Fraud Risk Assessment Frameworks Flashcards
7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Fraud Risk Assessment Frameworks flashcards as text
When the fraud risk assessment identifies a gap between inherent risk and existing controls, management should:
Answer: Develop a risk response plan to close the gap
A control gap requires management to design and implement additional or improved controls as part of a structured risk response plan.
Which of the following is a PRIMARY responsibility of the board of directors in the fraud risk management framework?
Answer: Overseeing management's fraud risk assessment process
The board provides oversight of management's fraud risk management activities, ensuring the program is adequate and functioning effectively.
In the context of fraud risk assessments, 'inherent risk' refers to:
Answer: The fraud risk that exists in the absence of any controls
Inherent risk is the raw exposure to fraud that exists in a process or area before considering the effect of any preventive or detective controls.
A company processes thousands of small vendor payments daily. Which fraud risk assessment approach would be MOST efficient for identifying anomalies?
Answer: Data analytics to examine 100% of transactions
Data analytics enables examination of entire populations of transactions to detect anomalies, duplicate payments, and patterns indicative of fraud at a scale manual testing cannot match.
Which element of the 'fraud diamond' theory extends the fraud triangle by adding a fourth element?
Answer: Capability
The fraud diamond adds 'capability' to the triangle's pressure, opportunity, and rationalization, recognizing that a person must also have the skills and position to execute the fraud.
When assessing fraud risks in a decentralized organization with multiple subsidiaries, which approach is MOST comprehensive?
Answer: Conducting separate assessments at each subsidiary and aggregating results
Each subsidiary may face unique fraud risks based on its geography, operations, and control environment, so separate assessments that are then aggregated provide the most complete picture.
The primary purpose of a fraud risk register is to:
Answer: Record identified fraud risks, their assessments, and assigned responses
A fraud risk register serves as the central repository for all identified fraud risks, their likelihood/impact ratings, existing controls, and planned remediation actions.