Module 1
Introduction to Fraud
A. Seriousness of the Fraud Problem
Individuals throughout the world lost money in Madoff’s pyramid scheme.4
While many of the victims were blue-collared workers that came from humble
backgrounds, others were extremely wealthy. For example, Prince Michel of Yugoslavia
traveled across Europe to raise money for Madoff. Other victims included various royal
families and even London’s House of Lords. Actor Kevin Bacon and producer Steven
Spielberg, as well as various other Hollywood movie stars had invested with Madoff.
Because Madoff had connections to the Jewish community, many Jewish charities and
institutions lost a significant amount of money in the scam.
Bernard Madoff is an example of an individual who misrepresented himself and
his company to commit fraud. Investment fraud, like the fraud committed by Bernard
Madoff, is just one of the many types of frauds that present major problems for
businesses and consumers throughout the world. Although most people and even most
researchers believe that fraud is increasing both in size and frequency, it is difficult to
know for sure.6 First, it is impossible to know what percentage of fraud perpetrators are
caught. Are there perfect frauds that are never detected, or are all frauds eventually
discovered? In addition, many frauds that are detected are quietly handled by the victims
and never made public. In many cases of employee fraud, for example, companies merely
hide the frauds and quietly terminate or transfer perpetrators rather than make the frauds
public. Companies and individuals who have been defrauded are often more concerned
about the embarrassment of making frauds public, and the costs of investigating fraud,
than they are about seeking justice and punishing fraud perpetrators.
The Association of Certified Fraud Examiners (ACFE) regularly conducts one of
the most comprehensive fraud studies in the United States. First conducted in 1996 and
then conducted again in 2002, 2004, 2006, and 2008, the ACFE study, also known as the
Report to the Nation on Occupational Fraud & Abuse, is based on actual fraud cases
reported by certified fraud examiners (CFEs) who investigate the frauds. The 2008 study
estimates that U.S. organizations lose roughly 7 percent of their annual revenues to fraud.
Applied to the 2008 U.S. gross domestic product (GDP), this 7 percent figure would
translate to approximately $994 billion in fraud losses—in the United States alone.
Even more alarming than the increased number of fraud cases is the size of
discovered frauds. In earlier times, if a perpetrator wanted to steal from his or her
employer, he or she had to physically remove the assets from the business premise.
Because of fear of being caught with the goods, frauds tended to be small. With the
advent of computers, the Internet, and complex accounting systems, perpetrators now
need only to make a telephone call, misdirect purchase invoices, bribe a supplier,
manipulate a computer program, or simply push a key on the keyboard to misplace
company assets.9 Because physical possession of stolen property is no longer required
and because it is just as easy to program a computer to embezzle $1 million as it is
$1,000, the size and number of frauds have increased tremendously.
To understand how costly fraud is to organizations, consider what happens when
fraud is committed against a company. Losses incurred from fraud reduce a firm’s
income on a dollar-for-dollar basis. This means that for every $1 of fraud, net income is
reduced by $1. Since fraud reduces net income, it takes significantly more revenue to
recover the effect of the fraud on net income. To illustrate, consider the $436 million
fraud loss that a large U.S. automobile manufacturer experienced a few years ago.10 If
the automobile manufacturer’s profit margin (net income divided by revenues) at the time
was 10 percent, the company would have to generate up to $4.36 billion in additional
revenue (or 10 times the amount of the fraud) to restore the effect on net income. If we
assume an average selling price of $20,000 per car, the company must make and sell an
additional 218,000 cars. Considered this way, fighting fraud is serious business. The
automobile company can spend its efforts manufacturing and marketing additional new
cars, or reducing fraud, or a combination of both.
Firms are not the only victims of fraud. In the aggregate, national economies also
suffer from largescale fraud and corruption. If we use the logic described in the case of
the automobile manufacturer described earlier, we can better understand how, from a
macrolevel, countries suffer from fraud. Take, for example, three different economies. If
Economy A, whose profit margin is 10 percent, loses $500 million to fraud, it must
generate $5 billion of additional revenue to offset the loss to net income. If Economy B,
whose profit margin is also 10 percent, loses $200 million to fraud, it must generate $2
billion. Finally, if Economy C, whose profit margin is 5 percent, loses $100 million to
fraud, it must also generate $2 billion. The strain fraud imposes on economies throughout
the world is tremendous. If just one fraud is prevented, billions of dollars can be saved—
resources that can be reinvested in building the economy. Given this analysis, it is easy to
see how difficult it is for countries with high amounts of corruption to ever compete with
countries with low rates of corruption. High-corruption countries are constantly trying to
overcome fraud losses, while low-corruption countries are growing and moving ahead.
As a result, many honest economists, politicians, and regulators spend a considerable
amount of time and resources trying to reduce fraud.
Because of different cost/revenue structures, the amount of additional revenues a
firm must generate to recover fraud losses varies from firm to firm and from industry to
industry. However, it is easy to see that in order to maximize profits, eliminating fraud
should be a key goal of every organization. The best way to minimize fraud is to prevent
it from occurring. In this book, we will cover fraud prevention, as well as fraud detection
and investigation. There are two principal methods of getting something from others
illegally. Either you physically force someone to give you what you want (using a gun,
knife, or other weapon), or you trick them out of their assets. The first type of theft we
call robbery, and the second type we call fraud. Robbery is generally more violent and
more traumatic than fraud and attracts much more media attention, but losses from fraud
far exceed losses from robbery.
Fraud is different from unintentional errors. If, for example, someone mistakenly
enters incorrect numbers on a financial statement, is this fraud? No, it is not fraud
because it was not done with intent or for the purpose of gaining advantage over another
through false pretense. But, if in the same situation, someone purposely enters incorrect
numbers on a financial statement to trick investors, then it is fraud! As was discussed in
the beginning of this chapter, one of the most common types of fraud today is a scam that
lures investment funds from victims and then pays those victims a premium or interest
from money that is paid by subsequent investors. This popular fraud scheme, also known
as a Ponzi scheme, was named after Charles Ponzi who perpetrated a large scam in the
early 1900s. To better understand fraud in general, let’s take a closer look at Charles
Ponzi.
Ponzi’s scam is extremely helpful in understanding fraud. Certainly, the scheme
involved deception. It also involved greed by the perpetrator and—this is important—
greed by the investors, who wanted higherthan-sensible returns. Finally, Ponzi’s scheme
involved the element of confidence. If he had not paid returns to original investors, no
one would have invested additional money. By paying early “returns,” Ponzi gained
investors’ confidence and convinced them that he had a legitimate business. In fact,
confidence is the single most critical element for fraud to be successful. (The word “con,”
which means to deceive, comes from “confidence.”) It is difficult to con anyone out of
anything unless the deceived has confidence in the deceiver. We cannot be conned unless
we trust the person trying to deceive us. Similarly, employers cannot con employees if
they do not have their employees’ trust and confidence. And, without investor
confidence, fraudulent companies cannot con unsuspecting investors.
