials (Form 10-K) used was from the SEC database. The
fraudulent financial statements of a U.S. publicly traded corporation represented high-
fraud risk, and the restated financial statements of the same corporation represented low-
fraud risk. Each participant in the three auditor certification groups was randomly
86
assigned, by Qualtrics, to the high-fraud risk group or the low-fraud risk group, which
created six groups for the research study. Qualtrics used a different question number for
the participants who were randomly assigned to the high-risk condition and to the low-
risk condition (See Appendix E; Question 10 represents the high-risk condition and
Question 11 represents the low-risk condition). MS Excel was used to code the
participants who were assigned to the high-fraud risk condition with a 1) and the
participants who were assigned to the low-fraud risk condition with a 2) to identify the
presence of the fraud condition for each participant. The MS Excel spreadsheet was
exported to SPSS, which was used for statistical analyses.
Construct 4- Professional skepticism. The professional skepticism control
variable was an interval variable measured by the Hurtt (2010) six-point Likert scale,
which ranged from 1 (Strongly Disagree) to 6 (Strongly Agree; See Appendix A). The
Hurtt Professional Skepticism Scale 30-item questionnaire was the instrument selected to
measure the participants’ level of professional skepticism towards financial statement
fraud detection. The participants’ results were exported from Qualtrics to MS Excel to
calculate the participants’ professional skepticism composite score by summing
participant responses. The professional skepticism composite scores were exported from
MS Excel to SPSS for use in the statistical analyses.
Study Procedures
Approval was obtained from Northcentral University’s Institutional Review
Board (IRB) prior to any data collection. The research design met Northcentral
University’s IRB Category 2 criterion for exempt reviews, which indicated that the
ethical issues associated with this research study were minimal. The ethical principles
87
and guidelines applied to this research study relate to plagiarism, risk of harm, informed
consent, privacy and confidentiality, and data collection and reporting. Participants’ risk
of harm was minimized as they only performed a fraud risk assessment on a set of
financial statements and completed a validated professional skepticism questionnaire.
Informed consent was obtained from all of the participants without deception or coercion.
Confidentiality was maintained, even though the research study used the Internet to
obtain data using an online survey. Confidentiality can be viewed as problematic, as
there is a potential risk for a confidentiality breach, though this breach did not occur in
this research study. Privacy and anonymity were provided as participant names were not
collected and a third-party online survey software, Qualtrics, was used, which used a
high-end firewall system to protect the data stored on the Qualtrics website. The data
downloaded from Qualtrics excluded the participants’ IP addresses. Furthermore,
password-protection was used on portable devices that stored the data. All paper files
and portable devices with data information continue to remain stored in a locked cabinet.
In accordance with IRB requirements, the paper and electronic data will be destroyed in
seven years (i.e., after the completion of this dissertation; Northcentral University, 2015).
The construct design of two fraud risk conditions, which were unknown to the
participants, did create a lack of full disclosure because of the need to strengthen the
study’s internal validity. As internal validity is achieved when the results can be
explained by the independent variable, the construct design provided that the participant
was not made aware of the presence of fraud condition since this was the variable tested.
The research study was conducted by obtaining volunteer participants from the
members participating in the online forums of the ACFE and VSCPA and the LinkedIn
88
ACFE and AICPA online forums. Qualtrics software was used to create the
questionnaire for the participants (See Appendix E). The questionnaire included the
informed consent form (See Appendix D), demographic questions (i.e., age, gender, U.S.
geographical location, years of audit experience, and years of fraud risk assessment
experience), the professional certification eligibility question (i.e., CFE, CFE/CPA, or
CPA), and the 30-item Hurtt Professional Skepticism Scale questionnaire. After
completing the skepticism questionnaire (See Appendix A) that was inputted into the
Qualtrics questionnaire, the participants were randomly assigned by the Qualtrics
application to either the high-fraud risk or to the low-fraud risk condition to review the
Form 10-K materials. Next, the participants performed a fraud risk assessment from the
Form 10-K materials using the seven-point Likert scale created in the Qualtrics software.
The survey concluded after the fraud risk assessment was complete.
Data Collection and Analysis
The proposed research study used human subjects to test the hypotheses in the
online environment. Qualtrics was used to collect data from the participants. The
financial data used in the fraud risk assessment process was collected from the Securities
and Exchange Commissions, which is a publicly available Internet database, that has
Form 10-K company filings and Accounting and Auditing Enforcement Releases
(Beasley et al., 2010). The Hurtt Professional Skepticism Scale was the instrument used
to measure professional skepticism. The collected data was processed with SPSS
Statistics version 24 and MS Excel software applications. A two-way ANOVA and
ANCOVA with planned contrasts were used to analyze the data.
89
Data collection. An online survey software tool, Qualtrics, was used to collect
the data from the participants. Qualtrics was designed to randomly assign the volunteer
participants to one of two conditions (e.g., high-fraud risk or low-fraud risk), which
occurred after the self-identification of professional certification (CFE, CFE/CPA, or
CPA). The software was programmed to alternate the assignment of participants with the
same professional certification to a different experimental condition to provide for
diversity of certifications in each group (i.e., CFE, CFE/CPA, or CPA). Once assigned to
a group, each participant completed a set of demographic questions, which included age,
gender, U.S. geographical location, years of audit experience, and years of fraud risk
assessment experience. The aforementioned demographic groups were chosen to
strengthen the external validity of the research study by providing support for the random
selection of the participants so that the findings could be generalized to the population.
As the sample used random selection, it was essential to validate that the participants had
sufficient audit and fraud risk assessment experience. Additionally, the demographics
provided strength to the generalizability of the study to provide the gender and the U.S.
geographical region of the participants. Next, the participants completed the inputted 30-
item six-point Hurtt Professional Skepticism Scale questionnaire, which examined
professional skepticism. This instrument was selected because of its use by researchers
to measure professional skepticism (Boyle et al., 2012; Carpenter & Reimers, 2013;
Peytcheva, 2014; Quadackers et al., 2014). After completing the skepticism
questionnaire, the participants were given the Form 10-K materials to review and to
perform a fraud risk assessment using the seven-point Likert scale created in the
Qualtrics software.
90
Data analysis. Data collected in the Qualtrics survey software program was
imported into MS Excel to prepare the data for importing into the SPSS Statistics version
24 statistical software for analysis. The demographic information of gender and
geographic region was coded by Qualtrics with a (1) for male participants and a (2) for
female participants and with a (1) for Northeast, (2) for Southeast, (3) for Southwest, (4)
for west, and (5) for Midwest. The auditor certification variable was coded by Qualtrics
with a (1) for CFE, (2) CFE/CPA, and (3) for CPA. Participants who performed the
fraud risk assessment on the Form 10-K with fraud were coded with a 1) for the presence
of fraud risk variable, and the participants who performed the fraud risk assessment on
the Form 10-K without fraud were coded with a 2) for the no presence of fraud risk
variable. This coding (e.g., 1 and 2) of the fraud risk variable was performed in MS
Excel. The professional skepticism questionnaire results for questions 1 to 30 were
summed for a composite score in MS Excel, in accordance with the Hurtt Professional
Skepticism Scale administration instructions (Hurtt, 2010, p. 168). The fraud risk
assessment questionnaire results for the four Likert scale questions were summed for a
composite score in MS Excel; the rating for the question “Significance of anti-fraud
controls in use” was reverse scored in summing the total score. The following data
elements for each participant were exported from MS Excel into SPSS for data analysis:
age, gender, U.S. geographic location, years of audit experience, years of fraud risk
assessment experience, professional certification classification, professional skepticism
score, fraud risk presence variable, and the fraud risk assessment score. The statistical
analyses performed in SPSS Statistics version 24, to test the hypotheses, were a two-way
91
ANOVA and an ANCOVA. Planned contrasts were also conducted in SPSS Statistics
version 24 to determine interaction effects of the auditor certification variables.
Assumptions
An experimental research design was assumed to be the appropriate design choice
to ascertain how different groups performed financial statement fraud risk assessments.
A quantitative research method was deemed appropriate for this research study in that the
intent of the study was to identify and evaluate the effect of the presence of fraud risk,
auditor certification, and professional skepticism on fraud risk assessment performance
by testing hypotheses. The selection of the online environment as the construct design
provided for the random selection of participants from online forums to strengthen the
assumption of generalization from the sample to the population. It was assumed by the
researcher that the professional online forums would provide for a higher response rate
and be more cost effective in securing the appropriate number of participants for the
sample, specifically as compared to mailing the research materials to eligible individuals
in the U.S. (Poynter, 2010). Additionally, Qualtrics was selected as the online survey
application as it had the capability to randomly assign participants to the fraud risk
groups. The study’s eligibility requirements, which required a professional certification
(i.e., CFE or CPA), provided for the assumption that the participants had knowledge and
experience in the research topic and financial statement fraud.
The primary assumption for the fraud risk assessment materials was the presence
of financial statement fraud in the Form 10-K selected for the corporation that was listed
in the SEC AAER database and the absence of fraud in the restated Form 10-K of the
same corporation. Additionally, it was assumed that the time period, 2005–2014, was
92
representative of auditors’ compliance with SOX and SAS No. 99. Participant honesty
was the primary assumption for eligibility, auditor certification self-reporting, and
professional skepticism assessment.
Limitations
One limitation of the study was that the research design only included U.S.
publicly traded companies, which limited generalizability to U.S. companies listed on
U.S. stock exchanges, which is not representative of the global environment or non-
publicly traded companies in the U.S. The study was also limited to the assessment of
fraud risk assessment performance as only one corporation’s financial and nonfinancial
data was examined, which reduced external validity. The fraud risk assessment design
was limited due to the exclusion of group interactions, such as brainstorming sessions, as
required by auditing standards for financial statement fraud risk assessment, which
weakened internal validity. Brainstorming is required by SAS No. 99 as part of the audit
team’s fraud risk assessment and audit planning to improve fraud risk performance (Wei
et al., 2015). Another internal validity construct limitation was the exclusion of financial
statement audit experience and/or forensic auditing experience as an independent or
mediating variable, which may have had an effect on the fraud risk assessment
performance outcome; however, this limitation was mitigated by only including
participants with specific auditor certification attributes (i.e., CFE and CPA) in the
sample.
Delimitations
Delimitations, which narrowed the scope of the study, were present in the
research design. The following delimitations applied to the research study: the time
93
period of 2005–2014 was used for the Form 10-K selection from the SEC database, the
selection of participants from only ACFE, AICPA, and VSCPA online group
memberships, the selection of only one U.S. publicly traded company’s financial and
nonfinancial data, and the selection of only three variables (i.e., the presence of fraud,
auditor certification, and professional skepticism), when numerous other variables may
have attributed to auditors’ fraud risk assessment performance.
Ethical Assurances
The proposed between-participants experimental research study was conducted in
accordance with the Belmont Report, the American Psychological Association’s Code of
Conduct, and Northcentral University’s ethical guidelines. Approval from the
Northcentral University Institutional Review Board (IRB) was received prior to any data
collection. The research design met Northcentral University’s IRB Category 2 criterion
for exempt reviews. The Category 2 criterion states:
Research involving the use of educational tests (cognitive, diagnostic, aptitude,
achievement), survey procedures, interview procedures or observation of public
behavior, unless: (i) information obtained is recorded in such a manner that
human participants can be identified, directly or through identifiers linked to the
participants; and (ii) any disclosure of the human participants' responses outside
the research could reasonably place the participants at risk of criminal or civil
liability or be damaging to the participants' financial standing, employability, or
reputation (Northcentral University, 2015, p. 15).
The ethical principles and guidelines applied relate to plagiarism, risk of harm,
informed consent, privacy and confidentiality, and data collection and reporting. The
94
research study presented no more than minimal risk to the participants because they only
performed a fraud risk assessment on a set of financial statements, and completed a
validated professional skepticism questionnaire, which did not provide for physical,
psychological, or social harm (Northcentral University, 2015). Moreover, vulnerable or
disempowered populations were not used in the study. There were not any monetary
costs associated with study involvement, nor was compensation paid to the participants.
Informed consent was obtained from all of the participants without deception or coercion.
Confidentiality was maintained even though the use of the Internet for the online survey
presented a risk for a confidentiality breach. Privacy and anonymity was provided as
participant names were not collected, which also minimized reputational risk. The
construct design of two fraud risk conditions, which were unknown to the participants,
did create a lack of full disclosure because of the need to strengthen the study’s internal
validity. The participants were not made aware that there were two fraud risk conditions
where one Form 10-K represented high-fraud risk and one Form 10-K represented low-
fraud risk. Each participant was randomly assigned one Form 10-K to evaluate fraud
risk.
