1 / 54100%
Students name : Scoots Bar
Course number and Name : IEE 454 - Risk Management
Instructors Name : Brittany Holloman
RISK MANAGEMENT: EARLY DETECTION OF FRAUD
PREVENTION EFFORTS
1.0 Introduction:
Fraud or better known as fraud, is still a phenomenal issue and is very interesting to
discuss and study various cases that currently occur frequently in society. The Association of
Certified Fraud Examiners (ACFE) defines fraud as the use of a position by someone to
enrich themselves through deliberate misuse or misuse of organizational assets or resources.
Or in other words, fraud is fraud regarding the benefits obtained by someone by presenting
something that is not in accordance with the actual situation. It includes elements of surprise /
unexpected, deceit, cunning, and dishonesty that harm other parties (ACFE, 2008). So fraud
can be interpreted as an act of fraud or error committed by a person or entity who knows that
the error can result in losses to other individuals or entities (Surjandari, 2015). Fraud creates
a misjudgment or maintains an existing false judgment to persuade someone to make a
contract. This is done because it involves enriching oneself intentionally by secretly reducing
the value of assets (Enofe, 2013).
Fraud includes intentional dishonesty, misrepresentation, manipulation and display of
facts that can harm others and organizations including banks. Fraud also includes theft,
appropriation, attempts to obtain something illegally, and errors in making financial
statements including the assets and liabilities of the organization (Gilbert & Wakefield,
2018). Thus, fraud is deception that includes the elements of: (a) a representation; (b) about
something material; (c) something that is not true; (d) and intentionally or gratuitously carried
out for later; (e) believed; (f) and acted upon by the victim; (g) so that in the end the victim
suffers losses (Zimbelmann, et. al, 2014).
Schematically, the ACFE describes occupational fraud in the form of a fraud tree.
This fraud tree depicts the branches of occupational fraud, along with their twigs and
branches. So the occupational fraud tree has three main branches, namely corruption, asset
misappropriation, and fraudulent statements (financial statement fraud) (Tuanakotta, 2010).
One theoretical explanation of the causes of someone committing fraud was first developed
by Donald Cressey with his theory known as the fraud triangle. In his theory, it is explained
that the fraud triangle is divided into three parts, namely pressure, opportunity, and
rationalization (Cressey, 1950). Pressure is the embezzlement of company money by a
perpetrator who starts from a pressure. The person has urgent financial needs, so that
personally individual needs are considered more important than organizational needs. The
second cause of fraud is opportunity, where fraud will be committed if there is an opportunity
where someone must have access to assets or have the authority to set control procedures that
allow fraud schemes to be carried out. The third cause is rationalization, meaning that fraud
is committed because there is a rationalization made by a person or group of people by
building justifications for the fraud committed. Fraud perpetrators usually look for reasons to
justify that what they are doing is not theft or fraud, but something that is indeed possible is
his or her right. However, some individuals are more prone to fraud than others. The
tendency to commit fraud depends on their ethical values and personal circumstances
(Abdullahi, et. al, 2015).
According to the Association of Certified Fraud Examiners (ACFE) report in 2020,
based on the frequency of fraud that occurs, asset misappropriation is the fraud that has the
highest frequency followed by corruption and the last is financial statement fraud. But
financial statement fraud is the type of fraud that has the most detrimental impact of fraud
among other types of fraud (ACFE, 2020).
Financial statement fraud is considered as management fraud that results in material
errors in the financial statements so that the financial statements contain misleading
information. The increase in various cases of accounting scandals in various countries around
the world has caused various parties to speculate that management has committed fraud in the
financial statements (Skousen & Wright, 2009).
Financial statement fraud is always related to corporate governance. According to
Dechow, et.el. (2012), the incidence of fraud is highest in companies with weak corporate
governance systems. The tendency to commit fraud is greater in companies with a
background dominated by insiders and most likely do not have an audit committee (Dechow,
et.al., 2012).
Prevention efforts against fraud will be more effective than repressive efforts.
Prevention needs to be done to avoid greater losses and damage to the reputation of
institutions and individuals. In addition, fraud incidents that are not immediately handled and
revealed because The slow handling will increasingly provide opportunities for the
perpetrator to cover up his actions with other fraud. Therefore, it is necessary to make efforts
to prevent the occurrence of true and targeted fraud, so that all forms and efforts of fraudulent
practices can be anticipated as early as possible in order to avoid the risk of loss (Kurniasari,
2017).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them. Every organizational activity will always have uncertainties that are
synonymous with risk, including the risk of fraud, so management must be responsible for
managing the risks that will be faced (Karyono, 2013).
2.0 Literature Review:
The Institute of Internal Auditors (IIA), an organization of internal auditors in the
United States, defines fraud as a set of impermissible and unlawful actions characterized by
an element of intentional fraud. This means that fraud is a fraud that implies a deviation and
unlawful act committed intentionally for a specific purpose, such as deceiving or misleading
other parties, which is carried out by the IIA people from both inside and outside the
organization (Karyono, 2013).
Furthermore, the Chartered Institute of Public Finance and Accountancy (CIPFA)
states fraud as intentional misconduct and concealment of material facts, omission of
evidence to commit fraud and manipulation to the financial detriment of an individual or
organization. Fraud includes embezzlement, theft, forgery, misappropriation, and
deliberately removing evidence (CIPFA, 2013).
It can be generally defined that fraud is a general term, and encompasses any means
that can be used with a certain shrewdness, chosen by an individual, to gain an advantage
over others by making false representations. There is no fixed rule that can be issued as a
general proposition in defining fraud, including surprise, deceit, or cunning and unnatural
means used to commit fraud. The only limits to defining fraud are those that limit human
dishonesty (Zimbelman, et.al., 2014).
Fraud in corporate organizations generally comes from two directions, namely
internal and external. Internal fraud is fraud originating from parties within the corporate
organization itself, such as corruption, presentation of false reports, financial statement
engineering, double financial statements, covering or disguising embezzlement,
incompetence in accounting, theft or improper use of organizational assets by employees and
management for personal or group interests and use that is not in accordance with its
designation. While external fraud is fraud that comes from outside the company's
organization, such as bribery, increasing the value of invoices, double invoicing and quality
fraud such as goods transactions that are not in accordance with the company's policies
agreed presentation (Sayyid, 2014).
Fraudulent statements, namely fraud by presenting financial statements better than
they actually are (over statement) and worse than they actually are (under statement)
(Karyono, 2013), presenting assets or revenues higher than they actually are, or presenting
assets and revenues lower than they actually are (Tuanakotta, 2010), deliberate actions to
produce misleading financial statement material to deceive or misrepresent the organization's
financial position (Albashrawi, 2016), making the organization look more or less profitable
(Apostolou & Apostolou, 2012). While asset misappropriation fraud is the illegal "taking"
(unauthorized or against the law) committed by someone who is authorized to manage or
oversee these assets (Tuanakotta, 2010). And corruption is an act that harms the public
interest or the wider community for the benefit of certain individuals or groups. Corruption
can occur in private corporate organizations as well as in the public sector of government
(Karyono, 2013).
There are several things that motivate management to present financial statements that
contain elements of fraud: (a) provide support to keep stock prices high; (b) provide support
for bonds and shares; and (c) maximize bonuses for management (Zimbelman, et. al., 2014).
According to the Association of Certified Fraud Examiners (ACFE) in its third edition
manual, fraud axioms include: 1) Hidden, this fraud is carried out in a hidden manner and
tries to cover up its actions; 2) Reverse evidence, to prove that fraud has occurred, it must be
attempted so that the fraud does not occur, and vice versa; 3) Types of fraud, which consists
of internal fraud and system control fraud. Internal fraud occurs naturally which is inherent
in every form of activity. System control fraud occurs due to a weak internal control system
and usually the perpetrator has knowledge of the internal work system (Karyono, 2013).
There are several factors that cause someone to commit fraud. Because almost every
criminal act or crime is always driven or triggered by a condition and behavior that causes it.
In this discussion, researchers limit it to using only the Fraud Triangle Theory. According to
this theory, that fraud behavior is carried out or carried out because of three elements, namely
pressure, opportunity, and justification (rationalization). The theory, first formulated by
criminologist Donald R. Cressey (1950), concludes that fraud is generally divided into three
general characteristics. First, fraudsters who have the opportunity to commit fraud
(opportunity). Second, fraudsters have urgent financial needs that cannot be told to others
(pressure). Third, individuals involved in fraud rationalize their fraudulent actions consistent
with their personal code of ethics (rationalization) (Cressey, 1950). And the three fraud
factors are reinforced by the results of research by Skousen et. al. as "triangle fraud"
(Skousen et.al., 2009).
Fraud that occurs in many fields is inseparable from the desire to take other people's
rights for personal or group interests and then justify that fraud is a common thing that can be
done and also because of the opportunity to commit fraud. Fraud in the accounting field can
occur in the process of processing accounting data contained in accounting information in the
form of financial statements. If the fraud factor occurs in the preparation of financial
statements, it is certain that the financial statements presented are not fair. Fraud not only
damages the trust relationship between management and investors but will also harm the
values of accounting itself.
Financial statement fraud affects various market participants, including investors,
organizations, and employees. As previous research provides information related to indirect
organizational losses for fraud. In addition to the material losses borne by the organization,
the organization's reputation may also be questioned when fraud occurs. Investors' trust in the
organization will be lost and may withdraw all their deposits including investments and
pension funds (Perols, 2011; Ugrin & Odom, 2010). Fraud that occurs in an organization is a
classic manifestation of weak organizational governance. In private organizations, there is a
difference of interest between the principal and the agent. This problem arises because when
the owner (principal) authorizes the manager (agent) to act on their behalf. Which is
basically due to differences in interests and information asymmetry between managers and
owners. This problem can be eliminated if both parties have the same interests (Jensen &
William, 1976).
Unhealthy practices in corporate governance allow fraud to occur which is difficult to
detect by stakeholders. Corporate governance is a tool to ensure that directors and managers
(insiders) act in the best interests of investors. Capital market management bodies in many
countries state that the implementation of good corporate governance in public companies has
succeeded in preventing fraudulent practices on financial reports to interested parties (Chen,
et. al., 2005).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them (Karyono, 2013). Every organizational activity will always have uncertainties
that are synonymous with risk including the risk of fraud, so management must be
responsible for managing the risks that will be faced.
The main foundation in implementing an effective fraud prevention program in the
organization is to carry out a thorough risk assessment process. The basic concept of fraud
risk assessment is an assessment of the occurrence and impact of the risks that have been
identified. In the Committee of Sponsoring Organizations of the Threadway Commission,
there are several stages in the fraud risk assessment process including: (a) form a risk
assessment team involving the appropriate level of management; (b) identify potential
organizational fraud risks by assessing risks at all levels of the organization and those from
the internal and external environment, accommodating various types of fraud and considering
the occurrence of management override control; (c) assess the likelihood and significance of
each identified fraud risk; (d) determine employees and departments potentially involved
based on the fraud triangle; (d) identifying existing controls and assessing their effectiveness;
(e) assessing and responding to any residual fraud risks that need to be mitigated; (f)
identifying any controls in place and assessing their effectiveness mitigated; (f) document the
fraud risk assessment; (g) reassess fraud risk periodically (COSO, 2017). And Fraud Risk
Assessment (FRA) is a unique procedure for distinguishing and evaluating the risk of gaps in
the achievement of organizational goals (Huber, et. al., 2015).
Furthermore, Popoola argues that the implementation of fraud risk assessment (FRA)
requires change and an iterative cyclical process to be able to identify and assess the risk of
gaps in the achievement of organizational goals. Fraud risk assessment requires taking into
account changes in the external environment and their impact on the activity model, the
purpose of which is to control ineffective internal activities. Assessment of fraud risk is
considered an effective tool for fraud prevention and because this tool can increase auditor
competence in searching for, detecting and preventing fraud (Popoola, et.al., 2016).
Risk management theory states that risk treatment can be done in various ways,
namely:
1) avoid risk, meaning by deciding not to carry out activities that carry risk; 2) reduce risk,
which is to reduce the likelihood of occurrence and reduce its consequences or impact; 3)
transfer risk, which is to transfer risk to other parties to bear the risk; 4) accept risk, meaning
without taking further action to compensate for the risks that must be taken; and 5) exploit
risk, which is the action to take risks in other options which are the result of proactive
decisions and are carried out consciously to take new risks because they have superior areas
(Susilo & Victor, 2019). Steps or processes carried out in a systematic way to manage risk
threats are known as risk management (Siahaan, 2009).
While the risk management process based on ISO 31000 consists of three major
processes, which include: (1) context setting, aimed at identifying and expressing
organizational goals; (2) risk assessment, which consists of risk identification, risk analysis,
and risk evaluation; (3) risk handling, which consists of: risk avoidance, risk mitigation, risk
transfer, and risk acceptance. The three major processes are accompanied by two processes,
namely: (a) communication and consultation; and (b) monitoring and review (Susilo &
Victor, 2019; Suwanda, et. al., 2019).
3.0 Research Methods:
The methodology used in this research is through library research, which is a research
method carried out by studying literature and writings that have a close relationship with the
problems raised in the research (Baidan, 2016), through a qualitative approach, which is
research that emphasizes process analysis of deductive and inductive thinking processes
related to the dynamics of relationships between observed phenomena, and always uses
scientific logic (Kisworo & Iwan, 2017).
