top of page
Search

Frauditing: The Best Way to Fight Corporate Fraud Is to Build Controls That Make Fraud Harder

Internal Controls to Prevent and Detect Corporate Fraud — October 2 and December 4, 2026


Organizations frequently respond to fraud after the money is gone.


An allegation surfaces. Internal Audit becomes involved. Investigators are called. Emails are reviewed. Transactions are reconstructed. Attorneys become involved. Management wants to know what happened.


Those activities may be necessary.


But there is a much more valuable question to ask before the fraud occurs:

What internal controls would make this fraud difficult to commit—and more likely to be detected quickly if someone tried?

That is the concept behind Frauditing.


Corporate Compliance Seminars' Frauditing – Internal Controls to Prevent and Detect Corporate Fraud is a 4-CPE Auditing webinar focused on fraud risk assessment, preventive controls, detective controls, segregation of duties, monitoring, control testing and real-world fraud scenarios. CCS emphasizes practical control execution rather than stopping with fraud theory.


Two upcoming webinar sessions are:

  • Friday, October 2, 2026

  • Friday, December 4, 2026



Fraud Doesn't Begin With the Investigation

When organizations discuss fraud, attention naturally gravitates toward the fraudster.


Who did it?


How much did they steal?


How did they conceal it?


How were they caught?


Those are interesting questions.


For Internal Audit, there is another set of questions that may be more valuable:

What controls failed?
What control should have prevented the fraud?
What control should have detected it?
Why didn't management's monitoring identify it sooner?
Could the same control weakness allow another fraud to occur?

That shifts fraud auditing away from merely studying dishonest people and toward evaluating the control environment that gave them an opportunity to succeed.


CCS's program is built around this approach: mapping fraud risks to preventive and detective controls and evaluating whether those controls actually work.


Start With the Fraud Risk Assessment

An effective anti-fraud program should begin with a structured fraud risk assessment.


The organization needs to ask:

How could someone steal from us?

But that isn't enough.


Also ask:

How could someone manipulate our financial results?
How could management override established controls?
Where could two employees collude?
Which assets are easiest to misappropriate?
Which transactions involve significant judgment?
Where do employees have excessive system access?
Where could a fictitious vendor, employee or customer be created?

The CCS program specifically addresses turning fraud brainstorming into a usable risk model and examining pressure points across revenue, procure-to-pay, payroll, treasury and financial reporting.


The process should look like:


Business Process

Fraud Scenario

Fraud Risk

Preventive Control

Detective Control

Evidence

Testing

Monitoring


Now the organization has something it can actually audit.


The Fraud Triangle Is Only the Beginning

Auditors are familiar with the Fraud Triangle:

  • Pressure

  • Opportunity

  • Rationalization


Internal controls have the greatest direct influence over opportunity.


Management cannot completely control whether an employee has financial problems.


It cannot eliminate every rationalization.


But management can make fraud considerably harder to execute and conceal.


Consider an employee experiencing financial pressure.


If that employee can:


Create a Vendor


Enter an Invoice


Approve the Invoice


Change Vendor Banking Information


Initiate Payment


the organization has created an extraordinary opportunity.


The above is how Nathan Mueller walked out with $8.5 million from a major insurance company using his knowledge of the Peoplesoft application controls and the other controls at ING. Nathan Mueller: A Real-Life Fraud Case Study


That is not primarily a character problem.


It is an internal-control problem.


Preventive Controls: Make the Fraud Harder to Commit

Preventive controls are designed to stop an inappropriate transaction before it happens.


Examples include:

  • Segregation of Duties

  • Access Restrictions

  • Approval Requirements

  • Vendor Validation

  • System Configuration

  • Transaction Limits

  • Dual Authorization

  • Master-Data Controls

  • Automated Workflow


CCS specifically addresses segregation of duties, access controls, workflow approvals, vendor setup, master-data governance, overrides and manual-entry risks.


The key question is:

Could someone circumvent this control?

If the answer is yes, the auditor should understand how.


Detective Controls: Assume Someone Gets Through

No preventive-control system is perfect.


Management override occurs.


Employees collude.


Credentials are compromised.


Controls malfunction.


People make mistakes.


That is why organizations also need detective controls.


These might include:

  • Exception Reports

  • Reconciliations

  • Management Reviews

  • Duplicate-Payment Reports

  • Journal-Entry Analytics

  • Vendor-Master Monitoring

  • Access Reviews

  • Budget-to-Actual Analysis

  • Continuous Transaction Monitoring


CCS's Frauditing program specifically addresses exception reporting, fraud red flags, escalation thresholds and continuous-monitoring concepts.