The online data collection methodology provided for a breach in privacy and
anonymity due to the Internet Protocol (IP) address of a computer accessing the Internet,
even though confidentiality was maintained. The research design employed the use of
third-party online survey software, Qualtrics, to collect the data; hence, to safeguard
participants’ privacy and anonymity, IP addresses were not included in the dataset
downloaded from Qualtrics. In accordance with Northcentral University (2015) research
confidentiality policies, password-protection was used on portable devices that stored the
95
data. All paper files and portable devices of the data are stored in a locked cabinet. In
accordance with IRB requirements, the paper and electronic data will be destroyed in
seven years, which begins upon the completion of this study.
Summary
The purpose of this between-participants 2X3 quantitative research study was to
examine the effects of the presence of fraud and auditor certification while considering
professional skepticism on fraud risk assessment performance. The literature reviewed
indicates that financial statement fraud is a global problem (Association of Fraud
Examiners, 2014; Drew, 2014; Murphy & Dacin, 2011), and regulations have been
enacted to improve auditors’ detection of financial statement fraud, which includes
conducting a fraud risk assessment. This research study determined whether a causal
relationship existed between the independent variables (e.g., the presence of fraud risk
and auditor certification, while controlling for professional skepticism) and the dependent
variable (e.g., fraud risk assessment performance) to fill a gap in the accounting literature
of fraud risk assessment influences.
The participants were randomly selected through volunteer consent from eligible
members of the ACFE, AICPA, and VSCPA online discussion forums to participate in
the online experiment that was administered by the use of Qualtrics survey software.
Qualtrics was designed to randomly assign the participants to either the high-fraud risk or
the low-fraud risk condition to perform a fraud risk assessment on a U.S. publicly traded
corporation’s Form 10-K. All participants used Qualtrics to complete a professional
skepticism questionnaire and self-report auditor certification status. Likert scales were
used to measure the professional skepticism level and the fraud risk assessment outcome.
96
The data collected in Qualtrics was exported to MS Excel to prepare the data for import
into SPSS Statistics version 24 statistical software. A two-way ANOVA and ANCOVA
were used to test the hypotheses and planned contrasts were conducted to determine
interaction effects of the auditor certification variable. Research was conducted and
handled in accordance with the Belmont Report and Northcentral University’s ethical
guidelines.
97
Chapter 4: Findings The purpose of this quantitative research study was to examine the effects of the
presence of fraud risk and auditor certification while considering professional skepticism
on fraud risk assessment performance. As reported by the Association of Certified Fraud
Examiners (2014), occupational fraud is a global problem and external audits are one of
the least effective methods of fraud detection. The auditing profession implemented SAS
No. 99/AU Section 316 to improve the detection of financial statement fraud by requiring
auditors to conduct a fraud risk assessment. Yet, despite the implementation of SAS No.
99/AU Section 316, the PCAOB found that auditors’ lack of professional skepticism
thwarted the detection of fraud (Trompeter et al., 2013). Nix and Morgan (2013)
purported that auditors with the CFE certification, which is indicative of a person having
fraud knowledge, may improve auditors’ fraud detection skills. Popoola et al. (2014)
confirmed a positive relationship between fraud knowledge and fraud risk assessment.
To answer the research questions and test the hypotheses, a 2X3 between-
participants design was constructed to manipulate two variables – presence of fraud and
auditor certification – while controlling for professional skepticism to ascertain the
outcome on the dependent variable, fraud risk assessment performance. Participant self-
identification was used to create three comparative groups (i.e., CFE, CFE/CPA, or CPA)
from the random sample to measure auditor certification. Random assignment was used
to divide the auditor certification groups into the following six comparative groups to
measure the presence of fraud: high-fraud risk with CFE, high-fraud risk with CFE and
CPA, high-fraud risk with CPA, low-fraud risk with CFE, low-fraud risk with CFE and
CPA, and low-fraud risk with CPA. The participants in each group performed a fraud
98
risk assessment on a company’s Form 10-K retrieved from the SEC database of U.S.
publicly traded companies using a seven-point Likert scale, which ranged from 1 (Very
Improbable/Insignificant) to 7 (Very Probable/Significant). The participants used four
similar Likert-type questions to assess fraud risk: a) likelihood of fraud risk, b)
significance of fraud risks, c) significance of anti-fraud controls in use, and d) likelihood
of fraud. Three groups analyzed high-fraud risk data by reviewing the company’s Form
10-K in a year with reported financial statement fraud, and three groups analyzed low-
fraud risk data by reviewing the selected company’s restated financial statements. Each
participant completed the Hurtt Professional Skepticism Scale, a 30-item professional
skepticism questionnaire, to measure professional skepticism using a six-point Likert
scale, which ranged from 1 (Strongly Disagree) to 6 (Strongly Agree).
This chapter presents the means by which the trustworthiness of data in relation to
credibility, transferability, dependability, and confirmability was secured. It provides the
descriptive statistics of the sample demographics and study variables, and the results of
ANOVA and ANCOVA statistical analyses, which were used to ascertain if a significant
relationship existed between the variables. This chapter also includes a brief evaluation
of the research findings.
Trustworthiness of Data
Credibility of the data was achieved by the use of only recognized professional
accounting forums to recruit the participants (i.e., ACFE, AICPA, and VSCPA). Third-
party software, Qualtrics, was used to develop the survey and store the participants’
responses, which provided for a secure and controlled research environment. A validated
instrument was used to measure professional skepticism, the Hurtt Professional
99
Skepticism Scale, which has been used by other researchers (i.e., Boyle et al., 2012;
Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014). The materials
used for the fraud risk assessment were Form 10-Ks retrieved from the SEC online public
database. Moreover, the company selected to represent the presence of fraud for the
Form 10-K material selection was found by a review of the SEC AAER online public
database.
Transferability of the data was achieved by the use of specific detailed
descriptions of the research problem, the purpose of the study, the participants, the
research design and methodology, and the statistical results. Auditors, regulators,
researchers, and academicians may compare other research studies and/or audit findings
to this research study to search for similarities and differences in the research
methodology used and the results found. The use of a third-party survey application,
Qualtrics, in conjunction with MS Excel and SPSS statistical applications, strengthened
the study’s transferability, as most readers of the study are familiar with these research
applications.
Dependability of the data was achieved by the use of instruments and online
forums to provide for the replication of the research study. The instruments used (i.e.,
Form 10-Ks, Hurtt Professional Skepticism Scale) are publicly available for other
researchers to use to duplicate the study design. The accounting and fraud-related
professional online discussion forums (i.e., ACFE and LinkedIn) are available to use to
recruit similar participants once authorization is obtained from the groups/organizations.
Confirmability of the data was achieved by the creation of an audit trail of the
participants’ responses in Qualtrics to the statistical results in SPSS. The survey
100
questionnaire (See Appendix E) was saved in Qualtrics along with the participants’
responses. The calculations performed using MS Excel to prepare the data for SPSS was
saved in MS Excel files that were backed up for future retrieval. Additionally, the SPSS
files generated from the statistical analyses (e.g., ANOVA and ANCOVA) were backed
up for future retrieval. As the original data source was saved in Qualtrics, the MS Excel
and SPSS calculations could be replicated, if needed. Hence, it may be assumed that the
study results were a result of the participants’ responses and not the researcher’s biases.
ANOVA and ANCOVA assumptions. A two-way analysis of variance
(ANOVA) and a two-way analysis of covariance (ANCOVA) were the statistical
analyses selected to ascertain if a significant relationship existed between the variables.
In accordance with Field (2013), the assumptions below (e.g., 1 to 6) were tested to
ascertain if an ANOVA was an appropriate statistical test to conduct for the data set. The
ANOVA assumptions had to pass before the additional ANCOVA assumptions were
tested, as the ANCOVA statistical test required that the ANOVA assumptions were met.
Assumption 1. Field (2013) stated that the dependent variable should be a
continuous variable. Fraud risk assessment performance was the dependent variable.
This variable was measured using a seven-point Likert scale. Data was assessed using
four Likert-type items combined, so that an interval measurement scale could be used for
quantitative analyses.
Assumption 2. Field (2013) stated that the independent variables should be
categorical variables. The presence of fraud and auditor certification were the two
independent variables. The 2X3 construct categorized the presence of fraud variable into
101
high-fraud risk and low-fraud risk levels, and auditor certification variable into CFE, CFE
and CPA, and CPA levels.
Assumption 3. Field (2013) stated that there should be independence of
observations, which means that participants cannot be in more than one group. There
were different participants in each of the six groups: High-fraud risk, CFE; High-fraud
risk, CFE and CPA; High-fraud risk, CPA; Low-fraud risk, CFE; Low-fraud risk, CFE
and CPA; and Low-fraud risk, CPA. The participants were assigned to the groups based
on self-identification of professional certification and then randomly assigned by
Qualtrics to one of the two presences of fraud conditions (e.g., high-fraud risk and low-
fraud risk).
Assumption 4. Field (2013) stated that there should be no significant outliers.
SPSS Statistics version 24 was used to identify outliers using boxplots. One participant
was an outlier in the boxplots of the CFE professional certification variable and the low-
fraud risk presence of fraud variable. This participant exhibited the attributes of an
extreme outlier as the total fraud risk assessment score was observed to be outside of the
fences of the boxplots for these two variables. Three of the other participants’ fraud risk
assessment scores were observable outliers in the boxplot for the CPA professional
certification variable, but were identified as mild compared to the extreme outlier
identified for the CFE professional certification variable. Before removing the outliers
from the data set, assumptions 5 and 6 were examined to see if the outliers were
significant enough to cause the assumptions to fail. One participant, the outlier in the
low-fraud risk, CFE group, did cause assumption 5 to fail, which, if not corrected, would
have violated the assumption for parametric analyses. Given this failure, this participant
102
was removed from the sample. The other outliers did not cause the assumptions to fail.
Therefore, these other participants were kept in the sample.
Assumption 5. The dependent variable should be normally distributed for each
combination of the groups of the two independent variables. SPSS Statistics version 24
was used to test for normality using the Shapiro-Wilk test. A non-significant (p > .05)
test result indicates that the sample is not significantly different from a normal
distribution. The CPE professional certification, W(48) = .969, p = .234, the CFE and
CPA professional certification, W(41) = .982, p = .758, the CPA professional
certification, W(72) = .967, p = .059, the high risk presence of fraud, W(78) = .984, p =
.459, and the low risk presence of fraud, W(83) = .979, p = .203 did not deviate
significantly from a normal distribution, which is identified as a bell-shaped curve where
observations lie within three standard deviations of the mean (Field, 2013).
Assumption 6. In accordance with Field (2013), there must be homogeneity of
variances for each combination of the groups of the two independent variables. SPSS
Statistics version 24 was used to test the homogeneity of variances using Levene’s test.
A non-significant (p > .05) test result indicates that the variance in the dependent variable
is approximately equal across the various combinations of the independent variables. For
the fraud risk assessment performance, the variances were equal, F(5, 155) = .709, p =
.618. Hence, homogeneity of variance was assumed.
As the ANOVA assumptions passed, two additional assumptions are required to
test the appropriateness of using a two-way ANCOVA for statistical analyses. In
accordance with Field (2013), the additional assumptions (e.g., covariate independence
103
and homogeneity of regression slopes) were tested. The assumption test results are
outlined below.
Assumption 7. Field (2013) stated that the covariate must be independent of the
independent variables. SPSS Statistics version 24 was used to test the covariate’s
independence by running a two-way ANOVA with professional skepticism as the
dependent variable and the independent variables, presence of fraud risk and auditor
certification, as the predictors. For the presence of fraud risk variable, F(1, 157) = .000, p
= .988. For the auditor certification variable, F(2, 157) = .402, p = .670. Hence,
professional skepticism was not significantly different in the two groups (p > .05), thus
independence of the covariate was assumed.
Assumption 8. Field (2013) stated that there must be homogeneity of regression
slopes, which means that the relationship between the dependent variable and the
covariate is the same in each of the groups. SPSS Statistics version 24 was used to test
the homogeneity by customizing the model of the two-way ANCOVA for an interaction
between the covariate and the independent variables. The outcome interaction (auditor
certification X presence of fraud X professional skepticism) resulted in F(5, 151) = 1.171,
p = .326, which demonstrated that the homogeneity of regression slopes was not broken
because p < .05.
Results
The sample demographics collected for the research study included age, gender,
U.S. geographical region, years of audit experience, and years of fraud risk assessment
experience. The study variables included the two independent variables, the presence of
fraud and auditor certification, while considering the covariate of professional skepticism,
104
on the dependent variable of fraud risk assessment performance. Three research
questions guided the study: a) Does the presence of fraud risk have an effect on fraud risk
assessment performance?, b) Does a certification in fraud knowledge have an effect on
fraud risk assessment performance?, and c) Does professional skepticism influence fraud
risk assessment performance? To answer the research questions, a two-way ANOVA and
a two-way ANCOVA were performed to determine the effect of the presence of fraud
risk and auditor certification on fraud risk assessment performance. A brief evaluation of
the findings is presented.
