CFS Fraud Risk Assessment Frameworks 3 — Questions and Answers
Question 1: The 'fraud triangle' is most useful in a fraud risk assessment for:
- Calculating the financial impact of detected fraud
- Understanding motivating conditions that enable fraud to occur (Correct answer)
- Designing detective controls for financial reporting
- Determining prosecution strategy after fraud is discovered
Correct answer: Understanding motivating conditions that enable fraud to occur
The fraud triangle (pressure, opportunity, rationalization) helps assessors understand the conditions that make individuals susceptible to committing fraud.
Question 2: In a fraud risk assessment, 'anti-fraud controls' are evaluated on which two dimensions?
- Speed and accuracy
- Design effectiveness and operating effectiveness (Correct answer)
- Cost and complexity
- Preventive scope and detective scope
Correct answer: Design effectiveness and operating effectiveness
Controls are evaluated on whether they are properly designed to address the risk (design effectiveness) and whether they are actually functioning as intended (operating effectiveness).
Question 3: Which scenario represents an example of 'control override' that a fraud risk assessment should specifically address?
- An employee failing to follow the expense reimbursement process
- A manager approving transactions that bypass the normal authorization limits (Correct answer)
- A vendor submitting duplicate invoices to accounts payable
- An IT technician accidentally deleting transaction logs
Correct answer: A manager approving transactions that bypass the normal authorization limits
Management override of controls is a specific fraud risk where individuals with authority circumvent established controls, and it must be explicitly assessed.
Question 4: During a fraud risk assessment workshop, the facilitator asks participants to consider 'what if a trusted employee decided to steal?' This approach is known as:
- Scenario analysis (Correct answer)
- Gap analysis
- Root cause analysis
- Materiality assessment
Correct answer: Scenario analysis
Scenario analysis involves constructing hypothetical fraud situations to stress-test the organization's controls and identify vulnerabilities.
Question 5: According to ISO 31000, the fraud risk assessment process should be:
- Conducted once during organizational formation and updated only after incidents
- An iterative process integrated into organizational management (Correct answer)
- Delegated entirely to external consultants for objectivity
- Performed only when required by regulatory mandate
Correct answer: An iterative process integrated into organizational management
ISO 31000 emphasizes that risk management, including fraud risk assessment, should be iterative, dynamic, and integrated into the organization's ongoing management activities.
Question 6: Which factor would most INCREASE the assessed likelihood of a fraud scheme occurring?
- Strong segregation of duties in the affected process
- Recent turnover in the internal audit function (Correct answer)
- Mandatory vacation policies for key employees
- A zero-tolerance fraud policy communicated to all staff
Correct answer: Recent turnover in the internal audit function
Turnover in internal audit reduces the organization's monitoring capacity, which is a control weakness that increases the likelihood of undetected fraud.
Question 7: A fraud risk heat map visually depicts risks based on which two factors?
- Frequency and recoverability
- Likelihood and impact (Correct answer)
- Detection time and monetary loss
- Perpetrator level and concealment method
Correct answer: Likelihood and impact
A heat map plots fraud risks on a matrix using likelihood (probability) on one axis and impact (consequence) on the other to prioritize risk responses.
The 'fraud triangle' is most useful in a fraud risk assessment for: