1 / 23100%
Evaluating the effectiveness of internal controls in preventing fraud
Introduction
Internal controls play an indispensable role in preventing and detecting fraud within
organisations. Fraud continues to pose significant risks and costs to businesses globally. As
such, having robust internal controls helps to safeguard against fraud and acts as a deterrent.
This paper aims to evaluate the effectiveness of internal controls in preventing fraud. It will
discuss the purpose and types of internal controls, fraud risks faced by organisations, as well as
challenges in implementing effective controls. Case studies will also be presented to examine
how lacking or poorly designed internal controls allowed fraud to occur. Finally,
recommendations will be provided on strengthening internal controls and anti-fraud measures.
Purpose and Types of Internal Controls
Internal controls are procedures and policies implemented by an organisation’s management
and staff to ensure the reliability of financial reporting, effectiveness and efficiency of operations,
and compliance with laws and regulations (COSO, 2013). They serve to reasonably assure that
undesired events such as fraud, losses, and non-compliance are prevented or detected and
corrected in a timely manner. When properly designed and functioning correctly, internal
controls help create accountability and protect the organisation’s assets.
There are five main components of internal control as defined by COSO (2013):
1. Control environment - The overall tone of an organisation regarding the importance of
integrity and control. This includes factors such as management philosophy, organisational
structure, assignment of authority and responsibility, and competence of personnel.
2. Risk assessment - Identification and analysis by management of risks relevant to achieving
organisational objectives and forming a basis for how risks should be managed.
3. Control activities - Policies and procedures that help ensure management directives are
carried out to address risks in achieving objectives. This includes authorisation, verification,
safeguarding of assets, and segregation of duties.
4. Information & communication - Relevant information is identified, captured and
communicated within the organisation to enable people to carry out internal control
responsibilities. Communication also occurs with external parties.
5. Monitoring - Ongoing or separate evaluations to ascertain whether components of internal
control are present and functioning. This includes both ongoing evaluations and separate
evaluations.
Common types of internal controls used by companies include physical controls (e.g. restricting
access to assets), authorisation controls (e.g. approval matrices), documentation and records
(e.g. record keeping), supervisory controls (e.g. review of transactions), and separation of duties
(e.g. distinct roles for initiation and approval).
Fraud Risks Faced by Organisations
There are various fraud schemes that pose serious risks, some common examples include:
- Asset misappropriation - Theft of cash or other valuable assets such as inventory, property,
equipment. This is the most common type of occupational fraud.
- Corruption - Illegal payments or kickbacks given to influence business decisions or actions,
this can involve bribery and conflicts of interest.
- Financial statement fraud - Intentional misstatement or omissions in financial reports to
deceive stakeholders about an organisation's performance or financial position.
- Customer and supplier fraud - False invoicing or refund schemes perpetrated by external
parties. For example, overbilling customers or creating fake suppliers.
- IT systems fraud - Manipulating IT systems to facilitate theft of money or data. Cybercrime is a
growing threat as more systems are digitised.
- Management override of controls - Senior management intentionally ignores, overrides or
disengages existing controls to commit fraud. Hardest to detect due to higher level of authority.
Industry sectors that typically face higher inherent risks of fraud include financial services,
construction, real estate, healthcare and government. Small businesses are also susceptible
due to more limited resources for implementing controls. Rapid business growth or restructuring
could introduce control gaps and lead to elevated risks.
Internal Control Implementation Challenges
For internal controls to be truly effective in deterring and detecting fraud, there are challenges
that organisations must address:
Resources and staffing - Approval and oversight of controls require effort and skilled personnel
which places resource demands. Small businesses may struggle to commit sufficient
investment.
Technology changes - Automation and digitalisation transform how work gets done, so controls
must adapt to changing IT environments and systems. Legacy controls may not match modern
operations.
Control fatigue - Overly complex or redundant controls lead to complacency and increased
likelihood of human errors or overrides. Balance is needed between control needs and ease of
compliance.
Fraudster adaptability - Criminals find ways to circumvent controls, so constant evaluation and
updates are required. Companies must stay vigilant against new schemes.
Management override - Controls generally function based on honesty and integrity, so override
is difficult to prevent without a robust control culture and fraud awareness.
Collusion - Multiple conspirators working together can more easily cover their tracks and bypass
segregation of duties controls. Increased coordination makes such fraud harder to detect.
Resistance to change - Implementing new controls requires disruption of existing workflows and
mindsets. People are often resistant to change which impedes control enhancements.
Relying solely on detective rather than preventive controls is also inadequate as reputational
damage may have already occurred by the time fraud is uncovered. Regular testing and
improvement of the internal control system is essential to address emerging risks.
Case Studies
The following fraud cases demonstrate how deficiencies in internal controls allowed exploitation
and significant losses for the victim organisations.
WorldCom - Former telecom WorldCom used improper accounting adjustments over several
years to inflate earnings and hide operating expenses amounting to over $3.8 billion. Poor
segregation of duties, lack of verifying journal entry support, and override of transactional
controls enabled the large-scale fraud.
Enron - Multiple complex off-balance sheet structures and special purpose entities were used by
Enron executives to hide debts and inflate profits, culminating in its $63.4 billion bankruptcy
filing in 2001. Weaknesses in areas such as authorisation controls, independent oversight
boards and financial statement verification contributed to this scandal.
Satyam Computer Services - The founder and chairman of Indian IT outsourcer Satyam
Computer Services fabricated $1 billion in cash and accounts to mask the company’s real
financial troubles in 2009. Absence of basic controls like bank reconciliation and restrictions on
access to modify accounting records enabled this accounting fraud.
