Chapter 8
Internal control, fraud
1 Internal checks
An internal check is a day-to-day procedure built into the accounting system so that one person’s work is independently checked by another person or by a later stage of the process. Examples include segregation of duties, authorisation of transactions, sequence checks, reconciliations, control totals and independent review. Internal checks are part of the wider system of internal control.
2 Types of fraud
theft or misappropriation of cash, inventory or other assets;
payroll fraud, including fictitious or “ghost” employees;
false supplier invoices, procurement fraud and kickbacks;
false expense claims;
teeming and lading, where one customer’s receipt is used to conceal the theft of another; and
fraudulent financial reporting or deliberate misrepresentation of results.
Preventing and reporting money laundering
Customer due diligence (CDD/KYC): verify the customer’s identity, beneficial owners, business and expected transactions; apply enhanced checks where risk is higher.
Ongoing monitoring and records: compare transactions with the expected business pattern, investigate unusual activity and retain identity and transaction records.
Policies and training: maintain risk-based AML procedures and train staff to recognise warning signs and avoid tipping off.
Internal reporting: an employee who has reasonable grounds for suspicion reports promptly to the Money Laundering Reporting Officer (MLRO).
External reporting: the MLRO evaluates the internal report and, where required, submits a Suspicious Activity Report (SAR) to the appropriate authority. The employee must not alert the customer.Internal controls
The term ‘internal controls’ refers to the collection of mechanisms whereby an organisation tries to ensure that all its transactions are properly authorised and recorded, and that its assets are safeguarded.
The proper management of a business (and indeed now part of corporate governance requirements) means that there has to be a good system of internal control in place if directors and other managers are going to exercise their stewardship responsibilities correctly. It is the directors’ responsibility to ensure that there is a good system of internal control operating.
The system of internal controls fall into two parts:
Control environment. This essentially refers to the culture within the organisation. Some organisations put a very high priority on having a good system of internal control in place whereas others see these as a nuisance. If the system of internal control is going to be effective there must be a good control environment, otherwise detailed controls which are there in theory would simply be ignored in practice because people don’t feel that these are important.
Detailed control processes. For example:
If someone works overtime you expect this to be authorised by a manager.
Once a supplier’s invoice has been paid, you expect that to be cancelled in some way to prevent it being paid twice.
Before you send goods to a new customer you should take up credit references, perhaps by writing to their bank and then setting a credit limit.
It should be impossible to dispatch goods to that customer if it puts it over their credit limit
There should be a system of reviewing receivables and following up slow payments to try to prevent the occurrence of bad debts.
Segregation of duties means that each part of a transaction is carried out by a different person. For example, one person orders goods, another checks their receipt, another checks the invoice and another pays it. Splitting up a transaction in this way reduces the incidence of fraud and error.
Internal control methods include
Physical safeguarding (eg for cash and inventory)
Authorisation (eg authorising overtime)
Segregation of duties (eg splitting up a transaction so that several people are involved)
Reconciliations (eg comparing the cash book to the bank statement or payables balances to suppliers’ statements)
Trial balances and control account reconciliations
Recalculation and re-performance (eg recalculating an invoice and ensuring the correct prices are used)
Internal audit.
Some businesses deal with clients’ money. For example, lawyers often hold clients’ cash during property purchase transactions so that when all the legal formalities are sorted out, payment can be quickly made by the lawyer on behalf of the client. There are strict rules that separate clients’ money from that of the legal firm and client money must be kept in a completely separate client bank account. If the firm of lawyers fails financially, the clients’ money is kept safe as it has been held in the separate account. Mixing up client cash with the company's cash is likely to lead to severe disciplinary measures against that company.
3 Controls in IT systems
IT poses particular risks to organisations’ internal control and information systems. Once an error is introduced many transactions can be quickly affected and this can lead to their operations being severely disrupted and subsequently to lost sales, increased costs, incorrect decisions and reputational damage.
3.1 Risks include:
Reliance on systems or programs that are inaccurately processing data, processing inaccurate data so that they report inaccurate, misleading results.
Unauthorised access to data leading to destruction of data, improper changes to data, or inaccurate recording of transactions.
Particular risks may arise where multiple users access a common database on which everyone in the organisation relies. The data could be incorrectly amended and all users will be affected.
The possibility of IT personnel gaining access privileges beyond those necessary to perform their assigned duties.
Unauthorised changes to data in master files. For example, changing a selling prices or credit limit.
Unauthorised changes to systems or programs so that they no longer operate correctly and reliably.
Failure to make necessary changes to systems or programs to keep them up-to-date and in line with legal and business requirements.