Descriptive statistics of the sample demographics and the study variables. Of
the 398 surveys started, 162 surveys were completed, which resulted in a 41% survey
completion rate over a seven-month period. Of the 162 participants, one outlier was
removed because it created violations in normality between the variables in the CFE low-
fraud risk group (Field, 2013). SPSS was used to test for normality between the variables
using the Shapiro-Wilk test, which resulted in a violation of normality as p = .006 for the
combination of the professional skepticism score and the fraud risk assessment
performance score. The resulting normally distributed sample of 161 participants
consisted of 78 participating in the high-fraud risk condition and 83 participating in the
low-fraud risk condition. The percentage of participants possessing the CFE, CPA and
CFE, and CPA certification was 30%, 25%, and 45%, respectively. The majority of the
participants (62%) were representative of the Northeast (29%) and the Southeast (33%)
U.S. geographical regions. More males (67%) than females (33%) participated in the
study. The overall average age was 47 years, the overall years of audit experience was 11
years, and the overall years of fraud risk assessment experience was 9 years. Descriptive
105
analyses were conducted to make comparisons in the age, years of audit experience, years
of fraud risk assessment experience, gender, and U.S. geographic region of the
participants in the six groups to provide support for generalizability of the research
findings.
Table 1 summarizes the mean, number of participants, and standard deviation for
age, years of audit experience, and years of fraud risk assessment experience for the six
groups. Table 2 summarizes the count of participants by gender and geographic region
for the six groups. Table 3 summarizes the mean, number of participants, and standard
deviation for the dependent variable, fraud risk assessment performance, and for the
covariate, professional skepticism, for the six groups.
Table 1
Descriptive Statistics of Age and Years of Experience for Audit and Fraud Risk Assessment
Certification Age
Years of Experience
Audit Fraud High- fraud risk
CFE
M N SD
46.96 28 12.48
10.79 28 11.70
11.57 28 10.13
High- fraud risk
CFE + CPA
M N SD
43.94 18 13.69
14.39 18 12.66
11.11 18 6.69
High- fraud risk
CPA
M N SD
46.59 32 13.10
10.16 32 10.48
6.69 32 9.21
High- fraud risk
Total
M N SD
46.12 78 12.91
11.36 78 11.42
9.46 78 9.61
Low- fraud risk
CFE
M N SD
48.15 20 13.32
6.65 20 5.97
7.45 20 6.79
106
Low- fraud risk
CFE + CPA
M N SD
51.43 23 13.04
19.91 23 10.37
13.91 23 9.07
Low- fraud risk
CPA M N SD
46.33 40 13.54
8.88 40 9.97
6.63 40 8.99
Low- fraud risk
Total M N SD
48.18 83 13.33
11.40 83 10.64
8.84 83 9.01
Total Fraud Risk
Total M N SD
47.18 161 13.13
11.38 161 10.99
9.02 161 9.28
The comparison of the mean and standard deviation, for the six groups, provide support
for the similarity in age, years of audit experience, and years of fraud risk assessment
experience between the groups.
Table 2
Descriptive Statistics of Gender and U.S. Geographic Region
Gender
Geographic Region Certification Male Female NE SE SW W MW
High- fraud risk
CFE 19 9 6 9 5 3 5 CFE+CPA 11 7 5 7 3 1 2
CPA 20 12 7 11 5 5 4
Total 50 28 18 27 13 9 11
Low- fraud risk
CFE 14 6 5 10 2 1 2
CFE+CPA 13 10 6 5 4 3 5
CPA 31 9 17 12 3 2 6
Total 58 25 28 27 9 6 13
Total 108 53 46 54 22 15 24
107
Table 2 illustrates a higher participation rate of males and a higher participation rate of
participants from the Northeast and Southeast U.S. geographic regions. This table also
illustrates the similarity of the gender and geographic region distribution between the six
groups.
Table 3
Descriptive Statistics of Fraud Risk Assessment and Professional Skepticism Score
Certification
Score
Fraud Risk Professional Skepticism
High- fraud risk
CFE
M N SD
19.61 28 3.24
145.11 28 20.84
High- fraud risk
CFE + CPA
M N SD
17.67 18 3.69
144.72 18 16.16
High- fraud risk
CPA
M N SD
18.19 32 3.37
139.25 32 23.54
High- fraud risk
Total
M N SD
18.58 78 3.45
142.62 78 21.00
Low- fraud risk
CFE
M N SD
19.80 20 3.02
139.40 20 26.20
Low- fraud risk
CFE + CPA
M N SD
20.87 23 3.79
145.04 23 25.08
Low- fraud risk
CPA M N SD
20.60 40 3.88
142.92 40 12.15
Low- fraud risk
Total M N SD
20.48 83 3.64
142.66 83 20.06
Total Fraud Risk
Total M N SD
19.56 161 3.67
142.64 161 20.54
108
The mean comparisons of the fraud risk assessment score variable did
demonstrate an observable change in the mean fraud risk assessment score between the
high-fraud risk group and the low-fraud risk group of 18.58 versus 20.48. In the high-
fraud risk group, the CFE certification participants had the highest average fraud risk
assessment score (19.61), and in the low-fraud risk group the CFE certification
participants had the lowest average fraud risk assessment score (19.80). The mean
comparisons of the professional skepticism score did not depict an observable change
between the high-fraud risk and the low-fraud risk groups, which means that it was not
possible to make the determination that the level professional skepticism does or does not
have an impact on fraud risk assessment performance. However, the CPA certification
participants had the lowest average professional skepticism score (139.25) in the high-
fraud risk group and the CFE certification participants had the lowest average
professional skepticism score (139.40) in the low-fraud risk group. CFE certification
participants in the high-fraud risk group and the CFE and CPA certification participants
in the low-fraud risk group, respectively demonstrated the highest average professional
skepticism scores of 145.11 and 145.04.
Adjusted group means. To better understand the effect of the covariate,
professional skepticism, on the group means for fraud risk assessment performance,
SPSS Statistics version 24 was used to adjust the group means for the covariate. Table 4
provides the group means with and without the effect of the covariate. The group means
were similar, which showed no observable influence of professional skepticism on fraud
risk assessment performance.
109
Table 4
Group Means With and Without the Effect of the Covariate
Certification With
Without High- fraud risk
CFE 19.54 19.61 CFE+CPA 17.61 17.67
CPA 18.29 18.19
Low- fraud risk
CFE 19.89 19.80
CFE+CPA 20.81 20.87
CPA 20.59 20.60
Research Question 1
Research Question 1 examined the effect of the presence of fraud risk on fraud
risk assessment performance. The hypothesis tested was that a high level of fraud risk
produced a high fraud risk assessment performance. SPSS version 24 was used to
perform statistical analyses on the data. A two-way ANOVA test was performed with
fraud risk assessment performance score as the dependent variable, and with the presence
of fraud risk and auditor certification as the independent variables. The ANOVA test
yielded a significant main effect of the presence of fraud on fraud risk assessment
performance, F(1, 155) = 11.17, p = .001. The mean fraud risk assessment score was
significantly greater for the low-fraud risk condition (M = 20.48, SD = 3.64) than for the
high-risk fraud condition (M = 18.58, SD = 3.45). Hence, this score resulted in the
rejection of the null and the alternative hypothesis. The alternative hypothesis was
rejected because the low-fraud risk condition produced a higher fraud risk assessment
performance than the high-fraud risk condition.
110
Research Question 2
Research Question 2 examined the effect of auditor certification (CFE, CFE and
CPA, or CPA) on fraud risk assessment performance. The hypothesis tested was that
auditors who possess a certification in fraud detection produce more effective fraud risk
assessment performance than auditors without the certification. SPSS version 24 was
used to perform statistical analyses on the data. A two-way ANOVA test was performed
with fraud risk assessment performance score as the dependent variable, and with the
presence of fraud risk and auditor certification as the independent variables. The
ANOVA test resulted in a non-significant main effect of auditor certification on fraud
risk assessment performance, F(2, 155) = .182, p = .834. Bonferroni post hoc tests
revealed no significant difference between the combinations of auditor certifications, p =
1 for all combinations, which indicated the means for the CPA, CPA/CFE, and CFE
variables were almost identical. Planned contrasts were also performed using a Helmert
contrast, which compared each auditor certification category against all subsequent
categories. Planned contrasts of the auditor certification variable revealed that having a
CFE certification compared to having either a CFE and CPA or a CPA certification, p =
.552, or a having a CFE and CFE certification compared to a CPA certification, p = .857,
did not have a significant effect on the fraud risk assessment performance. Additionally,
there was a non-significant interaction between the presence of fraud and auditor
certification on fraud risk assessment performance, F(2, 155) = 2.22, p = .112. The
aforementioned result indicates that the presence of fraud was not affected differently by
auditor certifications. Hence, these findings resulted in the acceptance of the null
hypothesis.
111
Research Question 3
Research Question 3 examined if professional skepticism influences fraud risk
assessment performance. The hypothesis tested was that auditors who exhibited
professional skepticism produce more effective fraud risk assessment performance than
auditors without professional skepticism. SPSS version 24 was used to perform
statistical analyses on the data. A two-way ANCOVA test was performed with fraud risk
assessment performance score as the dependent variable, the presence of fraud risk and
auditor certification as the independent variables, and professional skepticism as the
covariate. Planned contrasts were also performed using simple contrasts and post hoc
tests using a Sidak correction. Levene’s test was not significant, F(5, 155) = .509, p =
.769, which demonstrated that the group variances were equal and the assumption of
homogeneity of variance was not violated. The ANCOVA test and planned contrasts
resulted in the acceptance of the null hypothesis due to the following results:
• The covariate, professional skepticism, was not significantly related to fraud
risk assessment performance, F(1, 154) = 3.84, p = .052. There was not a
significant effect of professional certification on fraud risk assessment
performance after controlling for the effect of professional skepticism, F(2,
154) = .228, p = .797. There was a significant effect of presence of fraud on
fraud risk assessment performance after controlling for the effect professional
skepticism, F(1, 154) = 11.550, p = .001.
• Planned contrasts of the auditor certification variable revealed that having a
CPA certification compared to having a CFE certification, p = .674, or
compared to having a CFE and CFE certification, p = .743, did not have a
112
significant effect on the fraud risk assessment performance. Additionally, the
contrast of having a CFE certification compared to having a CPA and CFE
certification, p = .504, did not have a significant effect on the fraud risk
assessment performance.
• Planned contrasts revealed that having a CPA certification did not
significantly increase fraud risk assessment performance compared to having
a CFE certification, t(157) = -.733, p = .464 or a CFE and CPA certification,
t(158) = .232, p = .817.
• Planned contrasts revealed that the presence of no fraud significantly
increased the fraud risk assessment performance compared to the presence of
fraud, t(156), = -2.776, p = .006.
Evaluation of Findings
The 2X3 between-participants quantitative research study provided an evaluation
of two independent variables (e.g., the presence of fraud and auditor certification), while
considering a control variable (e.g., professional skepticism) to measure the outcome on
fraud risk assessment performance. The theoretical foundations for this research study
were fraud theory and attribution theory. Fraud theory uses the fraud triangle to explain
the criteria that must be present for fraud to occur (Dorminey et al., 2010). The elements
of the fraud triangle, opportunity, pressure, and rationalization, are used in fraud theory to
explain the presence of fraud (Dorminey et al., 2012). The auditing profession has
integrated the fraud triangle in the auditing standards (i.e., AU Section 316 and SAS No.
99) to assess fraud risk in financial statement audits. Attribution theory relates internal
and/or external attributes to the performance of a task. This research study investigated
113
the effects of the presence of fraud using a company’s fraudulent and restated Form 10-
K. This research study examined the effects of auditor certification through the selection
of participants with CPA and CFE certifications on the participants’ fraud risk assessment
performance of a randomly assigned Form 10-K. Fraud risk assessment performance was
measured by a seven-point Likert scale, which ranged from 1 (Very
Improbable/Insignificant) to 7 (Very Probable/Significant). Consideration was made for
the participants’ level of professional skepticism by the completion of the 30-item Hurtt
Professional Skepticism Scale questionnaire, which was measured using a six-point
Likert scale ranging from 1 (Strongly Disagree) to 6 (Strongly Agree).
Research Question 1. Research Question 1 examined the effect of the presence
of fraud risk on fraud risk assessment performance. The statistical results from a two-
way ANOVA showed a significant effect for the presence of fraud on fraud risk
assessment performance; hence, the null hypothesis was rejected. However, instead of a
direct relationship between the presence of fraud and the fraud risk assessment there was
an inverse relationship as the participants’ average fraud risk assessment score (20.48), in
the low-fraud risk group, was higher than the participants’ average fraud risk assessment
score (18.58) in the high-fraud risk group. Hence, the alternative hypothesis, which
hypothesized that the presence of fraud produces a high-fraud risk assessment, failed
because the experiment results did not support the assumption.