B. Types of Fraud
While there are many ways to classify the various types of fraud, the most
common way is to simply divide frauds into those that are committed against
organizations and those that are committed on behalf of organizations. In employee fraud,
for example—fraud committed against an organization—the victim of the fraud is the
employee’s organization.15 On the other hand, with financial statement fraud, for
example, executives usually commit fraud “on behalf” of an organization,16 usually to
make its reported financial results look better than they actually are. In this case, the
executives of the company benefit because a company’s stock price increases or remains
artificially high and the victims are investors in the company’s stock. Sometimes,
executives misstate earnings in order to ensure a larger year-end bonus. Financial
statement fraud often occurs in companies that are experiencing net losses or have profits
much less than expectations.
Employee embezzlement is the most common type of occupational fraud. As
stated previously, in this type of fraud, employees deceive their employers by taking
company assets.19 Embezzlement can be either direct or indirect. Direct fraud occurs
when an employee steals company cash, inventory, tools, supplies, or other assets. It also
occurs when employees establish dummy companies and have their employers pay for
goods that are not actually delivered. With direct fraud, company assets go directly into
the perpetrator’s pockets without the involvement of third parties. Indirect employee
fraud, on the other hand, occurs when employees take bribes or kickbacks from vendors,
customers, or others outside the company to allow for lower sales prices, higher purchase
prices, nondelivery of goods, or the delivery of inferior goods. In these cases, payment to
employees is usually made by organizations that deal with the perpetrator’s employer, not
the employer itself.
Vendor fraud has been in the news time and again over the years because of
significant overcharges by major vendors on defense and other government contracts.
Vendor fraud, which is extremely common in the United States, comes in two common
forms: (1) fraud perpetrated by vendors acting alone, and (2) fraud perpetrated through
collusion between buyers and vendors. Vendor fraud usually results in either an
overcharge for purchased goods, the shipment of inferior goods, or the nonshipment of
goods even though payment was made.
When customer fraud takes place, customers either do not pay for goods
purchased or they get something for nothing.22 For example, consider the bank customer
who walked into a branch of a large bank one Saturday morning and convinced the
branch manager to give her a $525,000 cashier’s check, even though she had only
$13,000 in her bank account. The manager believed she was a very wealthy customer and
didn’t want to lose her business. Unfortunately for the bank, she was a white-collar thief,
and she proceeded to defraud the bank of over $500,000. In another customer fraud, six
individuals sitting in a downtown Chicago hotel room pretended to be representatives of
large corporate customers, made three calls to a Chicago bank, and had the bank transfer
nearly $70 million to their accounts in another financial institution in New Jersey. Once
the money was transferred to New Jersey, it was quickly transferred to Switzerland,
withdrawn, and used to purchase Russian diamonds.
C. Criminal and Civil Prosecution of Fraud
When people commit fraud, they can be prosecuted criminally and/or civilly. To
succeed in a criminal or civil prosecution, it is usually necessary to show that the
perpetrator acted with intent to defraud the victim. This is best accomplished by gathering
evidential matter. Evidential matter consists of the underlying data and all corroborating
information available. In a later chapter, we will discuss types of evidence and the role
evidence plays in successful prosecution and/or litigation of fraud. Criminal law is that
branch of law that deals with offenses of a public nature. Criminal laws generally deal
with offenses against society as a whole. They are prosecuted either federally or by a
state for violating a statute that prohibits some type of activity. Every state and the federal
government have statutes prohibiting a wide variety of fraudulent and corrupt practices.
Civil law is the body of law that provides remedies for violations of private rights.
Civil law deals with rights of individuals. Civil claims begin when one party files a
complaint against another, usually for the purpose of gaining financial restitution. The
purpose of a civil lawsuit is to compensate for harm done to another individual. Unlike
criminal cases, juries in civil cases need not consist of 12 jurors but may have as few as
six jurors. The verdict of the jury need not be unanimous. Civil cases are often heard by
judges instead of juries. To be successful, plaintiffs in civil cases must only prove their
case by the “preponderance of the evidence.” In other words, there need only be slightly
more evidence supporting the plaintiff than supporting the defendant. In both civil and
criminal proceedings, the parties often call expert witnesses to give their opinion on
matters thought to be too technical for the jurors or judge to understand. Fraud examiners
and accountants are often used as experts in fraud cases to compute and testify to the
amount of damages. When fraud is committed, criminal prosecution usually proceeds
first.
D. Fraud-Related Careers
As the number of frauds and the amounts of fraud losses increase, so do the
opportunities for successful careers in fraud fighting. U.S. News and World Report
identified fraud examination as one of the fastest growing and most financially rewarding
careers.29 The American Institute of Certified Public Accountants (AICPA) touted fraud
examination/fraud auditing as one of the six fastest growing and most profitable
opportunities for accountants. Taken together, the cost of fighting fraud is very high. In
high-profile civil cases, it is not uncommon for defendants and plaintiffs to spend tens of
millions of dollars defending and prosecuting alleged frauds. Many large fraud cases
involve multiple law firms, multiple lawyers from each firm, multiple investigators,
expert witnesses, and large support staff. Often, after spending large sums of money
defending or prosecuting a fraud case, a pretrial settlement is reached, with no public
announcement of the terms of the settlement
Throughout the next few months, you will find your study of fraud examination to
be very interesting and helpful—whether or not you become a professional fraud fighter.
As a businessperson, understanding the tremendous costs of fraud and learning to
recognize fraud may someday mean the difference between your business surviving or
failing. If you become a financial consultant, you will be better equipped to help your
clients avoid high-risk and fraudulent investments. As an investor, you will learn skills
that help you distinguish between fraudulent and profitable investments. If you become
an auditor, you will find the document examination and evidence-gathering skills you
learn here invaluable. If you work with taxes, you will be alert to when information from
clients is questionable. Finally, the interviewing skills you learn will be helpful in nearly
every possible profession you may choose.
