1 / 28100%
Module 3
Fraud Detection
a. Symptoms of Fraud
A person’s lifestyle may change, a document may be missing, a general ledger
may be out of balance, someone may act suspiciously, a change in an analytical
relationship may not make sense, or someone may provide a tip that fraud is occurring.
Unlike videos in robbery or bodies in a murder, however, these factors are only
symptoms rather than conclusive proof of fraud. There may be other explanations for the
existence of these symptoms. Lifestyle changes may have occurred because of inherited
money. Documents may have been legitimately lost. The general ledger may be out of
balance because of an unintentional accounting error. Suspicious actions may be caused
by family dissension or personal problems. Unexplained analytical relationships may be
the result of unrecognized changes in underlying economic factors. A tip may be
motivated by an envious or disgruntled employee’s grudge or by someone outside the
company desiring to settle a score.
To detect fraud, managers, auditors, employees, and examiners must recognize
these fraud indicators or symptoms (sometimes called red flags) and investigate whether
the symptoms resulted from actual fraud or were caused by other factors. Unfortunately,
many fraud symptoms go unnoticed, and even symptoms that are recognized are often not
vigorously pursued. Many frauds could be detected earlier if fraud symptoms were
investigated. Accounting anomalies result from unusual processes or procedures in the
accounting system. Several accounting anomalies resulted from the Elgin Aircraft fraud.
The fraudulent claims forms from the 22 phony doctors originated from two locations.
One was a post office box, and the other was a business located in a nearby city that was
owned by the manager’s husband. The checks being paid to the 22 doctors were sent to
the same two common addresses. Checks were deposited in the same two bank accounts
and contained handwritten rather than stamped endorsements.
A major difference between financial statement auditors and fraud examiners is
that most financial statement auditors merely match documents to see whether support
exists and is adequate. Auditors and examiners who detect fraud go beyond ascertaining
the mere existence of documents to determine whether the documents are authentic or
fraudulent, whether the expenditures make sense, and whether all aspects of the
documentation are in order. Significant internal control weaknesses were ignored by the
Elgin Aircraft auditors. First, the claims payment department manager had not taken a
vacation in 10 years. Second, employees of Elgin Aircraft never received payment
confirmation so they could determine whether the medical claims being paid on their
behalf were incurred by them. Third, payments to new doctors were never investigated or
cleared by the company.
Allowing employees—especially those in accounting— to forfeit use of their
vacation time is a control weakness that must always be questioned. Implementing a
system of independent checks is one of the most effective ways to deter fraud. Employee
transfers, audits, and mandatory vacations are various ways of providing independent
checks on employees. The Office of the Controller of the Currency requires all bank
employees in the United States to take at least one week of consecutive vacation days
each year. Many frauds come to light when employees are on vacation and cannot cover
their tracks. In Elgin’s case, if another employee had made payments during the
manager’s absence, the common addresses or the payments being made to a business may
have been recognized.
Not confirming payments made to employees is also a serious control weakness.
In Elgin’s case, doctors were paid for hysterectomies, tonsillectomies, gallbladder
surgeries, and other procedures that were never performed. If employees were aware that
payments were made for these fabricated services, they probably would have complained
and the fraud scheme would have been discovered much sooner. Unfortunately, even if
an auditor or manager discovered the internal control weaknesses, they may still not have
uncovered the fraud. Most likely, they would have recommended that the weaknesses be
fixed without giving thought to the possibility that the weaknesses might have been
exploited. A major difference between an auditor who uncovers fraud and one who does
not is that the first auditor not only fixes a control weakness, but he or she also
immediately enlists procedures to determine whether the weakness has been exploited.
The second auditor merely fixes the control weakness without investigating possible
exploitation of the weakness.
Before doctors were cleared for payment, some form of background check should
have been conducted to determine whether the doctors were legitimate. Just as Dun &
Bradstreet checks should be performed on companies with which business is conducted,
the validity of a doctor who is requesting payment should be verified by checking
resources such as state licensing boards, medical groups, or phone listings.
Analytical anomalies are relationships in financial or nonfinancial data that do not
make sense, such as an unreasonable change in a volume, mix, or price. In the Elgin
Aircraft case, several analytical symptoms should have alerted others to the fraud. The
sheer volume of insurance work performed by the 22 fictitious doctors was very high.
Why would $12 million be paid to only 22 doctors over a period of four years? None of
the phony doctors were licensed by the state, yet payments to them exceeded payments to
almost all other doctors. Another analytical symptom was that there were no other
payments to any of the dummy doctors by outside insurance companies. In other words,
none of the payments to these doctors were for employees who incurred over $50,000 of
medical expenses in any year. Finally, the company’s medical costs increased
significantly (29 percent) during the four years of the fraud.
Several lifestyle symptoms at Elgin Aircraft, such as taking the employees to
lunch in a limousine, should have been recognized. The Defense Department auditor was
told that the manager paid for the limousine from personal funds and that she was
independently wealthy. She claimed that she had inherited a large sum of money from her
husband’s parents. Those who worked with her knew that she lived in a very expensive
house, drove luxury cars, and wore expensive clothes and jewelry. However, apparently
nobody wondered why she worked and never took a vacation. While wealthy people may
be employed because they love their work, rarely is their love so great that they never
take a vacation.
Several behavioral symptoms also should have alerted others that something was
wrong. Employees in the department regularly joked that their manager had a “Dr. Jekyll
and Mrs. Hyde” personality. Sometimes she was the nicest person to be around, and other
times she would have periods of unexplained anger. Interviews with employees revealed
that her highs and lows had become more intense and more frequent in recent months.
With the Elgin Aircraft fraud, there were no tips or complaints. No employees
who felt that something was wrong came forward, and other doctors were still getting all
the legitimate business. They had no reason to complain. Indeed, the only party really
being hurt was Elgin Aircraft. The Elgin Aircraft fraud was discovered because an
observant auditor noticed a fraud symptom.
b. Accounting Anomalies
In the first case, an alert internal auditor detected a fraud while examining the
purchase of new equipment. Further investigation revealed a large, collusive fraud. A thin
line running through a photocopied letter in a vendor invoice file alerted the auditor to
probe further. The photocopied letter was from a manufacturer who suggested the repair
of machinery parts as a less costly alternative to replacement, which was also set forth in
the letter. By cutting out the paragraph pertaining to the repair, the purchase of new
machinery appeared justified.