Toshiba - Japanese conglomerate Toshiba overstated profits by $1.2 billion over seven years
due to lax profit estimations, unverified cost accounting, and poor documentation standards.
This inflated stock prices and hid operational issues from stakeholders and regulators.
The above examples demonstrate how large-scale and prolonged frauds occurred as a result of
lacking internal controls across critical components like financial reporting, asset safeguarding,
and transaction authorisation. While complex schemes may still be attempted, basic preventive
and monitoring controls if adequately implemented, would likely have detected issues earlier
and curbed losses.
Strengthening Internal Controls
Given the myriad fraud risks and challenges in implementing effective controls, organisations
must take a multifaceted approach to reinforce internal controls and anti-fraud programmes.
Some recommended strategies include:
Tone at the top - Strong oversight and ethical leadership from top management creates an
integrity-centric culture and deters fraudulent behaviour. Management's commitment is vital.
Risk assessments - Regular identification of fraud vulnerabilities through exercises allows
controls to focus on higher risk areas. External assessments provide objective reviews.
Preventive controls - Emphasis should be placed on designing controls to prevent fraud from
occurring rather than just detecting after the fact. Access restrictions and pre-approval
measures are examples.
Detective controls - Key ongoing controls relate to verifying assets, transactions, accounting
entries including reconciliations, authorisation confirmations and analytical reviews.
Monitoring activities - Regular evaluation of internal controls through evaluation, compliance
testing, external audits ensures continued effectiveness and needs are addressed timely.
Fraud awareness training - Educating all staff about potential schemes and their responsibility
strengthens control environment and vigilance levels across the organisation.
Whistleblowing channels - Anonymous hotlines allow confidential disclosure of concerns or
wrongdoing, these need promotion and follow up investigation. The presence discourages
misconduct.
Consequence management - Companies must demonstrate commitment by investigating
allegations, taking disciplinary action against perpetrators, and correcting systemic issues
revealed by incidents.
Technology tools - Utilisation of data analytics and monitoring systems eases workload of
manual controls and enhances detection abilities for large volumes of complex financial or
operational data.
Regular control updates - Existing controls should evolve in tandem with the business and risks.
New threats and gaps uncovered during risk assessments require control enhancements on an
ongoing basis.
Stronger accountability - Employees involved in critical control functions should be given defined
roles, responsibilities and performance metrics linked to organisational objectives relating to
integrity and compliance.
Management override - Rigorous controls and independent verification of such requests helps
to safeguard against attempted subversion by senior staff. Overrides leave clear audit trails.
The combination of preventive and detective controls implemented using a risk-based approach
supported by an ethical culture and ongoing monitoring is most effective at deterring and timely
discovery of fraud attempts. Continual assessment and improvement is also needed for controls
to remain relevant to evolving risks.
Conclusion
In conclusion, internal controls represent a foundation for upholding good governance,
protecting assets, fulfilling responsibilities, and detecting any fraudulent misconduct within an
organisation. The costs of fraud are substantial across reputational damage, financial losses,
productivity declines and other impacts. Therefore, the implementation of well-designed controls
addressing inherent risks and focused on fraud prevention should be a priority. However,
controls alone are insufficient without a robust anti-fraud framework involving whistleblowing
channels, training, monitoring and consequences. Regular evaluation ensures controls match
emerging threats and business complexities. Organisations that prioritise maintaining effective
internal controls and anti-fraud measures will not only safeguard financial resources but also
uphold stakeholder trust in the long run.
Internal controls play an indispensable role in preventing and detecting fraud within
organisations. Fraud continues to pose significant risks and costs to businesses globally. As
such, having robust internal controls helps to safeguard against fraud and acts as a deterrent.
This paper aims to evaluate the effectiveness of internal controls in preventing fraud. It will
discuss the purpose and types of internal controls, fraud risks faced by organisations, as well as
challenges in implementing effective controls. Case studies will also be presented to examine
how lacking or poorly designed internal controls allowed fraud to occur. Finally,
recommendations will be provided on strengthening internal controls and anti-fraud measures.
Purpose and Types of Internal Controls
Internal controls are procedures and policies implemented by an organisation’s management
and staff to ensure the reliability of financial reporting, effectiveness and efficiency of operations,
and compliance with laws and regulations (COSO, 2013). They serve to reasonably assure that
undesired events such as fraud, losses, and non-compliance are prevented or detected and
corrected in a timely manner. When properly designed and functioning correctly, internal
controls help create accountability and protect the organisation’s assets.
There are five main components of internal control as defined by COSO (2013):
1. Control environment - The overall tone of an organisation regarding the importance of
integrity and control. This includes factors such as management philosophy, organisational
structure, assignment of authority and responsibility, and competence of personnel.
2. Risk assessment - Identification and analysis by management of risks relevant to achieving
organisational objectives and forming a basis for how risks should be managed.
3. Control activities - Policies and procedures that help ensure management directives are
carried out to address risks in achieving objectives. This includes authorisation, verification,
safeguarding of assets, and segregation of duties.
4. Information & communication - Relevant information is identified, captured and
communicated within the organisation to enable people to carry out internal control
responsibilities. Communication also occurs with external parties.
5. Monitoring - Ongoing or separate evaluations to ascertain whether components of internal
control are present and functioning. This includes both ongoing evaluations and separate
evaluations.
Common types of internal controls used by companies include physical controls (e.g. restricting
access to assets), authorisation controls (e.g. approval matrices), documentation and records
(e.g. record keeping), supervisory controls (e.g. review of transactions), and separation of duties
(e.g. distinct roles for initiation and approval).