E. The Fraud Triangle
Research shows that anyone can commit fraud. Fraud perpetrators usually can’t
be distinguished from other people on the basis of demographic or psychological
characteristics. Most fraud perpetrators have profiles that look like those of other honest
people.3 Several years ago, a study was conducted to determine the physical and
behavioral characteristics of fraud perpetrators. In this study, fraud perpetrators were
compared with (1) prisoners incarcerated for property offenses and (2) a sample of
noncriminal, college students. The personal backgrounds and psychological profiles of
the three groups were compared. The results indicated that incarcerated fraud perpetrators
were very different from other incarcerated prisoners. When compared to other criminals,
they were less likely to be caught, turned in, arrested, convicted, and incarcerated. They
were also less likely to serve long sentences. In addition, fraud perpetrators were
considerably older.
It is important to understand the characteristics of fraud perpetrators because they
appear to be very much like people who have traits that organizations look for in hiring
employees, seeking out customers and clients, and selecting vendors. This knowledge
helps us to understand that (1) most employees, customers, vendors, and business
associates and partners fit the profile of fraud perpetrators and are capable of committing
fraud and (2) it is impossible to predict in advance which employees, vendors, clients,
customers, and others will become dishonest. In fact, when fraud does occur, the most
common reaction by those around the fraud is denial. Victims cannot believe that trusted
colleagues or friends have behaved dishonestly.
While there are thousands of ways to perpetrate fraud, Dennis Greer’s example
(in the opening case of the chapter) illustrates the three key elements common to all of
them. His fraud included: (1) a perceived pressure, (2) a perceived opportunity, and (3)
some way to rationalize the fraud as acceptable. These three elements make up what we
call the fraud triangle,5 as shown in Figure 2.2.a After moving into an apartment, Dennis
Greer could not pay the second month’s rent. Faced with the choice between being
dishonest or going back to living in his car, Dennis chose to be dishonest. Every fraud
perpetrator faces some kind of perceived pressure. Most pressures involve a financial
need, although nonfinancial pressures, such as the need to report financial results better
than actual performance, frustration with work, or even a challenge to beat the system,
can also motivate fraud. In Dennis Greer’s case, he had an actual pressure. You may look
at a fraud perpetrator and think “but he or she didn’t have a real pressure.” However, it
doesn’t matter what you think—what matters is the perception of the perpetrator at the
time of the fraud. Later in this chapter, we will discuss the different kinds of pressures
experienced by fraud perpetrators.
Dennis found a way to commit fraud by repeatedly writing bad checks to give the
impression that he was depositing real money in his accounts. He didn’t need access to
cash, to use force, or to even confront his victims physically. Rather, he simply wrote
checks to himself in the privacy of his own apartment and deposited them in two different
banks. His weapons of crime were a pen and checks from the financial institutions.
Whether or not Dennis could actually get away with his crime didn’t matter. What
mattered was that Dennis believed he could conceal the fraud—in other words, he had a
perceived opportunity.
Perceived pressure, perceived opportunity, and rationalization are common to
every fraud. Whether the fraud is one that benefits the perpetrator directly, such as
employee fraud, or one that benefits the perpetrator’s organization, such as management
fraud, the three elements are always present. In the case of management fraud, for
example, the pressure could be the need to make earnings look better or to meet debt
covenants, the opportunity could be a weak audit committee and the rationalization could
be “we’ll only ‘cook the books’ until we can get over this temporary hump.” In many
ways, fraud is like fire. In order for a fire to occur, three elements are necessary: (1)
oxygen, (2) fuel, and (3) heat.
Firefighters know that a fire can be extinguished by eliminating any one of the
three elements. Oxygen is often eliminated by smothering, by using chemicals, or by
causing explosions, as is the case in oil well fires. Heat is most commonly eliminated by
pouring water on fires. Fuel is removed by building fire lines or fire breaks or by shutting
off the source of the fuel. As with the elements in the fire triangle, the three elements in
the fraud triangle are interactive. With fire, the more flammable the fuel, the less oxygen
and heat it takes to ignite. Similarly, the purer the oxygen, the less flammable the fuel
needs to be to ignite. With fraud, the greater the perceived opportunity or the more
intense the pressure, the less rationalization it takes to motivate someone to commit
fraud.
F. The Element of Pressure, Opportunity, and Rationalization
Fraud can be perpetrated to benefit oneself or an organization. Employee fraud, in
which an individual embezzles from his or her employer, usually benefits the perpetrator.
Management fraud, in which an organization’s officers deceive investors and creditors by
manipulating financial statements, is most often perpetrated to benefit an organization
and its officers. In this section, we will discuss the different pressures that motivate
individuals to perpetrate fraud on their own behalf. Most fraud experts believe that the
pressures can be divided into four main groups: (1) financial pressures, (2) vices, (3)
work-related pressures, and (4) other pressures.
Financial pressures can occur suddenly or be long term. Unfortunately, very few
fraud perpetrators inform others when they are having financial problems. As an
example, consider Susan Jones. She had worked at the same company for over 32 years.
Her integrity had never been questioned. At age 63, she became a grandmother.
Immediately, she became a “spendaholic.” She bought everything she could get her hands
on for her two grandchildren. She even became addicted to the Home Shopping Network.
During the three years prior to her retirement, Susan stole over $650,000 from her
employer. When caught, she was sentenced and served one year in prison. She also
deeded everything she and her husband owned to her former employer in an attempt to
repay the employer. By giving her employer her home, her retirement account, and her
cars, she repaid approximately $400,000 of the $650,000 she stole. She also entered into
a restitution agreement to pay back the remaining $250,000 she still owed. And, because
she had not paid income taxes on the $250,000 of fraudulent “income,” the IRS required
her to make monthly tax payments after she got out of prison.
Financial pressure is the most common type of pressure to commit fraud. Usually,
when management fraud occurs, companies overstate assets on the balance sheet and net
income on the income statement. They usually have pressure to do so because of a poor
cash position, receivables that aren’t collectible, a loss of customers, obsolete inventory, a
declining market, or restrictive loan covenants that are being violated. For example,
Regina Vacuum was a company whose management committed massive financial
statement fraud. Their major pressure was that the vacuum cleaners they were selling
were defective and had melting parts, and thousands were being returned. The large
number of sales returns reduced revenues significantly and created such income pressures
that management intentionally understated sales returns and significantly overstated
actual sales.
Closely related to financial pressures are motivations created by vices such as
gambling, drugs, alcohol, and expensive extramarital relationships. As an example of
these vices motivating a person to commit fraud, consider one individual’s confession of
how gambling led to his dishonest acts. Vices are the worst kind of pressures to commit
fraud. Examples include female employees who embezzled because their children were
on drugs and they couldn’t stand to see them go through withdrawal pains. Other
examples involve “successful” managers who, in addition to embezzling from their
companies, burglarized homes and engaged in other types of theft to support their drug
habits.
