1 / 29100%
Module 2
Fraud Prevention
a. Just About Everyone Can Be Dishonest
In understanding the dynamics of fraud within organizations, it becomes
imperative to delve into the intricacies of human behavior, organizational culture, and the
interplay of various factors that contribute to ethical or unethical conduct. While it may
be tempting to believe that individuals inherently possess a strong moral compass and
would abstain from fraudulent activities, empirical evidence suggests otherwise. Human
psychology is complex, influenced by external stimuli and environmental cues. When
individuals find themselves amidst an organizational culture characterized by low
integrity, lax controls, or high-pressure situations, their ethical boundaries may become
blurred. Research in behavioral economics has consistently shown that people are
susceptible to situational influences, often adapting their behavior to fit the prevailing
norms within their environment.
One significant catalyst for unethical behavior lies in the phenomenon of social
learning and modeling. Individuals, particularly employees, observe and emulate the
actions of those in positions of authority or leadership within their organization. When
top executives engage in dishonest practices or cut corners to achieve desired outcomes,
it sets a precedent that cascades down the organizational hierarchy. This process, known
as "tone at the top," can significantly shape the ethical climate within an organization.
The infamous case of Equity Funding serves as a poignant example of how unethical
conduct at the executive level can permeate throughout an organization. Management's
creation of fictitious policyholders and the issuance of fraudulent insurance policies not
only demonstrated a blatant disregard for ethical standards but also inadvertently
sanctioned such behavior among employees. The normalization of fraudulent practices,
coupled with the absence of accountability mechanisms, created an environment ripe for
misconduct.
Moreover, the presence of perceived opportunities and rationalizations further
exacerbates the likelihood of fraudulent behavior. Employees who witness fraudulent
activities may rationalize their participation by minimizing the perceived harm or
justifying their actions based on situational factors. In the case of Equity Funding, the
employee who decided to mimic management's fraudulent behavior likely rationalized his
actions by assuming that his involvement would go unnoticed amidst the pervasive
culture of deceit.
To mitigate the risk of fraud within organizations, proactive measures must be
taken to foster a culture of integrity, transparency, and accountability. This entails not
only setting clear ethical standards but also ensuring that these standards are reinforced
through robust controls, regular monitoring, and ethical leadership. By addressing the
root causes of fraud and promoting a culture of ethical conduct, organizations can create
an environment where fraudulent behavior is less likely to take root, ultimately
safeguarding their reputation and long-term viability.
In understanding the dynamics of fraud prevention within organizations, it is
crucial to explore in greater depth the multifaceted strategies and principles that
contribute to creating a low-fraud environment. This entails a comprehensive
examination of the various factors and approaches that can be implemented to foster a
culture of honesty, transparency, and accountability, while simultaneously mitigating
opportunities for fraudulent behavior.
First and foremost, cultivating a culture of honesty, openness, and assistance
serves as the cornerstone of a low-fraud environment. This involves instilling values and
ethical norms that prioritize integrity and ethical conduct across all levels of the
organization. Leaders play a pivotal role in setting the tone at the top by demonstrating
their commitment to ethical principles through their actions and decisions. By promoting
transparency, encouraging open communication, and fostering a sense of trust and
collaboration among employees, organizations can create an environment where
fraudulent behavior is not tolerated and ethical conduct is upheld as the norm.
Furthermore, creating expectations that fraud will be punished is essential in
deterring potential wrongdoers and reinforcing the consequences of unethical behavior.
This requires implementing robust mechanisms for detecting and investigating fraudulent
activities, as well as establishing clear policies and procedures for reporting suspected
misconduct. By establishing a zero-tolerance policy towards fraud and holding
individuals accountable for their actions, organizations send a clear message that
unethical behavior will not be condoned and will be met with swift and decisive
consequences.
In addition to fostering a culture of integrity and accountability, eliminating
opportunities to commit fraud is paramount in preventing fraudulent behavior. This
involves implementing stringent internal controls, policies, and procedures designed to
safeguard assets, mitigate risks, and deter fraudulent activities. From segregation of
duties and regular audits to implementing fraud detection technologies and conducting
thorough background checks on employees, organizations can proactively identify and
address vulnerabilities that may be exploited by would-be fraudsters.
At the heart of a comprehensive fraud prevention strategy lies the integration of
prevention, detection, and investigation efforts. By combining proactive measures to
prevent fraud, such as fostering a culture of integrity and implementing robust internal
controls, with reactive measures to detect and investigate suspicious activities,
organizations can effectively combat fraud at every stage. This requires a coordinated and
multifaceted approach that involves collaboration across various departments, including
finance, legal, compliance, and internal audit.
In conclusion, creating a low-fraud environment requires a concerted effort to
cultivate a culture of honesty, openness, and assistance, while simultaneously eliminating
opportunities for fraudulent behavior and establishing clear expectations that fraud will
be punished. By integrating prevention, detection, and investigation efforts into a
comprehensive fraud-fighting program, organizations can effectively mitigate the risk of
fraud and safeguard their reputation, assets, and stakeholders' trust.
b. Creating a Culture of Honesty, Openness, and Assistance
Three major factors in fraud prevention relate to creating a culture of honesty,
openness, and assistance. These three factors are (1) hiring honest people and providing
fraud awareness training; (2) creating a positive work environment, which means having
a well-defined code of conduct, having an open-door policy, not operating on a crisis
basis, and having a low-fraud atmosphere; and (3) providing an employee assistance
program (EAP) that helps employees deal with personal pressures.
Effectively screening applicants so that only “honest” employees are hired is very
important. As stated earlier in this book, studies have indicated that nearly 30 percent of
Americans are dishonest, 40 percent are situationally honest, and only about 30 percent
are honest all the time. Nonpublic studies conducted at firms with which we have
consulted have also shown that 25 percent of all frauds are committed by employees who
have worked three years or less. Individuals with gambling, financial, drug, or past
criminal problems should not be hired, or, at least, if they are hired, the adverse
information about their backgrounds or characters should be known.
With today’s stringent privacy laws, it is essential that companies have good
employee screening policies. Even in a highly controlled environment, dishonest
employees with severe pressures often commit fraud. Résumé verification and
certification are two tactics that organizations should use to prevent fraud. One of the
most important responsibilities of an employer is the hiring and retention of its
employees. In today’s market, turnover tends to be high and employee loyalty may be
low. Poor hiring decisions may not only lead to hiring employees who are dishonest but
also under a negligent hiring and/or retention claim, an employer may be liable for acts or
omissions of the employee, either within or outside the scope of the employee’s
employment, as long as the injured party can show specific negligent acts of the
employer itself. An example of negligent hiring and/or retention claims includes a
trucking company liable for a wrongful death resulting from one of its truckers driving
drunk on the wrong side of the road and colliding with an oncoming car, killing the
driver. The trucking company failed to verify the trucker’s claimed perfect driving
record, which would have shown numerous prior DUI violations.