Fraud Risks Faced by Organisations
There are various fraud schemes that pose serious risks, some common examples include:
- Asset misappropriation - Theft of cash or other valuable assets such as inventory, property,
equipment. This is the most common type of occupational fraud.
- Corruption - Illegal payments or kickbacks given to influence business decisions or actions,
this can involve bribery and conflicts of interest.
- Financial statement fraud - Intentional misstatement or omissions in financial reports to
deceive stakeholders about an organisation's performance or financial position.
- Customer and supplier fraud - False invoicing or refund schemes perpetrated by external
parties. For example, overbilling customers or creating fake suppliers.
- IT systems fraud - Manipulating IT systems to facilitate theft of money or data. Cybercrime is a
growing threat as more systems are digitised.
- Management override of controls - Senior management intentionally ignores, overrides or
disengages existing controls to commit fraud. Hardest to detect due to higher level of authority.
Industry sectors that typically face higher inherent risks of fraud include financial services,
construction, real estate, healthcare and government. Small businesses are also susceptible
due to more limited resources for implementing controls. Rapid business growth or restructuring
could introduce control gaps and lead to elevated risks.
Internal Control Implementation Challenges
For internal controls to be truly effective in deterring and detecting fraud, there are challenges
that organisations must address:
Resources and staffing - Approval and oversight of controls require effort and skilled personnel
which places resource demands. Small businesses may struggle to commit sufficient
investment.
Technology changes - Automation and digitalisation transform how work gets done, so controls
must adapt to changing IT environments and systems. Legacy controls may not match modern
operations.
Control fatigue - Overly complex or redundant controls lead to complacency and increased
likelihood of human errors or overrides. Balance is needed between control needs and ease of
compliance.
Fraudster adaptability - Criminals find ways to circumvent controls, so constant evaluation and
updates are required. Companies must stay vigilant against new schemes.
Management override - Controls generally function based on honesty and integrity, so override
is difficult to prevent without a robust control culture and fraud awareness.
Collusion - Multiple conspirators working together can more easily cover their tracks and bypass
segregation of duties controls. Increased coordination makes such fraud harder to detect.
Resistance to change - Implementing new controls requires disruption of existing workflows and
mindsets. People are often resistant to change which impedes control enhancements.
Relying solely on detective rather than preventive controls is also inadequate as reputational
damage may have already occurred by the time fraud is uncovered. Regular testing and
improvement of the internal control system is essential to address emerging risks.
Case Studies
The following fraud cases demonstrate how deficiencies in internal controls allowed exploitation
and significant losses for the victim organisations.
WorldCom - Former telecom WorldCom used improper accounting adjustments over several
years to inflate earnings and hide operating expenses amounting to over $3.8 billion. Poor
segregation of duties, lack of verifying journal entry support, and override of transactional
controls enabled the large-scale fraud.
Enron - Multiple complex off-balance sheet structures and special purpose entities were used by
Enron executives to hide debts and inflate profits, culminating in its $63.4 billion bankruptcy
filing in 2001. Weaknesses in areas such as authorisation controls, independent oversight
boards and financial statement verification contributed to this scandal.
Satyam Computer Services - The founder and chairman of Indian IT outsourcer Satyam
Computer Services fabricated $1 billion in cash and accounts to mask the company’s real
financial troubles in 2009. Absence of basic controls like bank reconciliation and restrictions on
access to modify accounting records enabled this accounting fraud.
Toshiba - Japanese conglomerate Toshiba overstated profits by $1.2 billion over seven years
due to lax profit estimations, unverified cost accounting, and poor documentation standards.
This inflated stock prices and hid operational issues from stakeholders and regulators.
The above examples demonstrate how large-scale and prolonged frauds occurred as a result of
lacking internal controls across critical components like financial reporting, asset safeguarding,
and transaction authorisation. While complex schemes may still be attempted, basic preventive
and monitoring controls if adequately implemented, would likely have detected issues earlier
and curbed losses.
Strengthening Internal Controls
Given the myriad fraud risks and challenges in implementing effective controls, organisations
must take a multifaceted approach to reinforce internal controls and anti-fraud programmes.
Some recommended strategies include:
Tone at the top - Strong oversight and ethical leadership from top management creates an
integrity-centric culture and deters fraudulent behaviour. Management's commitment is vital.
Risk assessments - Regular identification of fraud vulnerabilities through exercises allows
controls to focus on higher risk areas. External assessments provide objective reviews.
Preventive controls - Emphasis should be placed on designing controls to prevent fraud from
occurring rather than just detecting after the fact. Access restrictions and pre-approval
measures are examples.
Detective controls - Key ongoing controls relate to verifying assets, transactions, accounting
entries including reconciliations, authorisation confirmations and analytical reviews.
Monitoring activities - Regular evaluation of internal controls through evaluation, compliance
testing, external audits ensures continued effectiveness and needs are addressed timely.
Fraud awareness training - Educating all staff about potential schemes and their responsibility
strengthens control environment and vigilance levels across the organisation.
Whistleblowing channels - Anonymous hotlines allow confidential disclosure of concerns or
wrongdoing, these need promotion and follow up investigation. The presence discourages
misconduct.
Consequence management - Companies must demonstrate commitment by investigating
allegations, taking disciplinary action against perpetrators, and correcting systemic issues
revealed by incidents.
Technology tools - Utilisation of data analytics and monitoring systems eases workload of
manual controls and enhances detection abilities for large volumes of complex financial or
operational data.
Regular control updates - Existing controls should evolve in tandem with the business and risks.
New threats and gaps uncovered during risk assessments require control enhancements on an
ongoing basis.