While financial pressures and vices motivate most frauds, some people commit
fraud to get even with their employer or others. Factors such as getting little recognition
for job performance, having a feeling of job dissatisfaction, fearing losing one’s job,
being overlooked for a promotion, and feeling underpaid have motivated many frauds.
Once in a while, fraud is motivated by other pressures, such as a spouse who insists on an
improved lifestyle or a challenge to beat the system. In the famous Bernie Madoff
Scandal discussed in Chapter 1, for example, experts believe that one of the pressures that
led Madoff to commit fraud was the need to appear successful. When investments were
not performing well, in order to save face, Madoff would simply make up fictitious
returns. In another situation, the perpetrator embezzled over $450,000 so her husband
could drive a new car, enjoy a higher lifestyle, and eat steak instead of hamburger. One
famous computer consultant, who is now retained by major companies to help them deter
and detect computer fraud, once felt personally challenged to “commit the perfect crime.”
After purchasing and taking delivery of over $1.5 million in inventory that was paid for
by accessing a large company’s computer records, he was caught when one of his
inventory managers turned him in.
Most of us face pressures in our lives. We have legitimate financial needs, we
make foolish or speculative investments, we are possessed by addictive vices, we feel
overworked and/or underpaid, or we are greedy and want more. We sometimes have a
difficult time distinguishing between wants and needs. Indeed, the objective of most
people in a capitalistic society is to obtain wealth. We often measure success by how
much money or wealth a person has. If you say you have a very successful relative, you
probably mean that he or she lives in a big house, has a cabin or a condominium, drives
expensive automobiles, and has money to do whatever he or she wants.
Having an effective control framework is probably the most important step an
organization can take to prevent and detect employee fraud. The organization that
established the common internal control framework that most businesses subscribe to is
the Committee of Sponsoring Organizations (COSO). While COSO10 identifies five
elements of an organization’s internal control framework, we will discuss three of them
including the control environment, the accounting function, and control activities.
The control environment is the work atmosphere that an organization establishes
for its employees. The control environment includes management’s role and example,
management communication, appropriate hiring, clear organizational structure, and an
effective internal audit department. The most important element in establishing an
appropriate environment is management’s role and example. In numerous instances,
management’s dishonest or inappropriate behavior has been learned and modeled by
employees. In the famous Equity Funding case, management was writing insurance
policies on individuals who didn’t exist and selling them to other insurance companies.
Seeing this dishonest behavior, one employee said to himself, “It doesn’t make sense to
have all these fictitious people live forever. I’ll knock a few of them off and collect death
proceeds. My actions won’t be any different from those of the management of this
company.” In another case, employees realized top management was overstating
revenues. In response, the employees began overstating expenses on their travel
reimbursement forms, billing for hours not worked, and perpetrating other types of fraud.
The second critical element in the control environment is management’s
communication. Communicating what is and is not appropriate is critical. Just as parents
who are trying to teach their children to be honest must communicate often and openly
with them, organizations that want employees to behave in a certain way must clearly
label what is and is not acceptable. Codes of conduct, orientation meetings, training,
supervisor/employee discussions, and other types of communication that distinguish
between acceptable and unacceptable behavior are critical. To be an effective deterrent to
fraud, communication must be consistent. Messages that change based on circumstances
and situations serve not only to confuse employees but also to encourage rationalizations.
One of the reasons that so many frauds occur in crash or rush projects is that typical
control procedures are not followed. Inconsistent messages relating to procedures and
controls are often conveyed. Strikes, mergers, bankruptcies, and other dramatic events
usually result in inconsistent communication and allow for increased fraud.
The third critical element in creating the proper control structure is appropriate
hiring. Research has shown that nearly 30 percent of all people in the United States are
dishonest, another 40 percent are situationally honest (honest where it pays to be honest
and dishonest where it pays to be dishonest), and 30 percent are honest all the time.11
While most organizations are convinced that their employees, customers, and vendors are
among the 30 percent who are honest, this usually isn’t the case. When dishonest
individuals are hired, even the best controls will not prevent fraud. For example, a bank
has tellers, managers, loan officers, and others who have daily access to cash and can
steal. Because it is impossible to deter all bank fraud, banks hope that personal integrity,
together with preventive and detective controls and the fear of punishment, will deter
theft.
The fourth fraud deterring element of the control environment is a clear
organizational structure. When everyone in an organization knows exactly who has
responsibility for each business activity, fraud is less likely to be committed. In such
situations, it is easier to track missing assets and harder to embezzle without being
caught. Strict accountability for job performance is critical for a good control
environment. As an example of how failure to assign proper custody resulted in a fraud,
consider the case of Jane D.
The fifth element of the control environment is an effective internal audit
department, 13 combined with security or loss prevention programs. While most studies
have found that internal auditors detect only about 20 percent of all employee frauds
(others are detected through tips, by alert employees, or accidentally), the mere presence
of internal auditors provides a significant deterrent effect. Internal auditors provide
independent checks and cause perpetrators to question whether or not they can commit
fraud and not be caught. A visible and effective security function, in conjunction with an
appropriate loss prevention program, can help ensure that fraud is properly investigated
and that control weaknesses and violations are appropriately handled and punished.
Taken together, the five control environment elements—(1) management’s role and
example, (2) management communication, (3) appropriate hiring, (4) clear organizational
structure, and (5) an effective internal audit department—can create an atmosphere in
which fraud opportunities are decreased because employees see that fraud is not
acceptable and not tolerated. Relaxing any one of these five elements increases fraud
opportunities.
The second component of the control structure is a good accounting system.
Every fraud is comprised of three elements: (1) the theft act, in which assets are taken, (2)
concealment, which is the attempt to hide the fraud from others, and (3) conversion, in
which the perpetrator spends the money or converts the stolen assets to cash and then
spends the money. An effective accounting system provides an audit trail that allows
frauds to be discovered and makes concealment difficult. Unlike bank robbery, in which
there is usually no effort to conceal the theft act, concealment is one of the major
distinguishing elements of fraud.
The third component of the control structure is good control activities (or
procedures). An individual who owns his or her own business and is the sole employee
probably does not need many control procedures. While such people may have ample
opportunity to defraud their companies, they have no incentive to do so. They wouldn’t
steal from themselves, and they would never want to treat customers poorly. However,
organizations that involve many employees must have control procedures so that the
actions of employees will be congruent with the goals of management or the owners. In
addition, with control procedures, opportunities to commit and/or conceal frauds are
eliminated or minimized.
The second internal control procedure is a proper system of authorizations.