A second fraud was detected by recognizing an increase in past-due accounts
from customers. This fraud was committed against one of the largest Fortune 500
companies in the United States. Mark Rogers was the accounts receivable department
manager at XYZ Foods. In his position, he developed a close relationship with one of the
company’s largest customers and used the relationship to defraud his employer. In return
for a kickback, he offered to “manage” his company’s receivable from the customer. In
doing so, Mark permitted the customer to pay later than would otherwise have been
required. The customer’s payable was not recognized as delinquent or past due. Because
the receivable involved millions of dollars, paying 30 to 60 days later than was required
cost Mark’s employer $3 million in lost interest. Mark received kickbacks totaling
$350,000 from the customer. Mark’s fraud was discovered when an alert coworker
realized that the company’s accounts receivable turnover ratio was decreasing
substantially. The coworker prepared an aging schedule of individual accounts receivable
balances that identified the customer as the source of the problem. A subsequent
investigation revealed the kickback scheme.
A third fraud was discovered because of excessive credit memos. The case
involved a fraud of over $5,000 by a supervisor in the shipping department of a
wholesale-retail distribution center warehouse facility. The supervisor was responsible
for the overall operations of the warehouse and had individual accountability for a cash
fund that was used for collecting money (usually under $500) from customers who came
to the warehouse to pick up cashon-delivery orders. The established procedures called for
the supervisor to issue the customer a cash receipt, which was recorded in a will-call
delivery logbook. The file containing details on the customer order would eventually be
matched with cash receipts by accounting personnel, and the transaction would be closed.
Over approximately one year, the supervisor defrauded the company by stealing small
amounts of money. He attempted to conceal the fraud by submitting credit memos (with
statements such as “billed to the wrong account,” “to correct billing adjustment,” or
“miscellaneous”) to clear the accounts receivable file. The accounts would be matched
with the credit memo, and the transaction would be closed. A second signature was not
needed on the credit memos, and accounting personnel asked no questions about credit
memos originated by the supervisor of the warehouse.
At first, the supervisor submitted only two to three fraudulent credit memos a
week, totaling approximately $100. After a few months, however, he increased the
amount of his theft to about $300 per week. To give the appearance of randomness, so as
to keep the accounting personnel from becoming suspicious, the supervisor intermixed
small credit memo amounts with large ones. The fraud surfaced when the supervisor
accidentally credited the wrong customer’s account for a cash transaction. By
coincidence, the supervisor was on vacation when the customer complained and was not
available to cover his tracks when accounting personnel investigated the transaction.
Because of his absence, the accounts receivable clerk questioned the manager of the
warehouse who investigated the problem. The manager examined the cash receipts and
determined that fraud had occurred.
In the English language, this entry says, “An attorney was paid $5,000 in cash.” In
the language of accounting, this entry says, “Debit Legal Expense; credit Cash.” A person
who speaks both accounting and English will realize that these statements say exactly the
same thing. The problem with the language of accounting is that it can be manipulated to
tell a lie, just as can English or Japanese or any other language. For example, with the
above entry, how do you know that an attorney was actually paid $5,000? Instead, maybe
an employee embezzled $5,000 in cash and attempted to conceal the fraud by labeling the
theft as a legal expense. Smart embezzlers sometimes conceal their actions in exactly this
way, realizing that the fraudulent legal expense will be closed to Retained Earnings at the
end of the accounting period, making the audit trail difficult to follow. And, if the
fraudulent employer routinely pays large amounts of legal expenses, this small fraud
could easily go unnoticed. To understand whether journal entries represent truth or are
fictitious, one must learn to recognize journal entry fraud symptoms.
An embezzler usually steals assets, such as cash or inventory. (No one steals
liabilities!) To conceal the theft, the embezzler must find a way to decrease either the
liabilities or the equities of the victim organization. Otherwise, the accounting records
will not balance, and the embezzler will be quickly detected. Smart embezzlers
understand that decreasing liabilities is not a good concealment method. In reducing
payables, amounts owed are eliminated from the books. This manipulation of the
accounting records will be recognized when vendors do not receive payments for
amounts owed to them. When the liability becomes delinquent, they will notify the
company. Subsequent investigation will usually reveal the fraud.
Smart embezzlers also realize that most equity accounts should not be altered.
The owners’ equity balance is decreased by the payment of dividends and expenses and is
increased by sales of stock and by revenues. Embezzlers rarely conceal their frauds by
manipulating either dividends or stock accounts because these accounts have relatively
few transactions and alterations can be quickly noticed. In addition, transactions
involving stocks or dividends usually require board of director approval, go through a
transfer agent, and are monitored closely. Thus, income statement accounts such as
revenues and expenses remain as possible accounts for decreasing the right side of the
accounting equation and making the accounting records balance when stealing an asset.
Balancing the equation by manipulating revenues would require that individual revenue
accounts be reduced. However, since revenues rarely decrease (except through adjusting
entries at the end of an accounting period), a decrease in a revenue account would draw
attention. Therefore, embezzlers who manipulate accounting records to conceal their
frauds usually attempt to balance the accounting equation by increasing expenses.
Increasing expenses decreases net income, which decreases retained earnings and
owners’ equity, thus leaving the accounting equation in balance.
Recording an expense to conceal fraud involves making a fictitious journal entry.
Fraud examiners must be able to recognize signals that a journal entry may have been
manufactured to conceal a fraud. Manipulating expense accounts also has the advantage
that expenses are closed or brought to zero balances at year-end, thus obscuring the audit
trail.
John Doe was the controller of a small bank. Over a period of several years, he
embezzled approximately $150,000 from his employer by telephoning larger banks and
having them pay his personal credit card bills. He concealed his fraud by creating
fictitious journal entries to recognize the shortages as advertising expense. Because the
total advertising expense was large and the increase in expense resulting from his fraud
was relatively small, no one ever questioned his journal entries. Because he was the
bank’s controller and in charge of accounting, he did not even forge fictitious
documentation to support the entries. He was caught when he deposited a duplicate
$10,000 payment from one of the bank’s customers in his personal bank account. When
the customer realized he paid twice, he asked for a refund, and the deposit was traced to
John’s account.