Stronger accountability - Employees involved in critical control functions should be given defined
roles, responsibilities and performance metrics linked to organisational objectives relating to
integrity and compliance.
Management override - Rigorous controls and independent verification of such requests helps
to safeguard against attempted subversion by senior staff. Overrides leave clear audit trails.
The combination of preventive and detective controls implemented using a risk-based approach
supported by an ethical culture and ongoing monitoring is most effective at deterring and timely
discovery of fraud attempts. Continual assessment and improvement is also needed for controls
to remain relevant to evolving risks.
Conclusion
In conclusion, internal controls represent a foundation for upholding good governance,
protecting assets, fulfilling responsibilities, and detecting any fraudulent misconduct within an
organisation. The costs of fraud are substantial across reputational damage, financial losses,
productivity declines and other impacts. Therefore, the implementation of well-designed controls
addressing inherent risks and focused on fraud prevention should be a priority. However,
controls alone are insufficient without a robust anti-fraud framework involving whistleblowing
channels, training, monitoring and consequences. Regular evaluation ensures controls match
emerging threats and business complexities. Organisations that prioritise maintaining effective
internal controls and anti-fraud measures will not only safeguard financial resources but also
uphold stakeholder trust in the long run.
Internal controls play an indispensable role in preventing and detecting fraud within
organisations. Fraud continues to pose significant risks and costs to businesses globally. As
such, having robust internal controls helps to safeguard against fraud and acts as a deterrent.
This paper aims to evaluate the effectiveness of internal controls in preventing fraud. It will
discuss the purpose and types of internal controls, fraud risks faced by organisations, as well as
challenges in implementing effective controls. Case studies will also be presented to examine
how lacking or poorly designed internal controls allowed fraud to occur. Finally,
recommendations will be provided on strengthening internal controls and anti-fraud measures.
Purpose and Types of Internal Controls
Internal controls are procedures and policies implemented by an organisation’s management
and staff to ensure the reliability of financial reporting, effectiveness and efficiency of operations,
and compliance with laws and regulations (COSO, 2013). They serve to reasonably assure that
undesired events such as fraud, losses, and non-compliance are prevented or detected and
corrected in a timely manner. When properly designed and functioning correctly, internal
controls help create accountability and protect the organisation’s assets.
There are five main components of internal control as defined by COSO (2013):
1. Control environment - The overall tone of an organisation regarding the importance of
integrity and control. This includes factors such as management philosophy, organisational
structure, assignment of authority and responsibility, and competence of personnel.
2. Risk assessment - Identification and analysis by management of risks relevant to achieving
organisational objectives and forming a basis for how risks should be managed.
3. Control activities - Policies and procedures that help ensure management directives are
carried out to address risks in achieving objectives. This includes authorisation, verification,
safeguarding of assets, and segregation of duties.
4. Information & communication - Relevant information is identified, captured and
communicated within the organisation to enable people to carry out internal control
responsibilities. Communication also occurs with external parties.
5. Monitoring - Ongoing or separate evaluations to ascertain whether components of internal
control are present and functioning. This includes both ongoing evaluations and separate
evaluations.
Common types of internal controls used by companies include physical controls (e.g. restricting
access to assets), authorisation controls (e.g. approval matrices), documentation and records
(e.g. record keeping), supervisory controls (e.g. review of transactions), and separation of duties
(e.g. distinct roles for initiation and approval).
Fraud Risks Faced by Organisations
There are various fraud schemes that pose serious risks, some common examples include:
- Asset misappropriation - Theft of cash or other valuable assets such as inventory, property,
equipment. This is the most common type of occupational fraud.
- Corruption - Illegal payments or kickbacks given to influence business decisions or actions,
this can involve bribery and conflicts of interest.
- Financial statement fraud - Intentional misstatement or omissions in financial reports to
deceive stakeholders about an organisation's performance or financial position.
- Customer and supplier fraud - False invoicing or refund schemes perpetrated by external
parties. For example, overbilling customers or creating fake suppliers.
- IT systems fraud - Manipulating IT systems to facilitate theft of money or data. Cybercrime is a
growing threat as more systems are digitised.
- Management override of controls - Senior management intentionally ignores, overrides or
disengages existing controls to commit fraud. Hardest to detect due to higher level of authority.
Industry sectors that typically face higher inherent risks of fraud include financial services,
construction, real estate, healthcare and government. Small businesses are also susceptible
due to more limited resources for implementing controls. Rapid business growth or restructuring
could introduce control gaps and lead to elevated risks.
Internal Control Implementation Challenges
For internal controls to be truly effective in deterring and detecting fraud, there are challenges
that organisations must address:
Resources and staffing - Approval and oversight of controls require effort and skilled personnel
which places resource demands. Small businesses may struggle to commit sufficient
investment.
Technology changes - Automation and digitalisation transform how work gets done, so controls
must adapt to changing IT environments and systems. Legacy controls may not match modern
operations.
Control fatigue - Overly complex or redundant controls lead to complacency and increased
likelihood of human errors or overrides. Balance is needed between control needs and ease of
compliance.
Fraudster adaptability - Criminals find ways to circumvent controls, so constant evaluation and
updates are required. Companies must stay vigilant against new schemes.
Management override - Controls generally function based on honesty and integrity, so override
is difficult to prevent without a robust control culture and fraud awareness.
Collusion - Multiple conspirators working together can more easily cover their tracks and bypass
segregation of duties controls. Increased coordination makes such fraud harder to detect.
Resistance to change - Implementing new controls requires disruption of existing workflows and
mindsets. People are often resistant to change which impedes control enhancements.