Potential loss of data or inability to access data as required. This could prevent, for example, the processing of internet sales. These problems can be caused by viruses, hacking (improper outside access to data) and disasters affecting the IT system, such as a fire destroying the computers.
Cyber-attacks in which outside actors might change or steal information, take over processes such as the computerised control of machines, mount denial of service attacks in which web-sites are bombarded messages or demands for information so that the web-site goes down. Cybersecurity is the system of technology, processes and controls used to protect systems form cyber attacks.
3.2 Controls in computer systems
Controls in computer systems can be categorised as general controls and application controls.
General controls:
These are policies and procedures that relate to the computer environment and which are therefore relevant to all applications. They support the effective functioning of application controls by helping to ensure the continued proper operation of information systems. General IT controls that maintain the integrity of information and security of data commonly include controls over the following:
Data centre and network operations. A data centre is a central repository of data and it is important that controls there include back-up procedures, anti-virus software and firewalls to prevent hackers gaining access and other forms of cyber attack. Organisations should also have disaster recovery plans in place to minimise damage caused by events such as floods, fire and terrorist activities.
System software acquisition, change and maintenance. System software refers to operating systems, such as Windows or Apple’s OS. These systems often undergo updates as problems and vulnerabilities are identified and it is important for updates to be implemented promptly.
Application system acquisition, development, and maintenance. Applications systems are programs that carry out specific operations needed by the company – such as calculating wages and invoices and forecasting inventory usage. Just as much damage can be done by the incorrect operation of software as by inputting incorrect data. For example, think of the damage that could be done if sales analyses were incorrectly calculated and presented. Management could be led to withdraw products that are in fact very popular. All software amendments must be carefully specified and tested before implementation.
Access security. Physical access to file servers should be carefully controlled. This is where the company keeps it data and it is essential that this is safeguarded: data will usually endow companies with competitive advantage. Access to processing should also be restricted, typically through the use of log-on procedures and passwords.
Any system connected to the Internet must be protected by:
Passwords.
Virus-checkers
Fire-walls (which detect and prevent unauthorised access from outside the system).
Encryption. Messages are encrypted before being sent and can be decrypted only by the proper recipient. Anyone intercepting the message will be unable to understand it and will be unable to change it without detection.
Application controls:
Application controls are manual or automated procedures that typically operate at a business process level, such as the processing of sales orders, wages and payments to suppliers.
These controls help ensure that transactions are authorised, and are completely and accurately recorded, processed and reported. Examples include:
Edit checks of input data. For example, range tests can be applied to reject data outside an allowed range; format checks ensure that data is input in the correct format (credit card numbers should be 12 digits long; dependency checks where one piece of data implies something about another (you have probably had a travel booking rejected because you inadvertently had a return date earlier than the outward date); check digits, where a number, such as an account number, is specially constructed to comply with mathematical rules.
Numerical sequence checks to ensure that all accountable documents have been processed.
Drop down menus which constrain choices and ensure only allowable entries can be made.
Batch total checks. Here, the total value of the documents to be processed (for example ,invoices from suppliers) is first calculated. Each one of the batch of documents is then keyed in and the computer checks that the total of the documents entered agrees with the pre-established batch total.
On-line, real time systems can pose particular risks because any number of employees could be authorised to process certain transactions. Anonymity raises the prospect of both carelessness and fraud so it is important to be able to trace all transactions to their originator. This can be done by tagging each transactions with the identity of the person responsible.
Cyber-espionage is also a growing threat. Governments, competitors and criminals attempt to steal intellectual property or information about customers and contracts. Quite obviously the theft of valuable know-how will undermine a company’s competitive advantage and it is essential that for organisations to defend themselves as far as possible against these threats.
4 Implications of fraud
If a good system of internal control is not in place and if corporate governance is not operating correctly then there is a much higher chance that fraud will occur, and this has got serious implications.
Financial. The company may find that it hasn’t made the profit it thought, it may have lost assets, it might have a liquidity crisis. Most fraud means removing assets from a company and, of course, this will adversely affects its performance.
Misrepresentation. At a higher level directors sometimes commit fraud to misrepresent how the company is actually doing, and there have been several high profile events recently where financial institutions have pretended to be in a much better situation than they actually were.
If the finances of the company are incorrectly recorded then incorrect decisions could be made. The company might decide to expand when in fact the cash is not there or it may think a particular cost is very high, but that cost has artificially been boosted because of a fraud. The misrepresentation could also encourage investors to pay a higher price for shares than they are actually worth.
Reputation. The reputation of the company could be badly affected, and indeed many companies, for relatively minor frauds, prefer to keep these secret. It doesn’t look good if the directors have to admit that someone has been defrauding the company over a number of years. It rather makes people ask: what have the directors been doing? How competent are they? Do we want to have dealings with that company?