Research Question 2. Research Question 2 examined the effect of auditor
certification (CFE, CFE and CPA, or CPA) on fraud risk assessment performance. The
statistical results from a two-way ANOVA did not show a significant effect for auditor
certification on fraud risk assessment performance; hence, the null hypothesis was
114
accepted. This finding does not support the value of the CFE certification for fraud risk
assessment evaluations, as recommended by SAS No. 99 (Nix & Morgan, 2013).
Research Question 3. Research Question 3 examined if professional skepticism
influences fraud risk assessment performance. The statistical results from a two-way
ANCOVA did not show a significant effect for professional skepticism on fraud risk
assessment performance; hence, the null hypothesis was accepted. This finding is not
only contrary to the majority of past research studies, but to the beliefs of the regulators
(i.e., PCAOB and SEC) that a lack of professional skepticism provides for ineffective
fraud risk assessments (Trompeter et al., 2013).
Summary
The purpose of this research study was to examine the effects of the presence of
fraud risk and auditor certification while considering professional skepticism on fraud
risk assessment performance. The results of the two-way ANOVA and ANCOVA
statistical tests resulted in only one significant finding – the presence of fraud risk had a
significant effect on fraud risk assessment performance, with and without considering the
influence of professional skepticism. However, alternative hypothesis one, for the
presence of fraud risk on fraud risk assessment performance, was rejected because the
low-fraud risk groups produced a higher fraud risk assessment performance than the
high-fraud risk groups even though null hypothesis one was rejected. The test results did
not demonstrate a statistically significant effect of auditor certification or professional
skepticism on fraud risk assessment performance, which led to the acceptance of null
hypothesis two and three.
115
Chapter 5: Implications, Recommendations, and Conclusions
According to the ACFE’s Report to the Nations on Occupational Fraud and
Abuse (2014), occupational fraud continues to be a global problem with organizations
losing approximately 5% of annual revenues to fraud. Drew (2014) reported that
financial statement fraud is the most costly to organizations. The accounting profession
and regulators have enacted auditing standards and regulations (i.e., SAS No. 99 and AU
Section 316) to improve the detection and prevention of financial statement fraud. One
of the techniques that must be performed by external auditors during a financial statement
audit is a fraud risk assessment. However, fraud risk assessments have not produced
effective results in fraud detection (Hopwood et al., 2012). SAS No. 99 emphasizes the
importance of professional skepticism to detect financial statement fraud (Nix & Morgan,
2013). However, the PCAOB found deficiencies in auditors’ responses to fraud risk and
stated, “the lack of professional skepticism is a serious problem in auditors’ fraud
investigations” (Trompeter et al., 2013, p. 304).
The purpose of this experimental between-participants quantitative research study
was to examine the theoretical underpinnings of fraud and attribution in relation to the
independent variables of the presence of fraud and auditor certification, the control
variable of professional skepticism, and the dependent variable, fraud risk assessment
performance, for participants within the U.S., who identified themselves as either
certified fraud examiners and/or certified public accountants. The study was conducted
online by obtaining volunteer participants from professional online forums (i.e., ACFE,
AICPA, and VSCPA) to complete an experimental survey using the Qualtrics
application. Auditor certification was categorized by the participants’ self-identification
116
of professional certification(s) (e.g., CFE, CFE/CPA, or CPA). The participants in each
group completed the 30-item six-point Hurtt Professional Skepticism Scale questionnaire
to measure professional skepticism. After completing the professional skepticism
questionnaire, the participants were given one of two sets of financial statement materials
(e.g., Form 10-K) to review and to perform a fraud risk assessment using a seven-point
Likert scale. One set of materials represented fraudulent financial statements of a U.S.
publicly traded corporation (high-fraud risk), and the other set of materials represented
the restated financial statements of the same corporation (low-fraud risk). SPSS Statistics
version 24 was used to conduct a two-way ANOVA and ANCOVA to answer the
research questions and test the hypotheses.
Several limitations were identified for the current research study. First, the
selection of the experimental materials (i.e., Form 10-Ks) limited generalizability to only
U.S. companies listed on the U.S. stock exchange. Second, the study only used one
corporation’s financial statement and nonfinancial data (i.e., Form 10-Ks) to assess fraud
risk assessment performance, which reduced external validity. Third, the fraud risk
assessment design process excluded participant group interactions, such as brainstorming
sessions, as required by the SAS No. 99 auditing standards for financial statement fraud
risk assessment, which weakened internal validity. Fourth, the study excluded financial
statement audit experience and/or forensic auditing experience as an independent or
mediating variable, which may have had an effect on the fraud risk assessment
performance outcome; hence, this created an internal validity construct limitation.
However, the fourth limitation was mitigated by only including participants with specific
auditor certification attributes (i.e., CFE and CPA) in the study.
117
The research design met Northcentral University’s IRB Category 2 criterion for
exempt reviews, which indicated that the ethical issues associated with this research
study were minimal. Participants’ risk of harm was minimized as they only performed a
fraud risk assessment on a set of financial statements and completed a validated
professional skepticism questionnaire. Informed consent was obtained from all of the
participants without deception or coercion. Furthermore, confidentiality was maintained
through the secure storage of data, even though the use of the Internet for the online
survey presented a risk for a confidentiality breach. Finally, privacy and anonymity were
provided as participant names were not collected and a third-party online survey software
was used.
This chapter discusses the study implications of each research question and
hypothesis. Logical conclusions will be drawn for each research question with a
discussion of any potential limitations that may have affected the interpretation of the
results. Finally, this chapter concludes with recommendations for practice, as well as
recommendations for future research.
Implications
The following research questions guided the study: a) Does the presence of fraud
risk have an effect on fraud risk assessment performance?, b) Does a certification in fraud
knowledge have an effect on fraud risk assessment performance?, and c) Does
professional skepticism influence fraud risk assessment performance? To answer the
research questions, a two-way ANOVA was performed to determine the effect of the
presence of fraud risk and auditor certification on fraud risk assessment performance.
Then, after reviewing the results, a two-way ANCOVA was conducted to examine the
118
variability in the fraud risk assessment performance outcome due to the participants’
professional skepticism measurement. Results from the statistical analyses revealed that
neither auditor certification nor professional skepticism had a significant effect on fraud
risk assessment performance. However, the results did show that the presence of fraud
did have a significant effect on fraud risk assessment performance. Each question, and its
related hypothesis, are discussed below, along with logical conclusions and limitations.
The research implications and recommendations for practical application and future
research are also provided below.
Research Question 1. Does the presence of fraud have an effect on fraud risk
assessment performance?
The hypothesis that was tested to ascertain if the presence of fraud had an effect on fraud
risk assessment performance was as follows:
H10. The presence of fraud risk does not have a significant effect on fraud risk
assessment performance.
H1a. The presence of fraud risk produces a high level of fraud risk assessment
performance.
Financial statement fraud costs companies more financially than any other type of
occupational fraud (Alleyne & Elson, 2013). Auditing regulators have attempted to
minimize the losses from financial statement fraud by implementing fraud detection
auditing standards (e.g., SAS No. 99). Auditing standards require auditors to conduct a
fraud risk assessment during a financial statement audit; however, there is not a standard
fraud risk assessment framework to use for the assessment process. The material used by
the participants in this research study to examine financial statements fraud risk was a
119
company’s Form 10-K filing from the SEC database of U.S. publicly traded companies.
Three groups of participants assessed a U.S. company’s Form 10-K that contained known
fraud to create high-fraud risk groups, and three groups of participants assessed the
company’s restated Form 10-K that did not contain known fraud to create low-fraud risk
groups. The participants’ fraud risk assessment was measured by answering four fraud
assessment questions after reviewing the Form 10-K using a seven-point Likert scale. An
ANOVA statistical analysis revealed a statistically significant relationship between the
presence of fraud and fraud risk assessment performance; hence, the null hypothesis was
rejected. The rejection of the null hypothesis means that the presence of fraud is a
significant predictor of fraud risk assessment performance.
The alternative hypothesis was that the Form 10-K with the high-fraud risk would
produce a higher fraud risk assessment outcome than the Form 10-K with the low-fraud
risk. However, this was not the result. The average fraud risk assessment score was
19.56 for the low-fraud risk groups and 18.58 for the high-fraud risk groups. Therefore,
the alternative hypothesis was rejected. This alternative hypothesis rejection supports
Trotman and Wright’s (2012) beliefs that management’s ability to disguise fraud in
financial statements is a significant risk to fraud risk assessment outcomes. Goel and
Gangolly (2012) also posited that fraudulent companies employ various techniques in
annual financial reports to manipulate financial information, which may prevent auditors
from detecting financial statement fraud. This finding supports Hogan et al. (2008)
discussions that the use of traditional analytical procedures (e.g., ratio analysis,
relationships between financial and nonfinancial measures, and Benford’s Law) using
financial statement data has limited success in fraud detection. Kaminski and Wetzel (as
120
cited in Hogan et al., 2008) did not find any difference in the use of ratios to detect
financial statement fraud between fraudulent and non-fraudulent companies. The
experiment conducted by Kaminski and Wetzel (as cited in Hogan et al., 2008) did not
expose the participants to any conditions that may have influenced the results or require
the participants to use specific methods in performing the fraud risk assessment; hence,
the methodology used by the participants is unknown but the instrument (Form 10-K)
only provided data on business operations, financial condition, and management
discussion and analysis. This experiment provides support for the postulations of other
researchers that auditors need to expand the focus of fraud detection beyond the guidance
issued in AU Section 316 SAS No. 99 (Abbasi et al., 2012; Buchholz, 2012; Dorminey et
al., 2010; Goel & Gangolly, 2012; Kassem & Higson, 2012; Lokanan, 2015; Love, 2012;
Trotman & Wright, 2012).
Because the hypotheses were rejected, the implication is that fraud risk cannot be
effectively predicted. The research results also provide evidence to support that the
current financial statement fraud risk assessment process is not effective in fraud
detection, specifically since the financial statements evaluated in the low-fraud risk
condition produced a more effective fraud risk assessment performance than the financial
statements evaluated in the high-fraud risk condition. As auditing standards do not
require standardized approaches for performing fraud risk assessments, this experiment
allowed the participant to perform a fraud risk assessment of a company’s financial
statements without the use of standardized processes. The participants’ fraud risk
assessment was measured by a scale of four similar Likert-type questions: a) likelihood
of fraud risk, b) significance of fraud risks, c) significance of anti-fraud controls in use,
121
and d) likelihood of fraud. Hence, the fraud risk assessment was based on professional
judgment as it is in current practice. This study contributes to other researchers’
recommendations that the auditing profession should consider other methods for fraud
risk detection as the participants assessed the restated financial statements, assuming low-
fraud risk, higher than the fraudulent financial statements. Boritz and Timoshenko
(2014) recommended a standardized tool for conducting fraud risk assessments to
minimize auditor judgment. A standardized framework for performing fraud risk
assessments may strengthen risk assessment performance, as Hammersley et al. (2010)
found support for the use of priming before risk assessment; hence, a checklist could be
used to prime the auditor for the fraud risk assessment. Abbasi et al. (2012) developed a
metafraud framework using business intelligence for financial fraud risk assessment.
Abbasi et al. (2012) used financial ratios and organizational and industry contextual
information to evaluate companies’ quarterly and annual reports and found the metafraud
framework was effective for financial statement fraud detection. Favere-Marchesi (2013)
found that the use of fraud judgment decomposition was more effective than fraud risk
factor categorization, which is the SAS No. 99 requirement. SAS No. 99 requires the use
of the fraud triangle to evaluate risk by categorizing fraud risk into the elements of
opportunity, pressure/incentive, and rationalization (Nix & Morgan, 2013). Yet, Favere-
Marchesi (2013) found that examining the fraud risks, instead of classifying fraud risks,
resulted in more effective fraud risk assessments.
The results of the study may have implications to the auditing profession and
regulators regarding the development of auditing standards and processes for financial
statement fraud detection. The implication of using the fraud triangle as the theoretical
122
framework for predicting financial statement fraud may be too restrictive, as the lack of
fraud detection in financial statement audits is in excess of one trillion dollars (Kravitz,
2012), which is indicative of a significant problem. Dorminey et al. (2010) and Abbasi et
al. (2012) recommended a meta-fraud framework to broaden the scope of fraud detection.
Hogan et al. (2008) and Abbasi et al. (2012) proposed the use of business intelligence
(e.g., data mining and pattern recognition) for improving fraud assessments. As auditing
standards do not require checklists or models for evaluating fraud risk, the results of this
study provide support for the identification of accurate tools to detect financial statement
fraud and to minimize the costs associated with financial statement fraud. Boritz and
Timoshenko (2014) and Rose et al. (2012) found that the use of fraud checklists
increased the effectiveness of fraud risk assessments. Additionally, Knapp and Knapp
(2001) found that fraud risk assessment instructions resulted in more effective fraud risk
assessments.
This study adds to the existing research that the auditing profession needs to
develop more effective methodologies to evaluate the presence of fraud in financial
statements. It is apparent from the results of this study that more effective tools are
needed to identify warning factors present in financial statements to increase fraud risk
assessment outcomes. This study also provides support for the use of multiple
methodologies to detect fraud as the review of only a Form 10-K was not effective in
detecting fraud.
123
Research Question 2. Does a certification in fraud knowledge have an effect
on fraud risk assessment performance?
The hypothesis that was tested to ascertain if a certification in fraud knowledge
had an effect on fraud risk assessment performance was as follows:
H20. A certification in fraud knowledge does not have a significant effect on fraud
risk assessment performance.
H2a. Auditors that possess a certification in fraud detection produce more
effective fraud risk assessment performance than auditors without the
certification.
According to Nix and Morgan (2013), the CFE certification is indicative of fraud
assessment and detection knowledge. The participants were divided into three groups
based on the following certifications: CFE, CFE and CPA, and CPA. It was
hypothesized that the participants with the CFE certification would perform more
effective fraud risk assessments than the participants without the CFE certification due to
multiple research findings. Nix and Morgan (2013) and Popoola et al. (2014) confirmed
a positive relationship between fraud knowledge and fraud risk assessment. Hammersley
(2011) found support for fraud training, to gain fraud knowledge, which in turn resulted
in more accurate fraud risk assessments.
An ANOVA statistical analysis did not reveal a statistically significant
relationship between auditor certification and fraud risk assessment performance; hence,
the null hypothesis was accepted. This finding means that auditor certification is not a
significant predictor of fraud risk assessment performance. This outcome supported
Boritz et al.’s (2015) finding that fraud specialists were not more effective than financial
124
statement auditors in conducting fraud risk assessments. This research study, as well as
the study conducted by Boritz et al., excluded fraud brainstorming sessions as part of the
construct, which may be seen as a limitation for performing fraud risk assessments, as
required by SAS No. 99.
The results of the study may have implications to the ACFE’s certified fraud
examiner credential and SAS No. 99’s support of CFE certifications in fraud risk
assessment evaluations, since it did not support the belief that the CFE credential
produces more effective fraud risk assessment performance. Hence, regulators may want
to reconsider the recommendation that auditors should seek assistance from fraud
specialists during financial statement audits because the use of fraud specialists may not
result in more effective fraud risk assessment outcomes. The aforementioned finding
contradicted Carpenter, Durtschi, and Gaynor’s (2011) findings that fraud knowledge had
a positive impact on fraud risk assessment performance.
This study adds to the existing research that auditor certifications may not be the
best credential to use to measure fraud knowledge. The insignificant relationship
between the auditor certifications provides evidence that individuals with the CFE
credential do not provide more effective fraud risk assessment outcomes than individuals
with the CPA credential. Thus, this finding challenged Kassem and Higson’s (2012)
recommendation to regulators to consider requiring CPA candidates to obtain a CFE
certification prior to qualifying for a CPA certification.
125
Research Question 3: Does professional skepticism influence fraud risk
assessment performance?
The hypothesis that was tested to ascertain if professional skepticism has an
influence on fraud risk assessment performance was as follows:
H30. The level of auditor professional skepticism does not have a significant
influence on fraud risk assessment performance.
H3a. Auditors that exhibit professional skepticism produce more effective fraud
risk assessment performance than auditors without this attribute.
According to the PCAOB, auditors lack professional skepticism, which results in
ineffective fraud assessments (Trompeter et al., 2013). The instrument used by all of the
participants to measure professional skepticism was the 30-item Hurtt Professional
Skepticism Scale, which used a six-point Likert scale for measurement. The study results
provided evidence that the professional skepticism level of the participants was
negatively skewed, which indicated a higher level of professional skepticism. It was
hypothesized that the participants with a higher level of professional skepticism would
perform more effective fraud risk assessments. An ANCOVA statistical analysis did not
reveal a statistically significant relationship between professional skepticism and fraud
risk assessment performance; hence, the null hypothesis was accepted. Often, the finding
that professional skepticism does not have a significant influence on fraud risk
assessment performance would mean that professional skepticism is not a significant
predictor of fraud risk assessment performance. The negative skew of the professional
skepticism scores and the similarity of the average score between the six groups do not
provide sufficient evidence to make the determination that the level professional
126
skepticism does or does not have an impact on fraud risk assessment performance. As
the professional skepticism scores of all participants are similar, it is not possible to
compare participants with different levels of professional skepticism to evaluate the
influence on fraud risk assessment performance.
The negative skew (-2.341) of the participants’ professional skepticism scores,
which was due to high scores, and the pointy and heavy-tailed distribution demonstrated
by a positive kurtosis (9.130), may be due to the requirement that the participants had to
possess either a CFE and/or a CPA certification. The negative skew may explain the
finding that professional skepticism did not have a significant effect on fraud risk
assessment performance. Moreover, this finding may have implications for the PCAOB,
as the majority of the participants did exhibit high levels of professional skepticism, but
the high level of professional skepticism did not result in a more effective fraud risk
assessment outcome.
Nix and Morgan (2013) reported that SAS No. 99 emphasizes the importance of
professional skepticism in the performance of fraud risk assessment. Furthermore,
Carpenter and Reimers (2013) stated that the PCAOB cited the lack of professional
skepticism as a factor for ineffective fraud risk assessments. Hurtt et al. (2013)
acknowledged the importance of professional skepticism, and other researchers provided
support of a significant positive relationship between professional skepticism and fraud
risk assessment outcomes (Bowlin et al., 2015; Boyle et al., 2015; Carpenter & Reimers,
2013; Trotman & Wright, 2012; Wei et al., 2015). Moreover, Boyle et al.’s experiment
controlled for professional skepticism using the Hurtt Professional Skepticism Scale and
used ANCOVA to conduct statistical analysis, as did this research study. As SAS No. 99
127
emphasizes the importance of professional skepticism to evaluate the risks of financial
statement fraud, auditors must demonstrate appropriate levels of professional skepticism
(Boyle et al., 2015; Nix & Morgan, 2013).
The study results may have been influenced by the construct of the research
design. The participants were required to complete the professional skepticism
questionnaire prior to the fraud risk assessment of the Form 10-K, which may have
primed the participants to be more skeptical for the fraud risk assessment measurement.
Hammersley et al. (2010) investigated the influence of priming participants before
performing a fraud risk assessment and found a positive influence of priming before the
fraud risk assessment, especially when the participants received documented fraud risks
before the fraud risk assessment.
The results of the study may have implications to the auditing profession,
regulators, and researchers in regards to the influence of professional skepticism on fraud
risk assessments. As Hurtt et al. (2008) found, “the behavioral differences do not always
go in the direction of higher skepticism being associated with more skeptical behavior”
(p. 25). This research study provides support for the professional skepticism gap between
researchers and regulators, as posited by Hurtt et al. (2013). Both the SEC and PCAOB
believe that higher levels of professional skepticism result in more effective fraud risk
assessments (Carpenter & Reimers, 2013; Hurt et al., 2013; Trompeter et al., 2013).
While some researchers provide evidence to support that professional skepticism has a
positive influence on fraud risk assessments (Boyle et al., 2015; Wei et al., 2015), other
researchers did not find evidence to support the positive influence of professional
skepticism on fraud risk assessments (Jaffar et al., 2011; Peytcheva, 2014). Rasso (2015)
128
provided evidence to support the influence of behavior on professional skepticism by
comparing high-level versus low-level documentation instructions on fraud risk
assessments; hence, abstraction (low-level) outperformed specificity (high-level).
This study adds to the existing research that participants with higher levels of
professional skepticism did not significantly influence the fraud risk assessment
outcomes. Hence, the study provides support for more research on the influence of
professional skepticism behavior versus the influence of the professional skepticism
attribute on fraud risk assessment performance. Additionally, this study adds to the
existing research that participants that possess the CFE certification did not significantly
produce more effective fraud risk assessment outcomes than the participants that
possessed only the CPA certification. Thus, further research is needed to evaluate
differences in the CFE and CPA certification, specifically in relation to evaluating
financial statement fraud risks.
Recommendations for Practice
To expand the literature with regard to achieving effective fraud risk assessment
outcomes, two research recommendations are proposed for application. First, researchers
and regulators should develop a standard checklist to use for fraud risk assessments that
includes a quantifiable evaluation process. This research study and others (e.g., Favere-
Marchesi, 2013; Jaffar et al., 2011; Popoola et al., 2015; Rasso, 2015; Wei et al., 2015)
used a Likert scale to measure fraud risk assessment performance. Additional data needs
to be captured to better understand the formation of the high-risk versus low-risk
assessments. For example, analytical ratios, data comparisons, management disclosures,
management behaviors, corporate governance, corporate culture (client and audit firm),
129
and auditor attributes and behaviors may be factors affecting these assessments. In order
to understand the difference between effective and ineffective fraud risk assessments,
more detailed fraud risk assessments need to be conducted so that researchers are able to
study the relationships of the various factors that affect auditors’ judgments of fraud risk.
The collection of additional data using a standardized checklist would provide
quantifiable evidence to support the fraud risk assessment outcome, which should reduce
the influence of auditor bias and subjectivity during the fraud risk assessment evaluation.
The lack of a validated instrument for conducting fraud risk assessments provides for the
opportunity of inconsistency and auditor bias in fraud risk assessment outcomes, which
should be a concern for the accounting profession and the regulators.
Second, researchers and regulators need to further evaluate the use of the fraud
triangle as the theoretical framework to perform fraud risk assessments. As required by
SAS No. 99, the fraud triangle is the methodology used to conduct fraud risk assessments
(Dorminey et al., 2012). Numerous researchers have proposed other models to use for
fraud risk assessments (Kassem & Higson, 2012; Lokanan, 2015; Soltani, 2014;
Srivastava et al., 2011). Abbasi et al. (2012) and Dorminey et al. (2012) posited a meta-
model framework that incorporated additional elements for evaluation. Dorminey et al.
(2012) discussed the impact of other fraud models on the fraud triangle (e.g., fraud
diamond, fraud scale, M.I.C.E. model, triangle of fraud action) to provide support for the
weaknesses inherent in the fraud triangle framework for effective fraud detection.
Abbasi et al. (2012) compared the metafraud framework to other fraud detection models
and confirmed that “the viability of using meta-learning methods enhanced financial
statement fraud detection” (p. 1323). Regulators may want to consider the combination
130
of fraud theory with the theory of planned behavior (Cohen et al., 2010) and the
institutional theory of moral collapse (Shadnam & Lawrence, 2011) to strengthen the
theoretical framework used for financial statement fraud detection. As research supports,
a more comprehensive theoretical framework is needed to produce more effective fraud
risk assessment outcomes.
Recommendations for Future Research
To expand the literature, with regard to achieving effective fraud risk assessment
outcomes, several research recommendations are proposed for future research. First,
qualitative or mixed research studies could expand the evaluation of professional
skepticism behaviors on fraud risk assessment outcomes by developing complex practical
applications, which use observations, interviews, and documents to collect data to
increase the internal validity of the study results. Brainstorming, as prescribed in SAS
No. 99, should be incorporated into the qualitative fraud risk assessment construct to
expand upon Wei et al.’s (2015) research, which studied the effects of brainstorming on
auditors’ performance of fraud risk assessments.
Additionally, this research study used only one source of data, Form 10-K, to
measure fraud risk, which is not representative of fraud risk assessments in practice.
Auditors use other qualitative measures to form fraud risk judgments by investigating the
company’s culture, corporate governance, and management’s behaviors and attributes.
Further research is needed to expand upon Campbell and Göritz’s (2014) and Shadnam
and Lawrence’s (2011) examinations of organizational culture to ascertain the influences
of underlying assumptions, regulations, ideologies, values, and norms on financial
statement fraud. Future research is needed to provide more evidence to support Cohen et
131
al.’s (2010) research findings on the relationship between managers’ personality traits
and unethical behaviors. Evidence may support that managers’ behaviors may
significantly influence the occurrence of financial statement fraud.
Second, researchers should develop more instruments to measure professional
skepticism and to test the validity of the Hurtt Professional Skepticism Scale. The Hurtt
Professional Skepticism Scale has been used by many researchers to measure the level of
professional skepticism (e.g., Boyle et al., 2012; Carpenter & Reimers, 2013; Peytcheva,
2014; Quadackers et al., 2014). By combining the other studies that used the Hurtt
Professional Skepticism Scale with this study, researchers could ascertain if the
participants’ average professional skepticism scores varied to evaluate scale limitations.
If the average professional skepticism scores are similar for the participants in other
research studies, there may be reason to question the validity of the Hurtt Professional
Skepticism Scale to measure professional skepticism. To examine the effects of
professional skepticism on variables, researchers must be able to find participants with
both low and high levels of professional skepticism; hence, a validated instrument is
required.