Relying solely on detective rather than preventive controls is also inadequate as reputational
damage may have already occurred by the time fraud is uncovered. Regular testing and
improvement of the internal control system is essential to address emerging risks.
Case Studies
The following fraud cases demonstrate how deficiencies in internal controls allowed exploitation
and significant losses for the victim organisations.
WorldCom - Former telecom WorldCom used improper accounting adjustments over several
years to inflate earnings and hide operating expenses amounting to over $3.8 billion. Poor
segregation of duties, lack of verifying journal entry support, and override of transactional
controls enabled the large-scale fraud.
Enron - Multiple complex off-balance sheet structures and special purpose entities were used by
Enron executives to hide debts and inflate profits, culminating in its $63.4 billion bankruptcy
filing in 2001. Weaknesses in areas such as authorisation controls, independent oversight
boards and financial statement verification contributed to this scandal.
Satyam Computer Services - The founder and chairman of Indian IT outsourcer Satyam
Computer Services fabricated $1 billion in cash and accounts to mask the company’s real
financial troubles in 2009. Absence of basic controls like bank reconciliation and restrictions on
access to modify accounting records enabled this accounting fraud.
Toshiba - Japanese conglomerate Toshiba overstated profits by $1.2 billion over seven years
due to lax profit estimations, unverified cost accounting, and poor documentation standards.
This inflated stock prices and hid operational issues from stakeholders and regulators.
The above examples demonstrate how large-scale and prolonged frauds occurred as a result of
lacking internal controls across critical components like financial reporting, asset safeguarding,
and transaction authorisation. While complex schemes may still be attempted, basic preventive
and monitoring controls if adequately implemented, would likely have detected issues earlier
and curbed losses.
Strengthening Internal Controls
Given the myriad fraud risks and challenges in implementing effective controls, organisations
must take a multifaceted approach to reinforce internal controls and anti-fraud programmes.
Some recommended strategies include:
Tone at the top - Strong oversight and ethical leadership from top management creates an
integrity-centric culture and deters fraudulent behaviour. Management's commitment is vital.
Risk assessments - Regular identification of fraud vulnerabilities through exercises allows
controls to focus on higher risk areas. External assessments provide objective reviews.
Preventive controls - Emphasis should be placed on designing controls to prevent fraud from
occurring rather than just detecting after the fact. Access restrictions and pre-approval
measures are examples.
Detective controls - Key ongoing controls relate to verifying assets, transactions, accounting
entries including reconciliations, authorisation confirmations and analytical reviews.
Monitoring activities - Regular evaluation of internal controls through evaluation, compliance
testing, external audits ensures continued effectiveness and needs are addressed timely.
Fraud awareness training - Educating all staff about potential schemes and their responsibility
strengthens control environment and vigilance levels across the organisation.
Whistleblowing channels - Anonymous hotlines allow confidential disclosure of concerns or
wrongdoing, these need promotion and follow up investigation. The presence discourages
misconduct.
Consequence management - Companies must demonstrate commitment by investigating
allegations, taking disciplinary action against perpetrators, and correcting systemic issues
revealed by incidents.
Technology tools - Utilisation of data analytics and monitoring systems eases workload of
manual controls and enhances detection abilities for large volumes of complex financial or
operational data.
Regular control updates - Existing controls should evolve in tandem with the business and risks.
New threats and gaps uncovered during risk assessments require control enhancements on an
ongoing basis.
Stronger accountability - Employees involved in critical control functions should be given defined
roles, responsibilities and performance metrics linked to organisational objectives relating to
integrity and compliance.
Management override - Rigorous controls and independent verification of such requests helps
to safeguard against attempted subversion by senior staff. Overrides leave clear audit trails.
The combination of preventive and detective controls implemented using a risk-based approach
supported by an ethical culture and ongoing monitoring is most effective at deterring and timely
discovery of fraud attempts. Continual assessment and improvement is also needed for controls
to remain relevant to evolving risks.
Conclusion
In conclusion, internal controls represent a foundation for upholding good governance,
protecting assets, fulfilling responsibilities, and detecting any fraudulent misconduct within an
organisation. The costs of fraud are substantial across reputational damage, financial losses,
productivity declines and other impacts. Therefore, the implementation of well-designed controls
addressing inherent risks and focused on fraud prevention should be a priority. However,
controls alone are insufficient without a robust anti-fraud framework involving whistleblowing
channels, training, monitoring and consequences. Regular evaluation ensures controls match
emerging threats and business complexities. Organisations that prioritise maintaining effective
internal controls and anti-fraud measures will not only safeguard financial resources but also
uphold stakeholder trust in the long run.
Internal controls play an indispensable role in preventing and detecting fraud within
organisations. Fraud continues to pose significant risks and costs to businesses globally. As
such, having robust internal controls helps to safeguard against fraud and acts as a deterrent.
This paper aims to evaluate the effectiveness of internal controls in preventing fraud. It will
discuss the purpose and types of internal controls, fraud risks faced by organisations, as well as
challenges in implementing effective controls. Case studies will also be presented to examine
how lacking or poorly designed internal controls allowed fraud to occur. Finally,
recommendations will be provided on strengthening internal controls and anti-fraud measures.
Purpose and Types of Internal Controls
Internal controls are procedures and policies implemented by an organisation’s management
and staff to ensure the reliability of financial reporting, effectiveness and efficiency of operations,
and compliance with laws and regulations (COSO, 2013). They serve to reasonably assure that
undesired events such as fraud, losses, and non-compliance are prevented or detected and
corrected in a timely manner. When properly designed and functioning correctly, internal
controls help create accountability and protect the organisation’s assets.