Another example is a church member who was raped during counseling sessions
with a church employee. In his lawsuit, the church member claims that the church should
not have had the church employee in a counseling position, especially in light of his prior
record of sexual offenses during such sessions. No employer can totally immunize itself
from hiring fraudulent employees or from liability for claims asserting negligent hiring
and/or negligent retention. However, the employer that follows the following
recommendations as part of its hiring and retention policies and practices will be as
successful as possible in avoiding frauds and negligent hiring claims.
First, before hiring an applicant for any position, especially key management
positions, the employer should verify all information on the applicant’s résumé and/or
application. The verification should be complete and conducted by an employee who is
thorough and persistent in this important procedure. There is no question that verifying an
applicant’s résumé and/or application is a resource-consuming process. (In the case of a
top executive, you should make sure that a search firm that is hired verifies all
information on candidates’ résumés.) The benefits of such precautions include increased
knowledge of the applicant and his or her propensity to be truthful as well as significant
reduction in hiring and retaining dangerous, unfit, or dishonest employees. As an
example of a CEO who lied on his résumé, consider the case of RadioShack’s CEO
David Edmondson.3 Edmondson resigned after the StarTelegram of Fort Worth, Texas,
reported he had lied on his résumé.
Edmondson claimed degrees in both theology and psychology from Pacific Coast
Baptist College in California. The school’s registrar told the Star-Telegram that records
showed Edmondson had completed two semesters and that the school had never offered
degrees in psychology. Other prominent people who have recently lied on their résumés
include the mayor of Rancho Mirage, California, who admitted he didn’t hold degrees
that he’d claimed, a former football coach at Notre Dame, and a former spokesman for
NASA. A recent congressional investigation uncovered 463 federal employees who had
credentials from unaccredited schools giving bogus degrees. A recent example of resume
embellishment is Gregory Probert, COO of Herbalife who stated that he obtained an
M.B.A. from UCLA. After a report by the Fraud Discovery Institute, Probert admitted
that he faked his degree and resigned in May, 2008.
An important part of the employer’s verification of all information on the
applicant’s résumé and/or application is verification of the applicant’s references. Due to
statutory restrictions on the dissemination of such information and the applicant’s
reasonable expectation of privacy, employers should always obtain a written
authorization and/or a “hold harmless agreement” from the applicant to obtain
information from references.
Second, the employer should require all applicants to certify that all information
on their application and/or résumé is accurate. A requirement that all applicants must
affirm the truth of the matters set forth in their application and/or résumé will act as a
deterrent against false or misleading statements or omissions. The application should
provide, in writing acknowledged and agreed to by the applicant, that, in the event false
information in the form of statement or omission is discovered on the application and/or
résumé, then such discovery is grounds for immediate termination.
Third, the employer should train those involved in the hiring process to conduct
thorough and skillful interviews. Interviewing prospective employees is one of the most
important activities employers do. The employer’s objective of an interview is to
determine whether an applicant is suitable for an available position. The interview
provides the employer an opportunity to obtain in-depth information about a job
applicant’s skills, work history, and employment background. Many prudent employers
require interviewers to ask a standard set of questions designed to obtain certain
information from the application. The interviewer is then left to her own discretion to
follow up and/or ask additional questions during the course of the interview. Numerous
companies specialize in helping companies hire the right employees, ask the right hiring
questions, and avoid legal traps by asking illegal questions.
There are also other ways to be creative in hiring processes. Many financial
institutions, for example, now use systems to determine whether prospective employees
and customers have had past credit problems. Banks are also fingerprinting new
employees and customers and comparing the fingerprints with law enforcement records.
Other organizations are hiring private investigators or using publicly available databases
to search information about people’s backgrounds. Some organizations are administering
drug tests. Pen-and-pencil honesty tests are also being used as a screening tool. One
company, for example, extensively trained several interviewers to know which questions
were legal to ask and which were illegal, to recognize deception and lying, and to probe
legally into applicants’ backgrounds. It also adopted a policy of calling three previous
references instead of one. It developed a rule that if no gratuitously positive information
was received in any of the three background checks, these checks would be viewed as
negative. (The interviewers tried to call references who personally knew the applicants,
rather than personnel officers who didn’t know them.) Over a three-year period, this
company found that 851 prospective employees, or 14 percent of all applicants, had
undisclosed problems, such as previous unsatisfactory employment, false education or
military information, criminal records, poor credit ratings, alcoholism, or uncontrolled
tempers. People with these types of problems generally find it easier to rationalize
dishonest acts, and preventing such people from being hired can reduce fraud.
Once people have been hired, it is important to have them participate in an
employee awareness program that educates them about what is acceptable and
unacceptable, how all parties, including them, are hurt when someone is dishonest, and
what actions they should take if they see someone doing something improper. A
comprehensive awareness program should educate employees about how costly fraud and
other types of business abuses are. Employees must know that fraud takes a bite out of
their pay and benefits, as well as corporate profits and returns to shareholders, and that no
dishonest acts of any kind will be tolerated. Most companies with successful fraud
awareness programs have packaged fraud training with other sensitive issues important to
employees, such as employee safety, discrimination, substance abuse, and the availability
of EAPs.
One company, for example, educates all employees about abuses and gives them
small cards to carry in their purses or wallets. The cards list four possible actions
employees can take if they suspect abuses are taking place. They can (1) talk to their
immediate supervisor or management, (2) call corporate security, (3) call internal audit,
or (4) call an 800 hotline number. Employees are told that they can either provide hotline
information anonymously or disclose their identities. This company has also made
several videos about company abuses, including frauds, which are shown to all new
employees. New posters relating to the awareness program are posted conspicuously
throughout the organization on a regular basis. Because of these awareness programs,
fraud and other abuses have decreased substantially.