The definition of a ledger is “a book of accounts.” In other words, all transactions
related to specific accounts, such as cash or inventory, are summarized in the ledger. The
accuracy of account balances in the ledger is often proved by ensuring that the total of all
asset accounts equals the total of all liability and equity accounts or, if revenues and
expenses have not yet been closed out, that the total of all debit balances equals the total
of all credit balances. Many frauds involve manipulating receivables from customers or
payables to vendors. Most companies have master (control) receivable and payable
accounts, the total of which should equal the sum of all the individual customer and
vendor account balances.
The first symptom is indicative of a fraud in which cover-up in the accounting
records is incomplete. For example, a perpetrator may embezzle inventory (an asset) but
not reflect the reduction of inventory in the accounting records. In this case, the actual
inventory balance, as determined by a physical count, is lower than the recorded amount
of inventory, and the ledger does not balance. Another example of a ledger out of balance
is the theft of cash accompanied by the failure to record an expense. In this case, total
assets would be less than total liabilities plus owners’ equity. The second ledger symptom
is indicative of manipulation of an individual customer’s or vendor’s balance without
altering the master receivable or payable account in the ledger. In this case, the sum of
the individual customer or vendor balances does not agree with the master account
balance. The following example shows how this second ledger symptom revealed a fraud
that was perpetrated by the bookkeeper of a small bank.
Using the following schemes, she embezzled over $3 million from the bank,
which had only $30 million in assets. (Note: The Federal Reserve is the “bankers’ bank”;
that is, every bank has one or more accounts at the Federal Reserve. When a check drawn
on one bank is sent to the Federal Reserve by a different bank, the Federal Reserve
increases the account of the depositing bank and decreases the account of the bank on
which the check was drawn. The Federal Reserve then accumulates all checks drawn on a
given bank and sends them back to that bank in what’s called the incoming cash letter.
All checks are drawn on different banks and sent to the Federal Reserve for credit in what
is called the outgoing cash letter.)
Using two different schemes, Marjorie defrauded First National Bank of Atlanta
of over $3 million. Her first scheme involved writing personal checks on her bank
account at First National to pay for art, jewelry, automobiles, home furnishings, and other
expensive acquisitions. Then, when her check was sent from the Federal Reserve to the
bank (in the incoming cash letter), she would allow the overall demand deposit account
balance to be reduced but would pull her checks before they could be processed and
deducted from her personal account.
The result of this scheme was that the master demand deposit account balance
was lower than the sum of the bank’s individual customers’ demand deposits. The second
scheme involved making deposits into her account by using checks drawn on other banks
and then pulling the checks before they were sent in the outgoing cash letter to the
Federal Reserve. Thus, her checks were never deducted from her accounts at the other
banks. In fact, her accounts at the banks did not contain sufficient funds to cover the
checks if they had been processed. The result of this scheme was that the individual
demand deposit balances increased, but the master demand deposit account balance did
not.
Both of these schemes had the effect of making the master demand deposit
account balances lower than the sum of the individual account balances. Over time, as
Marjorie wrote checks and made fictitious deposits, the difference between the sum of the
individual accounts and the master account balances became larger and larger. At the end
of each accounting period, to cover her tracks and prevent the auditors from discovering
the fraud, Marjorie would pull some official bank checks (cashier’s checks) that had
previously been used and send them in the outgoing cash letter to the Federal Reserve.
Because the Federal Reserve procedures were automated, no one ever personally
examined the checks or noticed that they had already been processed several times. In
fact, some of the checks were totally black from being processed so many times. Her
fraud was assisted by the Federal Reserve’s policy of giving immediate credit to First
National for the total amount supposedly contained in the outgoing cash letter. The next
day, as the checks were processed using bank routing numbers, the Federal Reserve
would realize that the official checks were not drawn on other banks but were really First
National’s own checks and would reverse the credit previously given to First National.
The reduction would again throw First National’s ledger accounts out of balance. But, for
one day—the day the auditors examined the records—the bank’s books would be
balanced and the shortage would be “parked” at the Federal Reserve. Because the
financial statements were prepared for that one day, the bank records balanced for the
auditors and the Federal Reserve confirmed the misstated receivable from them as being
correct.
This fraud could easily have been discovered if someone had noticed that,
although the books balanced at month-end, they were out of balance during the rest of the
month. Bank managers received daily reports that showed balances significantly different
from the balances on the financial statements. They never questioned these unusual
balances. This fraud could also have been uncovered if someone had recognized many
other control weaknesses and other symptoms. For example, Marjorie had significant
personality conflicts with other employees, and she lived a lifestyle far beyond what her
income would support. In addition, individual accounting records had been altered, and a
previous fraud at the same bank had indicated a need for reports and procedures that, if
implemented, would have made the fraud impossible. Surprisingly, the fraud was not
discovered until a cashier’s check that Marjorie had reused several times was kicked out
of a Federal Reserve sorter because it could not be read.
c. Internal Control Weakness
Three examples of control weaknesses that allowed fraud to occur are discussed
in the following text. In the first, a control weakness allowed a customer to defraud a
bank of over $500,000. In the second, a significant internal control weakness allowed a
fraud to continue over several years.
Lorraine was a customer of Second National Bank. She opened her account 16
months previously, and she often made deposits and withdrawals in the hundreds of
thousands of dollars. She claimed to be a member of a wellknown, wealthy family. She
drove a Porsche, dressed very nicely, and was able to earn the trust and confidence of the
bank’s branch manager. One day, she approached the manager and said that she needed a
cashier’s check for $525,000. The manager, realizing that Lorraine had only $13,000 in
her account, denied the request. Then, deciding that Lorraine was a valued customer, and
based on Lorraine’s promise to cover the shortage the next day, the manager gave
Lorraine the cashier’s check. It turned out that Lorraine was not who she claimed to be.
In fact, she was an embezzler who had stolen over $5 million from her employer; all the
funds that had gone through her bank account were stolen. Her employer had caught her
and promised not to seek prosecution if she would repay the company. She was stealing
from Second National to repay the money.