There are five main components of internal control as defined by COSO (2013):
1. Control environment - The overall tone of an organisation regarding the importance of
integrity and control. This includes factors such as management philosophy, organisational
structure, assignment of authority and responsibility, and competence of personnel.
2. Risk assessment - Identification and analysis by management of risks relevant to achieving
organisational objectives and forming a basis for how risks should be managed.
3. Control activities - Policies and procedures that help ensure management directives are
carried out to address risks in achieving objectives. This includes authorisation, verification,
safeguarding of assets, and segregation of duties.
4. Information & communication - Relevant information is identified, captured and
communicated within the organisation to enable people to carry out internal control
responsibilities. Communication also occurs with external parties.
5. Monitoring - Ongoing or separate evaluations to ascertain whether components of internal
control are present and functioning. This includes both ongoing evaluations and separate
evaluations.
Common types of internal controls used by companies include physical controls (e.g. restricting
access to assets), authorisation controls (e.g. approval matrices), documentation and records
(e.g. record keeping), supervisory controls (e.g. review of transactions), and separation of duties
(e.g. distinct roles for initiation and approval).
Fraud Risks Faced by Organisations
There are various fraud schemes that pose serious risks, some common examples include:
- Asset misappropriation - Theft of cash or other valuable assets such as inventory, property,
equipment. This is the most common type of occupational fraud.
- Corruption - Illegal payments or kickbacks given to influence business decisions or actions,
this can involve bribery and conflicts of interest.
- Financial statement fraud - Intentional misstatement or omissions in financial reports to
deceive stakeholders about an organisation's performance or financial position.
- Customer and supplier fraud - False invoicing or refund schemes perpetrated by external
parties. For example, overbilling customers or creating fake suppliers.
- IT systems fraud - Manipulating IT systems to facilitate theft of money or data. Cybercrime is a
growing threat as more systems are digitised.
- Management override of controls - Senior management intentionally ignores, overrides or
disengages existing controls to commit fraud. Hardest to detect due to higher level of authority.
Industry sectors that typically face higher inherent risks of fraud include financial services,
construction, real estate, healthcare and government. Small businesses are also susceptible
due to more limited resources for implementing controls. Rapid business growth or restructuring
could introduce control gaps and lead to elevated risks.
Internal Control Implementation Challenges
For internal controls to be truly effective in deterring and detecting fraud, there are challenges
that organisations must address:
Resources and staffing - Approval and oversight of controls require effort and skilled personnel
which places resource demands. Small businesses may struggle to commit sufficient
investment.
Technology changes - Automation and digitalisation transform how work gets done, so controls
must adapt to changing IT environments and systems. Legacy controls may not match modern
operations.
Control fatigue - Overly complex or redundant controls lead to complacency and increased
likelihood of human errors or overrides. Balance is needed between control needs and ease of
compliance.
Fraudster adaptability - Criminals find ways to circumvent controls, so constant evaluation and
updates are required. Companies must stay vigilant against new schemes.
Management override - Controls generally function based on honesty and integrity, so override
is difficult to prevent without a robust control culture and fraud awareness.
Collusion - Multiple conspirators working together can more easily cover their tracks and bypass
segregation of duties controls. Increased coordination makes such fraud harder to detect.
Resistance to change - Implementing new controls requires disruption of existing workflows and
mindsets. People are often resistant to change which impedes control enhancements.
Relying solely on detective rather than preventive controls is also inadequate as reputational
damage may have already occurred by the time fraud is uncovered. Regular testing and
improvement of the internal control system is essential to address emerging risks.
Case Studies
The following fraud cases demonstrate how deficiencies in internal controls allowed exploitation
and significant losses for the victim organisations.
WorldCom - Former telecom WorldCom used improper accounting adjustments over several
years to inflate earnings and hide operating expenses amounting to over $3.8 billion. Poor
segregation of duties, lack of verifying journal entry support, and override of transactional
controls enabled the large-scale fraud.
Enron - Multiple complex off-balance sheet structures and special purpose entities were used by
Enron executives to hide debts and inflate profits, culminating in its $63.4 billion bankruptcy
filing in 2001. Weaknesses in areas such as authorisation controls, independent oversight
boards and financial statement verification contributed to this scandal.
Satyam Computer Services - The founder and chairman of Indian IT outsourcer Satyam
Computer Services fabricated $1 billion in cash and accounts to mask the company’s real
financial troubles in 2009. Absence of basic controls like bank reconciliation and restrictions on
access to modify accounting records enabled this accounting fraud.
Toshiba - Japanese conglomerate Toshiba overstated profits by $1.2 billion over seven years
due to lax profit estimations, unverified cost accounting, and poor documentation standards.
This inflated stock prices and hid operational issues from stakeholders and regulators.
The above examples demonstrate how large-scale and prolonged frauds occurred as a result of
lacking internal controls across critical components like financial reporting, asset safeguarding,
and transaction authorisation. While complex schemes may still be attempted, basic preventive
and monitoring controls if adequately implemented, would likely have detected issues earlier
and curbed losses.
Strengthening Internal Controls
Given the myriad fraud risks and challenges in implementing effective controls, organisations
must take a multifaceted approach to reinforce internal controls and anti-fraud programmes.
Some recommended strategies include:
Tone at the top - Strong oversight and ethical leadership from top management creates an
integrity-centric culture and deters fraudulent behaviour. Management's commitment is vital.
Risk assessments - Regular identification of fraud vulnerabilities through exercises allows
controls to focus on higher risk areas. External assessments provide objective reviews.
Preventive controls - Emphasis should be placed on designing controls to prevent fraud from
occurring rather than just detecting after the fact. Access restrictions and pre-approval
measures are examples.