While the data source of this research is a secondary data source consisting of relevant
previous scientific research works, in the form of books and other scientific works with
various points of view. Meanwhile, the data used is a variety of quality-assured qualitative
data in the form of words, sentences, gestures, facial expressions, charts, drawings and
photographs (Sugiyono, 2011) derived from these various sources.
4.0 Results and Discussion:
As previously discussed, in an effort to prevent fraud, management must carry out a
process of managing its organizational resources to anticipate risks that may occur which
have previously been identified, measured and considered how to handle them. Every
organizational activity will always have uncertainties that are synonymous with risk,
including the risk of fraud, so management must be responsible for managing the risks that
will be faced (Karyono, 2013).
Risk management and internal control contribute to the implementation of good
corporate governance (GCG), especially in improving the success of achieving
organizational goals. Without risk management, the internal control system becomes less
effective. Meanwhile, without an internal control system, the control aspects of GCG are less
effective (Susilo & Victor, 2019).
Robert Moeller in his study of the Committee of Sponsoring Organizations (COSO)
internal control, provides a clear picture of the relationship between corporate governance -
risk management - internal control, as shown in the following figure. In the section entitled
"Clearing up a few misconceptions" it is emphasized that, enterprise risk management (ERM)
goes further than internal control. Internal control is an integrated part of ERM. Internal
control is an important part of enterprise risk management (Moeller, 2014).
Furthermore, Ovidiu-Constantin et. al. (2010) highlighted the importance of risk
management and its role in an organization's internal audit. The existence of a risk
management program means placing high confidence in the organization's financial
statements and better audit risk. The implementation of a risk management program, as with
previous research, explains the role of internal auditors in providing assurance on risk
management. An audit risk model is offered to external auditors based on and tailored to the
organization's risk management, the essence of which is that risk management as a solution to
the fraud crisis (Constantin, et. al., 2010).
While the previous research focused on a holistic approach to risk management, in his
research, Lister (2007) discussed the importance of antifraud programs. Organizations must
know the risks in order to mitigate them. This requires a comprehensive fraud risk
assessment, and corresponds to a holistic approach. Anti-fraud programs can increase
stakeholder confidence. However, Lister suggests the approach should be proactive and
reactive, by identifying risks and having an action plan in case of fraud. The three main plan
components include setting regulations through policy and communication, making risk
assessment and monitoring more proactive, and responding by designing a reactive plan.
Lister evaluates planning and implementation using the fraud triangle, and includes third-
party assessments in designing the program (Lister, 2007).
Research conducted by Crockford (2005) discusses risk as a function of change. The
article was originally published in the Geneva Papers in 1976. It explained that risk
management as the ability to cope with change. Rapid change puts pressure on risk
management, this results in difficulties for the organization to adapt. As with Mehr and
Forbes (1973), Crockford recommends that risk management should function by all
managers, not just one department in the organization (Crockford, 2005).
Snider (1990) has also discussed risk management objectives and the importance of
clear risk management objectives. Snider (1990) highlights the steps in developing risk
management objectives. The creation of risk management policies should come from risk
managers or management consultants. A clear policy can generally provide guidance in
decision-making. When identified, there are several things that influence goal setting,
including organizational structure, reporting systems, and short- or long-term goals. Too
much focus on short-term goals in the past can lead to losses due to neglect of controls and
prevention (Snider, 1990).
As with previous research, Snider (1991) recognized the need to expand the risk
management function beyond insurance, and the need for risk management education. In
addition to discussing the concept of risk management, this study also covers the history and
development of risk management, including recognition by academics, the first academic
book on risk management, and the position of risk managers in organizations. He highlights
the initial resistance by senior management, citing the idea that change equals uncertainty.
Snider also discusses the crisis in the early 1970s, related to insurance, which led to the
acceptance of the concept of risk management. And in 1973, the Geneva Association was
founded, thus encouraging research on risk management, and publishing many conceptual
papers on this topic (Snider, 1991).
Aggarwal, Erel, Stulz, and Williamson (2009) studied the effect of a country's
economic and financial development on investment levels in relation to corporate
governance. The findings show that favorable development results in higher investment, and
less investment in firms with poor governance resulting in lower firm value. His research also
provides minimum governance standards for audits: (1) consulting fees are lower than audit
fees; (2) the audit committee consists of independent outsiders; and (3) the auditor must be
authorized at the annual meeting (Aggarwal, et.al., 2009). This is reinforced by Robu's
research (2015) providing an analysis of the relevance of IFRS (International Financial
Reporting Standars) adoption for trust in financial statement information. Researchers took a
sample of 59 companies before and after IFRS adoption. The results showed that there was an
increase in value relevance after IFRS adoption. The research methodology includes to
determine the effect of IFRS adoption on stock prices, and provides recommendations that
standardized reporting and transparency as a solution for a trusted financial market (Robu,
2015).
Previous research conducted by Kang (2008), provides an analysis from another point
of view in the fraud literature, namely the study of reputational penalties associated with
financial fraud and reputation as a penalty for the companies involved. The findings show an
increase in reputational penalties (decrease) for the companies involved. A decrease in market
value is one of the negative effects. The researcher used signalling theory and attribution
theory to explain the related company relationship. The study sampled 244 related firms and
30 suspect firms, from 1998 to 2002. The findings also show that an increase in uncertainty
leads to a negative effect decrease in investor confidence. However, good governance can
increase investor confidence. The implications of his findings recommend the need for
governance reform (Kang, 2008).
Still on financial statement fraud. Fleming, Riley Jr, Hermanson, and Kranacher
(2016) extended the fraud aspect of research with a study of the most fundamental differences
in financial statement fraud between public and private companies. The researchers found a
lack of data available for private companies by using data sources provided by the
Association of Certified Fraud Examiners (ACFE). Fleming et al. (2016) cite that financial
statement fraud is one of the most costly forms of fraud, with an average loss of $1.5 billion.
$1 million per incident. This is in addition to additional reputational impacts, such as
bankruptcy and loss of market value. Some of the other findings of this study are that the
increasing controls on publicly traded companies indicate the use of less obvious methods of
reporting fraud, such as differences in the timing of reporting. And it will usually continue to
grow if the existing controls continue to be improved. The main purpose of this study is for
audit purposes for its concern in highlighting the difference in treatment between public
companies and private companies (Fleming, et. al., 2016).
Furthermore, Ng, White, Lee, and Moneta (2009) examined the focus on developing
instruments to detect managers' fraud tendencies in managing income. Researchers used an
ethical scenario survey method to collect information to design fraud detection instruments
and factor analysis used as a response. Researchers also used the moral intensity construct to
determine managers' intention to act specifically. The construct consists of six characteristics
Moral intensity includes the magnitude of consequences and social consensus. The findings
suggest that the proposed instrument could be operationalized to measure moral intensity in
future studies (Ng, et. al, 2009).
Previously, Shafer (2002) also examined the role of morals. Shafer analyzed financial
statement fraud in the context of an ethical model of decision making. The ANOVA results
show that materiality and risk are significant factors that affect the likelihood of committing
fraud, while the morality factor is not significant. The researcher used Jones' theory of moral
intensity to explain the prevalence of earnings management. The findings mention the
materiality effect with a note of rationalization when the amount is not material, and a more
than 50% probability of committing fraud when the amount is not material. The key indicator
of the absence of ethical behavior is about the perception of what his friend is doing (Shafer,
2002).
Some researchers focus on auditor responsibility. Kostova (2013) revealed a
relationship between fraud characteristics and audit procedures. Kostova describes the
auditor's responsibility to disclose errors and fraud. Auditors are expected to provide opinions
and conclusions about the reliability of financial statements. Furthermore, the researcher also
revealed the existence of economic factors that cause fraud, also identifies its characteristics.
Researchers mention the economic environment as the main factor that leads to fraud. For
example, organizations are under pressure to achieve financial targets (Kostova, 2013).
In contrast to Kostova (2013) who focused on economic factors, Love (2012)
examined auditor responsibility for fraud detection related to reporting standards. It should be
noted that the GAAS (Generally Accepted Auditing Standars) standard recognizes the
absence of the ability to provide absolute assurance, but rather provides reasonable assurance
and reduces the risk of material misstatement. Auditor discovery of questionable information
requires re-evaluation of all audit areas. Fraudsters may conceal their actions through false
statements and documents during the audit process. Love noted the difference between
conducting a GAAS audit and a fraud examination. A GAAS audit results in an auditor's
opinion on the fairness of the financial statement presentation. Regarding auditor perceptions,
Johnson, Kuhn, Apostolou, and Hassell (2013) examined auditors' fraud risk assessment of
management attitudes. The researchers tested whether observable indicators of narcissism by
auditors are indicators of increased risk. The findings of this study indicate a link between
narcissism and fraud, consistently with the behaviors observed in recent fraud. Researchers
evaluated the ability of auditors to recognize fraud, which requires auditors with higher
abilities and experience. This study also concluded that managerial narcissism is an
observable action and recommended improving the assessment guidelines for fraud (Johnson,
et. al., 2013).
Philmore and Michael (2005) conducted a necessary study on the perceived
responsibility of auditors to detect Enron fraud. The study was to determine the nature and
extent of fraud in Barbados. The researchers used a mixed methods design for the exploratory
study. By conducting a survey of 43 respondents about perceptions and experiences in fraud.
The purpose of The qualitative approach was to support the quantitative survey in fully
understanding the research question. The researcher conducted face-to-face interviews to gain
multiple sources of insight. This article is useful for investors, auditors, and regulators, and
contributes to the understanding of the auditor's role in detecting fraud. The researchers
provided historical background on the role of the auditor, and a review of related literature,
but found there is still a lack of consensus on the role of the auditor. There are several
findings presented in this research study. The majority of respondents stated that fraud
detection is the responsibility of the auditor, while others stated that detection is the
responsibility of management. In particular, those respondents with an accounting
background assume that management is responsible for detecting fraud (Philmore and
Michael, 2005).
In contrast to previous research, Nicolaescu (2013) focuses on the role of internal
audit in detecting fraud. The size of the audit firm affects the quality of the audit report.
Researchers found that rigor can improve the ability to detect fraud. The ability to detect
fraud can also be enhanced by the presence of internal auditors. One finding suggested that
brainstorming can be used as a means for internal auditors to respond to risk assessment. This
study also concluded that internal audit is an important part of corporate governance
(Nicolaescu, 2013).
Previously, Kranacher and Stern (2004) provided suggestions for improving fraud
detection. According to a COSO (Committee of Sponsoring Organization) study, CEOs
commit 75% of all fraud. Meanwhile, Klarskov Jeppesen and Leder (2016) state the need for
auditors to question the integrity of managers, Kranacher and Stern (2004) note a potential
conflict of interest between the auditor and the hiring department executive. Legislation
serves as a deterrent to fraudulent behavior, as auditors must actively detect fraud.
Furthermore, researchers recommend that auditor education should be improved to include
behavioral understanding, investigative skills and deeper analysis (Kranacher and Stern,
2004).
Furthermore, Simha and Satyanarayan (2016) examined the perception of fraud
detection and prevention methods, using qualitative forensic auditor interviews. The
researchers also considered the role of technology in fraud detection and prevention. This
research is a response to the lack of qualitative articles, and the use of forensic auditors by
conducting qualitative interviews to expand the knowledge base. The researcher used a
literature review on the accounting context of fraud, coupled with other detection and
prevention methods. The literature review also included information related to the use of
technology to commit and combat fraud. The aim was to understand the phenomenon of
fraud from the perspective of forensic auditors, utilizing their experience. The researchers
described their methodology, which included the researcher as an instrument in the research
process. Simha and Satyanarayan found that forensic auditors are currently inadequate in
detecting fraud, so a method is needed to supplement, and increase the use of other
prevention methods. The researchers also recognized the role of technology in fraud. Other
findings included security concerns from respondents, and the need for auditors to receive
training in criminal profiling, technology, and behavioral finance. The researchers concluded
the discussion by encouraging further research in the future (Simha and Satyanarayan, 2016).
Other researchers conducted research on automated methods of detecting fraud.
Simeunović, Grubor, and Ristic (2016) examined the use of digital forensic analysis to detect
fraud. Specific cases were examined and researched related to employee fraud, the result of
which was that the introduced concept proved effective for investigating accounting fraud
and detecting evidence of digital fraud. The researchers noted that of the overall 65%
detected fraud, 10% were detected by auditors and 23% were detected by proactive internal
controls. Simeunović et al. added that proactive prevention requires adequate controls and
creating a culture of honesty and integrity in the workplace. In today's era of big data,
technology, and complexity, the authors recommend a combined approach of digital analytics
and audit skills for fraud prevention (Simeunović, et al., 2016).
5.0 Conclusions and Suggestions:
To explore and understand the relevant patterns and themes of early detection of
financial statement fraud, the relevant literature is on the topics of motivation, intention,
responsibility, and fraud prevention. Most of the literature focuses on the fraud triangle as a
consequence of previous fraud cases.
Much of the literature focuses on internal controls and corporate governance in
relation to the audit process, including the need for planned reviews of internal controls and
risk assessments as part of the audit process. Some researchers studied the ability of auditors
to recognize fraud and determined that more training is needed for auditors to determine the
motivation of someone committing fraud. So that further research is needed related to fraud
prevention in the audit process proactive prevention requires adequate controls and a good
ethical culture within the company.
It was found that current fraud detection methods are still inadequate. In addition to
focusing on the audit process, research was also conducted on internal control and corporate
governance. Another focus is on the ethical and behavioral aspects of corporate culture, for
the development of fraud detection models and some recommended prevention strategies.
