Chapter 3 Solutions Fraud, Ethics, and Internal Control
Turner/Accounting Information Systems, 2e
Solutions Manual
Chapter 3
Concept Check
1. b
2. c
3. a
4. d
5. d
6. b
Discussion Questions
15. (SO 1) Management is held accountable to various parties, both internal and
external to the business organization. To whom does management have a
stewardship obligation and to whom does it have reporting responsibilities?
16. (SO 2, 4) If an employee made a mistake that resulted in a loss of company funds
and misstated financial reports, would the employee be guilty of fraud? Discuss. No,
a mistake, or unintentional error, does not constitute fraud. In this situation, there is
no theft or concealment, so fraud does not exist.
17. (SO 2, 3) Do you think it is possible that a business manager may perpetrate fraud
and still have the company’s best interest in mind? Discuss. Student responses may
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-2
18. (SO 7) Distinguish between internal and external sources of computer fraud.
Employees are the source of internal computer fraud. When employees misuse the
computer system to commit fraud (through manipulation of inputs, programs, or
outputs), this is known as internal computer fraud. On the other hand, external
19. (SO 7) Identify and explain the three types of internal source computer fraud. The
three types of internal source computer fraud are input manipulation, program
20. (SO 7) Describe three popular program manipulation techniques. The salami
technique accomplishes a fraud by altering small “slices” of computer information.
These slices of fraud are difficult to detect because they are so small, but they may
accumulate to a considerable amount if they are carried out consistently across
many accounts. This is often accomplished by rounding or applying minor
adjustments. The perpetrator typically steals the amounts represented by these
slices or uses them to his or her benefit.
21. (SO 7) Distinguish between Internet spoofing and e-mail spoofing. Internet spoofing
involves a person working through the Internet to access a computer network while
pretending to be a trusted source. The packet of data containing the Internet
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-3
protocol (IP) address contains malicious data such as viruses or programs that
capture passwords and log-in names. E-mail spoofing bombards employee e-mail
accounts with junk mail intended to scam the recipients.
22. (SO 10) What are the objectives of a system of internal control? The objectives of
an internal control system are as follows:
To safeguard assets from fraud or errors
23. (SO 10) Name and distinguish among the three types of internal controls. The three
types of internal controls are preventative controls, detective controls, and corrective
24. (SO 10) Identify the COSO report’s five interrelated components of internal controls.
25. (SO 10) Name the COSO report’s five internal controls activities. According to the
26. (SO 10) Distinguish between general and specific authorization. General
authorization is a set of guidelines that allows transactions to be completed as long
as they fall within established parameters. Specific authorization means that explicit
approval is needed for that single transaction to be completed.
27. (SO 10) Due to cost/benefit considerations, many business organizations are unable
to achieve complete segregation of duties. What else could they do to minimize
risks? Close supervision may serve as a compensating control to lessen the risk of
negative effects when other controls, especially segregation of duties, are lacking.
28. (SO 10) Why is a policies and procedures manual considered an element of internal
control? Formally written and thorough documentation on prescribed policies and
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-4
29. (SO 10) Why does a company need to be concerned with controlling access to its
records? Securing and protecting company records is important to ensure that they
30. (SO 10) Many companies have mandatory vacation and periodic job rotation
policies. Discuss how these practices can be useful in strengthening internal
31. (SO 10) Name the objectives of an effective accounting system. An effective
accounting system must accomplish the following four objectives:
32. (SO 10) What does it mean when information flows “down, across, and up the
organization”? A business organization must implement procedures to assure that its
33. (SO 10) Provide examples of continuous monitoring and periodic monitoring. Any
ongoing review activity may be an example of continuous monitoring, such as a
supervisor’s examination of financial reports and a computer system’s review
modules. An example of periodic monitoring is an annual audit performed by a CPA
firm or a cyclical review performed by internal auditors.
34. (SO 10) What are the factors that limit the effectiveness of internal controls? It is not
possible for an internal control system to provide absolute assurance because of the
following factors that limit the effectiveness of internal controls:
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-5
35. (SO 11) Identify and describe the five categories of the AICPA Trust Services
Principles. The AICPA Trust Services Principles are divided into the following five
categories of risks and controls:
Security. Security is concerned with the risk of unauthorized physical and logical
36. (SO 11) Distinguish between the Trust Services Principles of privacy and
confidentiality. Both privacy and confidentiality are concerned with the risk of in
37. (SO 10) Identify the four domains of high-level internal control. As set forth in
Appendix B, COBIT establishes four domains of high level control objectives. These
include planning and organization, acquisition and implementation, delivery and
support, and monitoring.
