For a lot of people running smaller businesses or even organizations that are categorized as medium sized, making an effort to assess fraud risk is just not viewed as time well spent. While most will admit that the effects of fraud can be painful, there are so many other aspects of operations that seem to need more attention. Those working for entities that are just starting out, or those that are experiencing notable growth feel like they don’t have time to focus on something that “could” happen and instead worry about work aspects that appear to be more tangible.
It is important to remember that the business organizations out there are not the only parties undertaking fraud risk assessment activities. Those seeking to commit fraud are doing so as well. This means if a business does not work to find and fix control weaknesses that allow for fraud – a fraudster will work to find and exploit them.
I don’t want to get too technical, but the first foundational component of the COSO Internal Control Framework is risk assessment. By making it “foundational” the authors of the framework are communicating that it is an imperative step that needs to be taken when creating measures. Let us consider another authoritative source of information, the Association of Certified Fraud Examiners (ACFE). This organization publishes a biennial report called the Report to Nations on Occupational Fraud. It (the report), which by the way is free to download in PDF form, presents a wide range of very helpful statistical data about occupational (internal) fraud. One important bit of information that appears in just about every report is that businesses with less than 100 employees, small businesses, are attacked more frequently and suffer greater percentages of loss. Medium sized organizations are also targeted heavily and suffer notably as well.
A simple way to break the assessment process down is to look at every aspect of operations (that sounds simple – right) and consider consequences that might occur if a fraud is perpetrated. As an example, a party with ill-intent gains access to a cloud storage site that houses sensitive data belonging to both the company the customers or clients it serves. This is an easy one, everyone will come to the same conclusion, there are multiple risks such as damage to the company, damage to the clients served, legal and regulatory issues, and irreversible reputation issues. The next thing to consider is the chances that a fraud could be carried out successfully. Let’s do an example for this one. Risk that someone will be able to skim from monies received as accounts are collected. If the organization is using an accounting or receivables application with resident fraud deterrent features, fraud risk will probably be reduced. Finally, it is important to properly assess the value of entity assets. Small and medium sized organizations sometimes don’t realize where a perpetrator might find value.
It is not realistic to believe that a business owner, or a controller or even a small control team of two to four people could carry out a thorough assessment of an entity. So, how does it get done? There are a couple of avenues. Something I have found to be true as I have worked with smaller companies is that the ones that are successful have quality people in key roles. It’s time for another example. Consider a 70 to 75 employee machine shop that manufactures steel parts for the customers it serves. There will be numerous people on the shop floor that have a tremendous amount of well-rounded expertise. These workers can be very helpful in efforts to conduct fraud (and other) risk assessments. Just a moment ago I discussed knowledge available from shop floor workers, but there also will be people in other departments such as sales and marketing, accounting, shipping, and administration that can provide insight so risk can be more accurately gaged. Organizations generally have a lot of talent that is not being fully utilized, and they should tap into it to the greatest extent possible.
Another way to go is to contract with an outside party. CPA firms and organizations that specialize in fraud reduction can provide the expertise a company needs to mitigate fraud risk. Unfortunately, the idea of spending money to assess fraud risk and then spending more money to have controls established in order to alleviate this risk is a tough pill for small and medium sized businesses to swallow. In fact, it has been said that the only small companies willing to spend money to thwart fraud are those that have suffered through a fraud event. That being said, one of the positives that is coming from the technological upheaval that is currently occurring is that business organizations, no matter their size are feeling overwhelmed and therefore vulnerable which is leading them to look more closely at issues like fraud exposure.
If we cut to the chase, people in top level accounting and controllership roles have regularly struggled to convince those in ownership or top level management that significant resources are required to recognize fraud risk. This is exacerbated by the fact that even more effort is then needed to create security protocols to reduce exposure. This may sound like a silly approach it, but employing an oft used sales technique, “Create Pain”, may be one way to motivate organizations leaders to act against fraud. If you are not familiar with this sales method it is fairly straightforward. Establish a problem (the pain point) and then sell your product to solve it. When my father was in his 80’s he was afraid someone was going to take his driver’s license (because he couldn’t drive very well anymore). He had dings and scratches all over his car because his fine motor skills had waned. A local car salesman was able to sell him a new car because he harped on my dad’s fear of losing his license. The newer model had an array of sensors and warning alarms to help him drive without incident. He created pain and then sold a car to alleviate it. Unfortunately, my father still scrapped and bumped things with the same regularity, but now a little bell rang in his car as he did so.
We, as controller creators can create pain. It can be done by finding examples of other organizations that suffered greatly from fraud and presenting them to decision makers. The next step is to show how strong assessment followed by control measure creation can make our company more secure. Any way you look at it small and medium sized organizations are often not financially strong enough to recover from a successful fraud event. This means that fighting fraud should be a priority. A little pain now is better than a lot in the future!
Karl Egnatoff, CPA.CITP is a certified public accountant (CPA). During the past 33 years Karl has worked as a consultant, trainer, and as a software engineer while engaged on projects for business organizations of all types. Prior to this, he worked in public accounting as well as in private accounting sector, and since 2009, he has been presenting and creating material in association with numerous continuing educations organizations. In addition to being a CPA, he is also a Certified Information Technology Professional (CITP).
Karl has written training material, numerous articles and the book , "Stories to Build a Business On" which is available from Amazon. If you enjoyed the article, review the course, "How Fraud Can Affect Smaller Organizations” as a great follow-up to your learning partnered with CPA Crossings.
This article is provided as a complimentary resource by the PICPA and Karl Egnatoff, CPA.CITP. Statements of fact and opinion are the author’s responsibility alone and do not imply an opinion on the part of CPA Crossings officers or members. The information contained herein does not constitute accounting, legal, or professional advice. For actionable advice, you must engage or consult with a qualified professional.