This includes the extent of audit responsibility for detection in auditors' perceptions of fraud
prevention. And another recommendation is the lack of consensus on the role of auditors in
detecting and preventing fraud, and the limited qualitative research related to it.
Although there is a lot of literature on fraud on financial statements, there are still
gaps related to proactive prevention. That is, there is a gap in the concept of risk management
in current practice to detect and prevent fraud, as well as how auditors' perspectives on
detecting fraud and creating proactive models to detect and prevent fraud. In addition,
practitioners can also use this information in developing proactive risk management
procedures for fraud prevention, and auditors may be able to develop guidelines for early
fraud detection in risk monitoring.
Fraud includes intentional dishonesty, misrepresentation, manipulation and display of
facts that can harm others and organizations including banks. Fraud also includes theft,
appropriation, attempts to obtain something illegally, and errors in making financial
statements including the assets and liabilities of the organization (Gilbert & Wakefield,
2018). Thus, fraud is deception that includes the elements of: (a) a representation; (b) about
something material; (c) something that is not true; (d) and intentionally or gratuitously carried
out for later; (e) believed; (f) and acted upon by the victim; (g) so that in the end the victim
suffers losses (Zimbelmann, et. al, 2014).
Schematically, the ACFE describes occupational fraud in the form of a fraud tree.
This fraud tree depicts the branches of occupational fraud, along with their twigs and
branches. So the occupational fraud tree has three main branches, namely corruption, asset
misappropriation, and fraudulent statements (financial statement fraud) (Tuanakotta, 2010).
One theoretical explanation of the causes of someone committing fraud was first developed
by Donald Cressey with his theory known as the fraud triangle. In his theory, it is explained
that the fraud triangle is divided into three parts, namely pressure, opportunity, and
rationalization (Cressey, 1950). Pressure is the embezzlement of company money by a
perpetrator who starts from a pressure. The person has urgent financial needs, so that
personally individual needs are considered more important than organizational needs. The
second cause of fraud is opportunity, where fraud will be committed if there is an opportunity
where someone must have access to assets or have the authority to set control procedures that
allow fraud schemes to be carried out. The third cause is rationalization, meaning that fraud
is committed because there is a rationalization made by a person or group of people by
building justifications for the fraud committed. Fraud perpetrators usually look for reasons to
justify that what they are doing is not theft or fraud, but something that is indeed possible is
his or her right. However, some individuals are more prone to fraud than others. The
tendency to commit fraud depends on their ethical values and personal circumstances
(Abdullahi, et. al, 2015).
According to the Association of Certified Fraud Examiners (ACFE) report in 2020,
based on the frequency of fraud that occurs, asset misappropriation is the fraud that has the
highest frequency followed by corruption and the last is financial statement fraud. But
financial statement fraud is the type of fraud that has the most detrimental impact of fraud
among other types of fraud (ACFE, 2020).
Financial statement fraud is considered as management fraud that results in material
errors in the financial statements so that the financial statements contain misleading
information. The increase in various cases of accounting scandals in various countries around
the world has caused various parties to speculate that management has committed fraud in the
financial statements (Skousen & Wright, 2009).
Financial statement fraud is always related to corporate governance. According to
Dechow, et.el. (2012), the incidence of fraud is highest in companies with weak corporate
governance systems. The tendency to commit fraud is greater in companies with a
background dominated by insiders and most likely do not have an audit committee (Dechow,
et.al., 2012).
Prevention efforts against fraud will be more effective than repressive efforts.
Prevention needs to be done to avoid greater losses and damage to the reputation of
institutions and individuals. In addition, fraud incidents that are not immediately handled and
revealed because The slow handling will increasingly provide opportunities for the
perpetrator to cover up his actions with other fraud. Therefore, it is necessary to make efforts
to prevent the occurrence of true and targeted fraud, so that all forms and efforts of fraudulent
practices can be anticipated as early as possible in order to avoid the risk of loss (Kurniasari,
2017).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them. Every organizational activity will always have uncertainties that are
synonymous with risk, including the risk of fraud, so management must be responsible for
managing the risks that will be faced (Karyono, 2013).
2.0 Literature Review:
The Institute of Internal Auditors (IIA), an organization of internal auditors in the
United States, defines fraud as a set of impermissible and unlawful actions characterized by
an element of intentional fraud. This means that fraud is a fraud that implies a deviation and
unlawful act committed intentionally for a specific purpose, such as deceiving or misleading
other parties, which is carried out by the IIA people from both inside and outside the
organization (Karyono, 2013).
Furthermore, the Chartered Institute of Public Finance and Accountancy (CIPFA)
states fraud as intentional misconduct and concealment of material facts, omission of
evidence to commit fraud and manipulation to the financial detriment of an individual or
organization. Fraud includes embezzlement, theft, forgery, misappropriation, and
deliberately removing evidence (CIPFA, 2013).
It can be generally defined that fraud is a general term, and encompasses any means
that can be used with a certain shrewdness, chosen by an individual, to gain an advantage
over others by making false representations. There is no fixed rule that can be issued as a
general proposition in defining fraud, including surprise, deceit, or cunning and unnatural
means used to commit fraud. The only limits to defining fraud are those that limit human
dishonesty (Zimbelman, et.al., 2014).
Fraud in corporate organizations generally comes from two directions, namely
internal and external. Internal fraud is fraud originating from parties within the corporate
organization itself, such as corruption, presentation of false reports, financial statement
engineering, double financial statements, covering or disguising embezzlement,
incompetence in accounting, theft or improper use of organizational assets by employees and
management for personal or group interests and use that is not in accordance with its
designation. While external fraud is fraud that comes from outside the company's
organization, such as bribery, increasing the value of invoices, double invoicing and quality
fraud such as goods transactions that are not in accordance with the company's policies
agreed presentation (Sayyid, 2014).
Fraudulent statements, namely fraud by presenting financial statements better than
they actually are (over statement) and worse than they actually are (under statement)
(Karyono, 2013), presenting assets or revenues higher than they actually are, or presenting
assets and revenues lower than they actually are (Tuanakotta, 2010), deliberate actions to
produce misleading financial statement material to deceive or misrepresent the organization's
financial position (Albashrawi, 2016), making the organization look more or less profitable
(Apostolou & Apostolou, 2012). While asset misappropriation fraud is the illegal "taking"
(unauthorized or against the law) committed by someone who is authorized to manage or
oversee these assets (Tuanakotta, 2010). And corruption is an act that harms the public
interest or the wider community for the benefit of certain individuals or groups. Corruption
can occur in private corporate organizations as well as in the public sector of government
(Karyono, 2013).
There are several things that motivate management to present financial statements that
contain elements of fraud: (a) provide support to keep stock prices high; (b) provide support
for bonds and shares; and (c) maximize bonuses for management (Zimbelman, et. al., 2014).
According to the Association of Certified Fraud Examiners (ACFE) in its third edition
manual, fraud axioms include: 1) Hidden, this fraud is carried out in a hidden manner and
tries to cover up its actions; 2) Reverse evidence, to prove that fraud has occurred, it must be
attempted so that the fraud does not occur, and vice versa; 3) Types of fraud, which consists
of internal fraud and system control fraud. Internal fraud occurs naturally which is inherent
in every form of activity. System control fraud occurs due to a weak internal control system
and usually the perpetrator has knowledge of the internal work system (Karyono, 2013).
There are several factors that cause someone to commit fraud. Because almost every
criminal act or crime is always driven or triggered by a condition and behavior that causes it.
In this discussion, researchers limit it to using only the Fraud Triangle Theory. According to
this theory, that fraud behavior is carried out or carried out because of three elements, namely
pressure, opportunity, and justification (rationalization). The theory, first formulated by
criminologist Donald R. Cressey (1950), concludes that fraud is generally divided into three
general characteristics. First, fraudsters who have the opportunity to commit fraud
(opportunity). Second, fraudsters have urgent financial needs that cannot be told to others
(pressure). Third, individuals involved in fraud rationalize their fraudulent actions consistent
with their personal code of ethics (rationalization) (Cressey, 1950). And the three fraud
factors are reinforced by the results of research by Skousen et. al. as "triangle fraud"
(Skousen et.al., 2009).
Fraud that occurs in many fields is inseparable from the desire to take other people's
rights for personal or group interests and then justify that fraud is a common thing that can be
done and also because of the opportunity to commit fraud. Fraud in the accounting field can
occur in the process of processing accounting data contained in accounting information in the
form of financial statements. If the fraud factor occurs in the preparation of financial
statements, it is certain that the financial statements presented are not fair. Fraud not only
damages the trust relationship between management and investors but will also harm the
values of accounting itself.
Financial statement fraud affects various market participants, including investors,
organizations, and employees. As previous research provides information related to indirect
organizational losses for fraud. In addition to the material losses borne by the organization,
the organization's reputation may also be questioned when fraud occurs. Investors' trust in the
organization will be lost and may withdraw all their deposits including investments and
pension funds (Perols, 2011; Ugrin & Odom, 2010). Fraud that occurs in an organization is a
classic manifestation of weak organizational governance. In private organizations, there is a
difference of interest between the principal and the agent. This problem arises because when
the owner (principal) authorizes the manager (agent) to act on their behalf. Which is
basically due to differences in interests and information asymmetry between managers and
owners. This problem can be eliminated if both parties have the same interests (Jensen &
William, 1976).
Unhealthy practices in corporate governance allow fraud to occur which is difficult to
detect by stakeholders. Corporate governance is a tool to ensure that directors and managers
(insiders) act in the best interests of investors. Capital market management bodies in many
countries state that the implementation of good corporate governance in public companies has
succeeded in preventing fraudulent practices on financial reports to interested parties (Chen,
et. al., 2005).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them (Karyono, 2013). Every organizational activity will always have uncertainties
that are synonymous with risk including the risk of fraud, so management must be
responsible for managing the risks that will be faced.
The main foundation in implementing an effective fraud prevention program in the
organization is to carry out a thorough risk assessment process. The basic concept of fraud
risk assessment is an assessment of the occurrence and impact of the risks that have been
identified. In the Committee of Sponsoring Organizations of the Threadway Commission,
there are several stages in the fraud risk assessment process including: (a) form a risk
assessment team involving the appropriate level of management; (b) identify potential
organizational fraud risks by assessing risks at all levels of the organization and those from
the internal and external environment, accommodating various types of fraud and considering
the occurrence of management override control; (c) assess the likelihood and significance of
each identified fraud risk; (d) determine employees and departments potentially involved
based on the fraud triangle; (d) identifying existing controls and assessing their effectiveness;
(e) assessing and responding to any residual fraud risks that need to be mitigated; (f)
identifying any controls in place and assessing their effectiveness mitigated; (f) document the
fraud risk assessment; (g) reassess fraud risk periodically (COSO, 2017). And Fraud Risk
Assessment (FRA) is a unique procedure for distinguishing and evaluating the risk of gaps in
the achievement of organizational goals (Huber, et. al., 2015).
Furthermore, Popoola argues that the implementation of fraud risk assessment (FRA)
requires change and an iterative cyclical process to be able to identify and assess the risk of
gaps in the achievement of organizational goals. Fraud risk assessment requires taking into
account changes in the external environment and their impact on the activity model, the
purpose of which is to control ineffective internal activities. Assessment of fraud risk is
considered an effective tool for fraud prevention and because this tool can increase auditor
competence in searching for, detecting and preventing fraud (Popoola, et.al., 2016).
Risk management theory states that risk treatment can be done in various ways,
namely:
2) avoid risk, meaning by deciding not to carry out activities that carry risk; 2) reduce risk,
which is to reduce the likelihood of occurrence and reduce its consequences or impact; 3)
transfer risk, which is to transfer risk to other parties to bear the risk; 4) accept risk, meaning
without taking further action to compensate for the risks that must be taken; and 5) exploit
risk, which is the action to take risks in other options which are the result of proactive
decisions and are carried out consciously to take new risks because they have superior areas
(Susilo & Victor, 2019). Steps or processes carried out in a systematic way to manage risk
threats are known as risk management (Siahaan, 2009).
While the risk management process based on ISO 31000 consists of three major
processes, which include: (1) context setting, aimed at identifying and expressing
organizational goals; (2) risk assessment, which consists of risk identification, risk analysis,
and risk evaluation; (3) risk handling, which consists of: risk avoidance, risk mitigation, risk
transfer, and risk acceptance. The three major processes are accompanied by two processes,
namely: (a) communication and consultation; and (b) monitoring and review (Susilo &
Victor, 2019; Suwanda, et. al., 2019).
3.0 Research Methods:
The methodology used in this research is through library research, which is a research
method carried out by studying literature and writings that have a close relationship with the
problems raised in the research (Baidan, 2016), through a qualitative approach, which is
research that emphasizes process analysis of deductive and inductive thinking processes
related to the dynamics of relationships between observed phenomena, and always uses
scientific logic (Kisworo & Iwan, 2017).
While the data source of this research is a secondary data source consisting of relevant
previous scientific research works, in the form of books and other scientific works with
various points of view. Meanwhile, the data used is a variety of quality-assured qualitative
data in the form of words, sentences, gestures, facial expressions, charts, drawings and
photographs (Sugiyono, 2011) derived from these various sources.
