Frauditing: The Best Way to Fight Corporate Fraud Is to Build Controls That Make Fraud Harder
- John C. Blackshire, Jr.

- Aug 23
- 8 min read
Internal Controls to Prevent and Detect Corporate Fraud — October 2 and December 4, 2026
Organizations frequently respond to fraud after the money is gone.
An allegation surfaces. Internal Audit becomes involved. Investigators are called. Emails are reviewed. Transactions are reconstructed. Attorneys become involved. Management wants to know what happened.
Those activities may be necessary.
But there is a much more valuable question to ask before the fraud occurs:
What internal controls would make this fraud difficult to commit—and more likely to be detected quickly if someone tried?
That is the concept behind Frauditing.
Corporate Compliance Seminars' Frauditing – Internal Controls to Prevent and Detect Corporate Fraud is a 4-CPE Auditing webinar focused on fraud risk assessment, preventive controls, detective controls, segregation of duties, monitoring, control testing and real-world fraud scenarios. CCS emphasizes practical control execution rather than stopping with fraud theory.
Two upcoming webinar sessions are:
Friday, October 2, 2026
Friday, December 4, 2026
Frauditing – Internal Controls to Prevent and Detect Corporate Fraud | Corporate Compliance Seminars
Fraud Doesn't Begin With the Investigation
When organizations discuss fraud, attention naturally gravitates toward the fraudster.
Who did it?
How much did they steal?
How did they conceal it?
How were they caught?
Those are interesting questions.
For Internal Audit, there is another set of questions that may be more valuable:
What controls failed?
What control should have prevented the fraud?
What control should have detected it?
Why didn't management's monitoring identify it sooner?
Could the same control weakness allow another fraud to occur?
That shifts fraud auditing away from merely studying dishonest people and toward evaluating the control environment that gave them an opportunity to succeed.
CCS's program is built around this approach: mapping fraud risks to preventive and detective controls and evaluating whether those controls actually work.
Start With the Fraud Risk Assessment
An effective anti-fraud program should begin with a structured fraud risk assessment.
The organization needs to ask:
How could someone steal from us?
But that isn't enough.
Also ask:
How could someone manipulate our financial results?
How could management override established controls?
Where could two employees collude?
Which assets are easiest to misappropriate?
Which transactions involve significant judgment?
Where do employees have excessive system access?
Where could a fictitious vendor, employee or customer be created?
The CCS program specifically addresses turning fraud brainstorming into a usable risk model and examining pressure points across revenue, procure-to-pay, payroll, treasury and financial reporting.
The process should look like:
Business Process
→ Fraud Scenario
→ Fraud Risk
→ Preventive Control
→ Detective Control
→ Evidence
→ Testing
→ Monitoring
Now the organization has something it can actually audit.
The Fraud Triangle Is Only the Beginning
Auditors are familiar with the Fraud Triangle:
Pressure
Opportunity
Rationalization
Internal controls have the greatest direct influence over opportunity.
Management cannot completely control whether an employee has financial problems.
It cannot eliminate every rationalization.
But management can make fraud considerably harder to execute and conceal.
Consider an employee experiencing financial pressure.
If that employee can:
Create a Vendor
Enter an Invoice
Approve the Invoice
Change Vendor Banking Information
Initiate Payment
the organization has created an extraordinary opportunity.
The above is how Nathan Mueller walked out with $8.5 million from a major insurance company using his knowledge of the Peoplesoft application controls and the other controls at ING. Nathan Mueller: A Real-Life Fraud Case Study
That is not primarily a character problem.
It is an internal-control problem.
Preventive Controls: Make the Fraud Harder to Commit
Preventive controls are designed to stop an inappropriate transaction before it happens.
Examples include:
Segregation of Duties
Access Restrictions
Approval Requirements
Vendor Validation
System Configuration
Transaction Limits
Dual Authorization
Master-Data Controls
Automated Workflow
CCS specifically addresses segregation of duties, access controls, workflow approvals, vendor setup, master-data governance, overrides and manual-entry risks.
The key question is:
Could someone circumvent this control?
If the answer is yes, the auditor should understand how.
Detective Controls: Assume Someone Gets Through
No preventive-control system is perfect.
Management override occurs.
Employees collude.
Credentials are compromised.
Controls malfunction.
People make mistakes.
That is why organizations also need detective controls.
These might include:
Exception Reports
Reconciliations
Management Reviews
Duplicate-Payment Reports
Journal-Entry Analytics
Vendor-Master Monitoring
Access Reviews
Budget-to-Actual Analysis
Continuous Transaction Monitoring
CCS's Frauditing program specifically addresses exception reporting, fraud red flags, escalation thresholds and continuous-monitoring concepts.