The second factor important in a culture of honesty, openness, and assistance is
creating a positive work environment. Positive work environments do not happen
automatically; rather, they must be cultivated. It is a fact that employee fraud and other
dishonest acts are more prevalent in some organizations than in others. Organizations that
are highly vulnerable to fraud can be distinguished from those that are less vulnerable by
comparing their corporate climates. Three elements that contribute to the creation of a
positive work environment, thus making the organization less vulnerable to fraud, are (1)
creating expectations about honesty through having a good corporate code of conduct and
conveying those expectations throughout the organization, (2) having opendoor or easy
access policies, and (3) having positive personnel and operating procedures.
The explanation is often described as the Pygmalion effect. Sterling Livingston,
writing in the Harvard Business Review (September 1988), extended this phenomenon
into management with a simple thesis: People generally perform according to a leader’s
expectations. If expectations are low, actual performance is likely to be “substandard.” If,
however, expectations are high, performance is usually high as well. “It is as though there
were a law that caused subordinates’ performance to rise or fall to meet management’s
expectations,” Livingston wrote.
Livingston and others have also found that expectations must be genuine and
accepted by leaders. The studies have concluded that people know when they are being
conned. If expectations are unrealistically high or if they are not being taken seriously by
leaders, people know it. Conversely, if a manager pretends that he has confidence and
high expectations when he really has doubts, people will know that, too. The lesson about
expectations is clear: People have keen senses about expectations. You can’t fool them;
expectations must be genuine. Trying to create expectations, especially about integrity
and ethics, when top management isn’t serious about the expectations, only erodes their
credibility. According to the researchers, a good axiom to remember is, “What you expect
is what you’ll get.” 4 As an example of the power of expectations, consider the following
true story.
ons about what is and is not acceptable in an organization is to have an articulated
code of conduct. Section 406 of the Sarbanes-Oxley Act of 2002, “Code of Ethics for
Senior Financial Officers,” requires that every public company have a code of ethics for
management and its board of directors. Shortly after Congress passed the Sarbanes-Oxley
Act, the Securities and Exchange Commission (SEC) revised its listing standards to
require public companies to create and distribute a code of conduct to all employees.
Merely having a code of conduct, however, is not sufficient. It must be visible and
communicated frequently. Some companies have found it helpful to even have employees
read and sign their code annually and certify that they have not violated the code or seen
others who have.
Hormel’s code not only clarifies what is and is not acceptable, but it also specifies
the disciplinary action that will be applied to violators and provides contact (whistle-
blower) information for reporting violations. If Hormel is successful in keeping this code
in front of its employees, just the mere fact that everyone knows that others know what is
expected, what expected punishments are, and how to escalate information about
violations should reduce the number of dishonest incidents in the company.
Literature on moral development suggests that if you want someone to behave
honestly, you must both label and model honest behavior. As we have discussed, a
clearly defined code of conduct labels for employees what is acceptable and
unacceptable. Having employees periodically read and sign a company code of ethics
reinforces their understanding of what constitutes appropriate and inappropriate behavior.
A clearly specified code inhibits rationalizations, such as “It’s really not that serious,”
“You would understand if you knew how badly I needed it,” “I’m really not hurting
anyone,” “Everyone is a little dishonest,” or “I’m only temporarily borrowing it.” When a
company specifies what is acceptable and what is unacceptable and requires employees to
acknowledge that they understand the organization’s expectations, they realize that fraud
hurts the organization, that not everyone is a little dishonest, that the organization won’t
tolerate dishonest acts, that dishonest behavior is serious, and that unauthorized
borrowing is not acceptable.
A second way to create a positive work environment, thus making the
organization less vulnerable to fraud, is having open-door or easy access policies. Open-
door policies prevent fraud in two ways. First, many people commit fraud because they
feel they have no one to talk to. Sometimes, when people keep their problems to
themselves, they lose their perspectives about the appropriateness of actions and about
the consequences of wrongdoing. This loss of perspective can lead to making decisions to
be dishonest. Second, open-door policies allow managers and others to become aware of
employees’ pressures, problems, and rationalizations. This awareness enables managers
to take fraud prevention steps. Studies have shown that most frauds (71 percent in one
study) are committed by someone acting alone. Having people to talk to can prevent this
type of fraud. One person who had embezzled said, in retrospect, “Talk to someone. Tell
someone what you are thinking and what your pressures are. It’s definitely not worth
it…. It’s not worth the consequences.”
Each of these conditions or procedures contributes to creating a high-fraud
environment. For example, during crisis or rush jobs, there are additional opportunities to
commit fraud. When a special project is being hurried toward completion, for example,
the normal controls are often set aside or ignored. Signatures are obtained to authorize
uncertain purchases. Reimbursements are made rapidly, with little documentation.
Record keeping falls behind and cannot be reconstructed. Inventory and supplies come
and go rapidly and can easily be manipulated or misplaced. Job lines and responsibilities
are not as well defined.
The third factor in creating a culture of honesty, openness, and assistance is
having formal employee assistance programs (EAPs). One of the three elements of the
fraud triangle is perceived pressure. Often, fraudmotivating pressures are what
perpetrators consider to be unsharable or what they believe have no possible legal
solutions. Companies that provide employees with effective ways to deal with personal
pressures eliminate many potential frauds. The most common method of assisting
employees with pressures is by implementing formal EAPs. EAPs help employees deal
with substance abuse (alcohol and drugs); gambling; money management; and health,
family, and personal problems.
An EAP that is successfully integrated into an organization’s other employee
support systems with programs and services that include wellness, team building,
coaching, conflict resolution, critical incident response, assessment, counseling, and
referral can and does help reduce fraud and other forms of dishonesty. Employees
welcome this benefit, they use it, and they report consistently in impact surveys that the
EAP made a difference in their lives, and in the quality of their work. Most successful
organizations view EAPs as important contributors to the success of their businesses and
as valuable benefits for their employees. Employers are convinced that EAP programs
make a difference. Why? Organizations recognize that having the ability to provide a
troubled employee with timely and appropriate help results in reducing the financial and
human costs associated with an employee who is not fully functioning. Valuable
employees have been assisted in dealing successfully with issues that threatened their
health, finances, relationships, energy, and ability to contribute strongly in the workplace.
c. Eliminating Opportunities for Fraud to Occur
Earlier in this text, the fraud motivation triangle— perceived pressure, perceived
opportunity, and rationalization—was introduced to explain why fraud occurs. When
pressure, opportunity, and rationalization combine, the likelihood of a fraud being
perpetrated increases dramatically. If one of the three elements is missing, fraud is less
likely. In this section, we discuss the second major element in fraud prevention—
eliminating opportunities to commit dishonest acts. In this section, we will cover five
methods of eliminating fraud opportunities: (1) having good internal controls, (2)
discouraging collusion between employees and customers or vendors and clearly
informing vendors and other outside contacts of the company’s policies against fraud, (3)
monitoring employees and providing a hotline (whistle-blowing system) for anonymous
tips, (4) creating an expectation of punishment, and (5) conducting proactive auditing.
