CFE Fraud Prevention Programs 5 — Questions and Answers
Question 1: Which anti-fraud measure most directly addresses the 'rationalization' element of the fraud triangle?
- Implementing segregation of duties
- Enforcing a zero-tolerance fraud policy communicated to all employees (Correct answer)
- Installing surveillance cameras in financial areas
- Conducting surprise audits of cash drawers
Correct answer: Enforcing a zero-tolerance fraud policy communicated to all employees
A clearly communicated zero-tolerance policy challenges the rationalizations fraudsters use by making clear that no excuse justifies dishonest behavior.
Question 2: A company implements continuous monitoring software that flags all journal entries posted after business hours. This is an example of which type of control?
- Preventive control
- Corrective control
- Detective control (Correct answer)
- Directive control
Correct answer: Detective control
Flagging unusual journal entries is a detective control because it identifies anomalies after they occur rather than stopping them beforehand.
Question 3: Under the Sarbanes-Oxley Act, Section 301 requires audit committees to establish procedures for:
- Reviewing all internal audit reports before management
- Receiving, retaining, and treating complaints regarding accounting and internal controls, including anonymous employee submissions (Correct answer)
- Approving all capital expenditures above $1 million
- Certifying the accuracy of quarterly earnings releases
Correct answer: Receiving, retaining, and treating complaints regarding accounting and internal controls, including anonymous employee submissions
SOX Section 301 mandates that audit committees establish confidential, anonymous complaint procedures — essentially requiring ethics hotlines for public companies.
Question 4: What is the concept of 'anti-fraud training' specifically designed to accomplish among non-financial employees?
- Teach employees to perform forensic accounting on their own records
- Help employees recognize red flags of fraud and understand their reporting obligations (Correct answer)
- Enable employees to conduct internal investigations independently
- Replace the need for a dedicated compliance function
Correct answer: Help employees recognize red flags of fraud and understand their reporting obligations
Anti-fraud training equips employees at all levels to recognize warning signs and empowers them to report concerns through appropriate channels.
Question 5: Which of the following represents a key difference between fraud prevention and fraud detection controls?
- Prevention controls are always more cost-effective than detection controls
- Prevention controls stop fraud before it occurs; detection controls identify fraud after it has happened (Correct answer)
- Detection controls are only used by external auditors, not management
- Prevention controls are reactive while detection controls are proactive
Correct answer: Prevention controls stop fraud before it occurs; detection controls identify fraud after it has happened
Prevention controls (like approvals and access restrictions) stop fraud from occurring, while detection controls (like reconciliations and audits) identify fraud that has already taken place.
Question 6: When an organization performs a vendor due diligence review as part of its fraud prevention program, what is the PRIMARY concern being addressed?
- Ensuring vendors comply with the organization's environmental policies
- Identifying vendors with histories of fraudulent billing, bribery, or criminal conduct (Correct answer)
- Verifying that vendors carry adequate insurance coverage
- Confirming that vendors are registered in the correct business jurisdiction
Correct answer: Identifying vendors with histories of fraudulent billing, bribery, or criminal conduct
Vendor due diligence screens for red flags such as prior fraud convictions, bribery records, or shell company structures that indicate elevated risk of procurement fraud.
Question 7: Which practice BEST helps an organization ensure its fraud prevention program remains effective over time?
- Keeping the program design confidential so fraudsters cannot anticipate controls
- Periodically assessing and updating the program based on new fraud risks, control test results, and emerging schemes (Correct answer)
- Maintaining the same controls year-over-year to ensure consistency
- Delegating full responsibility for fraud prevention to the external auditor
Correct answer: Periodically assessing and updating the program based on new fraud risks, control test results, and emerging schemes
Fraud risks evolve constantly, so the prevention program must be regularly reassessed and updated to address new schemes, operational changes, and control weaknesses.
Which anti-fraud measure most directly addresses the 'rationalization' element of the fraud triangle?