Brief Exercises
38. (SO 2, 3) What possible motivation might a business manager have for perpetrating
fraud? Management might be motivated to perpetrate fraud in order to improve the
39. (SO 5) Discuss whether any of the following can be examples of customer fraud:
An employee billed a customer twice for the same transaction. This is not an
example of customer fraud; rather, the customer is being defrauded in this
scenario. This is an example of employee fraud (assuming that the double-billing
was intentional and the resulting cash receipts are stolen by employees).
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-6
40. (SO 7) Explain the relationship between computer hacking and industrial espionage.
Give a few additional examples of how hacking could cause damage in a business.
Computer hacking is the term commonly used for computer network break-ins.
Hacking may be undertaken for various purposes, including theft of proprietary
information, credit card theft, destruction or alteration of data, or merely thrill
41. (SO 9) What are some ways in which a business could promote its code of ethics?
42. (SO 10) Describe why the control environment is regarded as the foundation of a
business’s system of internal control. The control environment is regarded as the
foundation of a system of internal controls because it sets the tone of an
43. (SO 10) Think of a job you have held, and consider whether the control environment
was risky or conservative. Describe which you chose and why. Student responses
will vary. Characteristics of a risky control environment include absence of a code or
ethics or lack of enforcement of a code of ethics, aggressive management
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-7
44. (SO 10) Identify the steps involved in risk assessment. Do you think it would be
effective for an organization to hire external consultants to develop its risk
assessment plan? The steps involved in risk assessment include:
Identify the sources of risk, both internal and external.
Determine the impact of such risks in terms of finances and reputation.
45. (SO 10, 11) Discuss the accuracy of the following statements regarding internal
control:
The more computerized applications within a company’s accounting system, the
lower the risk will be that fraud or errors will occur. It is not necessarily true that
extensive computerized application will lower a company’s risk of fraud. This is
Problems
46. (SO 10) Identify whether each of the following accounting positions or duties
involves authorization, recording, or custody:
Chapter 3 Solutions Fraud, Ethics, and Internal Control
47. (SO 10) Identify whether each of the following activities represents preventative
controls, detective controls, or corrective controls:
job rotation – Detective
preparation of a bank reconciliation – Corrective
48. (SO 10) Shown is a list of selected sources of internal control guidelines, given in
order of issuance, followed by a list of primary purposes. Match each guideline with
its primary purpose.
I. Foreign Corrupt Practices Act b. Prevented bribery and established internal
control guidelines.
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-9
49. (SO 1, 3, 10) Using a search engine on the Internet, find articles or descriptions of
the collapse of Enron. The collapse began in November 2001, and many articles
appeared over the next two to three years. Required:
a. Briefly describe the fraud that occurred. Student responses are likely to
vary, but should focus on the accounting frauds which attempted to hide
the company’s debt and losses. For instance, Enron created special
purpose entities (related partnerships) for the purpose of off-balance sheet
50. (SO 3) Using a search engine on the Internet, search for articles on fraud that
occurred in 2000 to 2002 in the following companies:
Adelphia
Enron
Global Crossing
WorldCom
Xerox
Required:
a. Find information to help you complete the following table: Students are
not likely to find all of this information, but what they do find may help them
better understand the massive size and scope of these frauds. Some of
the stock prices or loss to investors can be found by web searches. For
example, the Xerox stock prices can be found by searching on Xerox,
fraud and “stock price”.
Company Name
Brief
Description of
Fraud
Position of
Those
Conducting
Fraud
Stock Price
when fraud
was
uncovered
Stock Price
one year
later
Shares
outstanding
Loss to
Investors
Adelphia
Off balance
sheet financing,
CEO, CFO, VP
of Operations
~$750 mil.
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-10
improper use of
company funds
Enron
through special
earnings
(Andrew
$90
$0.70
Global Crossing
Inflated
revenue
through
network
capacity swaps,
mis-
management
and excessive
spending
Founder (Gary
Winnick), CEO,
CFO, and Pres.
Of Finance
WorldCom
Off-balance
sheet credit,
inflated
earnings
through
improper
capitalization of
operating
expenses
CFO &
Controller
(possibly CEO)
$60
$0.20
Xerox
recognition on
leased assets
Senior
executives
$4.30
51. (SO 3) Using a search engine on the Internet, search for information on the following
two companies, which were paying bribes in foreign countries: Student responses
are likely to vary, but the information below highlights the main facts of these cases.