As it turned out, Second National had a control requiring two signatures on all
cashier’s checks exceeding $500,000. However, the bank manager, who was an
imposing, had “ordered” his assistant to sign the cashier’s check. Without making an
independent decision and because the manager told him to sign, the assistant had merely
followed the manager’s order without questioning the appropriateness of the request. As
a result, the control requiring two independent signatures was compromised. There were
two signatures, but they were not independent. Both the assistant and the manager were
quickly terminated, and the assistant wished he had made an independent, informed
decision.
The second example of an internal control weakness fraud is the famous
Hochfelder case. This fraud went to the U.S. Supreme Court before it was decided that
Ernst & Ernst (now Ernst & Young), a large public accounting firm, had not been
negligent in performing an audit.
Leston Nay, the president of First Securities Co. of Chicago, fraudulently
convinced certain customers to invest funds in escrow accounts that he represented would
yield a high return. There were no escrow accounts. Nay converted the customers’ funds
to his own use. The transactions were not in the usual form of dealings between First
Securities and its customers. First, all correspondence with customers was done solely by
Nay. Because of a “mail rule” that Nay imposed, such mail was opened only by him.
Second, checks of the customers were made payable to Nay. Third, the escrow accounts
were not reflected on the books of First Securities, nor in filings with the SEC, nor in
connection with customers’ other investment accounts. The fraud was uncovered only
after Nay’s suicide.
Respondent customers sued in district court for damages against Ernst & Ernst as
assisting in the fraud under Section 10b-5 of the 1933 SEC Act. They alleged that Ernst
& Ernst had failed to conduct a proper audit, which would have led them to discover the
mail rule and the fraud. The court reasoned that Ernst & Ernst had a common-law and
statutory duty of inquiry into the adequacy of First Securities’ internal control system,
because the firm had contracted to audit First Securities and to review the annual report
filings with the SEC.
The U.S. Supreme Court reversed the decision of the court of appeals, concluding
that the interpretation of Section 10b-5 required the “intent to deceive, manipulate or
defraud.” Justice Powell wrote, in the Supreme Court’s opinion: “When a statute speaks
so specifically in terms of manipulation and deception, and of implementing devices and
contrivances—the commonly understood terminology of intentional wrongdoing—and
when its history reflects no more expansive intent, we are quite unwilling to extend the
scope of the statute to negligent conduct.” The Supreme Court pointed out that in certain
areas of the law, recklessness is considered to be a form of intentional conduct for
purposes of imposing liability.
In this case, the mail rule that required that no one except Leston Nay open the
mail was an internal control weakness. Had this weakness not been allowed, Nay’s fraud
would probably have been revealed much earlier and investors would not have lost so
much money.
The third case is a very simple one. A few years ago, one of the authors of this
text had a new home built by a building contractor. Shortly after the home was finished,
the author received a call from the builder whom he had now come to know quite well.
The building contractor told the author that his secretary/bookkeeper had stolen over
$10,000 and he had caught her. When asked how she did it, the builder replied that “she
both wrote checks and reconciled the bank statement.” To steal the money, she had
simply written checks to herself and then listed the checks as “outstanding” on the bank
reconciliation. The builder had caught her when he had to submit bank statements to a
lender for a loan and the amount shown on the bank statements was significantly different
than what he had been told it was. After he discovered the theft, he called one of the
authors of this book and asked what he should do. The author told him that people who
embezzle and are not prosecuted have a high likelihood of committing fraud again and
that he should probably fire her and have her prosecuted. He didn’t follow this advice.
Unfortunately, later the secretary/bookkeeper stole over $25,000.
There are three simple procedures that small business owners should do
personally when they can’t afford sufficient employees to guarantee effective segregation
of duties. The first is that they should always open the bank statement themselves and, if
possible, reconcile the bank statement. Second, they should pay everything by check so
there is a record. Third, they should sign every check themselves and not delegate the
signing to anyone else. These simple procedures, if done on a timely basis, will prevent
many frauds.
d. Analytical Fraud Symptoms
Analytical fraud symptoms are procedures or relationships that are unusual or too
unrealistic to be believable. They include transactions or events that happen at odd times
or places; that are performed by or involve people who would not normally participate; or
that include odd procedures, policies, or practices. They also include transactions and
amounts that are too large or too small, that are performed or occur too often or too
rarely, that are too high or too low, or that result in too much or too little of something.
Basically, analytical symptoms represent anything out of the ordinary. They are the
unexpected.
The internal auditors for Mayberry Corporation, a conglomerate with about $1
billion in sales, were auditing the company’s sheet metal division. Every past audit had
resulted in favorable outcomes with few audit findings. This year, however, something
did not seem right. Their observation of inventory had revealed no serious shortages, and
yet inventory seemed dramatically overstated. Why would inventory increase fivefold in
one year? Suspecting that something was wrong, the auditors performed some “midnight
auditing” and found that the company’s sheet metal inventory was grossly overstated.
The auditors had almost been deceived. Local management had falsified the inventory by
preparing fictitious records. The auditors had verified the amount of inventory shown
during the yearend count and had deposited their verifications in a box in the conference
room they were using. A manager at Mayberry added fake inventory records to the box at
night with some of the records showing unreasonably large amounts of sheet metal. The
manager had also substituted new inventory reconciliation lists to agree with the total of
the valid and fictitious records.
The magnitude of the Mayberry fraud was discovered when the auditors
performed analytical tests. First, they converted the purported $30 million of sheet metal
inventory into cubic feet. Second, they determined the volume of the warehouse that was
supposed to contain the inventory. At most, it could have contained only one-half the
reported amounts; it was far too small to house the total amount. Third, they examined
the inventory tags and found that some rolls of sheet metal would weigh 50,000 pounds.
However, none of the forklifts that were used to move the inventory could possibly lift
over 3,000 pounds. Finally, the auditors verified the reported inventory purchases and
found purchase orders supporting an inventory of about 30 million pounds. Yet, the
reported amount was 60 million pounds. Faced with this evidence, the company’s
managers admitted that they had grossly overstated the value of the inventory to show
increased profits. The budget for the sheet metal division called for increased earnings,
and without the overstatement, the earnings would have fallen far short of target. In this
case, it was the relationship between amounts recorded and the weight and volume that
the recorded amounts represented that did not make sense. Unfortunately, few managers
or auditors ever think of examining physical characteristics of inventory.