The objective is straightforward:
If the preventive control fails, what will tell us?
Beware of the Control That Looks Like a Control
One of the more useful concepts in the CCS program is identifying what it calls control “fakes”—activities that appear to provide control but may not actually mitigate the risk.
Consider the familiar management-review control.
A manager signs a monthly reconciliation: Reviewed — JCB — 10/15/26
The auditor sees the signature.
Control passed?
Not necessarily.
Ask:
What did the manager review?
What criteria were used?
What discrepancies were investigated?
What threshold required follow-up?
What evidence demonstrates the review?
Could this review actually detect the fraud risk?
A signature proves that someone signed something.
It does not automatically prove an effective review control.
Segregation of Duties Still Matters
Technology has changed segregation of duties, but it has not made the principle obsolete.
Instead of asking only:
“Who signs the checks?”
auditors now need to ask:
Who can perform incompatible transactions within the system?
For procure-to-pay, examine combinations such as:
Create Vendor + Enter Invoice
Enter Invoice + Approve Invoice
Change Bank Account + Release Payment
Create Purchase Order + Confirm Receipt
For payroll:
Create Employee + Modify Pay Rate
Modify Employee + Process Payroll
For financial reporting:
Prepare Journal Entry + Approve Journal Entry
These conflicts can exist even when the organizational chart appears perfectly reasonable.
Management Override Deserves Special Attention
Management override is especially difficult because senior personnel may possess legitimate authority to bypass ordinary controls.
An executive may have authority to approve an unusual transaction.
A CFO may have access to manual journal entries.
An administrator may have privileged system access.
The question isn't simply:
“Can management override the control?”
It is:
“What control detects inappropriate management override?”
That may require:
Override Reports
Independent Review
Journal-Entry Analytics
Audit Committee Oversight
Whistleblower Mechanisms
Internal Audit Testing
Fraud controls need to recognize that sometimes the person circumventing the control is also the person with authority over it.
Collusion Can Defeat Good Control Design
Segregation of duties assumes independent people perform incompatible functions.
Collusion undermines that assumption.
Suppose one employee establishes the vendor and another approves payments.
On paper, segregation exists.
If those two employees are cooperating in the fraud, the control may fail.
This is why anti-fraud programs need multiple layers:
Prevent
Detect
Monitor
Investigate
A single control should rarely be the organization's entire defense against a significant fraud risk.
Procure-to-Pay Remains a Major Fraud Area
CCS includes P2P fraud and vendor kickbacks among its Frauditing case scenarios.
That makes sense because procure-to-pay contains numerous opportunities:
Fictitious Vendors
Vendor Kickbacks
Conflicts of Interest
Duplicate Payments
False Invoices
Invoice Splitting
Unauthorized Purchases
Vendor Bank-Account Changes
Purchases Just Below Approval Thresholds
A good fraud audit therefore doesn't simply sample invoices.
It evaluates the entire control architecture around purchasing and payment.
Financial Reporting Fraud Requires Different Controls
Asset misappropriation gets attention because it involves stealing.
Financial reporting fraud can be far more damaging.
Potential schemes may involve:
Premature Revenue Recognition
Fictitious Revenue
Improper Reserves
Manipulated Estimates
Capitalizing Expenses
Unrecorded Liabilities
Improper Journal Entries
Management Override
Here the auditor needs to think differently.
The question becomes:
Where does management have enough judgment or authority to materially influence the reported numbers?
Then:
What independent controls challenge those judgments?
Fraud Red Flags Should Trigger Questions, Not Conclusions
Suppose analytics identify:
An employee sharing an address with a vendor.
Repeated transactions immediately below an approval threshold.
A vendor receiving an unusual increase in payments.
Weekend journal entries.
Round-dollar invoices.
Frequent vendor bank-account changes.
Are these fraud?
No.
They are fraud indicators.
The appropriate progression is:
Red Flag
→ Question
→ Investigation
→ Evidence
→ Corroboration
→ Conclusion
An auditor should never confuse an anomaly with proof of misconduct.
Continuous Monitoring Can Change the Economics of Fraud Detection
Traditional auditing is retrospective.
Internal Audit examines transactions months after they occurred.
Modern data analytics can increasingly identify suspicious activity much sooner.
For example, organizations can monitor:
New vendors
Vendor-master changes
Duplicate invoices
Approval overrides
Journal entries
Bank-account changes
Dormant vendor reactivation
Access changes
Transactions below approval thresholds
CCS specifically includes continuous-monitoring concepts and decisions about what should be automated versus sampled.