4.0 Results and Discussion:
As previously discussed, in an effort to prevent fraud, management must carry out a
process of managing its organizational resources to anticipate risks that may occur which
have previously been identified, measured and considered how to handle them. Every
organizational activity will always have uncertainties that are synonymous with risk,
including the risk of fraud, so management must be responsible for managing the risks that
will be faced (Karyono, 2013).
Risk management and internal control contribute to the implementation of good
corporate governance (GCG), especially in improving the success of achieving
organizational goals. Without risk management, the internal control system becomes less
effective. Meanwhile, without an internal control system, the control aspects of GCG are less
effective (Susilo & Victor, 2019).
Robert Moeller in his study of the Committee of Sponsoring Organizations (COSO)
internal control, provides a clear picture of the relationship between corporate governance -
risk management - internal control, as shown in the following figure. In the section entitled
"Clearing up a few misconceptions" it is emphasized that, enterprise risk management (ERM)
goes further than internal control. Internal control is an integrated part of ERM. Internal
control is an important part of enterprise risk management (Moeller, 2014).
Furthermore, Ovidiu-Constantin et. al. (2010) highlighted the importance of risk
management and its role in an organization's internal audit. The existence of a risk
management program means placing high confidence in the organization's financial
statements and better audit risk. The implementation of a risk management program, as with
previous research, explains the role of internal auditors in providing assurance on risk
management. An audit risk model is offered to external auditors based on and tailored to the
organization's risk management, the essence of which is that risk management as a solution to
the fraud crisis (Constantin, et. al., 2010).
While the previous research focused on a holistic approach to risk management, in his
research, Lister (2007) discussed the importance of antifraud programs. Organizations must
know the risks in order to mitigate them. This requires a comprehensive fraud risk
assessment, and corresponds to a holistic approach. Anti-fraud programs can increase
stakeholder confidence. However, Lister suggests the approach should be proactive and
reactive, by identifying risks and having an action plan in case of fraud. The three main plan
components include setting regulations through policy and communication, making risk
assessment and monitoring more proactive, and responding by designing a reactive plan.
Lister evaluates planning and implementation using the fraud triangle, and includes third-
party assessments in designing the program (Lister, 2007).
Research conducted by Crockford (2005) discusses risk as a function of change. The
article was originally published in the Geneva Papers in 1976. It explained that risk
management as the ability to cope with change. Rapid change puts pressure on risk
management, this results in difficulties for the organization to adapt. As with Mehr and
Forbes (1973), Crockford recommends that risk management should function by all
managers, not just one department in the organization (Crockford, 2005).
Snider (1990) has also discussed risk management objectives and the importance of
clear risk management objectives. Snider (1990) highlights the steps in developing risk
management objectives. The creation of risk management policies should come from risk
managers or management consultants. A clear policy can generally provide guidance in
decision-making. When identified, there are several things that influence goal setting,
including organizational structure, reporting systems, and short- or long-term goals. Too
much focus on short-term goals in the past can lead to losses due to neglect of controls and
prevention (Snider, 1990).
As with previous research, Snider (1991) recognized the need to expand the risk
management function beyond insurance, and the need for risk management education. In
addition to discussing the concept of risk management, this study also covers the history and
development of risk management, including recognition by academics, the first academic
book on risk management, and the position of risk managers in organizations. He highlights
the initial resistance by senior management, citing the idea that change equals uncertainty.
Snider also discusses the crisis in the early 1970s, related to insurance, which led to the
acceptance of the concept of risk management. And in 1973, the Geneva Association was
founded, thus encouraging research on risk management, and publishing many conceptual
papers on this topic (Snider, 1991).
Aggarwal, Erel, Stulz, and Williamson (2009) studied the effect of a country's
economic and financial development on investment levels in relation to corporate
governance. The findings show that favorable development results in higher investment, and
less investment in firms with poor governance resulting in lower firm value. His research also
provides minimum governance standards for audits: (1) consulting fees are lower than audit
fees; (2) the audit committee consists of independent outsiders; and (3) the auditor must be
authorized at the annual meeting (Aggarwal, et.al., 2009). This is reinforced by Robu's
research (2015) providing an analysis of the relevance of IFRS (International Financial
Reporting Standars) adoption for trust in financial statement information. Researchers took a
sample of 59 companies before and after IFRS adoption. The results showed that there was an
increase in value relevance after IFRS adoption. The research methodology includes to
determine the effect of IFRS adoption on stock prices, and provides recommendations that
standardized reporting and transparency as a solution for a trusted financial market (Robu,
2015).
Previous research conducted by Kang (2008), provides an analysis from another point
of view in the fraud literature, namely the study of reputational penalties associated with
financial fraud and reputation as a penalty for the companies involved. The findings show an
increase in reputational penalties (decrease) for the companies involved. A decrease in market
value is one of the negative effects. The researcher used signalling theory and attribution
theory to explain the related company relationship. The study sampled 244 related firms and
30 suspect firms, from 1998 to 2002. The findings also show that an increase in uncertainty
leads to a negative effect decrease in investor confidence. However, good governance can
increase investor confidence. The implications of his findings recommend the need for
governance reform (Kang, 2008).
Still on financial statement fraud. Fleming, Riley Jr, Hermanson, and Kranacher
(2016) extended the fraud aspect of research with a study of the most fundamental differences
in financial statement fraud between public and private companies. The researchers found a
lack of data available for private companies by using data sources provided by the
Association of Certified Fraud Examiners (ACFE). Fleming et al. (2016) cite that financial
statement fraud is one of the most costly forms of fraud, with an average loss of $1.5 billion.
$1 million per incident. This is in addition to additional reputational impacts, such as
bankruptcy and loss of market value. Some of the other findings of this study are that the
increasing controls on publicly traded companies indicate the use of less obvious methods of
reporting fraud, such as differences in the timing of reporting. And it will usually continue to
grow if the existing controls continue to be improved. The main purpose of this study is for
audit purposes for its concern in highlighting the difference in treatment between public
companies and private companies (Fleming, et. al., 2016).
Furthermore, Ng, White, Lee, and Moneta (2009) examined the focus on developing
instruments to detect managers' fraud tendencies in managing income. Researchers used an
ethical scenario survey method to collect information to design fraud detection instruments
and factor analysis used as a response. Researchers also used the moral intensity construct to
determine managers' intention to act specifically. The construct consists of six characteristics
Moral intensity includes the magnitude of consequences and social consensus. The findings
suggest that the proposed instrument could be operationalized to measure moral intensity in
future studies (Ng, et. al, 2009).
Previously, Shafer (2002) also examined the role of morals. Shafer analyzed financial
statement fraud in the context of an ethical model of decision making. The ANOVA results
show that materiality and risk are significant factors that affect the likelihood of committing
fraud, while the morality factor is not significant. The researcher used Jones' theory of moral
intensity to explain the prevalence of earnings management. The findings mention the
materiality effect with a note of rationalization when the amount is not material, and a more
than 50% probability of committing fraud when the amount is not material. The key indicator
of the absence of ethical behavior is about the perception of what his friend is doing (Shafer,
2002).
Some researchers focus on auditor responsibility. Kostova (2013) revealed a
relationship between fraud characteristics and audit procedures. Kostova describes the
auditor's responsibility to disclose errors and fraud. Auditors are expected to provide opinions
and conclusions about the reliability of financial statements. Furthermore, the researcher also
revealed the existence of economic factors that cause fraud, also identifies its characteristics.
Researchers mention the economic environment as the main factor that leads to fraud. For
example, organizations are under pressure to achieve financial targets (Kostova, 2013).
In contrast to Kostova (2013) who focused on economic factors, Love (2012)
examined auditor responsibility for fraud detection related to reporting standards. It should be
noted that the GAAS (Generally Accepted Auditing Standars) standard recognizes the
absence of the ability to provide absolute assurance, but rather provides reasonable assurance
and reduces the risk of material misstatement. Auditor discovery of questionable information
requires re-evaluation of all audit areas. Fraudsters may conceal their actions through false
statements and documents during the audit process. Love noted the difference between
conducting a GAAS audit and a fraud examination. A GAAS audit results in an auditor's
opinion on the fairness of the financial statement presentation. Regarding auditor perceptions,
Johnson, Kuhn, Apostolou, and Hassell (2013) examined auditors' fraud risk assessment of
management attitudes. The researchers tested whether observable indicators of narcissism by
auditors are indicators of increased risk. The findings of this study indicate a link between
narcissism and fraud, consistently with the behaviors observed in recent fraud. Researchers
evaluated the ability of auditors to recognize fraud, which requires auditors with higher
abilities and experience. This study also concluded that managerial narcissism is an
observable action and recommended improving the assessment guidelines for fraud (Johnson,
et. al., 2013).
Philmore and Michael (2005) conducted a necessary study on the perceived
responsibility of auditors to detect Enron fraud. The study was to determine the nature and
extent of fraud in Barbados. The researchers used a mixed methods design for the exploratory
study. By conducting a survey of 43 respondents about perceptions and experiences in fraud.
The purpose of The qualitative approach was to support the quantitative survey in fully
understanding the research question. The researcher conducted face-to-face interviews to gain
multiple sources of insight. This article is useful for investors, auditors, and regulators, and
contributes to the understanding of the auditor's role in detecting fraud. The researchers
provided historical background on the role of the auditor, and a review of related literature,
but found there is still a lack of consensus on the role of the auditor. There are several
findings presented in this research study. The majority of respondents stated that fraud
detection is the responsibility of the auditor, while others stated that detection is the
responsibility of management. In particular, those respondents with an accounting
background assume that management is responsible for detecting fraud (Philmore and
Michael, 2005).
In contrast to previous research, Nicolaescu (2013) focuses on the role of internal
audit in detecting fraud. The size of the audit firm affects the quality of the audit report.
Researchers found that rigor can improve the ability to detect fraud. The ability to detect
fraud can also be enhanced by the presence of internal auditors. One finding suggested that
brainstorming can be used as a means for internal auditors to respond to risk assessment. This
study also concluded that internal audit is an important part of corporate governance
(Nicolaescu, 2013).
Previously, Kranacher and Stern (2004) provided suggestions for improving fraud
detection. According to a COSO (Committee of Sponsoring Organization) study, CEOs
commit 75% of all fraud. Meanwhile, Klarskov Jeppesen and Leder (2016) state the need for
auditors to question the integrity of managers, Kranacher and Stern (2004) note a potential
conflict of interest between the auditor and the hiring department executive. Legislation
serves as a deterrent to fraudulent behavior, as auditors must actively detect fraud.
Furthermore, researchers recommend that auditor education should be improved to include
behavioral understanding, investigative skills and deeper analysis (Kranacher and Stern,
2004).
Furthermore, Simha and Satyanarayan (2016) examined the perception of fraud
detection and prevention methods, using qualitative forensic auditor interviews. The
researchers also considered the role of technology in fraud detection and prevention. This
research is a response to the lack of qualitative articles, and the use of forensic auditors by
conducting qualitative interviews to expand the knowledge base. The researcher used a
literature review on the accounting context of fraud, coupled with other detection and
prevention methods. The literature review also included information related to the use of
technology to commit and combat fraud. The aim was to understand the phenomenon of
fraud from the perspective of forensic auditors, utilizing their experience. The researchers
described their methodology, which included the researcher as an instrument in the research
process. Simha and Satyanarayan found that forensic auditors are currently inadequate in
detecting fraud, so a method is needed to supplement, and increase the use of other
prevention methods. The researchers also recognized the role of technology in fraud. Other
findings included security concerns from respondents, and the need for auditors to receive
training in criminal profiling, technology, and behavioral finance. The researchers concluded
the discussion by encouraging further research in the future (Simha and Satyanarayan, 2016).
Other researchers conducted research on automated methods of detecting fraud.
Simeunović, Grubor, and Ristic (2016) examined the use of digital forensic analysis to detect
fraud. Specific cases were examined and researched related to employee fraud, the result of
which was that the introduced concept proved effective for investigating accounting fraud
and detecting evidence of digital fraud. The researchers noted that of the overall 65%
detected fraud, 10% were detected by auditors and 23% were detected by proactive internal
controls. Simeunović et al. added that proactive prevention requires adequate controls and
creating a culture of honesty and integrity in the workplace. In today's era of big data,
technology, and complexity, the authors recommend a combined approach of digital analytics
and audit skills for fraud prevention (Simeunović, et al., 2016).
5.0 Conclusions and Suggestions:
To explore and understand the relevant patterns and themes of early detection of
financial statement fraud, the relevant literature is on the topics of motivation, intention,
responsibility, and fraud prevention. Most of the literature focuses on the fraud triangle as a
consequence of previous fraud cases.
Much of the literature focuses on internal controls and corporate governance in
relation to the audit process, including the need for planned reviews of internal controls and
risk assessments as part of the audit process. Some researchers studied the ability of auditors
to recognize fraud and determined that more training is needed for auditors to determine the
motivation of someone committing fraud. So that further research is needed related to fraud
prevention in the audit process proactive prevention requires adequate controls and a good
ethical culture within the company.
It was found that current fraud detection methods are still inadequate. In addition to
focusing on the audit process, research was also conducted on internal control and corporate
governance. Another focus is on the ethical and behavioral aspects of corporate culture, for
the development of fraud detection models and some recommended prevention strategies.
This includes the extent of audit responsibility for detection in auditors' perceptions of fraud
prevention. And another recommendation is the lack of consensus on the role of auditors in
detecting and preventing fraud, and the limited qualitative research related to it.