Authorization control procedures take many forms. Passwords authorize individuals to
use computers and to access certain databases. Signature cards authorize individuals to
enter safe deposit boxes, to cash checks, and to perform other functions at financial
institutions. Spending limits authorize individuals to spend only what is in their budget or
approved level. When people are not authorized to perform an activity, the opportunity to
commit fraud is reduced. For example, when individuals are not authorized to enter safe
deposit boxes, they cannot enter and steal someone else’s contents. When individuals are
not authorized to approve purchases, they cannot order items for personal use and have
their companies pay for the goods. As the following fraud case shows, the failure to
enforce authorization controls makes the perpetration of fraud quite simple.
The theory behind independent checks is that if people know that their work or
activities will be monitored by others, the opportunity to commit and conceal a fraud will
be reduced. There are many varieties of independent checks. The Office of the Controller
of the Currency (OCC) requires that every bank employee in the United States take one
week’s vacation (five consecutive days) each year. While employees are gone, others are
supposed to perform their work. If an employee’s work piles up while he or she is out for
the week, this “mandatory vacation” control is not working as it should and the
opportunity to commit fraud is not eliminated.
Physical safeguards are often used to protect assets from theft by fraud or other
means. Physical safeguards, such as vaults, safes, fences, locks, and keys, take away
opportunities to commit fraud by making it difficult for people to access assets. Money
locked in a vault, for example, cannot be stolen unless someone gains unauthorized
access or unless someone who has access violates the trust. Physical controls are often
used to protect inventory by storing it in locked cages or warehouses, small assets such as
tools or supplies by locking them in cabinets, and cash by locking it in vaults or safes.
The fifth control procedure involves using documents and records to create a
record of transactions and an audit trail. Documents rarely serve as preventive controls
but provide excellent detective controls. Banks, for example, prepare kiting suspect
reports as well as reports of employee bank account activity to detect abuse by employees
or customers. Most companies require a customer order to initiate a sales transaction. In a
sense, the entire accounting system serves as a documentary control. Without documents,
no accountability exists. Without accountability, it is much easier to perpetrate fraud and
not get caught.
If you pay someone to construct a fence, you can probably examine the completed
job and determine whether or not the quality of work meets your specifications and is
consistent with the agreed contract. If, however, you hire a lawyer, a doctor, a dentist, an
accountant, an engineer, or an auto mechanic, it is often difficult to know whether you are
paying an excessive amount or receiving inferior service or products. With these kinds of
contracts, it is easy to overcharge, perform work not needed, provide inferior service, or
charge for work not performed. The Los Angeles Times recently reported on a California
dermatologist who was accused of saving skin samples from patients with skin cancer
and then using those cancerous tissues to diagnose healthy patients with skin cancer. The
doctor did this to increase his pay from roughly $50 for removing noncancerous skin
tissue to the more than $150 he was paid for removing cancerous tissues. Unfortunately,
once a search warrant was issued on his behalf, the pressure and associated guilt was too
much and contributed to his apparent suicide. Reports to the highway patrol stated that
the doctor basically parked his car and walked in front of traffic on a California freeway.
Employees of the doctor stated that hundreds of patience diagnoses had been faked.
In trying to understand why a well-established, wellreputed company such as
Sears might commit such a fraud, it is important to know that Sears had established a
quota for parts, services, and repair sales for each eight-hour shift. Allegedly, mechanics
who consistently did not meet their quotas either had their hours reduced or were
transferred out of the parts and services department. Apparently when faced with the
pressure to cheat or fail, and believing that customers would not know for themselves
whether or not the parts and services were actually needed, many service center
employees decided to commit fraud.
Criminologists generally agree that rapists have the highest rate of repeat offenses
(recidivism) of all criminals. The next highest rate of repeat offenders is probably fraud
perpetrators who are not prosecuted or disciplined. An individual who commits fraud and
is not punished or is merely terminated suffers no significant penalty and often resumes
the fraudulent behavior. Fraud perpetrators are usually individuals who command respect
in their jobs, communities, churches, and families. If they are marginally sanctioned or
terminated, they rarely inform their families and others of the real reason for their
termination or punishment. On the other hand, if they are prosecuted, they usually suffer
significant embarrassment from having family, friends, and business associates know
about their offenses. Indeed, suffering humiliation, more than any other factor, deters
future fraud activity by fraud perpetrators.
Many frauds are allowed to be perpetrated because victims don’t have access to
information possessed by the perpetrators. This is especially prevalent in many of the
large management frauds that have been perpetrated against stockholders, investors, and
debt holders. In the famous ESM fraud case, for example, the same securities had been
sold to investors several times. Yet, because those investment records were only in the
possession of ESM, victims didn’t know of the fraudulent sales. A classic example of a
fraud in which lack of information allowed the fraud to be perpetrated is the Lincoln
Savings and Loan case. On January 6, 1992, Charles Keating and his son, Charles
Keating III, were convicted on 73 and 64 counts, respectively, of racketeering and fraud.
Auditors didn’t know about any of the oral commitments, all of which violated
accounting standards for recording a real estate sale. Subsequent to these oral agreements,
in supposedly separate transactions, Keating loaned RA Homes $5 million (to cover the
down payment) and then continued to manage, market, and develop the “sold” property.
When the real estate agent, who supposedly had an exclusive selling arrangement,
discovered that the 1,300 acres had supposedly been sold by Charles Keating himself, he
contacted Charles Keating for a commission on the sale and was told that no real estate
commission was due because the land had just been “parked” with RA Homes. With the
higher reported profits of his company, Lincoln Savings and Loan was able to appear
profitable and further perpetrate its fraud on investors and others.
Asymmetrical information, where one party has more or better information than
another party, has in several cases led to lawsuits. For example, a company had a
controller who embezzled over $5 million. He committed the fraud by writing company
checks to himself. While the company had poor internal controls, especially a lack of
segregation of duties, it sued its financial institution for negligence to recover the stolen
funds. The basis of its lawsuit was that the organization’s bank had superior information
to detect the fraud because both the perpetrator and the company had accounts at the
same bank. And, since the perpetrator embezzled money by writing company checks
from an account in the bank and depositing the checks in his personal account at the
bank, the plaintiff company believed the bank had the best information to detect the
fraud.
The nurse had found that hospital patients were an easy target for theft. In a
hospital room, where patients are often under the influence of sedating drugs, victims
may not have the ability to recognize that they have been robbed. Frauds called pigeon
drops are specifically designed to take advantage of elderly victims. In such thefts,
perpetrators often pose as bank examiners trying to catch dishonest bankers, or they may
use some other scheme to get elderly or non-English-speaking customers to withdraw
money from banks. When these customers leave the bank with their money, the
perpetrators grab the money and flee instead of examining it as promised, knowing the
elderly person has no chance to catch them.