Each of these methods reduces either the actual or the perceived opportunity to commit
fraud, and all of them together combine with the culture factors described earlier to
provide a comprehensive fraud prevention program.
As stated previously in this text, the Committee of Sponsoring Organizations’
(COSO) definition of an internal control framework for an organization should include
(1) a good control environment, (2) a good accounting system, (3) good control activities,
(4) monitoring, and (5) good communication and information. The control environment is
the overall tone of the organization that management establishes through its modeling and
labeling, organization, communication, and other activities. As stated in COSO’s report,
the control environment sets the tone of an organization, influencing the control
consciousness of its people.7 It is the foundation for all other components of internal
control, providing discipline and structure. Control environment factors include the
integrity, ethical values, and competence of the entity’s people, management’s
philosophy and operating style, the way management assigns authority and responsibility
and organizes and develops its people, and the attention and direction provided by the
board of directors. The control environment also includes well-defined hiring practices,
clear organization, and a good internal audit department.
The second element—having a good accounting system—is important so that the
information used for decision making and provided to stakeholders is valid, complete,
and timely. The system should also provide information that is properly valued,
classified, authorized, and summarized. Good control activities involve policies and
practices that provide physical control of assets, proper authorizations, segregation of
duties, independent checks, and proper documentation. (Physical control, proper
authorization, and segregation of duties are controls that usually prevent fraud, thus
called preventive controls, while independent checks and documents and records are
usually detective controls that provide early fraud detection opportunities.) A control
system that meets these requirements provides reasonable assurance that the goals and
objectives of the organization will be met and that fraud will be reduced.
Obviously, if a person owns a company and is that company’s only employee, not
many controls are needed. The owner would not likely steal from the company or serve
customers poorly. In organizations with hundreds or thousands of employees or even two
or three, controls are needed to ensure that employees behave according to the owner’s
expectations. No internal control structure can ever be completely effective, regardless of
the care followed in its design and implementation. Even when an ideal control system is
designed, its effectiveness depends on the competency and dependability of the people
enforcing it. Consider, for example, an organization that has a policy requiring the dual
counting of all incoming cash receipts. If either of the two employees involved in the task
fails to understand the instructions, is careless in opening and counting incoming cash, or
fails to pay attention to the task at hand, money can easily be stolen or miscounted. One
of the employees might decide to understate the count intentionally to cover up a theft of
cash. Dual custody can be maintained only if both employees pay full attention to the task
and completely understand how it is to be performed.
Because of the inherent limitations of controls, a control system by itself can
never provide absolute assurance that all fraud will be prevented. Trying to prevent fraud
by having only a good control system is like fighting a skyscraper fire with a garden
hose. In combination with the other methods described in the following, however, having
a good control framework is an extremely important part of any fraud prevention
program. In determining what kind of control activities an organization should have, it is
important to identify the nature of risks involved and the types of abuses that could result
from these risks. There are only five types of control activities: (1) segregation of duties
—having two people do a task together or splitting the task into parts so that no one
person handles the complete assignment; (2) having a system of proper authorizations so
that only authorized or designated individuals have permissions to complete certain tasks;
(3) implementing physical safeguards such as locks, keys, safes, fences, and so on, to
prohibit access to assets and records; (4) implementing a system of independent checks
such as job rotations, mandatory vacations, audits, and so on; and (5) having a system of
documents and records that provide an audit trail that can be followed to check on
suspicious activity and to document transactions. As shown in Table 4.2, the first three
are preventive controls, and the last two are detective controls.
Once identified and put into place, controls need to be monitored and tested to
ensure that they are effective and are being followed. In fact, Section 404 of the
Sarbanes-Oxley Act requires all public companies to have their external auditors test their
system of internal controls and attest that there are no material weaknesses in the
controls. In determining what kinds of control activities to implement, it is important to
assess their costs and benefits. For example, while the most appropriate control from a
risk perspective might involve segregation of duties, this control is usually quite
expensive. In small businesses with only a few employees, segregation of duties may be
too expensive or even impossible. In such cases, it is important to identify less expensive
or “compensating” controls that can provide some fraud prevention assurance. For
example, in a small service business with eight employees, the owner might personally
sign all checks and reconcile all bank statements to control cash. Often, the problem
when fraud is committed is not a lack of controls, but the overriding of existing controls
by management or others. Consider the role of controls in the theft of $3.2 million from a
small bank—a case that we have discussed previously.
If these controls that were supposedly in place had been effective, Marjorie’s
fraud would have been prevented or at least detected in its early stages. Because
management and internal auditors were overriding controls, the bank’s “reasonable
assurance” provided by internal controls became “no assurance” at all. Having a good
system of internal control is the single most effective tool in preventing and detecting
fraud. Unfortunately, sometimes in practice, control procedures are rarely followed the
way they are designed or intended. Sometimes, a lack of compliance occurs because
employees emulate management’s apathetic attitude toward controls. Other times,
managers properly model and label good control procedures, but employees do not
comply because of disinterest, lack of reward for following or punishment for not
following controls, lack of focus, or other reasons. Because control procedures can
provide only “reasonable assurance” at best, controls are only one element of a
comprehensive fraud prevention plan.
As stated previously, empirical research has shown that approximately 71 percent
of all frauds are committed by individuals acting alone. The remaining 29 percent of
frauds—those involving collusion—are usually the most difficult to detect and often
involve the largest amounts. Collusive fraud is usually slower to develop (it takes time to
get to know others well enough to collude and to “trust” that they will cooperate rather
than blow the whistle) than frauds committed by one individual.
Unfortunately, two recent trends in business have probably increased the number
of collusive frauds. The first is the increasingly complex nature of business. In complex
environments, trusted employees are more likely to operate in isolated or specialized
surroundings in which they are separated from other individuals. The second is the
increasing frequency of supplier alliances, where oral agreements replace paper trails and
closer relationships exist between buyers and suppliers. Certainly, there are increased
cost savings and increased productivity from using supplier alliances. How much
increased complexity and supplier alliances will cause fraud to increase is still unknown,
although most fraud studies show that fraud is increasing every year. Generally, it is the
people we “trust” and “have confidence in” who can and do commit most frauds. The
reaction of one manager to a recent fraud involving a trusted vendor was, “I just couldn’t
believe he would do it. It’s like realizing your brother is a murderer.”