The objective is straightforward:

If the preventive control fails, what will tell us?

Beware of the Control That Looks Like a Control

One of the more useful concepts in the CCS program is identifying what it calls control “fakes”—activities that appear to provide control but may not actually mitigate the risk.


Consider the familiar management-review control.


A manager signs a monthly reconciliation: Reviewed — JCB — 10/15/26


The auditor sees the signature.


Control passed?


Not necessarily.


Ask:

What did the manager review?
What criteria were used?
What discrepancies were investigated?
What threshold required follow-up?
What evidence demonstrates the review?
Could this review actually detect the fraud risk?

A signature proves that someone signed something.


It does not automatically prove an effective review control.

Segregation of Duties Still Matters

Technology has changed segregation of duties, but it has not made the principle obsolete.

Instead of asking only:

“Who signs the checks?”

auditors now need to ask:

Who can perform incompatible transactions within the system?

For procure-to-pay, examine combinations such as:

  • Create Vendor + Enter Invoice

  • Enter Invoice + Approve Invoice

  • Change Bank Account + Release Payment

  • Create Purchase Order + Confirm Receipt


For payroll:

  • Create Employee + Modify Pay Rate

  • Modify Employee + Process Payroll


For financial reporting:

  • Prepare Journal Entry + Approve Journal Entry


These conflicts can exist even when the organizational chart appears perfectly reasonable.


Management Override Deserves Special Attention

Management override is especially difficult because senior personnel may possess legitimate authority to bypass ordinary controls.


An executive may have authority to approve an unusual transaction.


A CFO may have access to manual journal entries.


An administrator may have privileged system access.


The question isn't simply:

“Can management override the control?”

It is:

“What control detects inappropriate management override?”

That may require:

  • Override Reports

  • Independent Review

  • Journal-Entry Analytics

  • Audit Committee Oversight

  • Whistleblower Mechanisms

  • Internal Audit Testing


Fraud controls need to recognize that sometimes the person circumventing the control is also the person with authority over it.


Collusion Can Defeat Good Control Design

Segregation of duties assumes independent people perform incompatible functions.


Collusion undermines that assumption.


Suppose one employee establishes the vendor and another approves payments.


On paper, segregation exists.


If those two employees are cooperating in the fraud, the control may fail.


This is why anti-fraud programs need multiple layers:


Prevent


Detect


Monitor


Investigate


A single control should rarely be the organization's entire defense against a significant fraud risk.


Procure-to-Pay Remains a Major Fraud Area

CCS includes P2P fraud and vendor kickbacks among its Frauditing case scenarios.


That makes sense because procure-to-pay contains numerous opportunities:

  • Fictitious Vendors

  • Vendor Kickbacks

  • Conflicts of Interest

  • Duplicate Payments

  • False Invoices

  • Invoice Splitting

  • Unauthorized Purchases

  • Vendor Bank-Account Changes

  • Purchases Just Below Approval Thresholds


A good fraud audit therefore doesn't simply sample invoices.


It evaluates the entire control architecture around purchasing and payment.


Financial Reporting Fraud Requires Different Controls

Asset misappropriation gets attention because it involves stealing.


Financial reporting fraud can be far more damaging.


Potential schemes may involve:

  • Premature Revenue Recognition

  • Fictitious Revenue

  • Improper Reserves

  • Manipulated Estimates

  • Capitalizing Expenses

  • Unrecorded Liabilities

  • Improper Journal Entries

  • Management Override


Here the auditor needs to think differently.


The question becomes:

Where does management have enough judgment or authority to materially influence the reported numbers?

Then:

What independent controls challenge those judgments?

Fraud Red Flags Should Trigger Questions, Not Conclusions

Suppose analytics identify:

  • An employee sharing an address with a vendor.

  • Repeated transactions immediately below an approval threshold.

  • A vendor receiving an unusual increase in payments.

  • Weekend journal entries.

  • Round-dollar invoices.

  • Frequent vendor bank-account changes.


Are these fraud?


No.


They are fraud indicators.


The appropriate progression is:


Red Flag

Question

Investigation

Evidence

Corroboration

Conclusion


An auditor should never confuse an anomaly with proof of misconduct.


Continuous Monitoring Can Change the Economics of Fraud Detection

Traditional auditing is retrospective.


Internal Audit examines transactions months after they occurred.


Modern data analytics can increasingly identify suspicious activity much sooner.


For example, organizations can monitor:

  • New vendors

  • Vendor-master changes

  • Duplicate invoices

  • Approval overrides

  • Journal entries

  • Bank-account changes

  • Dormant vendor reactivation

  • Access changes

  • Transactions below approval thresholds


CCS specifically includes continuous-monitoring concepts and decisions about what should be automated versus sampled.