Many scams prey on elderly or uneducated victims. Various consumer frauds
such as prime bank fraud, pyramid scams, Internet fraud, phone scams, chain letters,
modeling agencies, telemarketing fraud, and Nigerian scams are all crimes of persuasion
that try to get victims to unknowingly invest money. Consider Nigerian investment
scams, for example. Very few of us have not received a letter inviting us to share in huge
wealth if only we will make a small investment or share bank account information.
Estimates put the losses from these “Nigerian Advance Fee” operations at over $1 million
“every single day” in the United States alone.
Organizations go to great lengths to create documents that will provide an audit
trail so that transactions can be reconstructed and understood. Many frauds, however,
involve cash payments or manipulation of records that cannot be followed. Smart fraud
perpetrators understand that their frauds must be concealed. They also know that such
concealment must usually involve manipulation of financial records. When faced with a
decision about which financial record to manipulate, perpetrators almost always
manipulate the income statement, because they understand that the audit trail will quickly
be erased.
So far, we have discussed the first two elements of the fraud triangle: perceived
pressure and perceived opportunity. The third element is rationalization. An example of
how rationalization contributes to fraud is the case of Jim Bakker and Richard Dortch.
These men were convicted on 23 counts of wire and mail fraud and one count of
conspiracy to commit wire and mail fraud. As a result of their conviction, the perpetrators
of one of the largest and most bizarre frauds in U.S.
To understand the extent of income tax fraud, consider that, in 1988, for the first
time, the IRS required taxpayers who claimed dependents to list the Social Security
numbers for their dependents. In 1987, 77 million dependents were claimed on federal
tax returns. In 1988, the number of dependents claimed dropped to 70 million. Fully one-
tenth of the dependents claimed, or 7 million dependents, disappeared. Where did they
go? Had they never existed? The IRS determined that in 1987 and probably in previous
years, over 60,000 households had claimed four or more dependents who didn’t exist, and
several million had claimed one or more who didn’t exist. Claiming dependents who
don’t exist is one of the most blatant and easiestto-catch income tax frauds. Yet, millions
of U.S. citizens rationalized and then blatantly cheated on their tax returns.
One of the first white-collar criminals to be convicted and incarcerated during the
major fraud scandals of 2002–2003 was Dr. Sam Waksal, CEO of ImClone.20 Waksal
was convicted in the same insider trading scandal involving Martha Stewart. In 2000,
Waksal was one of Wall Street’s men of the moment. As the CEO of ImClone, he had
just sold an interest in a new cancer drug called Erbitux to Bristol-Myers for $2 billion.
Everyone expected that the Food and Drug Administration would soon approve the drug.
Shortly thereafter, however, Waksal learned from a BristolMyers executive that the drug
wouldn’t be approved. The FDA was refusing to consider the Erbitux application—not
because the drug didn’t work, but because the data were insufficient. New clinical trials
would have to be conducted, and the price of ImClone stock was going to plummet.
Based on this insider information, Sam Waskal told his daughter to sell her shares,
thinking that the price was about to go down. He also tried to sell 79,000 of his own
shares (he owned millions of shares)—about $5 million worth. He transferred the 79,000
shares to his daughter thinking that if she sold them that was okay. He rationalized that he
wasn’t doing the selling.
G. Knowing Different Ways That Organizations Fight Fraud
Assume that you are the fraud-fighting consultant hired by the company. What
advice would you give this company? What kind of fraud prevention, detection, and
investigation programs would you recommend be implemented? What kind of ethics
programs would you put in place? What kind of prosecution policies would you
establish? A consultant would probably start by telling the management of the company
that there are four activities on which money can be spent to mitigate the occurrence of
fraud. These four activities are (1) fraud prevention, (2) early fraud detection, (3) fraud
investigation, and (4) follow-up legal action and/or resolution. The consultant would
inform the company representatives that there is no such thing as a small fraud—just
large frauds that are caught early. The consultant would most likely tell the company that
frauds grow geometrically and that, if frauds are allowed to continue unchecked,
perpetrators get braver and braver and the amounts stolen or manipulated in the final
weeks of the fraud usually dwarf the amounts taken in the early periods of the fraud. The
advice would include a combination of fraud training, ethics programs, better controls,
reviewing incentive programs, and harsher treatment of perpetrators. Indeed, a
comprehensive fraud program would focus on all four elements of fraud: prevention,
proactive detection, investigation, and legal follow-up. Like many organizations, Mark-X
has probably been concentrating its fraud-fighting efforts on only the last two: fraud
investigation (once the frauds had become so large and egregious that they could no
longer be ignored) and follow-up legal action. These are probably the least effective and
most expensive fraud-fighting efforts.
Preventing fraud is generally the most cost-effective way to reduce losses from
fraud.1 Once a fraud has been committed, there are no winners. Perpetrators lose because
they are usually first-time offenders who suffer humiliation and embarrassment as well as
legal consequences. They usually must make tax and restitution payments, and there are
often financial penalties and other consequences. Victims lose because not only are assets
stolen but they also incur legal fees, lost time, negative publicity, and other adverse
consequences. Further, if organizations don’t deal harshly with the perpetrators, a signal
is sent to others in the organization that nothing serious happens to fraud perpetrators,
making fraud by others more likely. Organizations and individuals that have proactive
fraud prevention measures usually find that their prevention efforts pay big dividends. On
the other hand, the investigation of fraud can be very expensive.
Organizations use several approaches to create a culture of honesty and high
ethics. Five of the most critical and common elements are (1) making sure that top
management models appropriate behavior, (2) hiring the right kind of employees, (3)
communicating expectations throughout the organization and requiring periodic written
confirmation of acceptance of those expectations, (4) creating a positive work
environment, and (5) developing and maintaining an effective policy for handling fraud
when it does occur.
Research into why people lie (or are dishonest) indicates that there are four major
reasons why people lie. The first is fear of punishment or adverse consequences. The fear
may be because they know they have done something wrong or their performance hasn’t
met expectations. Individuals who are constantly in fear of being punished develop a
habit of lying, which is a second reason for lying. Even when confronted by the truth,
once they are conditioned to lie, they usually insist the lie is the truth. A third reason for
lying is because they have learned to lie by watching others lie or through negative
modeling. When people see others lie, especially when those others get away with their
lies, people may become more prone to lying. Finally, people lie because they feel if they
tell the truth they won’t get what they want.