Fraud is similar to driving wagons over a treacherous road. When risks are higher,
there will be more problems. When employees are solely responsible for securing large
contracts with vendors, bribes and kickbacks often occur. In some cases, purchasing
employees can double or triple their salaries by allowing very small increases in the costs
of purchased goods. Purchase and sales frauds are the most common types of collusive
frauds. When the opportunity is too high, even individuals whose professional lives are
guided by professional codes of conduct will sometimes commit fraud. Consider the
ESM fraud as an example.
In the ESM fraud case, the CPA firm partner accepted under-the-table bribes from
his client, in return for staying quiet about fraudulent financial transactions. The fraud
being perpetrated by the client exceeded $300 million. The CPA had been the partner-in-
charge of the engagement for over eight years. For not disclosing the fraud, the client
paid him $150,000. If the CPA firm had not allowed him to be managing partner of the
job for such a long time, his participation in the fraud and erosion of integrity would
probably have been impossible.
Sometimes otherwise innocent vendors and customers are drawn into frauds by an
organization’s employees because they fear that if they don’t participate, the business
relationship will be lost. In most cases, such customers or vendors have only one or two
contacts with the firm. They are often intimidated by the person who requests illegal
gratuities or suggests other types of inappropriate behavior. A periodic letter to vendors
that explains an organization’s policy of not allowing employees to accept gifts or
gratuities helps vendors understand whether buyers and sellers are acting in accordance
with the organization’s rules. Such letters clarify expectations, which is very important in
preventing fraud. Many frauds have been uncovered when, after such a letter was sent,
vendors expressed concern about their buying or selling relationships.
A large chicken fast-food restaurant discovered a $200,000 fraud involving
kickbacks from suppliers. After investigating the fraud, the restaurant management
decided to write letters to all vendors explaining that it was against company policy for
buyers to accept any form of gratuities from suppliers. The result of the letters was the
discovery of two additional buyer-related frauds. A related precaution that is often
effective in discouraging collusive-type frauds is printing a “rightto-audit” clause on the
back of all purchase invoices. Such a clause alerts vendors that the company reserves the
right to audit their books any time. Vendors who know that their records are subject to
audit are generally more reluctant to make improper payments than those who believe
their records are confidential and will never be examined. A right-to-audit clause is also a
valuable tool when conducting fraud investigations.
Individuals who commit fraud and hoard stolen proceeds are virtually
nonexistent. Almost always, perpetrators use their stolen money to support habits,
increase their lifestyle, or pay for expenses already incurred. When managers and their
colleagues pay close attention to lifestyle symptoms resulting from these expenditures,
fraud can often be detected early. Most stolen funds are spent in conspicuous ways. Fraud
perpetrators usually buy automobiles, expensive clothes, or new homes; take extravagant
vacations; purchase expensive recreational toys, such as boats, condominiums, motor
homes, or airplanes; support extramarital relationships or outside business interests.
Close monitoring facilitates early detection. It also deters frauds because potential
perpetrators realize that “others are watching.” It is because monitoring by colleagues is
such an effective way to catch dishonest acts that Section 307 of the Sarbanes-Oxley Act
of 2002 requires all public companies to have a whistleblower system that makes it easy
for employees and others to report suspicious activities. In most cases of fraud we have
studied, individuals suspected or knew that fraud was occurring but were either afraid to
come forward with information or didn’t know how to reveal the information. The new
whistle-blowing laws should help in these cases.
Even with advances in technology, the most common way in which fraud is
detected is through tips. In one empirical study, for example, the authors found that 33
percent of all frauds were detected through tips, while only 18 percent were detected by
auditors. A company that experienced over 1,000 frauds in one year determined that 42
percent were discovered through tips and complaints from employees and customers. A
good whistle-blowing program is one of the most effective fraud prevention tools. When
employees know that colleagues have an easy, nonobligatory way to monitor each other
and report suspected fraud, they are more reluctant to become involved in dishonest acts.
Deloitte, one of the Big 4 CPA firms, in a worldwide study it conducted, concluded that
there were four reasons why some whistle-blowing systems fail in their attempts to detect
misconduct.
The fourth factor in eliminating fraud opportunities is creating an expectation that
dishonesty will be punished. As stated several times, one of the greatest deterrents to
dishonesty is fear of punishment. In today’s business and social environment, merely
being terminated is not meaningful punishment. Real punishment involves having to tell
family members and friends about the dishonest behavior. Fraud perpetrators are usually
first-time offenders who suffer tremendous embarrassment when they are forced to
inform their loved ones that they have committed fraud and been caught. When fraud
perpetrators are merely terminated, they usually give those close to them a morally
acceptable, but false, reason for the termination, such as, “the company laid me off,” “the
company is downsizing,” or “I just can’t stand working there any more.”
A strong prosecution policy that is well publicized lets employees know that
dishonest acts will be harshly punished, that not everyone is dishonest, and that
unauthorized borrowing from the company will not be tolerated. While investigation and
prosecution are often expensive and time consuming, and while pursuing legal action
stimulates concerns about unfavorable press coverage, not prosecuting is a cost-effective
strategy only in the short run. In the long run, failure to take legal action sends a message
to other employees that fraud is tolerated and that the worst thing that happens to
perpetrators is termination. Because of today’s privacy laws and high job turnover rates,
termination alone is not a strong fraud deterrent. Like a good code of ethics that conveys
expectations, a strong policy of punishment helps eliminate rationalizations. Some people
believe the reason there is so much fraud and white-collar crime is that perpetrators are
not usually punished and, when they are, the punishments are light.
Very few organizations actively audit for fraud. Rather, their auditors are content
to conduct financial, operational, and compliance audits and to investigate fraud only
when symptoms are so egregious that fraud is suspected. Organizations that proactively
audit for fraud create awareness among employees that employees’ actions are subject to
review at any time. By increasing the fear of getting caught, proactive auditing reduces
fraudulent behavior. One company, for example, decided to use proactive computer
auditing techniques to compare employees’ telephone numbers with vendors’ telephone
numbers. The search revealed 1,117 instances in which telephone numbers matched,
indicating that the company was purchasing goods and services from employees—a
direct conflict of interest.
Even CPA firms have become very serious about proactively auditing for fraud.