Siemens:
a. How it was discovered. The Siemens frauds were discovered after being
exposed by a middleman/consultant who helped carry out some of the
transactions to pay bribes and kickbacks to government officials in
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-11
b. The end result of the investigation. In 2008, Siemens pleaded guilty to
criminal violations of the corrupt practices act, and has paid over $1.6
billion in fines and settlements. In late 2011, civil bribery charges were
brought against several former Siemens executives.
c. What you think the company might have done to prevent this, or lessen
the impact. These frauds involved high-ranking company officials, so
internal controls should have been enhanced through practicing tone at
enforced by the SEC and seeks to root out companies who engage in
corrupt practices.
Johnson & Johnson:
a. How it was discovered. The J&J frauds were discovered internally and
were reported to the SEC. Most of the frauds involved paying bribes to
European doctors and hospital administrators in exchange for using J&J
medical devices. It also paid kickbacks to Iraq to obtain contracts under
the United Nations Oil for Food Program.
b. The end result of the investigation. J&J paid over $70 million in civil and
criminal fines. Its penalties were reduced because of the level of
cooperation the company provided throughout the investigation.
Cases
52. Fraud at Wooten’s city hall. Required:
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-12
a. Which internal control activity was violated in order for Mr. Peterman to
perpetrate this fraud? A case could be made for any or all of the internal
control activities were violated in this scenario. With regard to
authorization, it can be said that Mr. Peterman abused his authority by
circumventing the established controls in order to carry out these
anyone from stopping him.
c. Was the city’s procedural manual adequate for prescribing internal
controls to prevent this type of fraud? Why or why not? Although the case
states that written guidelines were in place regarding the mailroom and
bank deposit policies, requirements for logging checks received and
performing an independent verification of receipts, these guidelines were
obviously not followed when Mr. Peterman stepped in. Rather than being
a problem with the documented policies, this case seems to present a
situation marked by circumvention of controls.
e. Do you think a business in Wooten could be guilty of customer fraud if it
agreed to deliver its payments to Mr. Peterman personally rather than
send them to the city’s mailing address? A business that agreed to deliver
its payments to Mr. Peterman personally would not likely be guilty of fraud.
Customer fraud requires the intent to deceive, so unless the business had
knowledge or was otherwise involved in Mr. Petermans fraud scheme, it
would not be guilty of customer fraud.
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-13
53. Coupon accounting abuse. Required:
a. Discuss whether the situation described can happen to a company with a
good control environment. This situation would not be likely to happen to a
company with a good control environment. In a conservative control
environment, management would not place so much emphasis on
profitability, would not likely tie compensation to profitability and then give
employees responsibility for preparing their own profitability reports, and
would have likely provided for other controls (such as supervision and
review of Larry’s figures).
c. List those parties who might be harmed by this situation. The following
parties are likely to be harmed as a result of Larry’s fraud:
investors and creditors who rely upon the fair presentation of the
firm’s financial statements as a basis for business decisions
shareholders to whom the firms owes a stewardship obligation,
especially as they are deceived with respect to the firm’s current
financial status
54. Ethical dilemma involving a CEO. Required:
a. Discuss whether Mr. Brocamp’s violation of corporate ethics policy affects
or reflects the control environment of the company. Yes, Mr. Brocamp’s
actions affect the control environment of Mega Motor Company. As its
CEO, Mr. Brocamp has primary responsibility for setting the tone at the
top and living by the code of ethics. If others in the organization are aware
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-14
of this violation, it sends the message that the code of ethics is not
important. This is likely to lead to other problems, including fraud.
b. Since the violation is personal in nature, should Mr. Brocamp have been
forced to resign? Since the code of ethics specifically prohibits personal
relationships between managers and members of their management
55. Ethical dilemma involving mail order fraud. Required:
a. Discuss which type of fraud is involved in this case, from the perspective
of the mail order company. This case presents an example of customer
fraud, as Janie deceived the mail order company. She obtained property
and lied about it in order to avoid the corresponding liability.
b. Which of the AICPA Trust Services Principles most closely related to this
situation? Processing integrity is the Trust Services Principle that most
56. Ethical dilemma involving charitable fundraiser. Required:
a. Do you think Evan’s actions were justified? What would you have advised
him to do in this situation? No, Evans actions were not justified because
he did not use the donated funds for their intended purpose. Since Evan
represented to the donors that the monies were to be used for a charitable
Chapter 3 Solutions Fraud, Ethics, and Internal Control
Page 3-15
b. What internal control activities could the fraternity have implemented in
order to prevent Evan’s actions? The fraternity should have required its
treasurer to handle the cash receipts related to this fundraising campaign.
This would separate the custody of the cash receipts from the
recordkeeping that Evan was conducting.