CAPA Fraud Prevention and Detection 2 — Questions and Answers
Question 1: Which practice best prevents unauthorized changes to the vendor master file?
- Allowing AP staff to update vendor records as needed
- Restricting vendor master file changes to a designated individual separate from invoice processors (Correct answer)
- Requiring vendors to update their own records online
- Archiving vendor records annually
Correct answer: Restricting vendor master file changes to a designated individual separate from invoice processors
Restricting vendor master file access to a dedicated individual not involved in invoice processing creates a separation of duties that reduces fraudulent vendor creation.
Question 2: What is a 'lapping' scheme in accounts payable?
- Paying the same invoice twice
- Covering theft by applying subsequent payments to conceal earlier stolen funds (Correct answer)
- Creating a fictitious vendor and routing payments there
- Submitting personal expenses as business expenses
Correct answer: Covering theft by applying subsequent payments to conceal earlier stolen funds
Lapping involves stealing a payment, then using a later payment from another source to cover the missing amount, creating a rolling concealment of the theft.
Question 3: Which of the following is an example of an internal AP fraud indicator during invoice review?
- Invoice received on company letterhead
- Invoice lacks a purchase order number for a large purchase (Correct answer)
- Invoice references a contract number
- Invoice submitted within the payment terms window
Correct answer: Invoice lacks a purchase order number for a large purchase
A large invoice lacking a corresponding purchase order number bypasses the authorization control that POs provide, which is a red flag for potentially fraudulent or unauthorized purchases.
Question 4: What is the role of a 'positive pay' system in AP fraud prevention?
- It approves invoices automatically based on vendor history
- It matches checks presented for payment against an authorized list issued by the company to detect altered or counterfeit checks (Correct answer)
- It ensures vendors are paid on their preferred schedule
- It verifies that purchase orders match receiving reports
Correct answer: It matches checks presented for payment against an authorized list issued by the company to detect altered or counterfeit checks
Positive pay is a bank fraud prevention service where the company transmits authorized check details to the bank, which then flags any check not matching the list before paying it.
Question 5: An AP clerk submits reimbursement claims for the same business meal multiple times across different expense reports. This is best categorized as:
- Skimming
- Duplicate expense reimbursement fraud (Correct answer)
- Conflict of interest
- Shell company fraud
Correct answer: Duplicate expense reimbursement fraud
Submitting the same expense receipt multiple times to receive more than one reimbursement is a form of duplicate expense fraud, a common employee fraud scheme.
Question 6: Which control specifically helps prevent 'check tampering' fraud in AP?
- Three-way invoice matching
- Dual signature requirements and controlled check stock storage (Correct answer)
- Automated invoice approval workflows
- Vendor onboarding due diligence
Correct answer: Dual signature requirements and controlled check stock storage
Requiring dual signatures for checks above a threshold and securing blank check stock in a locked location makes it significantly harder for an employee to create or alter checks fraudulently.
Question 7: Which organizational policy most directly supports a culture of fraud prevention in AP?
- Paying all invoices within 15 days
- Establishing a confidential whistleblower hotline for reporting suspected fraud (Correct answer)
- Digitizing all paper invoices
- Centralizing all AP functions in one department
Correct answer: Establishing a confidential whistleblower hotline for reporting suspected fraud
A confidential whistleblower hotline encourages employees to report suspected fraud without fear of retaliation, which is one of the most effective fraud detection methods according to the ACFE.
Which practice best prevents unauthorized changes to the vendor master file?