ACFE Fraud Risk Assessment 5 — Questions and Answers
Question 1: Which of the following is a key limitation of relying solely on past fraud losses to assess current fraud risk?
- Historical data is always overstated due to insurance recoveries
- Past losses reflect detected frauds only and may miss undetected schemes (Correct answer)
- Historical data cannot be used in statistical models
- Fraud loss data is protected by attorney-client privilege
Correct answer: Past losses reflect detected frauds only and may miss undetected schemes
Historical fraud loss data only captures detected and reported incidents, leaving undetected frauds — which may represent the majority — entirely unmeasured.
Question 2: In fraud risk assessment terminology, 'risk tolerance' refers to:
- The maximum dollar loss an auditor will accept before issuing a qualified opinion
- The amount of residual fraud risk an organization is willing to accept (Correct answer)
- The number of fraud incidents allowed per fiscal year
- The time period over which fraud risks are assessed
Correct answer: The amount of residual fraud risk an organization is willing to accept
Risk tolerance defines the level of residual fraud risk that the board and management consider acceptable given the cost of controls.
Question 3: Which of the following best illustrates 'segregation of duties' as a fraud prevention control?
- One employee handles all aspects of payroll processing to ensure consistency
- The employee who approves vendor invoices is different from the one who processes payment (Correct answer)
- The CFO reviews all journal entries made during the year
- External auditors verify all bank reconciliations quarterly
Correct answer: The employee who approves vendor invoices is different from the one who processes payment
Segregation of duties requires that no single individual control all phases of a transaction, so that approval and payment functions are separated.
Question 4: A fraud risk assessment reveals that an organization's anonymous hotline has received zero reports over three years. A fraud examiner should interpret this finding as:
- Conclusive evidence that no fraud is occurring
- Potentially indicating low awareness of the hotline or fear of retaliation rather than absence of fraud (Correct answer)
- Evidence that the fraud prevention program is highly effective
- A sign that the organization should discontinue the hotline
Correct answer: Potentially indicating low awareness of the hotline or fear of retaliation rather than absence of fraud
Zero reports on a hotline may reflect poor awareness, lack of trust, or fear of retaliation rather than an absence of fraud.
Question 5: Which of the following fraud schemes would a fraud risk assessment focused on the revenue cycle most likely identify as a key risk?
- Ghost employee schemes in payroll
- Fictitious sales recorded to inflate revenue (Correct answer)
- Duplicate payments to vendors
- Unauthorized wire transfers to personal accounts
Correct answer: Fictitious sales recorded to inflate revenue
Fictitious or premature revenue recognition is the primary financial statement fraud risk in the revenue cycle.
Question 6: When conducting fraud risk interviews with process owners, which question type is MOST effective at uncovering hidden fraud risks?
- Closed-ended yes/no questions about policy compliance
- Open-ended questions asking what could go wrong in their area and how (Correct answer)
- Questions focused only on past frauds that have been detected
- Questions that ask employees to rate their own honesty
Correct answer: Open-ended questions asking what could go wrong in their area and how
Open-ended questions encourage process owners to think creatively about vulnerabilities and often surface risks that structured questionnaires miss.
Question 7: According to the ACFE's fraud risk management principles, what should happen after a fraud risk assessment is completed and risks are prioritized?
- The assessment results should remain confidential and be shared only with external auditors
- Management should design or enhance anti-fraud controls and responses for the highest-priority risks (Correct answer)
- All identified risks should be immediately reported to law enforcement
- The board should take direct operational control of the affected departments
Correct answer: Management should design or enhance anti-fraud controls and responses for the highest-priority risks
After prioritization, management is responsible for developing or strengthening controls and other responses targeted at the highest-rated fraud risks.
Which of the following is a key limitation of relying solely on past fraud losses to assess current fraud risk?