CFE Fraud Prevention Programs 3 — Questions and Answers
Question 1: Which of the following BEST describes a 'control environment' as it relates to fraud prevention?
- The physical security systems protecting company assets
- The overall attitude, awareness, and actions of management regarding internal controls (Correct answer)
- The set of IT security tools deployed by the organization
- The documented policies in the employee handbook
Correct answer: The overall attitude, awareness, and actions of management regarding internal controls
The control environment is the foundation of internal control, shaped by management's attitude and the ethical tone they set for the organization.
Question 2: A company requires all employees to take vacations of at least one consecutive week. What fraud scheme is this policy specifically designed to detect?
- Expense reimbursement fraud
- Check tampering and lapping schemes (Correct answer)
- Bid rigging in procurement
- Conflicts of interest with vendors
Correct answer: Check tampering and lapping schemes
Mandatory vacations expose lapping and check-tampering schemes because a substitute must handle the work, making it difficult for the fraudster to continue concealment.
Question 3: Which component of the COSO framework addresses the organization's risk appetite and tolerance for fraud risk?
- Control Activities
- Risk Assessment (Correct answer)
- Monitoring Activities
- Information and Communication
Correct answer: Risk Assessment
Risk Assessment under COSO includes identifying and analyzing fraud risks and determining the organization's tolerance for those risks.
Question 4: What is the key advantage of using data analytics in a proactive fraud prevention program?
- It eliminates the need for internal audit staff
- It detects anomalies and patterns that may indicate fraud before significant losses occur (Correct answer)
- It replaces the need for employee background checks
- It satisfies all regulatory reporting requirements automatically
Correct answer: It detects anomalies and patterns that may indicate fraud before significant losses occur
Data analytics continuously monitors transactions for red flags, enabling earlier detection and limiting fraud losses compared to periodic manual reviews.
Question 5: Which scenario represents a segregation of duties violation that creates fraud risk?
- The CFO reviews the internal audit report before the board does
- The same clerk who approves vendor invoices also signs the payment checks (Correct answer)
- A manager approves expense reports submitted by direct reports
- The external auditor tests controls designed by management
Correct answer: The same clerk who approves vendor invoices also signs the payment checks
Allowing one person to both approve invoices and issue payments eliminates a key check, enabling them to create fictitious payables and steal funds.
Question 6: Under the ACFE's fraud prevention framework, which action is described as a 'deterrent' rather than a 'detection' measure?
- Forensic accounting review of historical transactions
- Publicizing the successful prosecution of a former employee for fraud (Correct answer)
- Surprise cash counts in high-risk areas
- Reviewing exception reports from the accounting system
Correct answer: Publicizing the successful prosecution of a former employee for fraud
Publicizing prosecution outcomes deters potential fraudsters by demonstrating that fraud will be discovered and has serious consequences, without detecting an existing scheme.
Question 7: What is the purpose of an anti-fraud policy that requires employees to disclose potential conflicts of interest?
- To allow the company to charge employees for using company resources for personal benefit
- To give management information needed to assess and manage conflicts that could lead to fraud (Correct answer)
- To create grounds for termination of employees who own any outside business
- To satisfy IRS reporting requirements for related-party transactions
Correct answer: To give management information needed to assess and manage conflicts that could lead to fraud
Conflict-of-interest disclosures allow management to evaluate whether relationships create fraud risks and implement safeguards or restrictions accordingly.
Which of the following BEST describes a 'control environment' as it relates to fraud prevention?