1
Chapter 3 – Ethics, Fraud, and Internal Control
Instructor Manual
Introduction To The Need For A Code Of Ethics And Internal Controls. If the
top management of a company emphasizes ethical behavior, models ethical
behavior, and hires ethical employees, the chance of fraud or ethical lapses can be
reduced. In addition to acting ethically, the management of any organization has an
Accounting Related Fraud. Fraud is the theft, concealment and conversion to
personal gain of another’s money, physical assets, or information. There is a
distinction between misappropriation of assets and misstatement of financial
o Categories Of Accounting Fraud. The four categories of fraud are
management fraud, employee fraud, customer fraud, and vendor fraud.
o The Nature Of Management Fraud. It is conducted by one or more top-level
managers within the company, and it usually is misstating financial
statements through elaborate schemes or complex transactions. The
incentive for managers can include to increase incentive pay, or stock price,
opportunities for promotion, or the delay of cash flow or bankruptcy problems.
Some fraud involves circumventing internal controls, or management
override.
o The Nature Of Employee Fraud. It is usually the theft of assets, or the theft
of cash through false or fraudulent documentation. An example would be a
2
through deception. Although customer fraud may affect any company, it is an
especially common problem for retail firms and companies that sell goods
through internet-based commerce. Examples of customer fraud include credit
card fraud, check fraud, and refund fraud.
o The Nature Of Vendor Fraud. Vendor fraud occurs when vendors obtain
payments to which they are not entitled. Unethical vendors may accomplish
this by submitting duplicate or incorrect invoices, intentionally sending
o The Nature Of Computer Fraud. The computer system can be used as a
tool to commit fraud. A computer fraud can be conducted by someone
internal, or external to the company. Internal fraud can be conducted by input
manipulation, program manipulation, or output manipulation. Input
manipulation is altering or falsifying data that is input into the system.
Policies To Assist In The Avoidance Of Fraud And Errors. There are three main
policies an organization can undertake to help prevent or detect fraud. The three
are: maintain and enforce a code of ethics, maintain a system of accounting internal
controls, and maintain a system of IT controls.
Maintain A Code Of Ethics. While it has always been a good idea to have and
enforce a corporate code of ethics, the Sarbanes-Oxley act of 2002 requires publicly
traded companies to maintain one. To be of effect, the code should be adhered to
by top management and enforced throughout the company.
Maintain A System Of Internal Controls. Internal controls have four objectives: (1)
o The Details Of The COSO Report. The COSO report has become the
standard definition and description of internal control. It identifies five
3
interrelated components: the control environment; risk assessment; control
activities; information and communication; and monitoring.
Risk assessment is the continual monitoring of the risks from external and
internal sources. In order for management to maintain control over threats to
its business, it must constantly be engaged in risk assessment. It is important
that management develop a systematic and ongoing way to: Identify the
sources of risks, both internal and external; Determine the impact of such
risks in terms of finances and reputation; Estimate the chance of such risks
occurring; Develop an action plan to reduce the impact or probability of these
risks; Execute the action plan and continue the cycle beginning again with the
first step above.
specific authorization. Segregation of duties means that for any given
business process, no single person or department should authorize, record,
and have custody of the assets. Supervision is a compensating control when
segregation cannot be fully achieved. Adequate records and documents
means that there must be an audit trail as verifiable information about the
accuracy of the accounting records. Security of assets and documents
includes physical controls to limit access to assets, and policies and practices
to limit who has access to assets. Independent checks and reconciliations
are procedures to verify the accuracy and completeness of accounting
information.
4
Monitoring is the ongoing review and evaluation of the system. This includes
both continuous and periodic monitoring of the accounting system and
controls. Continuous review of reports and information by managers and
periodic audits are part of monitoring.
o Reasonable Assurance Of Internal Controls. The whole set of internal
Maintain A System Of Information Technology Of Controls. Information
technology increases the efficiency and effectiveness of organizations that use
them, but at the same time, it increases vulnerability. The risks include unauthorized
access, hackers, business interruption, and data inaccuracies. These extra risks of
computer systems call attention to the need for internal controls over and above
those described in the COSO report. One way to organize these risks and controls
is the Trust Services Principles. These principles divide IT risks and controls into
five categories: security; availability, processing integrity; online privacy; and
confidentiality.
Appendix A: Recent History Of Internal Control Standards. The 1977 Foreign
Corrupt Practices Act (FCPA) included a requirement that corporations that sell
stock in an SEC regulated stock exchange maintain a system of internal controls. In
1988 the AICPA issued SAS 55 which further emphasized management’s obligation
to maintain internal controls. In 1992, the COSO report was issued by the
Committee of Sponsoring Organizations (COSO). This report details the findings of
a comprehensive study of internal control and is recognized within the accounting
report within its annual report to stockholders. Thus, not only is the establishment
and operation of an internal control system a good practice, it has become
mandatory for publicly traded companies.
Appendix B: Control Objectives For Information Technology (COBIT). The
COBIT framework is a comprehensive description of the risks and controls in IT
environments. The framework establishes what COBIT terms four domains of “High