The second key element in creating a culture of honesty and high ethics is hiring
the right employees. Not all people are equally honest or have equally well-developed
personal codes of ethics. In fact, research results indicate that many people, when faced
with significant pressure and opportunity, will behave dishonestly rather than face the
“negative consequences” of honest behavior (e.g., losing reputation or esteem, failing to
meet quotas or expectations, having inadequate performance exposed, inability to pay
debts, etc.). If an organization is to be successful in preventing fraud, it must have
effective hiring policies that discriminate between marginal and highly ethical
individuals, especially when recruiting for high-risk positions. Proactive hiring
procedures include such things as conducting background investigations on prospective
employees, thoroughly checking references and learning how to interpret responses to
inquiries asked about candidates, and testing for honesty and other attributes.
The foundation of ethics, Personal Ethical Understanding, represents the most
basic ethical boundaries of personal actions. It involves learning the difference between
right and wrong, developing a sense of fair play, learning to care for and empathize with
others, developing respect for others, learning basic principles of integrity and reality,
and acting in a consistent manner with the values a person knows to be right. The second
level of the EMM, Application of Ethics to Business Situations, is being able to translate
one’s ethical understanding to the business world or to other settings in which people
earn a living (e.g., the medical profession, engineering profession, etc.). Such translation
is not always easy. For example, a person may have very strong ethics in the way he or
she treats family and friends, but may not understand how cooking the books or failing to
submit tax withholdings to the government affects peoples’ lives or constitutes unethical
or fraudulent behavior.
The third level of the EMM is Ethical Courage. Ethical courage is the strength
and conviction to act appropriately in difficult or questionable situations. A person can
have a personal ethical understanding and be able to translate that understanding to
business settings but may not have the courage to take a stand when necessary. In one
recent fraud, for example, more than 20 people falsified financial statements. All testified
they were aware that their actions were unethical, but none had the courage to stand for
their beliefs. The highest level, Ethical Leadership, is instilling in others a desire to
develop ethical awareness and courage. This higher form of ethical behavior requires a
person to inspire others through word, example, persuasion, and good management.
Research on honesty shows that individuals fall into three groups: (1) those who
will almost always be honest (approximately 30 percent of the population); (2) those who
are situationally honest,8 who will be honest when it pays to be honest but dishonest
when it pays to be dishonest (approximately 40 percent of the population); and (3) those
who will always be dishonest (approximately 30 percent of the population). Good
modeling and other good fraud prevention measures will usually keep the second group
from being dishonest; there is usually not much that can be done to prevent the third
group from being dishonest. As a result, having good screening policies in place to
eliminate the hiring of dishonest individuals and having positive modeling for
situationally honest individuals can prevent most frauds from occurring in an
organization.
The third critical element in creating a culture of honesty and high ethics—
communicating expectations of honesty and integrity—includes (1) identifying and
codifying appropriate values and ethics, (2) fraud awareness training that helps
employees understand potential fraud problems they may encounter and how to resolve
or report them, and (3) communicating consistent expectations about punishment of
violators. For codes of conduct to be effective, they must be written and communicated to
employees, vendors, and customers.9 They must also be developed in a manner that will
encourage management and employees to take ownership of them.10 Requiring
employees to confirm in writing that they understand the organization’s ethics
expectations is an effective element of communication in creating a culture of honesty. In
fact, many successful organizations have found that annual written confirmation is very
effective in both preventing and detecting frauds before they become large.
The fifth and final element in creating a culture of honesty and high ethics is
having appropriate policies in place for handling fraud if it occurs. No matter how good
an organization’s fraud prevention activities are, as stated previously, fraud can still
occur. The way an organization reacts to fraud incidents sends a strong signal that affects
the number of future incidents. An effective policy for handling fraud should ensure that
the facts are investigated thoroughly, firm and consistent actions are taken against
perpetrators, risks and controls are assessed and improved, and communication and
training are ongoing. Every organization should have a fraud policy that determines
whose responsibility fraud prevention, detection, and investigation are, how incidents of
fraud will be handled legally, and what kind of remediation and education efforts will
take place when fraud does occur.
The Sarbanes-Oxley Act of 2002 recognized the value of having a system for
employees and others to report wrongdoing, including fraud. Section 307 of that law
requires every public company to both have a whistle-blower system in place and
prohibit retaliation against any employee or other person who reports questionable
activities using the whistle-blower system. One of the events that prompted this
legislation was a letter that former Enron chairman Kenneth Lay received from a senior
executive in August 2001 warning that the company—once a pillar of the U.S. energy
industry—could “implode in a wave of financial scandals.” Apparently, the letter pointed
out the questionable nature of some partnerships involving company executives.
H. Fraud Detection
Not being caught, the perpetrator’s confidence in his fraud scheme increased, and
he became greedier and greedier. In fact, you will note that, on 7-23, there is a two-week
period where fraudulent behavior stopped. The reason for this pause in the perpetrator’s
dishonest behavior was that auditors came to the branch where he worked. You will also
notice that once the auditors left, the perpetrator resumed his fraudulent behavior but only
stole small amounts. For a short time, he was testing the system to make sure the auditors
hadn’t detected him or put processes in place that would reveal his dishonest activity.
Once he again had confidence that he wouldn’t be caught, he quickly escalated the
amounts stolen into hundreds of dollars per day.
When fraud is committed by the president or owner of an organization, as it was
in this case, prevention is very difficult. Maybe the president’s company could have had a
higher code of ethics, but if the president wants to commit fraud, there is probably
nothing anyone can do to stop him. Rather, the emphasis on these types of fraud must be
on fraud detection. Because all frauds cannot be prevented, organizations should have
both preventive and detective controls in place. Preventive controls are aimed at keeping
fraud from happening, while the goal of detective controls is to catch frauds early before
they have a chance to get very large.
Detection of fraud usually begins by identifying symptoms, indicators, or red
flags12 that tend to be associated with fraud. Unfortunately, these “red flags” can often
be associated with nonfraud factors as well. There are three primary ways to detect fraud:
(1) by chance, (2) by providing ways for people to report suspicions of fraud, and (3) by
examining transaction records and documents to determine if there are anomalies that
could represent fraud. In the past, most frauds were detected by accident. Unfortunately,
by the time detection occurred, the frauds were usually large and had been going on for
some time. In most cases, there were even individuals in the victim organizations who
suspected that fraud was occurring but did not come forward, either because they weren’t
sure it was fraud, didn’t want to wrongly accuse someone, didn’t know how to report the
fraud, or were fearful of the consequences of becoming a whistleblower.