Third, additional research needs to be conducted to better assess the effect of
fraud knowledge on fraud risk assessment performance. This research study measured
fraud knowledge by the presence or absence of the CFE certification for participants
within the U.S., which did not result in a significant effect on fraud risk assessment
performance. This study’s results agreed with Boritz et al. (2015) who used Canadian
participants to examine an actual company’s fraudulent financial statements and found no
significant difference between fraud specialists and financial statement auditors. In
132
contrast, Popoola et al. (2015) evaluated fraud knowledge of auditors and forensic
accountants in Nigeria using a 36-item questionnaire and found a positive relationship
between fraud knowledge and risk assessment. Researchers should not only evaluate the
methodology used to measure fraud knowledge, but also evaluate the cultural influence
on fraud risk assessment outcomes. Different cultures influence the values, norms, and
behaviors of individuals (Hofstede as cited in Ho et al., 2015). Campbell and Göritz
(2014) conducted a study in Germany and found that corrupt organizations shared the
belief that “the end justifies the means,” valued job and organizational security, and
punished non-corrupt behavior (p. 304). Thus, cultural influence may have a significant
effect on the occurrence of financial statement fraud.
Conclusions
The purpose of this quantitative research study was to examine the effect of the
presence of fraud and auditor certification, while controlling for professional skepticism,
on fraud risk assessment performance, for participants within the U.S. who identified as
certified fraud examiners and/or certified public accountants. Financial statement fraud
continues to be challenge for auditors and regulators even after the adoption of fraud
detection and reporting regulations (e.g., Association of Certified Fraud Examiners, 2014;
AU 316 and SAS No. 99). These aforementioned regulations emphasize the use of
professional skepticism when performing the required fraud risk assessment in financial
statement audits. The lack of professional skepticism and ineffective fraud risk
assessment are serious concerns of the PCAOB (Hopwood et al., 2012; Trompeter et al.,
2013). Fraud theory was chosen as one of the theoretical frameworks to guide this study
as SAS No. 99 requires the use of the fraud triangle by auditors to evaluate fraud risk
133
(Nix & Morgan, 2013). Many researchers argue that the fraud triangle is not broad
enough to perform an effective fraud risk assessment (e.g., Boyle et al., 2012; Dorminey
et al., 2010; Lokanan, 2015; Schuchter & Levis, 2015; Soltani, 2014).
The other theoretical framework utilized to ground the study was attribution
theory with a focus on auditors’ internal attributes of professional skepticism and fraud
knowledge in relation to the performance of fraud risk assessments. Fraud knowledge
was examined by comparing the effects of auditor certifications (i.e., CFE, CFE/CPA, or
CPA) on fraud risk assessment performance. Researchers were found to have different
beliefs on the role of professional skepticism in relation to fraud risk assessments (e.g.,
Bolin et al., 2015; Carpenter & Reimers, 2013; Glover & Prawitt, 2014; Lee et al., 2013;
Peytcheva, 2014). The literature also provided mixed perspectives on the importance of
auditors having the certified fraud examiner credential for the performance of fraud risk
assessments (e.g., Boritz et al., 2015; Nix & Morgan, 2013; Popoola et al., 2014).
An experimental 2X3 between-participants research design was assumed to be the
appropriate design choice for this study in order to ascertain how different groups
performed financial statement fraud risk assessments in relation to the presence of fraud
and auditor certification while considering professional skepticism. The participants
were randomly selected through volunteer consent from eligible members of the ACFE,
AICPA, and VSCPA online discussion forums to participate in the online experiment that
was administered by the use of Qualtrics survey software. Participants were randomly
assigned to either the high-fraud risk or the low-fraud risk condition to perform a fraud
risk assessment on a U.S. publicly traded corporation’s Form 10-K. All participants used
Qualtrics to complete a professional skepticism questionnaire and self-report auditor
134
certification status. Likert scales were used to measure the professional skepticism level
and the fraud risk assessment outcome.
The following hypotheses were tested: 1) a high level of fraud risk produces a
high-fraud risk assessment performance, 2) auditors that possess a certification in fraud
detection produce more effective fraud risk assessment performance than auditors
without the certification, and 3) auditors that exhibit professional skepticism produce
more effective fraud risk assessment performance than auditors without this attribute. An
ANOVA statistical analysis revealed a statistically significant relationship between the
presence of fraud and fraud risk assessment performance; however, the high-fraud risk
condition did not produce a higher fraud risk assessment than the low-fraud risk
condition. Therefore, both the null hypothesis and the alternative hypothesis were
rejected for the effect of the presence of fraud on fraud risk assessment performance.
Additionally, an ANOVA statistical analysis did not reveal a statistically significant
relationship between auditor certification and fraud risk assessment performance; hence,
auditor certification was not found to be a significant predictor of fraud risk assessment
performance. An ANCOVA statistical analysis did not reveal a statistically significant
relationship between professional skepticism and fraud risk assessment performance;
however, due to the similarity of the average scores, it was not possible to make the
determination that the level professional skepticism does or does not have an impact on
fraud risk assessment performance.
Several limitations were identified for the research study. First, generalizability
was limited to the U.S. companies listed on the U.S. stock exchanges, as the experimental
materials used were Form 10-Ks of only one company, which was a second limitation.
135
Third, participant group interactions (e.g., brainstorming) as required by SAS No. 99
were excluded from the fraud risk assessment design process. Fourth, financial statement
audit experience and/or forensic auditing experience was excluded as an independent or
mediating variable that may have had an effect on the fraud risk assessment performance
outcome; however, this was mitigated by only including participants with specific auditor
certification attributes (i.e., CFE and CPA) in the experiment.
Due to the multiple influences that effect auditors’ judgment during the
performance of fraud risk assessments, further application and research is needed to
better quantify and understand fraud risk assessments. Prior research studies used a
Likert scale to measure fraud risk assessment performance, as did this study (e.g., Favere-
Marchesi, 2013; Jaffar et al., 2011; Popoola et al., 2015; Rasso, 2015; Wei et al., 2015).
In accordance with Boritz and Timoshenko’s (2014) findings, a customized checklist that
considers the client’s business and the fraud risk assessment factors may strengthen the
standardization of fraud risk assessments and minimize the reliance on auditors’
judgments for fraud risk assessments. Additionally, Rose et al. (2012) reported positive
results from the use of checklists in audit risk assessments. Hence, it is recommended
that fraud risk assessment models should be developed and validated to produce more
effective fraud risk assessments.
Qualitative and/or mixed designs may be more appropriate to examine the
multiple factors influencing the assessment process and to evaluate auditors’ behaviors at
both high and low levels of professional skepticism. Auditors use other qualitative
measures to form fraud risk judgments by investigating the company’s culture, corporate
governance, and management’s behaviors and attributes. Prior research studies (e.g.,
136
Campbell & Göritz, 2014; Cohen et al., 2010; Shadnam & Lawrence, 2011) should be
expanded to better understand the effect of organizational culture and managers’ traits
and behaviors on fraud risk assessment performance. The trait of professional skepticism
may not always exhibit professional skepticism behavior, as posited by Hurtt et al.
(2008), “the behavioral differences do not always go in the direction of higher skepticism
being associated with more skeptical behavior” (p. 25).
Professional skepticism instruments should be developed and validated to
strengthen the validity of research findings for fraud risk assessment effectiveness. The
Hurtt Professional Skepticism Scale has been used by many researchers to measure the
level of professional skepticism, as it was used in this study (e.g., Boyle et al., 2012;
Carpenter & Reimers, 2013; Peytcheva, 2014; Quadackers et al., 2014). To examine the
effects of professional skepticism on variables, the researcher must be able to find
participants with both low and high levels of professional skepticism.
As gaps in current literature exist regarding the impact of auditor certification and
professional skepticism on fraud risk assessment performance, additional research needs
to be conducted to better assess the effect of fraud knowledge on fraud risk assessment
performance (Hammersley, 2011; Ray, 2015; Trompeter et al., 2013). This study’s
results agreed with Boritz et al.’s (2015) findings and contradicted Popoola et al.’s (2015)
results that fraud knowledge effects fraud risk assessment performance. Researchers
should evaluate the methodology used to measure fraud knowledge. Hence, further
research is needed to better understand the complexities of fraud risk assessments to
improve effectiveness in detecting financial statement fraud. Auditing regulations, fraud
137
risk assessment models, auditor attributes, and fraud knowledge have been found to
influence fraud risk assessment performance.
138
References
Abbasi, A., Albrecht, C., Vance, A., & Hansen, J. (2012). Metafraud: A meta-learning framework for detecting financial fraud. MIS Quarterly, 36(4), 1293-1327. Retrieved from http://misq.org/metafraud-a-meta-learning-framework-for- detecting-financial-fraud.html?SID=1t981l056pnhbr0h0d6tnel400
About the AICPA. (n.d.). American Institute of CPAs website. Retrieved from
http://www.aicpa.org/About/Pages/About.aspx About the Virginia Society of CPAs. (n.d.). Virginia Society of CPAs website. Retrieved
from https://www.vscpa.com/content/about_vscpa/mission_vision_goals.aspx Albrecht, W. S., & Hoopes, J. L. (2014). Why audits cannot detect all fraud. CPA
Journal, 84(10), 12-21. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11384
Alleyne, B. J., & Elson, R. J. (2013). The impact of federal regulations on identifying,
preventing, and eliminating corporate fraud. Journal of Legal, Ethical & Regulatory Issues, 16(1), 91-106. Retrieved from http://www.alliedacademies.org/legal-ethical-and-regulatory-issues/volume- issue.php?volume=Volume%2016,%20Issue%201&&year=2013
Association of Certified Fraud Examiners. (2014). 2014 Report to the nations: Summary
of findings. Retrieved from http://www.acfe.com/rttn-summary.aspx Barnham, C. (2015). Quantitative and qualitative research. International Journal of
Market Research, 57(6), 837-854. doi:10.2501/IJMR-2015-07 Beasley, M. S., Carcello, J. V., Hermanson, D. R., & Neal, T. L. (2010). Fraudulent
financial reporting 1998-2007: An analysis of U.S. public companies. Retrieved from http://www.coso.org/documents/cosofraudstudy2010.pdf