Part of this motivation comes from Statement on Auditing Standards (SAS) No. 99,
Consideration of Fraud in a Financial Statement Audit. SAS No. 99 includes sections
dealing with brainstorming the risks of fraud while emphasizing increased professional
skepticism; discussions with management and others as to whether or not they are aware
of fraud or fraud symptoms; the use of unpredictable audit tests; and responding to
management override of controls by requiring on every audit certain procedures
responsive to detecting management override. SAS No. 99 was issued because the
Auditing Standards Board [which has now been replaced by the Public Company
Accounting Oversight Board (PCAOB)] believes that by forcing auditors to explicitly
consider and brainstorm about fraud, the likelihood that auditors will detect material
misstatements due to fraud in a financial statement audit will be increased.
In addition to being more skeptical in their auditing of financial statements, large
CPA and other firms have developed dedicated units that specialize in proactively
detecting fraud. With advances in technology, the proactive detection of fraud is now
possible more than ever before. For now, you only need to know that proactive fraud
detection cannot only catch frauds that are occurring early, but it can also serve as a
powerful deterrent when employees and others know that an organization is always
searching for fraud that may be occurring.
d. A Comprehensive Approach to Fighting Fraud
Until now, this has focused only on preventing fraud. We will also combine
prevention with detection, investigation, and follow-up to consider a comprehensive
approach to fighting fraud. As mentioned earlier, the authors conducted a study that
involved surveying Fortune 500 companies about fraud. Questionnaires were sent to each
of the 500 companies, with instructions that the individual in the company who was most
responsible for fraud prevention should respond. Of the 242 responses, 62 percent (150
responses) came from directors of internal audit, 28 percent (67 responses) from directors
of corporate security, and 10 percent (25 responses) from personnel or human resource
directors. Many respondents wrote that their organization had no one person who was
“most responsible for fraud prevention,” but that they personally were taking
responsibility for completing the questionnaire.
The diversity in the job titles of respondents, combined with comments that no
one in the organization was primarily responsible for preventing fraud, is a discouraging
commentary on the status of fraud prevention in the United States. Fraud is an extremely
costly problem for organizations. Yet, responsibility for fraud in an organization is often
seen as belonging to “someone else.” Independent auditors maintain they can’t detect
fraud because it isn’t their responsibility and because their materiality levels are too
high.10 Internal auditors usually stress that their functions are to evaluate controls and to
improve operational efficiency. If they happen to find fraud, they’ll pursue or report it,
but fraud prevention and detection isn’t their primary responsibility. Corporate security
officers, in most organizations, believe that theirs is an investigative role and that they
will pursue reported frauds. They don’t envision their role as including prevention or
detection. Managers usually perceive running the business as their responsibility and
seldom even acknowledge the possibility that fraud could occur in their organization.
Fraud, to them, is something that happens in “other organizations.” Further, they don’t
know how to handle fraud situations that do occur. Employees who are usually in the best
position to prevent and detect fraud often don’t know what to do or whom to talk to when
they have suspicions, and they also often feel that it is unethical or unwise to blow the
whistle or report colleagues. Because this “non-ownership” attitude regarding fraud is
prevalent in most businesses, frauds like the one described below will continue to occur.
Jerry Watkins had been working for Ackroyd Airlines for 17 years. During this
time, he held several positions in accounting, finance, and purchasing. Jerry was the
father of three children, two boys and one girl. Over the years, Jerry and his family had
been active in the community and in their church. Jerry coached both Little League
baseball and football. He and his wife, Jill, both had college degrees, both worked full
time, and both had a long-term goal of sending their children to college. Despite their
plans for college, each year the Watkins spent most of what they made and saved very
little for college tuition and other expenses.
After Jerry had been working at Ackroyd for 15 years, Steve (Jerry and Jill’s
oldest son) attended college at a well-known Ivy League university. He performed well,
and both Jerry and Jill were proud of Steve’s and their other children’s accomplishments.
Approximately a year later, Jerry, who handled all the family finances, realized they
could no longer pay Steve’s college expenses, let alone pay future college expenses for
their other two children. Jerry, a proud man, could not bring himself to admit his financial
inadequacy to his family. He already had a large mortgage and several credit card and
other debts, and he knew he could not borrow the money needed for college.
Because of his financial predicament, Jerry decided to embezzle money from
Ackroyd Airlines. He had heard of several other thefts in the company, and none of the
perpetrators had been prosecuted. In fact, the frauds that he knew about had resulted in
the company merely transferring the employees. In addition, Jerry rationalized that he
would pay the money back in the future. In his current position as purchasing manager,
he found it easy to take kickbacks from a vendor who had previously approached him
with favors to get business. At first, Jerry took only small amounts. As the kickbacks
proceeded, however, he found that he increasingly relied on the extra money to meet all
kinds of financial “needs” in addition to college expenses. He felt guilty about the
kickbacks but knew that the company auditors never thought about fraud as a possibility.
Anyway, he felt the company would understand if they knew how badly he needed the
money. Significant good was coming from his “borrowing.” His children were getting an
education they could otherwise not have afforded, and Ackroyd didn’t really miss the
money. Because of his pressure, his opportunity, his rationalization, and Ackroyd’s
inattention to fraud prevention and detection, the company’s honest employee of 17 years
stole several hundred thousand dollars.
What is alarming is that Jerry’s case is not unusual. Jerry had never signed a code
of conduct. Ackroyd’s auditors had never proactively searched for fraud. The company
didn’t have an EAP to help employees with financial and other needs. Furthermore, as
Jerry was well aware, the company had never taken actions harsher than terminating
previous fraud offenders.
e. Organizations and Fraud – The Current Model
The prevalence of fraud within organizations, coupled with a lack of proactive
measures to address it, underscores the need for a fundamental shift in approach towards
fraud prevention and detection. Ackroyd Airlines serves as a poignant example of how
many organizations fail to prioritize fraud prevention, leading to confusion and ambiguity
regarding the responsibilities for detecting, preventing, and investigating fraudulent
behavior. In dissecting the shortcomings of the current model employed by most
organizations, it becomes evident that a more robust and integrated approach is necessary
to effectively combat fraud.
At the heart of the issue lies a pervasive lack of emphasis on fraud prevention
within many companies. All too often, organizations adopt a reactive stance towards
fraud, only addressing it after the damage has already been done. This reactive mindset
not only leaves organizations vulnerable to financial losses and reputational damage but
also fosters a culture of complacency where fraudulent behavior may go unchecked.
Moreover, the absence of a clearly defined framework for dealing with fraud exacerbates
the problem, leading to confusion and uncertainty regarding who holds responsibility for
addressing it. In many cases, the task of fraud detection, prevention, and investigation is
relegated to disparate departments or individuals within the organization, resulting in
fragmented efforts and ineffective outcomes. Without a cohesive strategy and designated
oversight, critical red flags may be overlooked, allowing fraudulent activities to persist
undetected.
The current model employed by most organizations often operates by default
rather than design, with little coordination or collaboration among key stakeholders. This
fragmented approach not only hampers the effectiveness of fraud prevention efforts but
also impedes the timely detection and investigation of fraudulent activities. Furthermore,
the lack of accountability and clear lines of responsibility further compounds the
problem, leaving organizations vulnerable to exploitation by opportunistic fraudsters.
To address these challenges, organizations must adopt a more proactive and
integrated approach to fraud prevention and detection. This entails establishing a
comprehensive fraud risk management framework that encompasses prevention,
detection, and investigation efforts across all levels of the organization.
By adopting a proactive and integrated approach to fraud prevention and
detection, organizations can effectively mitigate the risk of fraud and safeguard their
assets, reputation, and stakeholders' trust. However, achieving this goal requires a
concerted effort from senior management, employees, and key stakeholders across the
organization to prioritize fraud prevention and create a culture of vigilance and integrity.
The model delineating the stages of addressing fraud incidents within an organization
underscores the critical need for a more proactive and comprehensive approach to fraud
prevention. Stage 1, characterized by the occurrence of a fraud incident without prior
formal awareness training or preventive measures, highlights the reactive nature of many
organizations' responses to fraudulent activities. However, the ensuing crisis mode
presents an opportunity for organizations to reassess their strategies and implement
proactive measures to prevent future occurrences and mitigate the impact of fraudulent
incidents.
Expanding upon Stage 1, it becomes apparent that the reactive response to a fraud
incident is often driven by a myriad of factors, including the urgent need to identify the
perpetrator, mitigate financial losses, and safeguard the organization's reputation. The
lack of formal awareness training or preventive measures prior to the occurrence of the
fraud incident underscores the importance of investing in robust fraud prevention
programs and proactive risk management strategies.
Upon entering crisis mode, organizations may find themselves grappling with a
myriad of challenges, including the need to navigate legal and regulatory implications,
manage stakeholder perceptions, and restore trust and confidence in the organization's
integrity. The emotional toll of the crisis further complicates matters, as employees may
experience feelings of betrayal, mistrust, and uncertainty, further exacerbating the
organization's challenges in effectively addressing the fraud incident.
Expanding upon Stage 2, the investigation phase represents a critical juncture in
the organization's response to fraud incidents. Upon discovering fraudulent activities,
security and internal audit teams typically become involved, tasked with conducting
thorough investigations to uncover the extent of the fraud, identify the perpetrators, and
gather evidence for potential legal action. This phase often entails a meticulous process of
interviewing employees, examining documents, and conducting forensic analyses to
piece together the sequence of events leading to the fraud incident.
However, it's essential to acknowledge that the investigative process can be
fraught with challenges and complexities. Depending on the scope and scale of the fraud
incident, investigations may require extensive time, resources, and expertise to reach a
resolution. Moreover, the cost associated with investigations can vary significantly,
particularly in cases involving sophisticated schemes or widespread fraud across multiple
departments or locations.
Furthermore, the outcomes of the investigation are not always straightforward. In
some instances, investigations may fail to conclusively identify the perpetrators or
uncover sufficient evidence to support legal action. This can be particularly challenging
when dealing with sophisticated fraud schemes or when perpetrators have taken measures
to conceal their activities.
Transitioning to Stage 3, after the investigation has been completed, the
organization must grapple with the decision of how to proceed regarding the perpetrators
of the fraud. This decision-making process is multifaceted and may involve weighing
various factors, including the severity of the fraud, the extent of the financial losses
incurred, legal considerations, and the organization's internal policies and procedures.
Expanding upon Stage 4, the final phase of addressing fraud incidents within
organizations involves closing the file and implementing measures to prevent future
occurrences. This stage is crucial for tying together loose ends, replacing the employee
involved in the fraud (which often incurs additional costs), and resolving any lingering
issues resulting from the fraudulent activity. However, it's important to recognize that
simply closing the file and addressing the immediate aftermath of the fraud incident is
insufficient in effectively combating fraud in the long term.
Indeed, the cyclical nature of fraud highlights the inherent limitations of the
reactive model depicted in the four stages outlined. By only responding to fraud incidents
as they occur and taking corrective action without addressing underlying vulnerabilities
or implementing proactive preventive measures, organizations perpetuate a cycle of fraud
that is bound to recur.
Under this model, fraud incidents are treated as isolated events, with little
consideration given to the systemic weaknesses or cultural factors that may contribute to
their occurrence. Without addressing the root causes of fraud and implementing measures
to strengthen controls and foster a culture of integrity and accountability, organizations
remain susceptible to future incidents.
This approach involves a holistic and integrated strategy aimed at addressing
fraud risks at every stage of the fraud lifecycle, from prevention and detection to
investigation and response. Indeed, establishing a positive "tone at the top" is paramount
in any effective fraud-fighting model. This foundational element serves as the
cornerstone for fostering a culture of integrity, accountability, and ethical conduct
throughout the organization. Expanding upon this critical component involves delving
deeper into the multifaceted strategies and practices that contribute to setting a positive
tone at the top and cultivating a culture of fraud awareness and prevention.
First and foremost, effective fraud teaching and training initiatives must be
conducted throughout the organization to ensure that all employees understand the
importance of ethical behavior and their role in preventing fraud. This involves
implementing comprehensive training programs that educate employees about the various
forms of fraud, the red flags to watch out for, and the procedures for reporting suspected
fraudulent activities. By empowering employees with the knowledge and skills to
recognize and address fraud, organizations can create a vigilant and proactive workforce
that serves as the first line of defense against fraudulent behavior.
Moreover, promoting a well-defined corporate code of conduct is essential in
reinforcing the organization's commitment to ethical principles and guiding employees'
behavior. The code of conduct should clearly articulate the organization's values,
expectations, and standards of behavior, including prohibitions against fraud, dishonesty,
and unethical conduct. By providing employees with a clear framework for ethical
decision-making and behavior, organizations can establish a strong ethical foundation
that permeates throughout the organization.