Don was the business manager of Regal Industries. In his position, he often
arranged and paid for services performed by various vendors. An alert accountant caught
Don committing a fraud. The first symptom observed by the accountant was payments
made to an Oldsmobile dealership, though the company only had a few company cars and
all were Cadillacs. The accountant thought it strange that the company cars were being
serviced at an Oldsmobile dealership rather than a Cadillac dealership. He knew that both
cars were made by General Motors but he still wondered about the transactions. Maybe
the Oldsmobile dealership was closer, he reasoned. Upon checking, he discovered that it
was not. Further investigation by the accountant revealed that, although payments had
also been made to the Oldsmobile dealership for body damage on company cars, no
claims had been filed with insurance companies. The accountant also noticed that
payments of exactly the same amount were being made to the Oldsmobile dealer every
month. The combination of Oldsmobile dealer, body damage without corresponding
insurance claims, expenditures every month, and expenditures of the same amount raised
his suspicion. He concluded that the only legitimate explanation for these anomalies
would be a fixed-fee maintenance contract with the Oldsmobile dealer to service the
company’s Cadillacs. An investigation revealed that no such contract existed. Further
investigation revealed that Don had a girlfriend who worked at the Oldsmobile dealership
and that he was buying her a car by having the company make the monthly payments.
In this case, an alert accountant saved his company approximately $15,000.
Unfortunately, many accountants and auditors would have missed this fraud. They would
probably have seen the check being paid to the Oldsmobile dealer, matched it with the
invoice that Don’s girlfriend supplied each month, and been satisfied. They would not
have asked whether the expenditure made sense or why Cadillacs were being serviced at
an Oldsmobile dealership.
Recognizing analytical symptoms has always been an excellent method of
detecting fraud. A successful fraud investigator became interested in investigation when
he discovered his first fraud. This discovery, which determined his lifelong career, is one
of the best examples of the use of analytical symptoms. Here is the career-changing
experience.
It was the summer of 1956. That’s what I remember, at least, though it was a long
time ago and things get distorted when you look back. And, I have looked back quite a bit
since then, for the entire episode was quite an eye-opener for an 18-year-old kid. I was a
“numbers man” then and still am. Mathematics is an art to me. I find a beauty in pure
numbers that I never see in the vulgar excesses that most of society chases after. You
might wonder, then, what I was doing working in a movie theater that summer—the
summer that Grace Kelly became a princess and the whole country seemed to worship the
cardboard stars on the silver screens. Well, the truth is, I spent the summer in a movie
theater because I needed employment. I’d just graduated from South High and was
waiting to begin college. To earn money, I took a job as a ticket taker at the Classic
Theater. As movie theaters go, the Classic was considered one of the best. Not in terms of
elegance: it wasn’t one of those gild and velvet-lined monstrosities with fat plaster babies
and faux chandeliers. No! What the Classic had was a certain charm in the same way that
drive-in hamburger joints of the decade did. I think the style was called deco-modern and
it made me feel a bit like I was rushing toward the 21st century. So the place wasn’t all
bad, though it was not the kind of job that a dedicated numbers man usually sought. But
as it turned out, my numbers did come in useful. For that’s how I caught on to him, you
see; it was because of the numbers.
Ticket taking is not the most exciting job there is, and I didn’t find it a real
intellectual challenge. My mind was free to wander, and I got in the habit of noting the
number of each ticket that I tore: 57, 58, 59, 60. The numbers would march to me in a
more or less consecutive order as they came off the roll that the ticket seller sold from:
61, 62, 63, 64. But sometimes, I noticed, the sequence would be off. A whole chunk of
numbers would appear that should have come through earlier: 65, 66, 40, 41, 42. It would
happen almost every time I worked. I thought it was odd and was curious about what
could be disturbing the symmetry of my numbers. The world of numbers is orderly and
logical; for every apparent irrationality, there is an explanation. I began to use the puzzle
as a mental game to occupy my working hours. Noting each time the sequence was off, I
came to realize that it always happened after my daily break. The manager, Mr. Smith,
would relieve me while I was on break. I watched closer and noticed another fact: the
numbers would always be off while the ticket seller, who had the break after mine, was
being relieved. Mr. Smith filled in for the ticket seller, too.
Until this point, the amateur detective work had been merely a way to pass the
time. I began to suspect that something wrong was going on, and it made me
uncomfortable. After more observation and thought, I solved Mr. Smith’s scheme. When
he relieved me as ticket taker during my break, he would pocket the tickets instead of
tearing them in two. Then, when he relieved the ticket seller, he would resell the tickets
he had just pocketed and keep the cash. Thus, the ticket numbers that I saw coming
through out of sequence were really coming through for the second time.
Although this was a small fraud that took place in a little theater, it illustrates that
when things do not look right, they probably are not right. If the ticket taker had not been
fascinated with numbers, the manager probably would not have been detected. The
manager was trusted more than other workers. The number of tickets he pocketed was
small in relation to the total number of tickets sold in a day, and so management did not
see a large drop in profits. Every night, the bookkeeper computed the total number of
tickets sold, using the beginning and ending ticket numbers, and compared the total to the
cash taken in. Unfortunately, the balance was not wrong. The theater hired separate
people to sell and take tickets specifically to avoid this type of fraud. But Mr. Smith was
the manager, and no one perceived a problem with letting him do both jobs while others
were on break. There is probably no way Mr. Smith’s fraud would have been caught if it
had not been for a “numbers man” who saw relationships in the numbers that did not
make sense.
Relationships between financial statement numbers are also predictable. To
individuals who really understand accounting, financial statements tell a story. The
elements of the story must be internally consistent. Many large financial statement frauds
could have been discovered much earlier if financial statement preparers, auditors,
analysts, and others had understood numbers in the financial statements the way the ticket
taker understood his numbers. One of the best examples of financial statement numbers
that did not make sense was in MiniScribe Corporation’s financial statements. MiniScribe
was a Denver-based producer of computer disk drives. Here is a description of the
MiniScribe fraud and an analysis of the numbers in the firm’s financial statements that
did not make sense.
Several analytical symptoms indicated that things were not right at MiniScribe.