This changes the objective from:
“Can we discover the fraud?”
to:
“How quickly can we identify the behavior before the loss becomes significant?”
Internal Audit Should Test the Anti-Fraud Program
An organization may have:
A Code of Conduct.
A whistleblower hotline.
Fraud policies.
Segregation-of-duties rules.
Approval requirements.
Annual fraud training.
Those things sound good.
Internal Audit should determine whether they actually work.
CCS's program specifically covers testing approvals, reconciliations, monitoring and access controls and evaluating management's overall anti-fraud program for coverage and effectiveness.
Internal Audit should ask:
Are the major fraud risks identified?
Does each significant risk have appropriate controls?
Are those controls properly designed?
Are they operating effectively?
Is there evidence of performance?
Are exceptions investigated?
Does management monitor fraud indicators?
Are corrective actions implemented?
That's assurance over the anti-fraud program.
AI Is Making Frauditing More Powerful
Artificial intelligence and analytics add another layer.
Auditors can now use technology to identify relationships and anomalies that would be extremely difficult to find manually.
For example:
Vendor address ↔ Employee address
Vendor bank account ↔ Another vendor
Invoice ↔ Duplicate invoice
Transaction ↔ Approval threshold
Journal entry ↔ Unusual user
Payment ↔ Unusual time
Vendor ↔ Sudden change in activity
CCS itself identifies data-driven fraud detection as a major component of its broader fraud and forensic training strategy.
But AI does not determine whether fraud occurred.
It tells the auditor:
“Look here.”
The auditor still has to gather and evaluate evidence.
The Audit Committee Has a Role
Fraud risk is also a governance issue.
The Audit Committee should understand:
What are our most significant fraud risks?
Where could management override controls?
What significant allegations have been received?
Are investigations independent?
Are employees comfortable reporting concerns?
What does Internal Audit believe about the anti-fraud control environment?
Are significant corrective actions overdue?
Most importantly:
Could a senior executive circumvent our normal controls without being detected?
That is a governance question worth asking.
Four Hours Focused on Practical Fraud Controls
CCS's Frauditing program is structured around six areas: how fraud occurs when controls break; fraud risk assessment; preventive controls; detective controls and monitoring; testing anti-fraud controls; and practical case examples and implementation tools. The course includes scenarios involving P2P fraud, expense fraud, revenue manipulation and vendor kickbacks.
This is an important distinction.
The program isn't simply:
“Here are interesting stories about famous frauds.”
The emphasis is:
“What control should have stopped this—and how would you test whether that control works?”
That is much more useful to an Internal Auditor.
Who Should Attend?
CCS identifies the audience as Internal Auditors, External Auditors, SOX teams, compliance and risk professionals, controllers, finance leaders, process owners, investigators, forensic accounting personnel and governance professionals.
The webinar version is listed by CCS as a 4-CPE program, and CCS's fraud and forensic curriculum emphasizes practical fraud scenarios, control weaknesses, investigative judgment, fraud risk assessment, anti-fraud controls, segregation of duties and data-driven detection.
Two Opportunities to Attend in 2026
Corporate Compliance Seminars has two upcoming webinar presentations:
Friday, October 2, 2026
The October session provides an opportunity for Internal Audit, compliance and finance professionals to strengthen their fraud-control methodology before year-end.
Friday, December 4, 2026
The December session is particularly well positioned for organizations developing their 2027 Internal Audit plans and fraud risk assessments.
One useful year-end question should be:
Which fraud risks should be explicitly included in our 2027 Internal Audit plan?
If the answer is unclear, a formal fraud risk assessment is a good place to start.
The Bottom Line: Audit the Opportunity
Auditors cannot predict which employee will become dishonest.
They can identify where an employee could commit fraud.
That distinction is critical.
Don't start by asking:
“Who do we distrust?”
Start with:
“Where does our control environment create an opportunity?”
Then follow the methodology:
Identify the Fraud Scenario
→ Assess the Risk
→ Identify the Preventive Control
→ Identify the Detective Control
→ Evaluate Design Effectiveness
→ Test Operating Effectiveness
→ Analyze Exceptions
→ Monitor Continuously
→ Correct Weaknesses
That is Frauditing.
And it moves the auditor from investigating yesterday's fraud toward helping the organization prevent tomorrow's fraud.
Corporate Compliance Seminars' Frauditing – Internal Controls to Prevent and Detect Corporate Fraud on October 2 and December 4, 2026 provides four CPE hours focused on developing those skills.
Comments