Setting a proper example and modeling appropriate management behavior is
equally crucial in shaping the organization's culture and fostering a positive tone at the
top. Leaders and executives must lead by example, demonstrating their commitment to
ethical conduct and adherence to the organization's code of conduct in their actions and
decisions. This entails acting with integrity, transparency, and accountability in all
aspects of their roles and responsibilities, thereby setting a precedent for ethical behavior
that cascades throughout the organization.
Furthermore, management and the board of directors play a pivotal role in
establishing accountability mechanisms and reinforcing the consequences of unethical
behavior. This may involve implementing robust internal controls, monitoring
mechanisms, and oversight processes to detect and deter fraudulent activities.
Additionally, holding individuals accountable for their actions, regardless of their
position or seniority within the organization, sends a clear message that unethical
behavior will not be tolerated and will be met with swift and decisive consequences.
In summary, setting a positive tone at the top requires a multifaceted approach
that encompasses effective fraud teaching and training, promoting a well-defined
corporate code of conduct, modeling appropriate management behavior, and establishing
accountability mechanisms. By prioritizing these elements, organizations can create a
culture of integrity, transparency, and accountability that serves as a powerful deterrent
against fraudulent behavior and fosters trust and confidence among employees,
stakeholders, and the broader community.
When the management of one company changed its attitude from “we want to
know when someone who commits fraud is prosecuted” to “we want to know when
someone who commits fraud isn’t prosecuted” and made fraud against the company,
along with safety, discrimination, and substance abuse, significant issues in the
organization, the number and size of frauds decreased substantially. Likewise, top
management cannot accept expensive perks and gifts from vendors and others and not
expect employees to do the same.
The second element in this fraud-fighting model is educating employees and
others about the seriousness of fraud and informing them what to do if fraud is suspected.
As we have repeatedly said, it is fraud prevention, not detection or investigation, that
results in big savings. Therefore, significant attention should be given to instituting
proactive fraud education initiatives, rather than to dealing with losses that have already
occurred. Fraud awareness training helps to prevent fraud and ensure that frauds that do
occur are detected at early stages, thus limiting financial exposure to the corporation and
minimizing the negative impact on the work environment. Education includes instructing
vendors and other outsiders, not just employees, about the organization’s expectations.
The third fraud-fighting element involves integrity risk assessment and having a
good internal control system. We have already discussed internal controls. It is important
to note that having a good system of controls means that there will be an explicit study of
all frauds and why they occurred, together with implementation of control activities
necessary to prevent future occurrences of the same types of frauds in the future.
Analysis of frauds involves determinations by people in management, audit,
security, human resources, control, and finance of why and how the fraud occurred. The
focus is on the individuals who were involved, the controls that were compromised or
absent, the environment that facilitated the fraud, and related factors. This step is
important in understanding the kinds of preventive measures that are needed within the
environment in which the fraud occurred. An appropriate preventive solution does not
take long to be developed, once all the parties work together to resolve the problems.
Obviously, additional or new controls must meet the cost-effectiveness test and may not
be implemented. The decision not to implement, however, should be based on an analysis
of costs and benefits. They should not be made by default because the proper analysis
was not conducted.
The fourth element includes having a system of reporting and monitoring. Fraud
reporting must be facilitated. With murder, bank robbery, or assault, there is usually no
question about whether a crime has been committed. Fraud, however, is a subtle crime,
for which there are usually no obvious signs. Only fraud symptoms or red flags are
observed. Because hotlines or other reporting systems often don’t exist, employees rarely
volunteer information about possible fraud symptoms. This lack of reporting is
unfortunate, because employees are in the best position to recognize dishonest behavior
or to question red flags with which they are more familiar than anyone else. Monitoring
involves having internal auditors, external auditors, and even management performing
audits and reviews. Employees and vendors who know that an effective monitoring and
reporting system is in place are much less likely to commit fraud than are individuals
who work in high fraud environments. Effective prevention of fraud usually involves
efforts to create in the minds of potential perpetrators that their activities will be
uncovered. For prevention purposes, it doesn’t really matter whether a perpetrator
actually will be caught, but rather only whether he or she thinks they will.
Reporting also involves publishing facts about the fraud to those who can benefit
from the information. Publication does not mean making sure the case and all its
accompanying details are in local newspapers. Indeed, until there is a conviction, such
publication is ill-advised, because it can lead to slander or libel suits. Rather, what
“publication” means in this context is depersonalizing the case (that is, disguising the
identities of the perpetrators and other people involved) and publishing it internally in a
security newsletter or a memo that is distributed to auditors, security personnel, and
appropriate management and employees. Even generic publication of fraud has a
tremendous impact, because it helps readers understand that fraud happens in their own
organization and is not just a horrible nightmare that occurs elsewhere.
The fifth element of a good fraud-fighting system involves having proactive fraud
detection methods in place. No matter how good fraud prevention efforts are, some
frauds will still be committed. And, since frauds grow geometrically over time, it is
important to detect frauds early. Proactive fraud detection methods, are not only effective
in detecting fraud, but knowledge of their use is a good fraud deterrent.
The final element involves having effective investigation and follow-up when
fraud occurs. Effective investigation means an organization will have prespecified formal
fraud policies stating who will carry out all elements of an investigation. The
investigation procedures must be well established, including (a) who will conduct the
investigation; (b) how the matter will be communicated to management; (c) whether and
when law enforcement officials will be contacted; (d) who will determine the scope of
investigation; (e) who will determine the investigation methods; (f) who will follow up
on tips of suspected fraud; (g) who will conduct interviews, review documents, and
perform other investigation steps; and (h) who will ultimately determine the corporate
response to fraud, disciplines, control, and so on. This stage also involves having preset
policies regarding follow-up actions against perpetrators.
Taking no action should not even be a possibility; rather, whenever possible,
fraud perpetrators should be prosecuted. A strong prosecution policy must have the
support of top managers, and they must be informed if someone commits fraud and is not
prosecuted. Gone are the days when prosecution resulted in bad publicity. Most people
now realize that fraud exists in every organization. They also realize that organizations
that take a tough prosecution stance will reduce the number of future frauds significantly
and will ultimately be more profitable because of the deterrent effect of prosecution. As
stated previously, the single greatest factor in deterring dishonest acts is the fear of
punishment. Companies with successful prosecution policies have developed their own
internal investigation experts. They recognize that in order to obtain cooperation from
law enforcement officers and the justice system, it is almost always necessary to conduct
a thorough and complete investigation (usually including obtaining a signed confession)
before the overworked law enforcement agencies and criminal justice systems can
accommodate the prosecution.
Students also viewed