First, MiniScribe’s results were not consistent with industry performance. During the
period of the fraud, severe price cutting was going on, sales were declining, and
competition was stiff. MiniScribe reported increases in sales and profits, while other
companies were reporting losses. MiniScribe had very few large customers and had lost
several major customers, including Apple Computer, IBM, and Digital Equipment
Corporation. MiniScribe was also falling behind on its payments to suppliers. Returns to
suppliers forced the bankruptcy of MiniScribe’s major supplier of aluminum disks,
Domain Technologies.
In addition, numbers that were reported at the end of each quarter were amazingly
close to the projections made by Wiles. Financial results were the sole basis for
management bonuses. There were significant increases in receivables, and yet the
allowance for doubtful accounts was far less than the industry average. An aging of
receivables revealed that many accounts were old and probably not collectible. A simple
correlation of inventory with sales would have revealed that while reported sales were
increasing, inventory was not increasing proportionately. Indeed, the financial statement
numbers did not make sense. Relationships within the statements, relationships with
industry trends, and an examination of MiniScribe’s customers provided analytical
symptoms suggesting that something was seriously wrong. Unfortunately, by the time
these symptoms were recognized, investors, auditors, lawyers, and others had been
fooled, and many people lost money.
Several research papers have studied different analytical “symptoms” to
determine if they can be used to predict fraud. For example, one study examined the
relationship between high management turnover and financial distress and accounting
fraud. This paper, based on an analysis of SEC Accounting and Auditing Enforcement
Releases between 1990 and 2000 found that fraud firms are more likely to be financially
distressed and have higher management turnover (both analytical symptoms) than are
nonfraud firms.
Auditors often use analytical procedures to look for fraud symptoms.
Unfortunately, analytical procedures are not always effective because sometimes
analytical relationships stay the same even when fraud is being perpetrated. Such was the
case at WorldCom. In the WorldCom case, significant decreases in the purchase of fixed
assets were offset by improper capitalization of expenses, thus leaving the relative
amount of increases in assets about the same from period to period.
e. Extravagant Lifestyles
Most people who commit fraud are under financial pressure. Sometimes the
pressures are real; sometimes they merely represent greed. Once perpetrators meet their
financial needs, they usually continue to steal, using the embezzled funds to improve
their lifestyles. Often, they buy new cars. They sometimes buy other expensive toys, take
vacations, remodel their homes or move into more expensive houses, buy expensive
jewelry or clothes, or just start spending more money on food and other day-to-day living
expenses. Very few perpetrators save what they steal. Indeed, most immediately spend
everything they steal. As they become more and more confident in their fraud schemes,
they steal and spend larger amounts. Soon they are living lifestyles far beyond what they
can afford.
Embezzlers are people who take shortcuts to appear successful. Very few crooks,
at least those who are caught, save embezzled money. The same motivation for stealing
seems to also compel them to seek immediate gratification. People who can delay
gratification and spending are much less likely to possess the motivation to be dishonest.
Lifestyle changes are often the easiest of all symptoms to detect. They are often
very helpful in detecting fraud against organizations by employees and others but not as
helpful in detecting fraud on behalf of a corporation, such as management fraud. If
managers, coworkers, and others pay attention, they notice embezzlers living lifestyles
that their incomes do not support. While lifestyle symptoms provide only circumstantial
evidence of fraud, such evidence is easy to corroborate. Bank records, investment
records, and tax return information are difficult to access; but property records, Uniform
Commercial Code (UCC) filings, and other records are easy to check to determine
whether assets have been purchased or liens have been removed.
f. Unusual Behaviors
Research in psychology reveals that when a person (especially a first-time fraud
perpetrator) commits a crime, he or she becomes engulfed by emotions of fear and guilt.
These emotions express themselves as stress. The individual often exhibits unusual and
recognizable behavior patterns to cope with the stress. No particular behavior signals
fraud; rather, changes in behavior are signals. People who are normally nice may become
intimidating and belligerent. People who are normally belligerent may suddenly become
nice.
Even perpetrators recognize their behavioral changes. A woman who stole over
$400,000 said, “I had to be giving off signals. I could not look anyone in the eye.” A man
who embezzled over $150,000 said, “Sometimes I would be so wound up I would work
12 or 14 hours a day, often standing up. Other times I would be so despondent I could not
get off the couch for over a week at a time.” Eddie Antar, mastermind of the Crazy Eddie
fraud described in the following text, became very intimidating and then finally vanished.
Two other examples of changes in behavior motivated by the stress caused by
committing fraud were the behaviors of Donald Sheelen, CEO of Regina Vacuum
Company, and Leston Nay, CEO of First National of Chicago. Although their actions
were different, neither was able to cope with the stress. Before his fraud was discovered,
Sheelen went to his priest and confessed his entire scheme. Nay’s actions were even more
dramatic. After penning a suicide note detailing how he defrauded investors of millions
of dollars, he took his life. However a fraud perpetrator copes with the stress caused by
guilt—by being intimidating, by confessing, or by committing suicide— stress always
seems to be present.
In this case, Joseph’s intimidating personality had kept the office manager and
others at a distance. Although the office manager seemed to know something was wrong,
he had never been given the chance to find out. The office manager had always been
blamed by Joseph when petty cash was out of balance, yet he had never been allowed to
balance it. In fact, Joseph had constantly blamed others for problems. In retrospect,
employees understood that Joseph’s intimidating behavior was his way of keeping the
fraud from being discovered and of dealing with the stress he felt from committing the
crime.
The largest fraud ever to be perpetrated in Australia was HIH, a fraud that was
discovered in 2002. The HIH fraud was concealed for years by an executive who changed
his behavior to intimidate others so that they did exactly what he wanted. By becoming
almost totalitarian, he was able to do anything he wanted. Here is the story. HIH was one
of Australia’s biggest home-building market insurers. HIH was the underwriter for
thousands of professional indemnity, public liability, home warranty, and travel insurance
policies.3 HIH was started in 1968 by Raymond Williams and Michael Payne. Michael
Payne was chief executive of the UK operations until 1997, when health problems forced
him to limit his activities in the company. He became chairman of the main UK entity in
1999. He was an executive director of the holding company from 1992 until June 1998
and a nonexecutive director from July 1998 until September 2000.