This changes the objective from:

“Can we discover the fraud?”

to:

“How quickly can we identify the behavior before the loss becomes significant?”

Internal Audit Should Test the Anti-Fraud Program

An organization may have:

  • A Code of Conduct.

  • A whistleblower hotline.

  • Fraud policies.

  • Segregation-of-duties rules.

  • Approval requirements.

  • Annual fraud training.


Those things sound good.


Internal Audit should determine whether they actually work.


CCS's program specifically covers testing approvals, reconciliations, monitoring and access controls and evaluating management's overall anti-fraud program for coverage and effectiveness.


Internal Audit should ask:

Are the major fraud risks identified?
Does each significant risk have appropriate controls?
Are those controls properly designed?
Are they operating effectively?
Is there evidence of performance?
Are exceptions investigated?
Does management monitor fraud indicators?
Are corrective actions implemented?

That's assurance over the anti-fraud program.


AI Is Making Frauditing More Powerful

Artificial intelligence and analytics add another layer.


Auditors can now use technology to identify relationships and anomalies that would be extremely difficult to find manually.


For example:

  • Vendor address ↔ Employee address

  • Vendor bank account ↔ Another vendor

  • Invoice ↔ Duplicate invoice

  • Transaction ↔ Approval threshold

  • Journal entry ↔ Unusual user

  • Payment ↔ Unusual time

  • Vendor ↔ Sudden change in activity


CCS itself identifies data-driven fraud detection as a major component of its broader fraud and forensic training strategy.


But AI does not determine whether fraud occurred.


It tells the auditor:

“Look here.”

The auditor still has to gather and evaluate evidence.


The Audit Committee Has a Role

Fraud risk is also a governance issue.


The Audit Committee should understand:

What are our most significant fraud risks?
Where could management override controls?
What significant allegations have been received?
Are investigations independent?
Are employees comfortable reporting concerns?
What does Internal Audit believe about the anti-fraud control environment?
Are significant corrective actions overdue?

Most importantly:

Could a senior executive circumvent our normal controls without being detected?

That is a governance question worth asking.


Four Hours Focused on Practical Fraud Controls

CCS's Frauditing program is structured around six areas: how fraud occurs when controls break; fraud risk assessment; preventive controls; detective controls and monitoring; testing anti-fraud controls; and practical case examples and implementation tools. The course includes scenarios involving P2P fraud, expense fraud, revenue manipulation and vendor kickbacks.


This is an important distinction.


The program isn't simply:

“Here are interesting stories about famous frauds.”

The emphasis is:

“What control should have stopped this—and how would you test whether that control works?”

That is much more useful to an Internal Auditor.


Who Should Attend?

CCS identifies the audience as Internal Auditors, External Auditors, SOX teams, compliance and risk professionals, controllers, finance leaders, process owners, investigators, forensic accounting personnel and governance professionals.

The webinar version is listed by CCS as a 4-CPE program, and CCS's fraud and forensic curriculum emphasizes practical fraud scenarios, control weaknesses, investigative judgment, fraud risk assessment, anti-fraud controls, segregation of duties and data-driven detection.


Two Opportunities to Attend in 2026

Corporate Compliance Seminars has two upcoming webinar presentations:


Friday, October 2, 2026

The October session provides an opportunity for Internal Audit, compliance and finance professionals to strengthen their fraud-control methodology before year-end.


Friday, December 4, 2026

The December session is particularly well positioned for organizations developing their 2027 Internal Audit plans and fraud risk assessments.


One useful year-end question should be:

Which fraud risks should be explicitly included in our 2027 Internal Audit plan?

If the answer is unclear, a formal fraud risk assessment is a good place to start.


The Bottom Line: Audit the Opportunity

Auditors cannot predict which employee will become dishonest.


They can identify where an employee could commit fraud.


That distinction is critical.


Don't start by asking:

“Who do we distrust?”

Start with:

“Where does our control environment create an opportunity?”

Then follow the methodology:


Identify the Fraud Scenario

Assess the Risk

Identify the Preventive Control

Identify the Detective Control

Evaluate Design Effectiveness

Test Operating Effectiveness

Analyze Exceptions

Monitor Continuously

Correct Weaknesses


That is Frauditing.


And it moves the auditor from investigating yesterday's fraud toward helping the organization prevent tomorrow's fraud.


Corporate Compliance Seminars' Frauditing – Internal Controls to Prevent and Detect Corporate Fraud on October 2 and December 4, 2026 provides four CPE hours focused on developing those skills.


 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page