Boone, H. N., & Boone, D. A. (2012). Analyzing Likert data. Journal of Extension,
50(2). Retrieved from http://www.joe.org/joe/2012april/tt2.php Boritz, J. E., Kochetova-Kozloski, N., & Robinson, L. (2015). Are fraud specialists
relatively more effective than auditors at modifying audit programs in the presence of fraud risk?. Accounting Review, 90(3), 881-915. doi:10.2308/accr-50911
Boritz, J. E., & Timoshenko, L. M. (2014). On the use of checklists in auditing: A
commentary. Current Issues in Auditing, 8(1), C1-C25. doi:10.2308/ciia-50741
139
Bowlin, K. O., Hobson, J. L., & Piercey, M. D. (2015). The effects of auditor rotation, professional skepticism, and interactions with managers on audit quality. Accounting Review, 90(4), 1363-1393. doi:10.2308/accr-51032
Boyle, D. N., Carpenter, B. W., & Hermanson, D. R. (2012). CEOs, CFOs, and
accounting fraud. CPA Journal, 82(1), 62-65. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=10911
Boyle, D. M., DeZoort, F. T., & Hermanson, D. R. (2015). The effect of alternative fraud
model use on auditors’ fraud risk judgments. Journal of Accounting & Public Policy, 34(6), 578-596. doi:10.1016/j.jaccpubpol.2015.05.006
Brazel, J. F., Carpenter, T. D., & Jenkins, J. G. (2010). Auditors’ use of brainstorming in
the consideration of fraud: Reports from the field. Accounting Review, 85(4), 1273-1301. doi:10.2308/accr.2010.85.4.1273
Brazel, J. F., Jones, K. L., & Prawitt, D. F. (2014). Auditors' reactions to inconsistencies
between financial and nonfinancial measures: The interactive effects of fraud risk assessment and a decision prompt. Behavioral Research in Accounting, 26(1), 131- 156. doi:10.2308/bria-50630
Buchholz, A. K. (2012). SAS 99: Deconstructing the fraud triangle and some classroom
suggestions. Journal of Leadership, Accountability & Ethics, 9(2), 109-118. Retrieved from http://www.na-businesspress.com/jlaeopen.html
Campbell, J., & Göritz, A. (2014). Culture corrupts! A qualitative study of organizational
culture in corrupt organizations. Journal of Business Ethics, 120(3), 291-311. doi:10.1007/s10551-013-1665-7
Carpenter, T. D., Durtschi, C., & Gaynor, L. M. (2011). The incremental benefits of a
forensic accounting course on skepticism and fraud-related judgments. Issues in Accounting Education, 26(1), 1-21. doi:10.2308/iace.2011.26.1.1
Carpenter, T. D., & Reimers, J. L. (2013). Professional skepticism: The effects of a
partner's influence and the level of fraud indicators on auditors' fraud judgments and actions. Behavioral Research in Accounting, 25(2), 45-69. doi:10.2308/bria-50468
Cavaliere, F. J., Mulvaney, T., Swerdlow, M., & Baldo, M. (2014). Congress kickstarts
securities laws to jumpstart the economy: The JOBS Act awaits SEC implementation. Southern Law Journal, 24(1), 149-164. Retrieved from http://www.southernlawjournal.com/2014_1/SLJ_Spring_2014_Cavaliere et al.pdf
140
Cohen, J., Ding, Y., Lesage, C., & Stolowy, H. (2010). Corporate fraud and managers' behavior: Evidence from the press. Journal of Business Ethics, 95, 271-315. doi:10.1007/s10551-011-0857-2
Connect. (n.d.). Virginia Society of CPAs website. Retrieved from
http://connect.vscpa.com/home Dorminey, J. W., Fleming, A. S., Kranacher, M., & Riley, R. A. (2010). Beyond the fraud
triangle. CPA Journal, 80(7), 16-23. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=10614
Dorminey, J., Fleming, A. S., Kranacher, M., & Riley, R. A. (2012). The evolution of
fraud theory. Issues in Accounting Education, 27(2), 555-579. doi:10.2308/iace-50131
Drew, J. (2014, May 20). Biennial report details fraud’s impact worldwide. CGMA
Magazine. Retrieved from http://www.cgma.org/magazine/news/pages/201410170.aspx
Fathil, F. M., & Schmidtke, J. M. (2010). The relation between individual differences and
accountants' fraud detection ability. International Journal of Auditing, 14(2), 163- 173. doi:10.1111/j.1099-1123.2009.00412.x
Favere-Marchesi, M. (2013). Effects of decomposition and categorization on fraud-risk
assessments. Auditing: A Journal of Practice & Theory, 32(4), 201-219. doi:10.2308/ajpt-50528
Ferrell, O., & Ferrell, L. (2011). The responsibility and accountability of CEOs: The last
interview with Ken Lay. Journal of Business Ethics, 100(2), 209-219. doi:10.1007/s10551-010-0675-y
Field, A. (2013). Discovering statistics using IBM SPSS Statistics (4th ed.). Thousand
Oaks, CA: Sage Publications. Fraud. (2011). In Merriam-Webster's dictionary of law. Retrieved from
http://search.credoreference.com.proxy1.ncu.edu/content/entry/mwdlaw/fraud/0?id =21348837
George, N. (2012). Financial statement fraud and corporate governance. Review of
Business Research, 12(3), 34-43. Retrieved from http://www.iabe.org/domains/IABE-DOI/Journal.aspx?P=12
Glover, S. M., & Prawitt, D. F. (2014). Enhancing auditor professional skepticism: The
professional skepticism continuum. Current Issues in Auditing, 8(2), P1-P10. doi:10.2308/ciia-50895
141
Goel, S., & Gangolly, J. (2012). Beyond the numbers: Mining the annual reports for hidden cues indicative of financial statement fraud. Intelligent Systems in Accounting, Finance & Management, 19(2), 75-89. doi:10.1002/isaf.1326
Hammersley, J. S., Bamber, E. M., & Carpenter, T. D. (2010). The influence of
documentation specificity and priming on auditors' fraud risk assessments and evidence evaluation decisions. Accounting Review, 85(2), 547-571. doi:10.2308/accr.2010.85.2.547
Hammersley, J. S. (2011). A review and model of auditor judgments in fraud-related
planning tasks. Auditing: A Journal of Practice & Theory, 30(4), 101-128. doi:10.2308/ajpt-10145
Ho, R., Kwock, B., & James, M. (2015). Cultural implications on Chinese accounting
students' professional skepticism. Journal of Business Studies Quarterly, 7(2), 274- 289. Retrieved from http://jbsq.org/wp-content/uploads/2015/12/December_2015_19.pdf
Hogan, C. E., Rezaee, Z., Riley, J. A., & Velury, U. K. (2008). Financial statement fraud: Insights from the academic literature. Auditing: A Journal of Practice & Theory, 27(2), 231-252. doi:10.2308/aud.2008.27.2.231
Hopwood, W. S., Leiner, J. J., & Young, G. R. (2012). Forensic accounting and fraud
examination (2nd ed.). New York, NY: McGraw-Hill Education. Hulsart, R. W., James, K. M., & Cummings, D. M. (2012). Fraud in the lost decade: The
impact of the economic downturn on the prevalence of fraud. Business Studies Journal, 4(1), 9-24. Retrieved from http://www.alliedacademies.org/business- studies-journal/volume-issue.php?volume=Volume 4, Issue 1&&year=2012
Hurtt, K., Eining, M., & Plumlee, D. (2008, May). An experimental examination of
professional skepticism. Social Science Research Network. Retrieved from https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1140267
Hurtt, R. K. (2010). Development of a scale to measure professional skepticism.
Auditing: A Journal of Practice & Theory, 29(1), 149-171. doi:10.2308/aud.2010.29.1.149
Hurtt, R. K., Brown-Liburd, H., Earley, C. E., & Krishnamoorthy, G. (2013). Research
on auditor professional skepticism: Literature synthesis and opportunities for future research. Auditing: A Journal of Practice & Theory, 32(1), 45-97. doi:10.2308/ajpt-50361
Jaffar, N., Haron, H., Iskandar, T., & Salleh, A. (2011). Fraud risk assessment and
detection of fraud: The moderating effect of personality. International Journal of
142
Business & Management, 6(7), 40-50. Retrieved from http://www.ccsenet.org/journal/index.php/ijbm/article/view/9198/7903
Kassem, R., & Higson, A. (2012). Financial reporting fraud: Are standards' setters and
external auditors doing enough?. International Journal of Business & Social Science, 3(19), 283-290. Retrieved from http://ijbssnet.com/journals/Vol_3_No_19_October_2012/32.pdf
Kassem, R., & Higson, A. (2012). The new fraud triangle model. Journal of Emerging
Trends in Economics & Management Sciences, 3(3), 191-195. Retrieved from http://jetems.scholarlinkresearch.com/articlesearch.php
Knapp, C. A., & Knapp, M. C. (2001). The effects of experience and explicit fraud risk
assessment in detecting fraud with analytical procedures. Accounting, Organizations and Society, 26(1), 25-37. doi:10.1016/S0361-3682(00)00005-2
Kochetova-Kozloski, N., Messier, W. F., & Eilifsen, A. (2011). Improving auditors' fraud
judgments using a frequency response mode. Contemporary Accounting Research, 28(3), 837-858. doi:10.1111/j.1911-3846.2011.01067.x
Kravitz, R. H. (2012). Auditors' responsibility for detecting fraud. CPA Journal, 82(6),
24-30. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11056
Lee, C., Welker, R. B., & Wang, T. (2013). An experimental investigation of professional
skepticism in audit interviews. International Journal of Auditing, 17(2), 213-226. doi:10.1111/ijau.12001
LinkedIn. (n.d.). LinkedIn Corp. Retrieved from https://www.linkedin.com/groups/ Lokanan, M. E. (2015). Challenges to the fraud triangle: Questions on its usefulness.
Accounting Forum, 39(3), 201-224. doi:10.1016/j.accfor.2015.05.002 Love, V. J. (2012). Auditors' responsibility for detecting fraud. CPA Journal, 82(6), 32-
38. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=11057
Morales, J., Gendron, Y., & Guénin-Paracini, H. (2014). The construction of the risky
individual and vigilant organization: A genealogy of the fraud triangle. Accounting, Organizations & Society, 39(3), 170-194. doi:10.1016/j.aos.2014.01.006
143
Morgan, M., & Nix, W. (2011). CPA perceptions of the marketability, career enhancements and quality of services of certified fraud examiners. Southern Business & Economic Journal, 34(3/4), 31-50. Retrieved from http://www.business.aum.edu/about/southern-business-economic-journal
Murphy, P., & Dacin, M. (2011). Psychological pathways to fraud: Understanding and
preventing fraud in organizations. Journal of Business Ethics, 101(4), 601-618. doi:10.1007/s10551-011-0741-0
NGO Security. (2010, February 14). Using the Likert scale to assess risk [Web log post].
Retrieved from http://ngosecurity.blogspot.com/2010/02/using-likert-scale-to-assess-risk.html
Nix, W., & Morgan, M. (2013). Chief financial officers give credit to certified fraud
examiners' fight against fraud. Academy of Business Journal, 2(1), 1-15. Retrieved from http://www.aobronline.com/#!journals/c5ro
Northcentral University. (2015). Institutional Review Board Handbook. Retrieved from
http://learners.ncu.edu Park, J., & Park, M. (2016). Qualitative versus quantitative research methods: Discovery
or justification?. Journal Of Marketing Thought, 3(1), 1-7. doi:10.15577/jmt.2016.03.01.1
PCAOB focuses on 3 key areas for 2015. (2015, December 1). Retrieved from
http://www.journalofaccountancy.com/issues/2015/dec/pcaob-audit-focus.html Peytcheva, M. (2014). Professional skepticism and auditor cognitive performance in a
hypothesis-testing task. Managerial Auditing Journal, 29(1), 27-49. doi:10.1108/MAJ-04-2013-0852
Piercey, D. M. (2011). Documentation requirements and quantified versus qualitative
audit risk assessments. Auditing: A Journal of Practice & Theory, 30(4), 223-248. doi:10.2308/ajpt-10171
Popoola, O. J., Che-Ahmad, A. B., & Samsudin, R. S. (2014). Fraud and forensic
accounting: Knowledge and risk assessment task performance in Malaysian public sector -- Conceptual study. Annual International Conference on Accounting & Finance, 103-109. doi:10.5176/2251-1997_AF14.55
Popoola, O. J., Che-Ahmad, A. B., & Samsudin, R. S. (2015). An empirical investigation
of fraud risk assessment and knowledge requirement on fraud related problem representation in Nigeria. Accounting Research Journal, 28(1), 78-97. doi:10.1108/ARJ-08-2014-0067
144
Poynter, R. (2010). The handbook of online and social media research: Tools and techniques for market researchers. Hoboken, NJ: Wiley Publishing.
Quadackers, L., Groot, T., & Wright, A. (2014). Auditors' professional skepticism:
Neutrality versus presumptive doubt. Contemporary Accounting Research, 31(3), 639-657. doi:10.1111/1911-3846.12052
Radecki, T. (1982). Similarity measures for Boolean search request formulations. Journal
of the American Society for Information Science, 33(1), 8-17. Retrieved from https://www.asist.org/publications/jasist/
Rasso, J. T. (2015). Construal instructions and professional skepticism in evaluating
complex estimates. Accounting, Organizations & Society, 4(6) 44-55. doi:10.1016/j.aos.2015.03.003
Ray, T. (2015). Auditors still challenged by professional skepticism. CPA Journal, 85(1),
21-27. Retrieved from https://www.nysscpa.org/news/publications/the-cpa-journal/article- preview?ArticleID=9952
Reffett, A. B. (2010). Can identifying and investigating fraud risks increase auditors'
liability?. Accounting Review, 85(6), 2145-2167. doi:10.2308/accr.2010.85.6.2145 Rose, J. M., McKay, B. A., Norman, C. S., & Rose, A. M. (2012). Designing decision
aids to promote the development of expertise. Journal of Information Systems, 26(1), 7-34. doi:10.2308/isys-10188
Schmidt, R. N. (2014). The effects of auditors' accessibility to “tone at the top”
knowledge on audit judgments. Behavioral Research in Accounting, 26(2), 73-96. doi:10.2308/bria-50824
Schuchter, A., & Levi, M. (2015). Beyond the fraud triangle: Swiss and Austrian elite
fraudsters. Accounting Forum, 39(3), 176-187. doi:10.1016/j.accfor.2014.12.001 Shadnam, M., & Lawrence, T. B. (2011). Understanding widespread misconduct in
organizations: An institutional theory of moral collapse. Business Ethics Quarterly, 21(3), 379-407. Retrieved from https://www.pdcnet.org/pdc/bvdb.nsf/purchase?openform&fp=beq&id=beq_2011_ 0021_0003_0379_0407
Soltani, B. B. (2014). The anatomy of corporate fraud: A comparative analysis of high
profile American and European corporate scandals. Journal of Business Ethics, 120(2), 251-274. Retrieved from http://link.springer.com/article/10.1007%2Fs10551-013-1660-z#/page-1
145
Srivastava, R. P., Mock, T. J., & Gao, L. (2011). The Dempster-Shafer theory: An introduction and fraud risk assessment illustration. Australian Accounting Review, 21(3), 282-291. doi:10.1111/j.1835-2561.2011.00135.x
Stephens, N. M. (2011). External auditor characteristics and internal control reporting
under SOX section 302. Managerial Auditing Journal, 26(2), 114-129. Retrieved from http://dx.doi.org/10.1108/02686901111095001
Trompeter, G. M., Carpenter, T. D., Desai, N., Jones, K. L., & Riley, R. A. (2013). A
synthesis of fraud-related research. Auditing: A Journal of Practice & Theory, 32(S1), 287-321. doi:10.2308/ajpt-50360
Trotman, K. T., & Wright, W. F. (2012). Triangulation of audit evidence in fraud risk
assessments. Accounting, Organizations and Society, 37(1), 41-53. doi:10.1016/j.aos.2011.11.003
Verschoor, C. C. (2014). Fraud continues to cause significant losses. Strategic Finance,
96(8), 11-85. Retrieved from http://www.imanet.org/docs/default-source/sf/08_2014_ethics-pdf.pdf?sfvrsn=0
Victoravich, L. M. (2010). The mediated effect of SAS No. 99 and Sarbanes–Oxley
officer certification on jurors’ evaluation of auditor liability. Journal of Accounting & Public Policy, 29(6), 559-577. doi:10.1016/j.jaccpubpol.2010.09.006
Wei, C., Khalifa, A. S., & Trotman, K. T. (2015). Facilitating brainstorming: Impact of
task representation on auditors' identification of potential frauds. Auditing: A Journal of Practice & Theory, 34(3), 1-22. doi:10.2308/ajpt-50986
146
Appendix A: Hurtt Professional Skepticism Scale
Strongly Disagree
Strongly Agree
I often accept other people’s explanations without further thought. 1 2 3 4 5 6 I feel good about myself. 1 2 3 4 5 6 I wait to decide on issues until I can get more information. 1 2 3 4 5 6 The prospect of learning excites me. 1 2 3 4 5 6 I am interested in what causes people to behave the way that they do. 1 2 3 4 5 6 I am confident of my abilities. 1 2 3 4 5 6 I often reject statements unless I have proof that they are true. 1 2 3 4 5 6 Discovering new information is fun. 1 2 3 4 5 6 I take my time when making decisions. 1 2 3 4 5 6 I tend to immediately accept what other people tell me. 1 2 3 4 5 6 Other people’s behavior does not interest me. 1 2 3 4 5 6 I am self-assured. 1 2 3 4 5 6 My friends tell me that I usually question things that I see or hear. 1 2 3 4 5 6 I like to understand the reason for other people's behavior. 1 2 3 4 5 6 I think that learning is exciting. 1 2 3 4 5 6 I usually accept things I see, read, or hear at face value. 1 2 3 4 5 6 I do not feel sure of myself. 1 2 3 4 5 6 I usually notice inconsistencies in explanations. 1 2 3 4 5 6 Most often I agree with what the others in my group think. 1 2 3 4 5 6 I dislike having to make decisions quickly. 1 2 3 4 5 6 I have confidence in myself. 1 2 3 4 5 6 I do not like to decide until I've looked at all of the readily available information. 1 2 3 4 5 6 I like searching for knowledge. 1 2 3 4 5 6 I frequently question things that I see or hear. 1 2 3 4 5 6 It is easy for other people to convince me. 1 2 3 4 5 6 I seldom consider why people behave in a certain way. 1 2 3 4 5 6 I like to ensure that I’ve considered most available information before making a decision. 1 2 3 4 5 6 I enjoy trying to determine if what I read or hear is true. 1 2 3 4 5 6 I relish learning. 1 2 3 4 5 6 The actions people take and the reasons for those actions are fascinating. 1 2 3 4 5 6
147
Appendix B: CITI Requirements Report
148
Appendix C: Internal Review Board Approval
149
Appendix D: Informed Consent Form
Introduction:
My name is Cynthia Vance. I am a doctoral student at Northcentral University. I am conducting a research study on the effects of auditor certification (i.e., CFE and/or CPA), professional skepticism, and the presence of fraud on fraud risk assessment performance. I am completing this research as part of my doctoral degree. I invite you to participate.
Activities:
If you participate in this research, you will be asked to:
1. Answer demographic questions – 3 minutes 2. Complete a 30-item professional skepticism questionnaire – 7 minutes 3. Review a company’s financial statements and perform a fraud risk assessment
by answering four Likert-type questions – 50 minutes
Eligibility:
You are eligible to participate in this research if you:
1. Are the age of 18 or older 2. Possess either the certified fraud examiner (CFE) and/or the certified public
accountant (CPA) credential 3. Work in the United States
You are not eligible to participate in this research if you:
1. Are not 18 years of age 2. Do not possess the certified fraud examiner (CFE) and/or the certified public
accountant (CPA) credential 3. Do not work in the United States
I hope to include 200 people in this research.
Risks:
There are minimal risks in this study. No identifiable data will be collected from this research. The research design employs the use of third-party online survey software to collect the data; hence, the participants’ privacy and anonymity will be safeguarded.
150
To decrease the impact of these risks, you can stop participation at any time.
Benefits:
If you decide to participate, there are no direct benefits to you.
The others receiving potential benefits are the accounting profession namely, auditors, regulators, and academicians. It will enhance the body of knowledge of the influences of auditor attributes (i.e., certification and professional skepticism) to the outcome of fraud risk assessments, which are used to detect fraudulent financial statements.
Confidentiality:
The information you provide will be kept confidential to the extent allowable by law. Confidentiality will be maintained as no identifiable data will be collected. The use of the Internet for the online survey does present a risk for a confidentiality breach of the IP address. However, IP addresses will not be included in the research dataset used by the researcher to analyze the data.
The people who will have access to your information are: myself, my dissertation chair, and my dissertation committee. The Institutional Review Board may also review my research and view your information.
I will secure your information with these steps: use of a third-party software company that uses high-end firewall systems to protect the data stored on its site, exclude IP addresses from the data downloaded from the third-party software, store all paper files of the downloaded data in a locked cabinet, use a password to lock all downloaded computer files stored on portable devices (i.e., flash drives, external hard drives), which will be stored in a locked cabinet.
I will keep your data for 7 years. Then, I will delete electronic data and destroy paper data.
Contact Information:
If you have questions for me, you can contact me at: C.Vance4867@email.ncu.edu.
My current dissertation chair’s name is Dr. Gail Gessert. She works for Northcentral University and is supervising me on the research. You can contact her at: ggessert@ncu.edu.
If you have questions about your rights in the research, or if a problem has occurred, or if you are injured during your participation, please contact the Institutional Review Board at: irb@ncu.edu or 1-888-327-2877 ext 8014.
151
Voluntary Participation:
Your participation is voluntary. If you decide not to participate, or if you stop participation after you start, there will be no penalty to you. You will not lose any benefit to which you are otherwise entitled.
Signature:
By selecting the “Agree” option, you agree to willfully participate in the research project and you understand this consent form. By selecting the “Decline” option you decline to willfully to participate in the research project.
152
Appendix E: Qualtrics Online Survey Financial Statement Fraud Risk Assessment - Launched Q1. Financial statement fraud is a challenge for the global business environment. The Public Company Accounting Oversight Board (PCAOB) continues to find deficiencies in auditors' responses to fraud risk. This is a research study on financial statement fraud risk in relation to the effects of professional certifications and professional skepticism on the fraud risk assessment process. You may participate in this research study if you are 18 years old or older, have either a certified fraud examiner (CFE) and/or a certified public accountant (CPA) certification, and work in the United States. If you participate in this research, you will answer a few demographic questions, complete a questionnaire on skepticism, and review a company’s financial statements to perform a fraud risk assessment. The three activities should take no longer than an hour. All responses will be kept confidential and no personally recognizable data will be collected. You can stop participation in the study at any time. If you have questions for me, you can contact me at C.Vance4867@email.ncu.edu. Thank you in advance for considering participating in this research study. Yes, I am eligible to participate in this study. (1) No, I am not eligible to participate in this study. (2) If No, I am not eligible to part... Is Selected, Then Skip To End of Block Q2. Please read the following consent form IRB Consent Form before you agree to participate in the study. After reading the consent form, click on your decision to participate. I agree to willfully participate in the research study. (1) I decline to willfully participate in the research study. (2) If I decline to willfully part... Is Selected, Then Skip To End of Block Q3. Age of participant If Age of participant Is Less Than 18, Then Skip To End of Block Q4. Gender of participant Male (1) Female (2) Q5. U.S. Geographic Work Region Northeast (1) Southeast (2) Southwest (3) West (4) Midwest (5) Q6. Years of Audit Experience Q7. Years of Fraud Risk Assessment Experience
153
Q8. Professional Certification Certified Fraud Examiner (1) Certified Fraud Examiner & Certified Public Accountant (2) Certified Public Accountant (3) Neither a Certified Fraud Examiner or Certified Public Accountant (4) If Neither a Certified Fraud E... Is Selected, Then Skip To End of Block
154
Q9. Select the response that indicates how you generally feel. There are no right or wrong answers. Do not spend too much time on any one statement.
Strongly
Agree 1 2 3 4 5
Strongly Disagree
6 I often accept other people’s explanations
without further thought. (1)
I feel good about myself.
(2)
I wait to decide on
issues until I can get more information.
(3)
The prospect of learning
excites me. (4)
I am interested in what causes
people to behave the
way that they do. (5)
I am confident of my abilities.
(6)
I often reject statements
unless I have proof that they
are true. (7)
Discovering new
information is fun. (8)
I take my time when making decisions. (9)
155
I tend to immediately accept what other people tell me. (10)
Other people’s behavior does
not interest me. (11)
I am self- assured. (12)
My friends tell me that I usually
question things that I see or hear.
(13)
I like to understand the
reason for other people's behavior. (14)
I think that learning is
exciting. (15)
I usually accept things I see, read, or hear at face value. (16)
I do not feel sure of myself.
(17)
I usually notice
inconsistencies in
explanations. (18)
Most often I agree with what the
others in my group think.
(19)
156
I dislike having to
make decisions
quickly. (20)
I have confidence in myself. (21)
I do not like to decide until
I've looked at all of the readily
available information.
(22)
I like searching for knowledge.
(23)
I frequently question
things that I see or hear.
(24)
It is easy for other people to convince me.
(25)
I seldom consider why people behave
in a certain way. (26)
I like to ensure that I’ve
considered most available
information before making
a decision. (27)
I enjoy trying to determine if what I read or hear is true.
(28)
157
I relish learning. (29)
The actions people take
and the reasons for
those actions are
fascinating. (30)
Q10. Perform a fraud risk assessment for ABC, Inc. for the fiscal year 2006 by responding to the following questions after reviewing the attached 10-K Form ABC Inc_12302006 .
Very improba
ble /insignif icant (1)
Improbable/ insignificant
(2)
Somewhat improbabl
e /insignific
ant (3)
Neith er (4)
Somewh at
probable /
significa nt (5)
Probable /
significa nt (6)
Very probabl
e/ signific ant (7)
Likelihoo d of fraud risks (1)
Significan ce of fraud
risks (2)
Significan ce of anti-
fraud controls
in use (3)
Likelihoo d of fraud
(4)
158
Q11. Perform a fraud risk assessment for XYZ, Inc. for the fiscal year 2006 by responding to the following questions after reviewing the attached 10-K Form XYZ Inc_12292007.
Very improbable/ insignificant
(1)
Improbable/ insignificant
(2)
Somewhat improbable/ insignificant
(3)
Neither (4)
Somewhat probable/ significant
(5)
Probable/ significant
(6)
Very probable/ significant
(7)
Likelihood of fraud risks (1)
Significance of fraud risks (2)
Significance of anti- fraud
controls in use (3)
Likelihood of fraud
(4)
- Chapter 1: Introduction
- Statement of the Problem
- Purpose of the Study
- Theoretical Framework
- Nature of the Study
- Research Questions
- Q3. Does professional skepticism influence fraud risk assessment performance?
- Hypotheses
- Significance of the Study
- Definition of Key Terms
- Summary
- Chapter 2: Literature Review
- A synthesis of extant literature on fraud and attribution theory was conducted to find gaps in the current body of knowledge in relation to financial statement fraud. The literature review was organized into the following categories: regulations, ris...
- Theoretical Framework
- Certified Fraud Examiners
- Summary
- Chapter 3: Research Method
- Q1. Does the presence of fraud risk have an effect on fraud risk assessment performance?
- Q2. Does a certification in fraud knowledge have an effect on fraud risk assessment performance?
- Research Design
- Population
- Materials/Instrumentation
- Operational Definition of Variables
- Study Procedures
- Data Collection and Analysis
- Assumptions
- Limitations
- Delimitations
- Ethical Assurances
- Summary
- Chapter 4: Findings
- Results
- Evaluation of Findings
- Summary
- Chapter 5: Implications, Recommendations, and Conclusions
- Implications
- References
- Appendix A: Hurtt Professional Skepticism Scale