Raymond Williams was the CEO for HIH from its inception in 1968 until October
2000. Other key employees were George Sturesteps and Terrence Cassidy, who became
members of senior management in 1969 and 1970, respectively. They both held their
positions until September 2000 and March 2001, respectively. Williams was the
dominant member of management at HIH. Although many close members of upper
management had been with him for over 25 years, they were reluctant to tell him how to
run the business, give suggestions, or question Williams’ motives and business decisions.
The Royal Commission report, which summarizes the Australian government’s
investigation of HIH, suggested that a lack of strategic direction and of questioning
authority set the stage for the eventual downfall of the HIH Insurance group. If asked
about the strategic goals or mission of HIH, the report states that neither Williams nor the
board of directors would have been able to explain them. Although HIH was a public
company that had grown quickly, the report states that Williams continued to run HIH
much like the small company it had been when it first started. That is, he made most of
the decisions, used business accounts as personal accounts, overrode internal controls,
and so forth.
g. Anomalies and Frauds
Auditors have analyzed data to detect fraud and anomalies for many decades. In
particular, the advent of the personal computer, with applications like VisiCalc, Lotus 1-
2-3, Excel, dBASE, and Access, provided auditors with user-oriented and accessible tools
to analyze large and small data sets. However, it is important to realize that the methods
auditors used (and still often use) were based on traditional audit procedures like
statistical sampling, spot checking, and control totals. While the tools became electronic,
many auditors still performed analysis techniques tailored to manual checking methods.
Unfortunately, these traditional methods were more suited to finding anomalies than
fraud.
Accounting anomalies are primarily caused by control weaknesses. They are not
intentional mistakes; they are simply problems in the system caused by failures in
systems, procedures, and policies. For example, a typical anomaly might be double
payment of invoices because of printer errors. If a system often has printer errors (such as
running out of paper or ink) and does not correctly respond to these errors, employees
may simply reenter the invoices and cause two credits to Cash in the journal entry table.
This is a simple error, but it illustrates several attributes of control and system
weaknesses.
First, anomalies are not intentional. They do not represent fraud and normally do
not result in legal action being taken. There is no “criminal” other than a weak system or
an employee that needs to be censured or reprimanded.
Second, anomalies will be found throughout a data set. For example, the double-
payment-of-invoices anomaly would likely occur every time a printer failure happens. If
paper or ink problems occur every two weeks, the problem will be found in the journal
entry table at the corresponding intervals. An auditor simply needs to take a statistical
sample of the data set to discover the anomaly because the anomaly is spread throughout
the data set. If you look at the entire data set as a haystack, the anomaly will be spread
fairly evenly throughout the haystack. Taking a handful of hay brings about good chances
that you’ll catch the anomaly. Fraud is different: it is the intentional subvertion of
controls by intelligent human beings. Perpetrators cover their tracks by creating false
documents or changing records in database systems. Evidence of fraud may be found in
very few transactions—sometimes only one or two. Rather than being spread throughout
the data set, fraudulent symptoms are found in single cases or limited areas of the data
set. Detecting a fraud is like finding the proverbial “needle in the haystack.”
Because discovery of anomalies has been a very important part of financial
statement, control, and compliance audits in recent decades, it is not surprising that
statistical sampling has become a standard auditing procedure. Sampling is often the
subject of entire and sections of auditing textbooks. It is an effective analysis procedure
for finding routine anomalies spread throughout a data set.
In contrast, sampling is usually a poor analysis technique when looking for a
needle in a haystack. If you sample at a 5 percent rate, you effectively take a 95 percent
chance that you will miss the few fraudulent transactions! Fraud examiners must take a
different approach; they should normally complete full-population analysis to ensure that
the “needles” are found.
Fortunately, almost all data in today’s audits and fraud investigations are
electronic. Computers can often analyze full populations almost as fast as they can
analyze samples. Certainly, some tasks will always require sampling. But the majority of
tasks can be analyzed at a full-population level without significant increases in cost or
time. When given a task to complete—whether as part of an audit or a full fraud
investigation—the benefits and costs of full-population analysis should be considered.
Given the right tools and techniques, full-population analysis is often an attractive option.
h. The Data Analysis Process
Data analysis for fraud detection requires reengineered methods to be effective.
Simply applying yesterday’s sampling-based techniques to full populations should be
considered a less effective method. Fraud investigators must be prepared to learn new
methodologies, software tools, and analysis techniques to successfully take advantage of
data-oriented methods. Consider the traditional approach to fraud detection: it is usually a
reactive approach that starts when an anonymous tip is received or when a symptom is
detected. It is considered a reactive approach because the investigator waits for a reason
(predication of fraud) to investigate.
Data-driven fraud detection is proactive in nature. The investigator no longer has
to wait for a tip to be received; instead, he or she brainstorms the schemes and symptoms
that might be found and looks for them. It should be considered a hypothesis-testing
approach: the investigator makes hypotheses and tests to see if each one holds true. The
proactive (data-driven) method of fraud detection. These steps are described in the next
sections.
The proactive detection process starts with an understanding of the business or
unit being examined. Since each business environment is different—even within the same
industry or firm—fraud detection is largely an analytical process. Since examiners are
going to make hypotheses about the schemes that could exist, they must have a good
understanding of the business processes and procedures. The same fraud detection
procedures cannot be applied generically to all businesses or even to different units of the
same organization. The proactive method is an analytical approach that takes analytical
thinking on the part of the investigator. Rather than rely on generic fraud detection
methods or generic queries, examiners must gain intimate knowledge of each specific
organization and its processes. Having a detailed understanding underlies the entire
strategic fraud detection process.
Once the team members are confident in their understanding of the business, the
next step is to identify what possible frauds might exist or could occur in the operation
being examined. This risk assessment step requires an understanding of the nature of
different frauds, how they occur, and what symptoms they exhibit. The fraud
identification process begins by conceptually dividing the business unit into its individual
functions or cycles.
Most businesses or even subunits are simply too large and diverse for examiners
to consider simultaneously. Dividing the business into its individual functions or cycles
helps focus the detection process. For example, an examiner might decide to focus
directly on the manufacturing plant, the collections department, or the purchasing
function. In this step, people involved in the business functions are interviewed.
As you learned previously, fraud itself is rarely seen; only its symptoms are
usually observed. What may appear to be a fraud symptom often ends up being explained
by nonfraud factors, which creates confusion, delay, and additional expense for the fraud
team. For example, a company’s accounts receivable balance might be increasing at a
rate that appears to be unrealistically high. The increasing receivable balance could be the
result of fraud, the result of major customers having financial difficulties, or a change in
credit terms. In addition, no empirical evidence suggests that the presence of more
apparent red flags increases the probability of fraud (although the more confirmed red
flags there are, the higher the probability of fraud), or that certain red flags have greater
predictive ability than other red flags.
Even with these weaknesses, however, identifying red flags or fraud symptoms is
often the best—and sometimes the only—practical method of proactive fraud detection.
All auditing fraud standards, for example, recommend the red flag approach for detecting
fraud. Although tips and reports account for the detection of most serious frauds, they
usually occur too late, after the fraud has grown to the stage that the tipster overcomes his
or her natural reluctance to report it.
Once symptoms are defined and correlated (catalogued) with specific frauds,
supporting data are extracted from corporate databases, online Web sites, and other
sources. While the previous steps were general, analytical exercises, searching for
symptoms is specific to each company and even each unit or cycle in a company.
Searching and analysis are normally done with data analysis applications or with custom
structured query language (SQL) queries and scripts that are specific to the client.
The deliverable of this step is a set of data that matches the symptoms identified
in the previous step. Since real-world data sources are noisy (meaning they contain errors
from a variety of sources), searching for symptoms is often an iterative process. For
example, the first run of queries and algorithms usually generates thousands of hits. Since
most businesses do not have thousands of frauds occurring, it is almost always necessary
to analyze the results to find trends and other cases that do not constitute fraud. After
inspection, the fraud examiner usually modifies and reruns the analysis to filter out the
nonfraud results. A second run might produce a few hundred results. Subsequent filtering
and runs will continue to hone the results until a manageable set of indicators is found.
Once anomalies are refined and determined by the examiners to be likely
indications of fraud, they are analyzed using either traditional or technology-based
methods. Since computer-based analysis is often the most efficient method of
investigation, every effort should be made to screen results using computer algorithms.
Investigation of leads should only be done on anomalies that cannot be explained through
continued analysis. Examiners normally work with auditors and security personnel to
identify reasons for anomalies. They talk with coworkers, investigate paper documents,
and contact outside individuals.
These include discovery of outliers, digital analysis, stratification and
summarization, trending, and text matching. One advantage of the deductive approach is
its potential reuse. Analyses can often be automated and integrated directly into corporate
systems in a way that provides real-time analysis and detection of fraud as well as
prevention of known fraud types. Subsequent runs through the deductive steps reach
economies of scale because many of the steps can be reused.
The final step of the data-driven approach is investigation into the most promising
indicators. Investigators should continue to use computer analyses to provide support and
detail. Investigation of fraud is the subject of the next section of this book.
The primary advantage of the data-driven approach is the investigator takes
charge of the fraud investigation process. Instead of merely waiting for tips or other
indicators to become egregious enough to show on their own, the data-driven approach
can highlight frauds while they are still small. Instead of simply throwing a “fishing line”
into the water and waiting for a bite, this approach allows the investigator to dive in and
directly target potential frauds. The primary drawback to the data-driven approach is that
it can be more expensive and time intensive than the traditional approach. Since the
brainstorming process in Steps 2 and 3 usually results in hundreds of potential indicators,
it can take a significant amount of time to complete Steps 4 and 5.
i. Data Analysis Software
In recent years, many data analysis software packages have been developed to aid
investigators. As data analysis is a large field with many uses, it is not possible to list all
the available software. However, several software packages are widely used by auditors
and investigators for data analysis.
The most important (and often most difficult) step in data analysis is gathering the
right data in the right format during the right time period. Often, just getting an
understanding of the available data can be a daunting task for investigators who are under
time and cost constraints. For example, at one organization, the IT department identified
over 400 potential databases in the company that might be useful for data-driven fraud
detection. It took many days for the investigator to narrow the list down to two primary
databases the team would search.
During the last few decades, most businesses have standardized on relational
databases, especially for financial, payroll, and purchasing systems. This standardization
is a significant benefit to investigators—if they can learn the basics of table structure,
field types, primary and foreign key relationships, and query syntax, they can access data
in almost any company. A discussion of relational databases is beyond the scope of this
book; however, it is a must for any investigator who wants to do data analysis. Even
though Microsoft Access is often not considered a “professional” database (like Oracle,
MySQL, or SQL Server), it is an excellent way to learn relational database principles.
Those wanting to perform quality data analysis are encouraged to learn the Microsoft
Access platform by reading online tutorials, taking an entry-level database class, or
purchasing a help book.
Open Database Connectivity (ODBC) is a standard method of querying data from
corporate relational databases. It is a connector between analysis applications like ACL,
IDEA, and Picalo and databases like Oracle, SQL Server, and MySQL. It is usually the
best way to retrieve data for analysis because (1) it can retrieve data in real time, (2) it
allows use of the powerful SQL language for searching and filtering, (3) it allows
repeated pulls for iterative analysis, and (4) it retrieves metadata like column types and
relationships directly. ODBC is already included with most operating systems. It is a
system-wide setting rather than an application-level setting. Once a connection is created
on a computer, it is available in all data analysis applications installed on that computer.
For example, Windows users set up ODBC connections in the control panel under “Data
Sources (ODBC).”
Each database vendor publishes ODBC drivers for its products. These drivers can
be downloaded for free from vendor Web sites. For example, a Web search of “Oracle
ODBC drivers” finds Oracle’s download page with drivers for most versions of its
products. Once a driver is installed, it shows up in the control panel. Many IT
departments are not comfortable giving out ODBC connections because of security and
privacy issues. One way to compromise with these real concerns is to ask the IT
department for a read-only connection to a limited number of tables in the database. This
ensures that data are not modified and allows efficient use of system resources. As an
alternative to extracting data from databases using ODBC, ACL has server-based
technology that enables auditors and fraud examiners to analyze data directly from
Oracle, DB2, and Microsoft SQL Server databases.
Students also viewed