Detective controls - Key ongoing controls relate to verifying assets, transactions, accounting
entries including reconciliations, authorisation confirmations and analytical reviews.
Monitoring activities - Regular evaluation of internal controls through evaluation, compliance
testing, external audits ensures continued effectiveness and needs are addressed timely.
Fraud awareness training - Educating all staff about potential schemes and their responsibility
strengthens control environment and vigilance levels across the organisation.
Whistleblowing channels - Anonymous hotlines allow confidential disclosure of concerns or
wrongdoing, these need promotion and follow up investigation. The presence discourages
misconduct.
Consequence management - Companies must demonstrate commitment by investigating
allegations, taking disciplinary action against perpetrators, and correcting systemic issues
revealed by incidents.
Technology tools - Utilisation of data analytics and monitoring systems eases workload of
manual controls and enhances detection abilities for large volumes of complex financial or
operational data.
Regular control updates - Existing controls should evolve in tandem with the business and risks.
New threats and gaps uncovered during risk assessments require control enhancements on an
ongoing basis.
Stronger accountability - Employees involved in critical control functions should be given defined
roles, responsibilities and performance metrics linked to organisational objectives relating to
integrity and compliance.
Management override - Rigorous controls and independent verification of such requests helps
to safeguard against attempted subversion by senior staff. Overrides leave clear audit trails.
The combination of preventive and detective controls implemented using a risk-based approach
supported by an ethical culture and ongoing monitoring is most effective at deterring and timely
discovery of fraud attempts. Continual assessment and improvement is also needed for controls
to remain relevant to evolving risks.
Conclusion
In conclusion, internal controls represent a foundation for upholding good governance,
protecting assets, fulfilling responsibilities, and detecting any fraudulent misconduct within an
organisation. The costs of fraud are substantial across reputational damage, financial losses,
productivity declines and other impacts. Therefore, the implementation of well-designed controls
addressing inherent risks and focused on fraud prevention should be a priority. However,
controls alone are insufficient without a robust anti-fraud framework involving whistleblowing
channels, training, monitoring and consequences. Regular evaluation ensures controls match
emerging threats and business complexities. Organisations that prioritise maintaining effective
internal controls and anti-fraud measures will not only safeguard financial resources but also
uphold stakeholder trust in the long run.
Internal controls play an indispensable role in preventing and detecting fraud within
organisations. Fraud continues to pose significant risks and costs to businesses globally. As
such, having robust internal controls helps to safeguard against fraud and acts as a deterrent.
This paper aims to evaluate the effectiveness of internal controls in preventing fraud. It will
discuss the purpose and types of internal controls, fraud risks faced by organisations, as well as
challenges in implementing effective controls. Case studies will also be presented to examine
how lacking or poorly designed internal controls allowed fraud to occur. Finally,
recommendations will be provided on strengthening internal controls and anti-fraud measures.
Purpose and Types of Internal Controls
Internal controls are procedures and policies implemented by an organisation’s management
and staff to ensure the reliability of financial reporting, effectiveness and efficiency of operations,
and compliance with laws and regulations (COSO, 2013). They serve to reasonably assure that
undesired events such as fraud, losses, and non-compliance are prevented or detected and
corrected in a timely manner. When properly designed and functioning correctly, internal
controls help create accountability and protect the organisation’s assets.
There are five main components of internal control as defined by COSO (2013):
1. Control environment - The overall tone of an organisation regarding the importance of
integrity and control. This includes factors such as management philosophy, organisational
structure, assignment of authority and responsibility, and competence of personnel.
2. Risk assessment - Identification and analysis by management of risks relevant to achieving
organisational objectives and forming a basis for how risks should be managed.
3. Control activities - Policies and procedures that help ensure management directives are
carried out to address risks in achieving objectives. This includes authorisation, verification,
safeguarding of assets, and segregation of duties.
4. Information & communication - Relevant information is identified, captured and
communicated within the organisation to enable people to carry out internal control
responsibilities. Communication also occurs with external parties.
5. Monitoring - Ongoing or separate evaluations to ascertain whether components of internal
control are present and functioning. This includes both ongoing evaluations and separate
evaluations.
Common types of internal controls used by companies include physical controls (e.g. restricting
access to assets), authorisation controls (e.g. approval matrices), documentation and records
(e.g. record keeping), supervisory controls (e.g. review of transactions), and separation of duties
(e.g. distinct roles for initiation and approval).
Fraud Risks Faced by Organisations
There are various fraud schemes that pose serious risks, some common examples include:
- Asset misappropriation - Theft of cash or other valuable assets such as inventory, property,
equipment. This is the most common type of occupational fraud.
- Corruption - Illegal payments or kickbacks given to influence business decisions or actions,
this can involve bribery and conflicts of interest.
- Financial statement fraud - Intentional misstatement or omissions in financial reports to
deceive stakeholders about an organisation's performance or financial position.
- Customer and supplier fraud - False invoicing or refund schemes perpetrated by external
parties. For example, overbilling customers or creating fake suppliers.
- IT systems fraud - Manipulating IT systems to facilitate theft of money or data. Cybercrime is a
growing threat as more systems are digitised.
- Management override of controls - Senior management intentionally ignores, overrides or
disengages existing controls to commit fraud. Hardest to detect due to higher level of authority.
Industry sectors that typically face higher inherent risks of fraud include financial services,
construction, real estate, healthcare and government. Small businesses are also susceptible
due to more limited resources for implementing controls. Rapid business growth or restructuring
could introduce control gaps and lead to elevated risks.