Although there is a lot of literature on fraud on financial statements, there are still
gaps related to proactive prevention. That is, there is a gap in the concept of risk management
in current practice to detect and prevent fraud, as well as how auditors' perspectives on
detecting fraud and creating proactive models to detect and prevent fraud. In addition,
practitioners can also use this information in developing proactive risk management
procedures for fraud prevention, and auditors may be able to develop guidelines for early
fraud detection in risk monitoring.
Fraud includes intentional dishonesty, misrepresentation, manipulation and display of
facts that can harm others and organizations including banks. Fraud also includes theft,
appropriation, attempts to obtain something illegally, and errors in making financial
statements including the assets and liabilities of the organization (Gilbert & Wakefield,
2018). Thus, fraud is deception that includes the elements of: (a) a representation; (b) about
something material; (c) something that is not true; (d) and intentionally or gratuitously carried
out for later; (e) believed; (f) and acted upon by the victim; (g) so that in the end the victim
suffers losses (Zimbelmann, et. al, 2014).
Schematically, the ACFE describes occupational fraud in the form of a fraud tree.
This fraud tree depicts the branches of occupational fraud, along with their twigs and
branches. So the occupational fraud tree has three main branches, namely corruption, asset
misappropriation, and fraudulent statements (financial statement fraud) (Tuanakotta, 2010).
One theoretical explanation of the causes of someone committing fraud was first developed
by Donald Cressey with his theory known as the fraud triangle. In his theory, it is explained
that the fraud triangle is divided into three parts, namely pressure, opportunity, and
rationalization (Cressey, 1950). Pressure is the embezzlement of company money by a
perpetrator who starts from a pressure. The person has urgent financial needs, so that
personally individual needs are considered more important than organizational needs. The
second cause of fraud is opportunity, where fraud will be committed if there is an opportunity
where someone must have access to assets or have the authority to set control procedures that
allow fraud schemes to be carried out. The third cause is rationalization, meaning that fraud
is committed because there is a rationalization made by a person or group of people by
building justifications for the fraud committed. Fraud perpetrators usually look for reasons to
justify that what they are doing is not theft or fraud, but something that is indeed possible is
his or her right. However, some individuals are more prone to fraud than others. The
tendency to commit fraud depends on their ethical values and personal circumstances
(Abdullahi, et. al, 2015).
According to the Association of Certified Fraud Examiners (ACFE) report in 2020,
based on the frequency of fraud that occurs, asset misappropriation is the fraud that has the
highest frequency followed by corruption and the last is financial statement fraud. But
financial statement fraud is the type of fraud that has the most detrimental impact of fraud
among other types of fraud (ACFE, 2020).
Financial statement fraud is considered as management fraud that results in material
errors in the financial statements so that the financial statements contain misleading
information. The increase in various cases of accounting scandals in various countries around
the world has caused various parties to speculate that management has committed fraud in the
financial statements (Skousen & Wright, 2009).
Financial statement fraud is always related to corporate governance. According to
Dechow, et.el. (2012), the incidence of fraud is highest in companies with weak corporate
governance systems. The tendency to commit fraud is greater in companies with a
background dominated by insiders and most likely do not have an audit committee (Dechow,
et.al., 2012).
Prevention efforts against fraud will be more effective than repressive efforts.
Prevention needs to be done to avoid greater losses and damage to the reputation of
institutions and individuals. In addition, fraud incidents that are not immediately handled and
revealed because The slow handling will increasingly provide opportunities for the
perpetrator to cover up his actions with other fraud. Therefore, it is necessary to make efforts
to prevent the occurrence of true and targeted fraud, so that all forms and efforts of fraudulent
practices can be anticipated as early as possible in order to avoid the risk of loss (Kurniasari,
2017).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them. Every organizational activity will always have uncertainties that are
synonymous with risk, including the risk of fraud, so management must be responsible for
managing the risks that will be faced (Karyono, 2013).
2.0 Literature Review:
The Institute of Internal Auditors (IIA), an organization of internal auditors in the
United States, defines fraud as a set of impermissible and unlawful actions characterized by
an element of intentional fraud. This means that fraud is a fraud that implies a deviation and
unlawful act committed intentionally for a specific purpose, such as deceiving or misleading
other parties, which is carried out by the IIA people from both inside and outside the
organization (Karyono, 2013).
Furthermore, the Chartered Institute of Public Finance and Accountancy (CIPFA)
states fraud as intentional misconduct and concealment of material facts, omission of
evidence to commit fraud and manipulation to the financial detriment of an individual or
organization. Fraud includes embezzlement, theft, forgery, misappropriation, and
deliberately removing evidence (CIPFA, 2013).
It can be generally defined that fraud is a general term, and encompasses any means
that can be used with a certain shrewdness, chosen by an individual, to gain an advantage
over others by making false representations. There is no fixed rule that can be issued as a
general proposition in defining fraud, including surprise, deceit, or cunning and unnatural
means used to commit fraud. The only limits to defining fraud are those that limit human
dishonesty (Zimbelman, et.al., 2014).
Fraud in corporate organizations generally comes from two directions, namely
internal and external. Internal fraud is fraud originating from parties within the corporate
organization itself, such as corruption, presentation of false reports, financial statement
engineering, double financial statements, covering or disguising embezzlement,
incompetence in accounting, theft or improper use of organizational assets by employees and
management for personal or group interests and use that is not in accordance with its
designation. While external fraud is fraud that comes from outside the company's
organization, such as bribery, increasing the value of invoices, double invoicing and quality
fraud such as goods transactions that are not in accordance with the company's policies
agreed presentation (Sayyid, 2014).
Fraudulent statements, namely fraud by presenting financial statements better than
they actually are (over statement) and worse than they actually are (under statement)
(Karyono, 2013), presenting assets or revenues higher than they actually are, or presenting
assets and revenues lower than they actually are (Tuanakotta, 2010), deliberate actions to
produce misleading financial statement material to deceive or misrepresent the organization's
financial position (Albashrawi, 2016), making the organization look more or less profitable
(Apostolou & Apostolou, 2012). While asset misappropriation fraud is the illegal "taking"
(unauthorized or against the law) committed by someone who is authorized to manage or
oversee these assets (Tuanakotta, 2010). And corruption is an act that harms the public
interest or the wider community for the benefit of certain individuals or groups. Corruption
can occur in private corporate organizations as well as in the public sector of government
(Karyono, 2013).
There are several things that motivate management to present financial statements that
contain elements of fraud: (a) provide support to keep stock prices high; (b) provide support
for bonds and shares; and (c) maximize bonuses for management (Zimbelman, et. al., 2014).
According to the Association of Certified Fraud Examiners (ACFE) in its third edition
manual, fraud axioms include: 1) Hidden, this fraud is carried out in a hidden manner and
tries to cover up its actions; 2) Reverse evidence, to prove that fraud has occurred, it must be
attempted so that the fraud does not occur, and vice versa; 3) Types of fraud, which consists
of internal fraud and system control fraud. Internal fraud occurs naturally which is inherent
in every form of activity. System control fraud occurs due to a weak internal control system
and usually the perpetrator has knowledge of the internal work system (Karyono, 2013).
There are several factors that cause someone to commit fraud. Because almost every
criminal act or crime is always driven or triggered by a condition and behavior that causes it.
In this discussion, researchers limit it to using only the Fraud Triangle Theory. According to
this theory, that fraud behavior is carried out or carried out because of three elements, namely
pressure, opportunity, and justification (rationalization). The theory, first formulated by
criminologist Donald R. Cressey (1950), concludes that fraud is generally divided into three
general characteristics. First, fraudsters who have the opportunity to commit fraud
(opportunity). Second, fraudsters have urgent financial needs that cannot be told to others
(pressure). Third, individuals involved in fraud rationalize their fraudulent actions consistent
with their personal code of ethics (rationalization) (Cressey, 1950). And the three fraud
factors are reinforced by the results of research by Skousen et. al. as "triangle fraud"
(Skousen et.al., 2009).
Fraud that occurs in many fields is inseparable from the desire to take other people's
rights for personal or group interests and then justify that fraud is a common thing that can be
done and also because of the opportunity to commit fraud. Fraud in the accounting field can
occur in the process of processing accounting data contained in accounting information in the
form of financial statements. If the fraud factor occurs in the preparation of financial
statements, it is certain that the financial statements presented are not fair. Fraud not only
damages the trust relationship between management and investors but will also harm the
values of accounting itself.
Financial statement fraud affects various market participants, including investors,
organizations, and employees. As previous research provides information related to indirect
organizational losses for fraud. In addition to the material losses borne by the organization,
the organization's reputation may also be questioned when fraud occurs. Investors' trust in the
organization will be lost and may withdraw all their deposits including investments and
pension funds (Perols, 2011; Ugrin & Odom, 2010). Fraud that occurs in an organization is a
classic manifestation of weak organizational governance. In private organizations, there is a
difference of interest between the principal and the agent. This problem arises because when
the owner (principal) authorizes the manager (agent) to act on their behalf. Which is
basically due to differences in interests and information asymmetry between managers and
owners. This problem can be eliminated if both parties have the same interests (Jensen &
William, 1976).
Unhealthy practices in corporate governance allow fraud to occur which is difficult to
detect by stakeholders. Corporate governance is a tool to ensure that directors and managers
(insiders) act in the best interests of investors. Capital market management bodies in many
countries state that the implementation of good corporate governance in public companies has
succeeded in preventing fraudulent practices on financial reports to interested parties (Chen,
et. al., 2005).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them (Karyono, 2013). Every organizational activity will always have uncertainties
that are synonymous with risk including the risk of fraud, so management must be
responsible for managing the risks that will be faced.
The main foundation in implementing an effective fraud prevention program in the
organization is to carry out a thorough risk assessment process. The basic concept of fraud
risk assessment is an assessment of the occurrence and impact of the risks that have been
identified. In the Committee of Sponsoring Organizations of the Threadway Commission,
there are several stages in the fraud risk assessment process including: (a) form a risk
assessment team involving the appropriate level of management; (b) identify potential
organizational fraud risks by assessing risks at all levels of the organization and those from
the internal and external environment, accommodating various types of fraud and considering
the occurrence of management override control; (c) assess the likelihood and significance of
each identified fraud risk; (d) determine employees and departments potentially involved
based on the fraud triangle; (d) identifying existing controls and assessing their effectiveness;
(e) assessing and responding to any residual fraud risks that need to be mitigated; (f)
identifying any controls in place and assessing their effectiveness mitigated; (f) document the
fraud risk assessment; (g) reassess fraud risk periodically (COSO, 2017). And Fraud Risk
Assessment (FRA) is a unique procedure for distinguishing and evaluating the risk of gaps in
the achievement of organizational goals (Huber, et. al., 2015).
Furthermore, Popoola argues that the implementation of fraud risk assessment (FRA)
requires change and an iterative cyclical process to be able to identify and assess the risk of
gaps in the achievement of organizational goals. Fraud risk assessment requires taking into
account changes in the external environment and their impact on the activity model, the
purpose of which is to control ineffective internal activities. Assessment of fraud risk is
considered an effective tool for fraud prevention and because this tool can increase auditor
competence in searching for, detecting and preventing fraud (Popoola, et.al., 2016).
Risk management theory states that risk treatment can be done in various ways,
namely:
3) avoid risk, meaning by deciding not to carry out activities that carry risk; 2) reduce risk,
which is to reduce the likelihood of occurrence and reduce its consequences or impact; 3)
transfer risk, which is to transfer risk to other parties to bear the risk; 4) accept risk, meaning
without taking further action to compensate for the risks that must be taken; and 5) exploit
risk, which is the action to take risks in other options which are the result of proactive
decisions and are carried out consciously to take new risks because they have superior areas
(Susilo & Victor, 2019). Steps or processes carried out in a systematic way to manage risk
threats are known as risk management (Siahaan, 2009).
While the risk management process based on ISO 31000 consists of three major
processes, which include: (1) context setting, aimed at identifying and expressing
organizational goals; (2) risk assessment, which consists of risk identification, risk analysis,
and risk evaluation; (3) risk handling, which consists of: risk avoidance, risk mitigation, risk
transfer, and risk acceptance. The three major processes are accompanied by two processes,
namely: (a) communication and consultation; and (b) monitoring and review (Susilo &
Victor, 2019; Suwanda, et. al., 2019).
3.0 Research Methods:
The methodology used in this research is through library research, which is a research
method carried out by studying literature and writings that have a close relationship with the
problems raised in the research (Baidan, 2016), through a qualitative approach, which is
research that emphasizes process analysis of deductive and inductive thinking processes
related to the dynamics of relationships between observed phenomena, and always uses
scientific logic (Kisworo & Iwan, 2017).
While the data source of this research is a secondary data source consisting of relevant
previous scientific research works, in the form of books and other scientific works with
various points of view. Meanwhile, the data used is a variety of quality-assured qualitative
data in the form of words, sentences, gestures, facial expressions, charts, drawings and
photographs (Sugiyono, 2011) derived from these various sources.
4.0 Results and Discussion:
As previously discussed, in an effort to prevent fraud, management must carry out a
process of managing its organizational resources to anticipate risks that may occur which
have previously been identified, measured and considered how to handle them. Every
organizational activity will always have uncertainties that are synonymous with risk,
including the risk of fraud, so management must be responsible for managing the risks that
will be faced (Karyono, 2013).
Risk management and internal control contribute to the implementation of good
corporate governance (GCG), especially in improving the success of achieving
organizational goals. Without risk management, the internal control system becomes less
effective. Meanwhile, without an internal control system, the control aspects of GCG are less
effective (Susilo & Victor, 2019).
Robert Moeller in his study of the Committee of Sponsoring Organizations (COSO)
internal control, provides a clear picture of the relationship between corporate governance -
risk management - internal control, as shown in the following figure. In the section entitled
"Clearing up a few misconceptions" it is emphasized that, enterprise risk management (ERM)
goes further than internal control. Internal control is an integrated part of ERM. Internal
control is an important part of enterprise risk management (Moeller, 2014).
Furthermore, Ovidiu-Constantin et. al. (2010) highlighted the importance of risk
management and its role in an organization's internal audit. The existence of a risk
management program means placing high confidence in the organization's financial
statements and better audit risk. The implementation of a risk management program, as with
previous research, explains the role of internal auditors in providing assurance on risk
management. An audit risk model is offered to external auditors based on and tailored to the
organization's risk management, the essence of which is that risk management as a solution to
the fraud crisis (Constantin, et. al., 2010).
While the previous research focused on a holistic approach to risk management, in his
research, Lister (2007) discussed the importance of antifraud programs. Organizations must
know the risks in order to mitigate them. This requires a comprehensive fraud risk
assessment, and corresponds to a holistic approach. Anti-fraud programs can increase
stakeholder confidence. However, Lister suggests the approach should be proactive and
reactive, by identifying risks and having an action plan in case of fraud. The three main plan
components include setting regulations through policy and communication, making risk
assessment and monitoring more proactive, and responding by designing a reactive plan.
Lister evaluates planning and implementation using the fraud triangle, and includes third-
party assessments in designing the program (Lister, 2007).
Research conducted by Crockford (2005) discusses risk as a function of change. The
article was originally published in the Geneva Papers in 1976. It explained that risk
management as the ability to cope with change. Rapid change puts pressure on risk
management, this results in difficulties for the organization to adapt. As with Mehr and
Forbes (1973), Crockford recommends that risk management should function by all
managers, not just one department in the organization (Crockford, 2005).
Snider (1990) has also discussed risk management objectives and the importance of
clear risk management objectives. Snider (1990) highlights the steps in developing risk
management objectives. The creation of risk management policies should come from risk
managers or management consultants. A clear policy can generally provide guidance in
decision-making. When identified, there are several things that influence goal setting,
including organizational structure, reporting systems, and short- or long-term goals. Too
much focus on short-term goals in the past can lead to losses due to neglect of controls and
prevention (Snider, 1990).
As with previous research, Snider (1991) recognized the need to expand the risk
management function beyond insurance, and the need for risk management education. In
addition to discussing the concept of risk management, this study also covers the history and
development of risk management, including recognition by academics, the first academic
book on risk management, and the position of risk managers in organizations. He highlights
the initial resistance by senior management, citing the idea that change equals uncertainty.
Snider also discusses the crisis in the early 1970s, related to insurance, which led to the
acceptance of the concept of risk management. And in 1973, the Geneva Association was
founded, thus encouraging research on risk management, and publishing many conceptual
papers on this topic (Snider, 1991).
Aggarwal, Erel, Stulz, and Williamson (2009) studied the effect of a country's
economic and financial development on investment levels in relation to corporate
governance. The findings show that favorable development results in higher investment, and
less investment in firms with poor governance resulting in lower firm value. His research also
provides minimum governance standards for audits: (1) consulting fees are lower than audit
fees; (2) the audit committee consists of independent outsiders; and (3) the auditor must be
authorized at the annual meeting (Aggarwal, et.al., 2009). This is reinforced by Robu's
research (2015) providing an analysis of the relevance of IFRS (International Financial
Reporting Standars) adoption for trust in financial statement information. Researchers took a
sample of 59 companies before and after IFRS adoption. The results showed that there was an
increase in value relevance after IFRS adoption. The research methodology includes to
determine the effect of IFRS adoption on stock prices, and provides recommendations that
standardized reporting and transparency as a solution for a trusted financial market (Robu,
2015).
Previous research conducted by Kang (2008), provides an analysis from another point
of view in the fraud literature, namely the study of reputational penalties associated with
financial fraud and reputation as a penalty for the companies involved. The findings show an
increase in reputational penalties (decrease) for the companies involved. A decrease in market
value is one of the negative effects. The researcher used signalling theory and attribution
theory to explain the related company relationship. The study sampled 244 related firms and
30 suspect firms, from 1998 to 2002. The findings also show that an increase in uncertainty
leads to a negative effect decrease in investor confidence. However, good governance can
increase investor confidence. The implications of his findings recommend the need for
governance reform (Kang, 2008).
Still on financial statement fraud. Fleming, Riley Jr, Hermanson, and Kranacher
(2016) extended the fraud aspect of research with a study of the most fundamental differences
in financial statement fraud between public and private companies. The researchers found a
lack of data available for private companies by using data sources provided by the
Association of Certified Fraud Examiners (ACFE). Fleming et al. (2016) cite that financial
statement fraud is one of the most costly forms of fraud, with an average loss of $1.5 billion.
$1 million per incident. This is in addition to additional reputational impacts, such as
bankruptcy and loss of market value. Some of the other findings of this study are that the
increasing controls on publicly traded companies indicate the use of less obvious methods of
reporting fraud, such as differences in the timing of reporting. And it will usually continue to
grow if the existing controls continue to be improved. The main purpose of this study is for
audit purposes for its concern in highlighting the difference in treatment between public
companies and private companies (Fleming, et. al., 2016).
Furthermore, Ng, White, Lee, and Moneta (2009) examined the focus on developing
instruments to detect managers' fraud tendencies in managing income. Researchers used an
ethical scenario survey method to collect information to design fraud detection instruments
and factor analysis used as a response. Researchers also used the moral intensity construct to
determine managers' intention to act specifically. The construct consists of six characteristics
Moral intensity includes the magnitude of consequences and social consensus. The findings
suggest that the proposed instrument could be operationalized to measure moral intensity in
future studies (Ng, et. al, 2009).
Previously, Shafer (2002) also examined the role of morals. Shafer analyzed financial
statement fraud in the context of an ethical model of decision making. The ANOVA results
show that materiality and risk are significant factors that affect the likelihood of committing
fraud, while the morality factor is not significant. The researcher used Jones' theory of moral
intensity to explain the prevalence of earnings management. The findings mention the
materiality effect with a note of rationalization when the amount is not material, and a more
than 50% probability of committing fraud when the amount is not material. The key indicator
of the absence of ethical behavior is about the perception of what his friend is doing (Shafer,
2002).
Some researchers focus on auditor responsibility. Kostova (2013) revealed a
relationship between fraud characteristics and audit procedures. Kostova describes the
auditor's responsibility to disclose errors and fraud. Auditors are expected to provide opinions
and conclusions about the reliability of financial statements. Furthermore, the researcher also
revealed the existence of economic factors that cause fraud, also identifies its characteristics.
Researchers mention the economic environment as the main factor that leads to fraud. For
example, organizations are under pressure to achieve financial targets (Kostova, 2013).
In contrast to Kostova (2013) who focused on economic factors, Love (2012)
examined auditor responsibility for fraud detection related to reporting standards. It should be
noted that the GAAS (Generally Accepted Auditing Standars) standard recognizes the
absence of the ability to provide absolute assurance, but rather provides reasonable assurance
and reduces the risk of material misstatement. Auditor discovery of questionable information
requires re-evaluation of all audit areas. Fraudsters may conceal their actions through false
statements and documents during the audit process. Love noted the difference between
conducting a GAAS audit and a fraud examination. A GAAS audit results in an auditor's
opinion on the fairness of the financial statement presentation. Regarding auditor perceptions,
Johnson, Kuhn, Apostolou, and Hassell (2013) examined auditors' fraud risk assessment of
management attitudes. The researchers tested whether observable indicators of narcissism by
auditors are indicators of increased risk. The findings of this study indicate a link between
narcissism and fraud, consistently with the behaviors observed in recent fraud. Researchers
evaluated the ability of auditors to recognize fraud, which requires auditors with higher
abilities and experience. This study also concluded that managerial narcissism is an
observable action and recommended improving the assessment guidelines for fraud (Johnson,
et. al., 2013).
Philmore and Michael (2005) conducted a necessary study on the perceived
responsibility of auditors to detect Enron fraud. The study was to determine the nature and
extent of fraud in Barbados. The researchers used a mixed methods design for the exploratory
study. By conducting a survey of 43 respondents about perceptions and experiences in fraud.
The purpose of The qualitative approach was to support the quantitative survey in fully
understanding the research question. The researcher conducted face-to-face interviews to gain
multiple sources of insight. This article is useful for investors, auditors, and regulators, and
contributes to the understanding of the auditor's role in detecting fraud. The researchers
provided historical background on the role of the auditor, and a review of related literature,
but found there is still a lack of consensus on the role of the auditor. There are several
findings presented in this research study. The majority of respondents stated that fraud
detection is the responsibility of the auditor, while others stated that detection is the
responsibility of management. In particular, those respondents with an accounting
background assume that management is responsible for detecting fraud (Philmore and
Michael, 2005).
In contrast to previous research, Nicolaescu (2013) focuses on the role of internal
audit in detecting fraud. The size of the audit firm affects the quality of the audit report.
Researchers found that rigor can improve the ability to detect fraud. The ability to detect
fraud can also be enhanced by the presence of internal auditors. One finding suggested that
brainstorming can be used as a means for internal auditors to respond to risk assessment. This
study also concluded that internal audit is an important part of corporate governance
(Nicolaescu, 2013).
Previously, Kranacher and Stern (2004) provided suggestions for improving fraud
detection. According to a COSO (Committee of Sponsoring Organization) study, CEOs
commit 75% of all fraud. Meanwhile, Klarskov Jeppesen and Leder (2016) state the need for
auditors to question the integrity of managers, Kranacher and Stern (2004) note a potential
conflict of interest between the auditor and the hiring department executive. Legislation
serves as a deterrent to fraudulent behavior, as auditors must actively detect fraud.
Furthermore, researchers recommend that auditor education should be improved to include
behavioral understanding, investigative skills and deeper analysis (Kranacher and Stern,
2004).
Furthermore, Simha and Satyanarayan (2016) examined the perception of fraud
detection and prevention methods, using qualitative forensic auditor interviews. The
researchers also considered the role of technology in fraud detection and prevention. This
research is a response to the lack of qualitative articles, and the use of forensic auditors by
conducting qualitative interviews to expand the knowledge base. The researcher used a
literature review on the accounting context of fraud, coupled with other detection and
prevention methods. The literature review also included information related to the use of
technology to commit and combat fraud. The aim was to understand the phenomenon of
fraud from the perspective of forensic auditors, utilizing their experience. The researchers
described their methodology, which included the researcher as an instrument in the research
process. Simha and Satyanarayan found that forensic auditors are currently inadequate in
detecting fraud, so a method is needed to supplement, and increase the use of other
prevention methods. The researchers also recognized the role of technology in fraud. Other
findings included security concerns from respondents, and the need for auditors to receive
training in criminal profiling, technology, and behavioral finance. The researchers concluded
the discussion by encouraging further research in the future (Simha and Satyanarayan, 2016).
Other researchers conducted research on automated methods of detecting fraud.
Simeunović, Grubor, and Ristic (2016) examined the use of digital forensic analysis to detect
fraud. Specific cases were examined and researched related to employee fraud, the result of
which was that the introduced concept proved effective for investigating accounting fraud
and detecting evidence of digital fraud. The researchers noted that of the overall 65%
detected fraud, 10% were detected by auditors and 23% were detected by proactive internal
controls. Simeunović et al. added that proactive prevention requires adequate controls and
creating a culture of honesty and integrity in the workplace. In today's era of big data,
technology, and complexity, the authors recommend a combined approach of digital analytics
and audit skills for fraud prevention (Simeunović, et al., 2016).
5.0 Conclusions and Suggestions:
To explore and understand the relevant patterns and themes of early detection of
financial statement fraud, the relevant literature is on the topics of motivation, intention,
responsibility, and fraud prevention. Most of the literature focuses on the fraud triangle as a
consequence of previous fraud cases.
Much of the literature focuses on internal controls and corporate governance in
relation to the audit process, including the need for planned reviews of internal controls and
risk assessments as part of the audit process. Some researchers studied the ability of auditors
to recognize fraud and determined that more training is needed for auditors to determine the
motivation of someone committing fraud. So that further research is needed related to fraud
prevention in the audit process proactive prevention requires adequate controls and a good
ethical culture within the company.
It was found that current fraud detection methods are still inadequate. In addition to
focusing on the audit process, research was also conducted on internal control and corporate
governance. Another focus is on the ethical and behavioral aspects of corporate culture, for
the development of fraud detection models and some recommended prevention strategies.
This includes the extent of audit responsibility for detection in auditors' perceptions of fraud
prevention. And another recommendation is the lack of consensus on the role of auditors in
detecting and preventing fraud, and the limited qualitative research related to it.
Although there is a lot of literature on fraud on financial statements, there are still
gaps related to proactive prevention. That is, there is a gap in the concept of risk management
in current practice to detect and prevent fraud, as well as how auditors' perspectives on
detecting fraud and creating proactive models to detect and prevent fraud. In addition,
practitioners can also use this information in developing proactive risk management
procedures for fraud prevention, and auditors may be able to develop guidelines for early
fraud detection in risk monitoring.