For fraud to occur the following conditions are necessary:
Opportunity: for example, poor internal control, unguarded inventory and unguarded cash
Motivation/incentive: for example, an employee being short of money - or just simple greed.
Attitude: the willingness to carry out the fraud because of poor ethical principles and poor guidance.
5 Detecting and preventing fraud
Preventing and detecting fraud depends on the following:
First, a good internal control system. As we said before, make sure that overtime payments are authorised, purchases are authorised, invoices are cancelled, bank reconciliations are performed and so on. This makes it much more difficult that either innocent or deliberate manipulation of figures can occur. Part of the internal control system will be internal audit. This is a team of people within the organisation whose function is to go around the organisation, checking if the system of internal control is effective and being operated as expected.
When assigning responsibilities, keep internal audit distinct: it tests whether controls work effectively; preparing financial statements and sales budgets belongs to accounting or management functions.
Secondly, ethics. It goes without saying that if everyone within the company has high ethical principles, fraud will not be committed. It’s therefore essential to emphasise the role of ethics. This is particularly important at the higher levels of the company where managers might be induced to misrepresent figures so the company appears to be doing well.
Both control systems and ethics depend on training. If training is not given:
How will people know how to act appropriately?
How to comply with the internal control system as set down?
How to deal with ethical dilemmas? (Which can sometimes mean asking for help and advice.)
6 Money laundering: introduction
Money laundering is a process whereby the proceeds of criminal activity are converted into assets appearing to have a legitimate origin.
Dirty money is made clean-looking. The money typically comes from extortion, drugs, prostitution, illegal gambling, illegal arms sales and people-trafficking.
7 The stages of money laundering
The process of money laundering can be described in the following three steps:
Placement: this is the process of introducing the money into a legitimate business activity so that its origins appear bona fide. Methods include:
Blending funds: mixing the dirty money with legitimate cash such as boosting the cash takings n a business. Tax will have to be paid, but that’s a small price if the remainder of the money is safe-guarded.
Gambling: winnings are artificially increased and this can be used to explain the source of the funds.
Currency smuggling: move the cash to a lax jurisdiction where few questions will be asked.
You will notice that cash transactions facilitate placement because cash is relatively difficult to trace compared to bank or credit transactions
Layering: repeated transfer of money through different bank accounts and different countries in an attempt to conceal or camouflage its origins. That way, even if the placement process becomes known to the authorities it becomes difficult for them to trace the cash and recover it.
Integration: the movement of previously laundered money into the economy so that the money can be safely used. Examples include the purchase of assets such as expensive cars and art works and jewellery.
8 Legislation
Many countries now have legislation attacking money laundering and the proceeds of crime and also to interfere with money being used by terrorism organisations. As well as creating criminal offences for the immediate perpetrators of the crimes the legislation can also cover the behaviour and responsibilities of auditors and accountants.
In the UK the Proceeds of Crime Act 2002 sets out five types of offence:
Concealing, disguising, converting or transferring money that is from the proceeds of crime.
Entering into an arrangement to launder the proceeds of crime or having the suspicion that money laundering is taking place yet not reporting it.
Acquisition, use and possession of criminal property
Failure to disclose
Tipping off
The penalties are severe. For example, taking part in money laundering attracts a maximum prison sentence of 14 years and/or a fine.
Note that if the prosecution can show that a defendant had a even suspicion that money had criminal origins that the defendant can be found guilty of these crimes. So, ‘turning a blind eye’ is no defence
Obviously an accountant could be directly participating in or abetting money laundering, but here we will assume you are all ethical and won’t take part in that. However, it is easier to inadvertently commit some of the other offences.
For example, suspicions would be expected to arise if:
You work in a bank and see a customer dealing in large amounts of cash without any reasonable explanation of their origin.
You are an auditor and see cash passing through various banks accounts for no apparent reason.
Tipping off is the offence of acting in a way that discloses to the potential suspect information that is likely to prejudice an investigation. So, saying to a client “I think this is money laundering and I am going to report my suspicions to the authorities” is clearly tipping off. However, what if you repeatedly ask for evidence about a transaction. The client then knows that you might be suspicious and that your next step is to report the matter. However, if you make no enquiries at all or inadequate enquiries, you might fail to uncover a perfectly innocent explanation.
9 Risk factors for money laundering
A cash-based business
Many similar deposits and withdrawals in various bank accounts for not obvious reason
Many jurisdiction involved in the transfer of money
The use of tax havens
Bearer bonds or cheques
Higher profits than could be reasonably expected
Poor documentation for transactions
Secrecy
Internal control and fraud
7 questionsAnswer the questions one at a time. Your progress is saved so you can leave and come back.
Open chapter practice