In recent years, organizations have implemented a number of initiatives to detect
fraud more proactively. The first and most common proactive fraud detection approach
has been to install reporting hotlines (whistle-blowing systems) as described earlier
whereby employees, coworkers, and others can call in using a telephone or submit (using
a Web page) an anonymous tip of a suspicion of fraud. Some of these hotlines are
maintained within the company, and others are outsourced to independent organizations
to provide hotline services for them. (The Association of Certified Fraud Examiners and a
company called Allegience [formerly Silent Whistle], for example, provide feebased
hotline service.) Organizations that have installed hotlines have detected many frauds that
would have remained undetected, but they have often paid a fairly high price for doing
so. Not surprisingly, many of the calls made through hotlines do not involve fraud at all.
The second proactive fraud detection approach is to analyze data and transactions
to look for suspicious trends, numbers, and other anomalies. Recent developments in
technology have allowed organizations to comprehensively analyze and mine databases
to proactively look for fraud symptoms. Banks, for example, have installed programs to
identify suspected kiting. These programs draw the bank’s attention to customers who
have a high volume of bank transactions within a short period of time. Insurance
companies have implemented programs that examine claims within a short time after
purchasing insurance. Some organizations have even implemented comprehensive fraud
detection programs by systematically identifying the kinds of frauds that could be
occurring, cataloging the various symptoms those frauds would generate, and then
building realtime queries into their computer systems to search for these symptoms.
Fraud detection research, mostly using technology-based search techniques, is now being
conducted by academics and other investigators. Anyone who is seriously interested in
understanding and fighting fraud should be following this research. In the next two
chapters, we will discuss proactive fraud detection.
I. Fraud Investigation
Both of these situations involve matters that need to be investigated. If Mark does
not investigate the anonymous tip, he may never uncover a possible kickback fraud and
inflated purchasing costs for the company. Likewise, Jane needs to perform some follow-
up investigation on the revenue problem brought to her attention by the junior auditor.
There are at least three reasons why the auditors in this case must investigate to
determine whether or not the client is really overstating revenues. First, the company’s
shareholders could face significant losses. Second, the auditors’ failure to discover the
overstatement could expose them to legal action (and consequent losses). Finally, and
perhaps most important, an overstatement of revenues may expose management’s
integrity to such serious doubt as to make the firm “unauditable.”
Both of these situations have created a “predication of fraud.” Predication refers
to the circumstances, taken as a whole, that would lead a reasonable, prudent professional
to believe a fraud has occurred, is occurring, or will occur. Fraud investigations should
not be conducted without predication. A specific allegation of fraud against another party
is not necessary, but there must be some reasonable basis for concern that fraud may be
occurring. Once predication is present, as in these cases, an investigation is usually
undertaken to determine whether or not fraud is actually occurring, as well as the who,
why, how, when, and where elements of the fraud. The purpose of an investigation is to
find the truth—to determine whether the symptoms observed actually represent fraud or
whether they represent unintentional errors or other factors. Fraud investigation is a
complex and sensitive matter. If investigations are not properly conducted, the
reputations of innocent individuals can be irreparably injured, guilty parties can go
undetected and be free to repeat the act, and the offended entity may not have information
to use in preventing and detecting similar incidents or in recovering damages.
The investigation of fraud symptoms within an organization must have
management’s approval. Investigations can be quite expensive and should be pursued
only when there is reason to believe that fraud has occurred (when predication is present).
The approaches to fraud investigation vary, although most investigators rely heavily on
interviews. Fraud investigations can be classified according to the types of evidence
produced or according to the elements of fraud.
Investigation involves investigating the various elements of each of these
triangles. In focusing on the fraud motivation triangle, investigators search for perceived
pressures, perceived opportunities, or rationalizations that others have observed or heard.
Focusing on the fraud element triangle is a little more complicated. Theft act
investigative methods involve efforts to catch the perpetrator(s) in the embezzlement act
or to gather information about the actual theft acts. Concealment investigative methods
involve focusing on records, documents, computer programs and servers, and other
places where perpetrators might try to conceal or hide their dishonest acts. Conversion
investigative methods involve searching for ways in which perpetrators have spent or
used their stolen assets.
For now, it is important to know that a fraud investigator needs some way to
coordinate the fraud investigation. Some investigations are extremely large, and
conducting the various investigative steps in the wrong order or doing them
inappropriately can lead to a failed investigation as well as other problems. As a result, it
is very important to understand the significant risks that investigators face. And, as stated
in the previous caution box, you must also remember that investigating a fraud is a
traumatic experience for everyone involved, including the perpetrators. Most fraud
perpetrators have positive reputations in their work, community, family, and church
environments.
J. Follow-Up Legal Action
One of the major decisions a company, stockholders, or others must make when
fraud is committed is what kind of follow-up legal and other actions should be taken.
Why the fraud occurred should always be determined, and controls or other measures to
prevent or deter its reoccurrence should be implemented. Training of appropriate people
so that similar frauds won’t reoccur is also required. The bigger question that must be
addressed, however, is what, if any, legal action should be taken with respect to the
perpetrators. Most organizations and other fraud victims usually make one of three
choices: (1) take no legal action, (2) pursue civil remedies, and/or (3) pursue criminal
action against the perpetrators, which is sometimes done for them by law enforcement
agencies.
Similarly, stockholders and creditors who suffer losses when management fraud
occurs almost always sue not only the perpetrators but also usually the auditors and any
others associated with the company who may have “deep pockets.” The plaintiff’s
lawyers are usually more than willing to represent shareholders in class action, contingent
fee lawsuits. Criminal action can only be brought by law enforcement or statutory
agencies. Organizations that want to pursue criminal action against perpetrators must
work with local, state, or federal agencies to get their employees or other perpetrators
prosecuted. As you learned in Chapter 1, criminal penalties usually involve fines, prison
terms, or both. They can also involve the perpetrators entering into restitution agreements
to pay back stolen funds over a period of time. Pursuing criminal penalties is becoming
more and more common in fraud cases. Corporate executives who commit fraud are often
sentenced for up to 10 years in jail and ordered to pay fines equal to the amounts they
embezzled.
Assessing and mitigating the risk of fraud means that an organization should have
a process in place that both defines where the greatest fraud risks are and evaluates and
tests controls that mitigate those risks. In identifying fraud risks, organizations should
consider organizational, industry, and country-specific characteristics that influence the
risk of fraud. No matter how good a company’s fraud prevention activities are, some
frauds will still occur. Companies should use proactive fraud detection techniques, such
as whistle-blower systems and data mining tools, to detect frauds before they become
large.