Fraud includes intentional dishonesty, misrepresentation, manipulation and display of
facts that can harm others and organizations including banks. Fraud also includes theft,
appropriation, attempts to obtain something illegally, and errors in making financial
statements including the assets and liabilities of the organization (Gilbert & Wakefield,
2018). Thus, fraud is deception that includes the elements of: (a) a representation; (b) about
something material; (c) something that is not true; (d) and intentionally or gratuitously carried
out for later; (e) believed; (f) and acted upon by the victim; (g) so that in the end the victim
suffers losses (Zimbelmann, et. al, 2014).
Schematically, the ACFE describes occupational fraud in the form of a fraud tree.
This fraud tree depicts the branches of occupational fraud, along with their twigs and
branches. So the occupational fraud tree has three main branches, namely corruption, asset
misappropriation, and fraudulent statements (financial statement fraud) (Tuanakotta, 2010).
One theoretical explanation of the causes of someone committing fraud was first developed
by Donald Cressey with his theory known as the fraud triangle. In his theory, it is explained
that the fraud triangle is divided into three parts, namely pressure, opportunity, and
rationalization (Cressey, 1950). Pressure is the embezzlement of company money by a
perpetrator who starts from a pressure. The person has urgent financial needs, so that
personally individual needs are considered more important than organizational needs. The
second cause of fraud is opportunity, where fraud will be committed if there is an opportunity
where someone must have access to assets or have the authority to set control procedures that
allow fraud schemes to be carried out. The third cause is rationalization, meaning that fraud
is committed because there is a rationalization made by a person or group of people by
building justifications for the fraud committed. Fraud perpetrators usually look for reasons to
justify that what they are doing is not theft or fraud, but something that is indeed possible is
his or her right. However, some individuals are more prone to fraud than others. The
tendency to commit fraud depends on their ethical values and personal circumstances
(Abdullahi, et. al, 2015).
According to the Association of Certified Fraud Examiners (ACFE) report in 2020,
based on the frequency of fraud that occurs, asset misappropriation is the fraud that has the
highest frequency followed by corruption and the last is financial statement fraud. But
financial statement fraud is the type of fraud that has the most detrimental impact of fraud
among other types of fraud (ACFE, 2020).
Financial statement fraud is considered as management fraud that results in material
errors in the financial statements so that the financial statements contain misleading
information. The increase in various cases of accounting scandals in various countries around
the world has caused various parties to speculate that management has committed fraud in the
financial statements (Skousen & Wright, 2009).
Financial statement fraud is always related to corporate governance. According to
Dechow, et.el. (2012), the incidence of fraud is highest in companies with weak corporate
governance systems. The tendency to commit fraud is greater in companies with a
background dominated by insiders and most likely do not have an audit committee (Dechow,
et.al., 2012).
Prevention efforts against fraud will be more effective than repressive efforts.
Prevention needs to be done to avoid greater losses and damage to the reputation of
institutions and individuals. In addition, fraud incidents that are not immediately handled and
revealed because The slow handling will increasingly provide opportunities for the
perpetrator to cover up his actions with other fraud. Therefore, it is necessary to make efforts
to prevent the occurrence of true and targeted fraud, so that all forms and efforts of fraudulent
practices can be anticipated as early as possible in order to avoid the risk of loss (Kurniasari,
2017).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them. Every organizational activity will always have uncertainties that are
synonymous with risk, including the risk of fraud, so management must be responsible for
managing the risks that will be faced (Karyono, 2013).
2.0 Literature Review:
The Institute of Internal Auditors (IIA), an organization of internal auditors in the
United States, defines fraud as a set of impermissible and unlawful actions characterized by
an element of intentional fraud. This means that fraud is a fraud that implies a deviation and
unlawful act committed intentionally for a specific purpose, such as deceiving or misleading
other parties, which is carried out by the IIA people from both inside and outside the
organization (Karyono, 2013).
Furthermore, the Chartered Institute of Public Finance and Accountancy (CIPFA)
states fraud as intentional misconduct and concealment of material facts, omission of
evidence to commit fraud and manipulation to the financial detriment of an individual or
organization. Fraud includes embezzlement, theft, forgery, misappropriation, and
deliberately removing evidence (CIPFA, 2013).
It can be generally defined that fraud is a general term, and encompasses any means
that can be used with a certain shrewdness, chosen by an individual, to gain an advantage
over others by making false representations. There is no fixed rule that can be issued as a
general proposition in defining fraud, including surprise, deceit, or cunning and unnatural
means used to commit fraud. The only limits to defining fraud are those that limit human
dishonesty (Zimbelman, et.al., 2014).
Fraud in corporate organizations generally comes from two directions, namely
internal and external. Internal fraud is fraud originating from parties within the corporate
organization itself, such as corruption, presentation of false reports, financial statement
engineering, double financial statements, covering or disguising embezzlement,
incompetence in accounting, theft or improper use of organizational assets by employees and
management for personal or group interests and use that is not in accordance with its
designation. While external fraud is fraud that comes from outside the company's
organization, such as bribery, increasing the value of invoices, double invoicing and quality
fraud such as goods transactions that are not in accordance with the company's policies
agreed presentation (Sayyid, 2014).
Fraudulent statements, namely fraud by presenting financial statements better than
they actually are (over statement) and worse than they actually are (under statement)
(Karyono, 2013), presenting assets or revenues higher than they actually are, or presenting
assets and revenues lower than they actually are (Tuanakotta, 2010), deliberate actions to
produce misleading financial statement material to deceive or misrepresent the organization's
financial position (Albashrawi, 2016), making the organization look more or less profitable
(Apostolou & Apostolou, 2012). While asset misappropriation fraud is the illegal "taking"
(unauthorized or against the law) committed by someone who is authorized to manage or
oversee these assets (Tuanakotta, 2010). And corruption is an act that harms the public
interest or the wider community for the benefit of certain individuals or groups. Corruption
can occur in private corporate organizations as well as in the public sector of government
(Karyono, 2013).
There are several things that motivate management to present financial statements that
contain elements of fraud: (a) provide support to keep stock prices high; (b) provide support
for bonds and shares; and (c) maximize bonuses for management (Zimbelman, et. al., 2014).
According to the Association of Certified Fraud Examiners (ACFE) in its third edition
manual, fraud axioms include: 1) Hidden, this fraud is carried out in a hidden manner and
tries to cover up its actions; 2) Reverse evidence, to prove that fraud has occurred, it must be
attempted so that the fraud does not occur, and vice versa; 3) Types of fraud, which consists
of internal fraud and system control fraud. Internal fraud occurs naturally which is inherent
in every form of activity. System control fraud occurs due to a weak internal control system
and usually the perpetrator has knowledge of the internal work system (Karyono, 2013).
There are several factors that cause someone to commit fraud. Because almost every
criminal act or crime is always driven or triggered by a condition and behavior that causes it.
In this discussion, researchers limit it to using only the Fraud Triangle Theory. According to
this theory, that fraud behavior is carried out or carried out because of three elements, namely
pressure, opportunity, and justification (rationalization). The theory, first formulated by
criminologist Donald R. Cressey (1950), concludes that fraud is generally divided into three
general characteristics. First, fraudsters who have the opportunity to commit fraud
(opportunity). Second, fraudsters have urgent financial needs that cannot be told to others
(pressure). Third, individuals involved in fraud rationalize their fraudulent actions consistent
with their personal code of ethics (rationalization) (Cressey, 1950). And the three fraud
factors are reinforced by the results of research by Skousen et. al. as "triangle fraud"
(Skousen et.al., 2009).
Fraud that occurs in many fields is inseparable from the desire to take other people's
rights for personal or group interests and then justify that fraud is a common thing that can be
done and also because of the opportunity to commit fraud. Fraud in the accounting field can
occur in the process of processing accounting data contained in accounting information in the
form of financial statements. If the fraud factor occurs in the preparation of financial
statements, it is certain that the financial statements presented are not fair. Fraud not only
damages the trust relationship between management and investors but will also harm the
values of accounting itself.
Financial statement fraud affects various market participants, including investors,
organizations, and employees. As previous research provides information related to indirect
organizational losses for fraud. In addition to the material losses borne by the organization,
the organization's reputation may also be questioned when fraud occurs. Investors' trust in the
organization will be lost and may withdraw all their deposits including investments and
pension funds (Perols, 2011; Ugrin & Odom, 2010). Fraud that occurs in an organization is a
classic manifestation of weak organizational governance. In private organizations, there is a
difference of interest between the principal and the agent. This problem arises because when
the owner (principal) authorizes the manager (agent) to act on their behalf. Which is
basically due to differences in interests and information asymmetry between managers and
owners. This problem can be eliminated if both parties have the same interests (Jensen &
William, 1976).
Unhealthy practices in corporate governance allow fraud to occur which is difficult to
detect by stakeholders. Corporate governance is a tool to ensure that directors and managers
(insiders) act in the best interests of investors. Capital market management bodies in many
countries state that the implementation of good corporate governance in public companies has
succeeded in preventing fraudulent practices on financial reports to interested parties (Chen,
et. al., 2005).
Many efforts to prevent fraudulent practices have been made based on existing
theories and research, with the hope that fraudulent practices can be anticipated as early as
possible. One of them is preventing fraud by implementing risk management, which
describes that risk is a concept that describes an uncertainty, or an event on conditions related
to obstacles in achieving goals (Susilo & Victor, 2019). In an effort to prevent fraud,
management must carry out a process of managing its organizational resources to anticipate
risks that may occur which have previously been identified, measured and considered how to
handle them (Karyono, 2013). Every organizational activity will always have uncertainties
that are synonymous with risk including the risk of fraud, so management must be
responsible for managing the risks that will be faced.
The main foundation in implementing an effective fraud prevention program in the
organization is to carry out a thorough risk assessment process. The basic concept of fraud
risk assessment is an assessment of the occurrence and impact of the risks that have been
identified. In the Committee of Sponsoring Organizations of the Threadway Commission,
there are several stages in the fraud risk assessment process including: (a) form a risk
assessment team involving the appropriate level of management; (b) identify potential
organizational fraud risks by assessing risks at all levels of the organization and those from
the internal and external environment, accommodating various types of fraud and considering
the occurrence of management override control; (c) assess the likelihood and significance of
each identified fraud risk; (d) determine employees and departments potentially involved
based on the fraud triangle; (d) identifying existing controls and assessing their effectiveness;
(e) assessing and responding to any residual fraud risks that need to be mitigated; (f)
identifying any controls in place and assessing their effectiveness mitigated; (f) document the
fraud risk assessment; (g) reassess fraud risk periodically (COSO, 2017). And Fraud Risk
Assessment (FRA) is a unique procedure for distinguishing and evaluating the risk of gaps in
the achievement of organizational goals (Huber, et. al., 2015).
Furthermore, Popoola argues that the implementation of fraud risk assessment (FRA)
requires change and an iterative cyclical process to be able to identify and assess the risk of
gaps in the achievement of organizational goals. Fraud risk assessment requires taking into
account changes in the external environment and their impact on the activity model, the
purpose of which is to control ineffective internal activities. Assessment of fraud risk is
considered an effective tool for fraud prevention and because this tool can increase auditor
competence in searching for, detecting and preventing fraud (Popoola, et.al., 2016).
Risk management theory states that risk treatment can be done in various ways,
namely:
4) avoid risk, meaning by deciding not to carry out activities that carry risk; 2) reduce risk,
which is to reduce the likelihood of occurrence and reduce its consequences or impact; 3)
transfer risk, which is to transfer risk to other parties to bear the risk; 4) accept risk, meaning
without taking further action to compensate for the risks that must be taken; and 5) exploit
risk, which is the action to take risks in other options which are the result of proactive
decisions and are carried out consciously to take new risks because they have superior areas
(Susilo & Victor, 2019). Steps or processes carried out in a systematic way to manage risk
threats are known as risk management (Siahaan, 2009).
While the risk management process based on ISO 31000 consists of three major
processes, which include: (1) context setting, aimed at identifying and expressing
organizational goals; (2) risk assessment, which consists of risk identification, risk analysis,
and risk evaluation; (3) risk handling, which consists of: risk avoidance, risk mitigation, risk
transfer, and risk acceptance. The three major processes are accompanied by two processes,
namely: (a) communication and consultation; and (b) monitoring and review (Susilo &
Victor, 2019; Suwanda, et. al., 2019).
3.0 Research Methods:
The methodology used in this research is through library research, which is a research
method carried out by studying literature and writings that have a close relationship with the
problems raised in the research (Baidan, 2016), through a qualitative approach, which is
research that emphasizes process analysis of deductive and inductive thinking processes
related to the dynamics of relationships between observed phenomena, and always uses
scientific logic (Kisworo & Iwan, 2017).
While the data source of this research is a secondary data source consisting of relevant
previous scientific research works, in the form of books and other scientific works with
various points of view. Meanwhile, the data used is a variety of quality-assured qualitative
data in the form of words, sentences, gestures, facial expressions, charts, drawings and
photographs (Sugiyono, 2011) derived from these various sources.
4.0 Results and Discussion:
As previously discussed, in an effort to prevent fraud, management must carry out a
process of managing its organizational resources to anticipate risks that may occur which
have previously been identified, measured and considered how to handle them. Every
organizational activity will always have uncertainties that are synonymous with risk,
including the risk of fraud, so management must be responsible for managing the risks that
will be faced (Karyono, 2013).
