Purpose and framework

Fraud risk assessment occupies a specific place in the governance architecture. The COSO Internal Control—Integrated Framework (2013) requires, under Principle 8, that an organization consider the potential for fraud in assessing risks to the achievement of its objectives. The COSO and ACFE Fraud Risk Management Guide, first issued in 2016 and revised in 2023, elaborates that requirement into five principles: governance, assessment, control activities, investigation and corrective action, and monitoring. The assessment is the second of those principles and the foundation for the remaining three.

The scale of the exposure is well documented. The ACFE's Occupational Fraud 2024: A Report to the Nations reports a median loss per case of $145,000, estimates that organizations lose about five percent of revenue to fraud annually, and finds that tips remain the most common means of detection, at roughly 43 percent of cases. Those findings carry two implications for the assessment: schemes that persist for years are usually the ones no control was designed to detect, and reporting mechanisms deserve the same rigor as transactional controls.

Scoping the assessment

An effective assessment is scoped by business process rather than by department. Procurement and vendor management, disbursements, payroll, revenue and receivables, inventory, treasury, and financial reporting are the customary starting points; grant-funded and government-contracting organizations add cost allocation, subrecipient monitoring, and compliance with applicable cost principles. For entities administering federal awards, 2 C.F.R. § 200.303 requires internal controls that provide reasonable assurance of compliance, which makes the fraud assessment a compliance obligation as well as a governance practice.

Scope also defines participants. The assessment draws on process owners, finance, internal audit where it exists, legal, and information technology, because fraud schemes exploit the seams between functions. Interviews and facilitated workshops surface schemes that documentation alone does not reveal.

Method

The method proceeds in five steps, each producing a documented artifact.

  1. Scheme identification. For each in-scope process, enumerate the specific ways fraud could occur, using the ACFE fraud tree (asset misappropriation, corruption, and financial statement fraud) as a checklist and the organization's own history, industry cases, and control environment as context. Generic risk statements are of little use; the schemes should be specific enough that a control can be mapped to them.
  2. Inherent risk rating. Rate each scheme for likelihood and significance before considering controls. Significance includes financial, regulatory, and reputational consequences. The rating scale should be defined in advance and applied consistently.
  3. Control mapping. Identify the preventive and detective controls that address each scheme, distinguishing controls that exist on paper from those that are demonstrably operating. Where a control is asserted, the assessment should identify the evidence that shows it operates.
  4. Residual risk and gap analysis. Determine the risk that remains after controls, and identify schemes with no control, weak controls, or controls that depend on a single individual.
  5. Response plan. For each material residual risk, specify the response: a new or strengthened control, a detective analytic, a change in segregation of duties, acceptance with monitoring, or transfer. Assign an owner and a date.

Deliverables

The assessment should produce a fraud risk register that records each scheme, its ratings, its controls, and its residual risk; a heat map that presents the register visually for the board; a control-gap schedule; and a corrective action plan with named owners, target dates, and a monitoring cadence. A written methodology section, describing the scope, participants, rating scale, and limitations, allows the assessment to be relied upon by auditors, regulators, and, if necessary, counsel.

What boards and audit committees should expect

Directors are entitled to ask several questions of a completed assessment. Was it scoped by process, and which processes were excluded? Are the schemes specific? Were controls tested or merely described? Who owns each corrective action, and when will the committee see evidence of completion? How will the register be refreshed as the business, its systems, and its people change? An assessment that cannot answer these questions is a document rather than a control. One that can becomes the basis for a fraud risk management program in which detection is designed rather than left to chance.