Internal Control Implementation Challenges
For internal controls to be truly effective in deterring and detecting fraud, there are challenges
that organisations must address:
Resources and staffing - Approval and oversight of controls require effort and skilled personnel
which places resource demands. Small businesses may struggle to commit sufficient
investment.
Technology changes - Automation and digitalisation transform how work gets done, so controls
must adapt to changing IT environments and systems. Legacy controls may not match modern
operations.
Control fatigue - Overly complex or redundant controls lead to complacency and increased
likelihood of human errors or overrides. Balance is needed between control needs and ease of
compliance.
Fraudster adaptability - Criminals find ways to circumvent controls, so constant evaluation and
updates are required. Companies must stay vigilant against new schemes.
Management override - Controls generally function based on honesty and integrity, so override
is difficult to prevent without a robust control culture and fraud awareness.
Collusion - Multiple conspirators working together can more easily cover their tracks and bypass
segregation of duties controls. Increased coordination makes such fraud harder to detect.
Resistance to change - Implementing new controls requires disruption of existing workflows and
mindsets. People are often resistant to change which impedes control enhancements.
Relying solely on detective rather than preventive controls is also inadequate as reputational
damage may have already occurred by the time fraud is uncovered. Regular testing and
improvement of the internal control system is essential to address emerging risks.
Case Studies
The following fraud cases demonstrate how deficiencies in internal controls allowed exploitation
and significant losses for the victim organisations.
WorldCom - Former telecom WorldCom used improper accounting adjustments over several
years to inflate earnings and hide operating expenses amounting to over $3.8 billion. Poor
segregation of duties, lack of verifying journal entry support, and override of transactional
controls enabled the large-scale fraud.
Enron - Multiple complex off-balance sheet structures and special purpose entities were used by
Enron executives to hide debts and inflate profits, culminating in its $63.4 billion bankruptcy
filing in 2001. Weaknesses in areas such as authorisation controls, independent oversight
boards and financial statement verification contributed to this scandal.
Satyam Computer Services - The founder and chairman of Indian IT outsourcer Satyam
Computer Services fabricated $1 billion in cash and accounts to mask the company’s real
financial troubles in 2009. Absence of basic controls like bank reconciliation and restrictions on
access to modify accounting records enabled this accounting fraud.
Toshiba - Japanese conglomerate Toshiba overstated profits by $1.2 billion over seven years
due to lax profit estimations, unverified cost accounting, and poor documentation standards.
This inflated stock prices and hid operational issues from stakeholders and regulators.
The above examples demonstrate how large-scale and prolonged frauds occurred as a result of
lacking internal controls across critical components like financial reporting, asset safeguarding,
and transaction authorisation. While complex schemes may still be attempted, basic preventive
and monitoring controls if adequately implemented, would likely have detected issues earlier
and curbed losses.
Strengthening Internal Controls
Given the myriad fraud risks and challenges in implementing effective controls, organisations
must take a multifaceted approach to reinforce internal controls and anti-fraud programmes.
Some recommended strategies include:
Tone at the top - Strong oversight and ethical leadership from top management creates an
integrity-centric culture and deters fraudulent behaviour. Management's commitment is vital.
Risk assessments - Regular identification of fraud vulnerabilities through exercises allows
controls to focus on higher risk areas. External assessments provide objective reviews.
Preventive controls - Emphasis should be placed on designing controls to prevent fraud from
occurring rather than just detecting after the fact. Access restrictions and pre-approval
measures are examples.
Detective controls - Key ongoing controls relate to verifying assets, transactions, accounting
entries including reconciliations, authorisation confirmations and analytical reviews.
Monitoring activities - Regular evaluation of internal controls through evaluation, compliance
testing, external audits ensures continued effectiveness and needs are addressed timely.
Fraud awareness training - Educating all staff about potential schemes and their responsibility
strengthens control environment and vigilance levels across the organisation.
Whistleblowing channels - Anonymous hotlines allow confidential disclosure of concerns or
wrongdoing, these need promotion and follow up investigation. The presence discourages
misconduct.
Consequence management - Companies must demonstrate commitment by investigating
allegations, taking disciplinary action against perpetrators, and correcting systemic issues
revealed by incidents.
Technology tools - Utilisation of data analytics and monitoring systems eases workload of
manual controls and enhances detection abilities for large volumes of complex financial or
operational data.
Regular control updates - Existing controls should evolve in tandem with the business and risks.
New threats and gaps uncovered during risk assessments require control enhancements on an
ongoing basis.
Stronger accountability - Employees involved in critical control functions should be given defined
roles, responsibilities and performance metrics linked to organisational objectives relating to
integrity and compliance.
Management override - Rigorous controls and independent verification of such requests helps
to safeguard against attempted subversion by senior staff. Overrides leave clear audit trails.
The combination of preventive and detective controls implemented using a risk-based approach
supported by an ethical culture and ongoing monitoring is most effective at deterring and timely
discovery of fraud attempts. Continual assessment and improvement is also needed for controls
to remain relevant to evolving risks.
Conclusion
In conclusion, internal controls represent a foundation for upholding good governance,
protecting assets, fulfilling responsibilities, and detecting any fraudulent misconduct within an
organisation. The costs of fraud are substantial across reputational damage, financial losses,
productivity declines and other impacts. Therefore, the implementation of well-designed controls
addressing inherent risks and focused on fraud prevention should be a priority. However,
controls alone are insufficient without a robust anti-fraud framework involving whistleblowing
channels, training, monitoring and consequences. Regular evaluation ensures controls match
emerging threats and business complexities. Organisations that prioritise maintaining effective
internal controls and anti-fraud measures will not only safeguard financial resources but also
uphold stakeholder trust in the long run.
Students also viewed