Risk management and internal control contribute to the implementation of good
corporate governance (GCG), especially in improving the success of achieving
organizational goals. Without risk management, the internal control system becomes less
effective. Meanwhile, without an internal control system, the control aspects of GCG are less
effective (Susilo & Victor, 2019).
Robert Moeller in his study of the Committee of Sponsoring Organizations (COSO)
internal control, provides a clear picture of the relationship between corporate governance -
risk management - internal control, as shown in the following figure. In the section entitled
"Clearing up a few misconceptions" it is emphasized that, enterprise risk management (ERM)
goes further than internal control. Internal control is an integrated part of ERM. Internal
control is an important part of enterprise risk management (Moeller, 2014).
Furthermore, Ovidiu-Constantin et. al. (2010) highlighted the importance of risk
management and its role in an organization's internal audit. The existence of a risk
management program means placing high confidence in the organization's financial
statements and better audit risk. The implementation of a risk management program, as with
previous research, explains the role of internal auditors in providing assurance on risk
management. An audit risk model is offered to external auditors based on and tailored to the
organization's risk management, the essence of which is that risk management as a solution to
the fraud crisis (Constantin, et. al., 2010).
While the previous research focused on a holistic approach to risk management, in his
research, Lister (2007) discussed the importance of antifraud programs. Organizations must
know the risks in order to mitigate them. This requires a comprehensive fraud risk
assessment, and corresponds to a holistic approach. Anti-fraud programs can increase
stakeholder confidence. However, Lister suggests the approach should be proactive and
reactive, by identifying risks and having an action plan in case of fraud. The three main plan
components include setting regulations through policy and communication, making risk
assessment and monitoring more proactive, and responding by designing a reactive plan.
Lister evaluates planning and implementation using the fraud triangle, and includes third-
party assessments in designing the program (Lister, 2007).
Research conducted by Crockford (2005) discusses risk as a function of change. The
article was originally published in the Geneva Papers in 1976. It explained that risk
management as the ability to cope with change. Rapid change puts pressure on risk
management, this results in difficulties for the organization to adapt. As with Mehr and
Forbes (1973), Crockford recommends that risk management should function by all
managers, not just one department in the organization (Crockford, 2005).
Snider (1990) has also discussed risk management objectives and the importance of
clear risk management objectives. Snider (1990) highlights the steps in developing risk
management objectives. The creation of risk management policies should come from risk
managers or management consultants. A clear policy can generally provide guidance in
decision-making. When identified, there are several things that influence goal setting,
including organizational structure, reporting systems, and short- or long-term goals. Too
much focus on short-term goals in the past can lead to losses due to neglect of controls and
prevention (Snider, 1990).
As with previous research, Snider (1991) recognized the need to expand the risk
management function beyond insurance, and the need for risk management education. In
addition to discussing the concept of risk management, this study also covers the history and
development of risk management, including recognition by academics, the first academic
book on risk management, and the position of risk managers in organizations. He highlights
the initial resistance by senior management, citing the idea that change equals uncertainty.
Snider also discusses the crisis in the early 1970s, related to insurance, which led to the
acceptance of the concept of risk management. And in 1973, the Geneva Association was
founded, thus encouraging research on risk management, and publishing many conceptual
papers on this topic (Snider, 1991).
Aggarwal, Erel, Stulz, and Williamson (2009) studied the effect of a country's
economic and financial development on investment levels in relation to corporate
governance. The findings show that favorable development results in higher investment, and
less investment in firms with poor governance resulting in lower firm value. His research also
provides minimum governance standards for audits: (1) consulting fees are lower than audit
fees; (2) the audit committee consists of independent outsiders; and (3) the auditor must be
authorized at the annual meeting (Aggarwal, et.al., 2009). This is reinforced by Robu's
research (2015) providing an analysis of the relevance of IFRS (International Financial
Reporting Standars) adoption for trust in financial statement information. Researchers took a
sample of 59 companies before and after IFRS adoption. The results showed that there was an
increase in value relevance after IFRS adoption. The research methodology includes to
determine the effect of IFRS adoption on stock prices, and provides recommendations that
standardized reporting and transparency as a solution for a trusted financial market (Robu,
2015).
Previous research conducted by Kang (2008), provides an analysis from another point
of view in the fraud literature, namely the study of reputational penalties associated with
financial fraud and reputation as a penalty for the companies involved. The findings show an
increase in reputational penalties (decrease) for the companies involved. A decrease in market
value is one of the negative effects. The researcher used signalling theory and attribution
theory to explain the related company relationship. The study sampled 244 related firms and
30 suspect firms, from 1998 to 2002. The findings also show that an increase in uncertainty
leads to a negative effect decrease in investor confidence. However, good governance can
increase investor confidence. The implications of his findings recommend the need for
governance reform (Kang, 2008).
Still on financial statement fraud. Fleming, Riley Jr, Hermanson, and Kranacher
(2016) extended the fraud aspect of research with a study of the most fundamental differences
in financial statement fraud between public and private companies. The researchers found a
lack of data available for private companies by using data sources provided by the
Association of Certified Fraud Examiners (ACFE). Fleming et al. (2016) cite that financial
statement fraud is one of the most costly forms of fraud, with an average loss of $1.5 billion.
$1 million per incident. This is in addition to additional reputational impacts, such as
bankruptcy and loss of market value. Some of the other findings of this study are that the
increasing controls on publicly traded companies indicate the use of less obvious methods of
reporting fraud, such as differences in the timing of reporting. And it will usually continue to
grow if the existing controls continue to be improved. The main purpose of this study is for
audit purposes for its concern in highlighting the difference in treatment between public
companies and private companies (Fleming, et. al., 2016).
Furthermore, Ng, White, Lee, and Moneta (2009) examined the focus on developing
instruments to detect managers' fraud tendencies in managing income. Researchers used an
ethical scenario survey method to collect information to design fraud detection instruments
and factor analysis used as a response. Researchers also used the moral intensity construct to
determine managers' intention to act specifically. The construct consists of six characteristics
Moral intensity includes the magnitude of consequences and social consensus. The findings
suggest that the proposed instrument could be operationalized to measure moral intensity in
future studies (Ng, et. al, 2009).
Previously, Shafer (2002) also examined the role of morals. Shafer analyzed financial
statement fraud in the context of an ethical model of decision making. The ANOVA results
show that materiality and risk are significant factors that affect the likelihood of committing
fraud, while the morality factor is not significant. The researcher used Jones' theory of moral
intensity to explain the prevalence of earnings management. The findings mention the
materiality effect with a note of rationalization when the amount is not material, and a more
than 50% probability of committing fraud when the amount is not material. The key indicator
of the absence of ethical behavior is about the perception of what his friend is doing (Shafer,
2002).
Some researchers focus on auditor responsibility. Kostova (2013) revealed a
relationship between fraud characteristics and audit procedures. Kostova describes the
auditor's responsibility to disclose errors and fraud. Auditors are expected to provide opinions
and conclusions about the reliability of financial statements. Furthermore, the researcher also
revealed the existence of economic factors that cause fraud, also identifies its characteristics.
Researchers mention the economic environment as the main factor that leads to fraud. For
example, organizations are under pressure to achieve financial targets (Kostova, 2013).
In contrast to Kostova (2013) who focused on economic factors, Love (2012)
examined auditor responsibility for fraud detection related to reporting standards. It should be
noted that the GAAS (Generally Accepted Auditing Standars) standard recognizes the
absence of the ability to provide absolute assurance, but rather provides reasonable assurance
and reduces the risk of material misstatement. Auditor discovery of questionable information
requires re-evaluation of all audit areas. Fraudsters may conceal their actions through false
statements and documents during the audit process. Love noted the difference between
conducting a GAAS audit and a fraud examination. A GAAS audit results in an auditor's
opinion on the fairness of the financial statement presentation. Regarding auditor perceptions,
Johnson, Kuhn, Apostolou, and Hassell (2013) examined auditors' fraud risk assessment of
management attitudes. The researchers tested whether observable indicators of narcissism by
auditors are indicators of increased risk. The findings of this study indicate a link between
narcissism and fraud, consistently with the behaviors observed in recent fraud. Researchers
evaluated the ability of auditors to recognize fraud, which requires auditors with higher
abilities and experience. This study also concluded that managerial narcissism is an
observable action and recommended improving the assessment guidelines for fraud (Johnson,
et. al., 2013).
Philmore and Michael (2005) conducted a necessary study on the perceived
responsibility of auditors to detect Enron fraud. The study was to determine the nature and
extent of fraud in Barbados. The researchers used a mixed methods design for the exploratory
study. By conducting a survey of 43 respondents about perceptions and experiences in fraud.
The purpose of The qualitative approach was to support the quantitative survey in fully
understanding the research question. The researcher conducted face-to-face interviews to gain
multiple sources of insight. This article is useful for investors, auditors, and regulators, and
contributes to the understanding of the auditor's role in detecting fraud. The researchers
provided historical background on the role of the auditor, and a review of related literature,
but found there is still a lack of consensus on the role of the auditor. There are several
findings presented in this research study. The majority of respondents stated that fraud
detection is the responsibility of the auditor, while others stated that detection is the
responsibility of management. In particular, those respondents with an accounting
background assume that management is responsible for detecting fraud (Philmore and
Michael, 2005).
In contrast to previous research, Nicolaescu (2013) focuses on the role of internal
audit in detecting fraud. The size of the audit firm affects the quality of the audit report.
Researchers found that rigor can improve the ability to detect fraud. The ability to detect
fraud can also be enhanced by the presence of internal auditors. One finding suggested that
brainstorming can be used as a means for internal auditors to respond to risk assessment. This
study also concluded that internal audit is an important part of corporate governance
(Nicolaescu, 2013).
Previously, Kranacher and Stern (2004) provided suggestions for improving fraud
detection. According to a COSO (Committee of Sponsoring Organization) study, CEOs
commit 75% of all fraud. Meanwhile, Klarskov Jeppesen and Leder (2016) state the need for
auditors to question the integrity of managers, Kranacher and Stern (2004) note a potential
conflict of interest between the auditor and the hiring department executive. Legislation
serves as a deterrent to fraudulent behavior, as auditors must actively detect fraud.
Furthermore, researchers recommend that auditor education should be improved to include
behavioral understanding, investigative skills and deeper analysis (Kranacher and Stern,
2004).
Furthermore, Simha and Satyanarayan (2016) examined the perception of fraud
detection and prevention methods, using qualitative forensic auditor interviews. The
researchers also considered the role of technology in fraud detection and prevention. This
research is a response to the lack of qualitative articles, and the use of forensic auditors by
conducting qualitative interviews to expand the knowledge base. The researcher used a
literature review on the accounting context of fraud, coupled with other detection and
prevention methods. The literature review also included information related to the use of
technology to commit and combat fraud. The aim was to understand the phenomenon of
fraud from the perspective of forensic auditors, utilizing their experience. The researchers
described their methodology, which included the researcher as an instrument in the research
process. Simha and Satyanarayan found that forensic auditors are currently inadequate in
detecting fraud, so a method is needed to supplement, and increase the use of other
prevention methods. The researchers also recognized the role of technology in fraud. Other
findings included security concerns from respondents, and the need for auditors to receive
training in criminal profiling, technology, and behavioral finance. The researchers concluded
the discussion by encouraging further research in the future (Simha and Satyanarayan, 2016).
Other researchers conducted research on automated methods of detecting fraud.
Simeunović, Grubor, and Ristic (2016) examined the use of digital forensic analysis to detect
fraud. Specific cases were examined and researched related to employee fraud, the result of
which was that the introduced concept proved effective for investigating accounting fraud
and detecting evidence of digital fraud. The researchers noted that of the overall 65%
detected fraud, 10% were detected by auditors and 23% were detected by proactive internal
controls. Simeunović et al. added that proactive prevention requires adequate controls and
creating a culture of honesty and integrity in the workplace. In today's era of big data,
technology, and complexity, the authors recommend a combined approach of digital analytics
and audit skills for fraud prevention (Simeunović, et al., 2016).
5.0 Conclusions and Suggestions:
To explore and understand the relevant patterns and themes of early detection of
financial statement fraud, the relevant literature is on the topics of motivation, intention,
responsibility, and fraud prevention. Most of the literature focuses on the fraud triangle as a
consequence of previous fraud cases.
Much of the literature focuses on internal controls and corporate governance in
relation to the audit process, including the need for planned reviews of internal controls and
risk assessments as part of the audit process. Some researchers studied the ability of auditors
to recognize fraud and determined that more training is needed for auditors to determine the
motivation of someone committing fraud. So that further research is needed related to fraud
prevention in the audit process proactive prevention requires adequate controls and a good
ethical culture within the company.
It was found that current fraud detection methods are still inadequate. In addition to
focusing on the audit process, research was also conducted on internal control and corporate
governance. Another focus is on the ethical and behavioral aspects of corporate culture, for
the development of fraud detection models and some recommended prevention strategies.
This includes the extent of audit responsibility for detection in auditors' perceptions of fraud
prevention. And another recommendation is the lack of consensus on the role of auditors in
detecting and preventing fraud, and the limited qualitative research related to it.
Although there is a lot of literature on fraud on financial statements, there are still
gaps related to proactive prevention. That is, there is a gap in the concept of risk management
in current practice to detect and prevent fraud, as well as how auditors' perspectives on
detecting fraud and creating proactive models to detect and prevent fraud. In addition,
practitioners can also use this information in developing proactive risk management
procedures for fraud prevention, and auditors may be able to develop guidelines for early
fraud detection in risk monitoring.
Students also viewed