Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Fraud Risk Assessment: A Complete Guide to the COSO 5 Principles

A fraud risk assessment is the exercise COSO’s Internal Control — Integrated Framework requires under principle 8 — “the organization considers the potential for fraud in assessing risks to the achievement of objectives” — and the one the COSO/ACFE Fraud Risk Management Guide, in its second edition of May 2023, builds an entire programme around. The Guide’s five fraud risk management principles mirror COSO’s five components, and its second principle states the assessment’s job in one sentence: “the organization performs comprehensive fraud risk assessments to identify specific fraud schemes and risks, assess their likelihood and significance, evaluate existing fraud control activities, and implement actions to mitigate residual fraud risks.” Most assessments fail on the word “specific”: they rate “fraud” as a risk and stop, where the Guide asks for named schemes, named perpetrators, named controls and a residual risk decision per scheme. This guide sets out the five principles, the assessment method scheme by scheme with a worked row, the scheme categories the Guide expects to be considered, how data analytics is expected to be used in the second edition, and the errors that leave an organisation with a heat map and no programme.

Fraud risk assessment inside the COSO/ACFE Fraud Risk Management Guide
Principle 1 governance → Principle 2 fraud risk assessment (schemes × likelihood × significance × existing controls → residual risk) → Principle 3 preventive and detective controls → Principle 4 investigation and corrective action → Principle 5 monitoring.

The five fraud risk management principles

# Principle (Fraud Risk Management Guide, 2nd edition) COSO component it aligns with
1 The organization establishes and communicates a Fraud Risk Management Program that demonstrates the expectations of the board of directors and senior management and their commitment to high integrity and ethical values regarding managing fraud risk Control environment
2 The organization performs comprehensive fraud risk assessments to identify specific fraud schemes and risks, assess their likelihood and significance, evaluate existing fraud control activities, and implement actions to mitigate residual fraud risks Risk assessment
3 The organization selects, develops, and deploys preventive and detective fraud control activities to mitigate the risk of fraud events occurring or not being detected in a timely manner Control activities
4 The organization establishes a communication process to obtain information about potential fraud and deploys a coordinated approach to investigation and corrective action to address fraud appropriately and in a timely manner Information and communication
5 The organization selects, develops, and performs ongoing evaluations to ascertain whether each of the five principles of fraud risk management is present and functioning and communicates Fraud Risk Management Program deficiencies in a timely manner to parties responsible for taking corrective action, including senior management and the board of directors Monitoring activities

The assessment is principle 2, but it only works inside the other four: without governance (1) nobody owns it; without controls (3) it produces a list; without a reporting channel and investigation process (4) the detective controls have nowhere to report; without monitoring (5) it is done once. The Guide describes the assessment as “a dynamic and iterative process”, not an annual document. Our guide to the COSO 17 principles covers principle 8, the anchor in the internal control framework.

The fraud risk assessment method, scheme by scheme

Step What is done Worked row: accounts payable
Identify the scheme Specific, not generic: how would fraud be committed, by whom, against which process Fictitious vendor set up by an AP clerk with vendor-master access; invoices approved under the clerk’s own delegated limit
Identify the perpetrator and incentive Internal, external, collusive; the pressure, opportunity and rationalisation the fraud triangle names Internal; opportunity from combined vendor-master and invoice-entry access; pressure from personal debt
Assess likelihood Probability the scheme is attempted and succeeds, given the environment — history, industry, controls known to be weak Moderate: access combination exists for three users
Assess significance Financial magnitude and non-financial impact — reputation, regulatory, operational Up to the approval limit per invoice, unlimited over time; regulatory exposure if government-funded
Evaluate existing controls Preventive and detective controls that address this scheme, and whether they are designed and operating Vendor-master changes reviewed monthly (detective, low precision); no segregation between master data and invoice entry
Determine residual risk Inherent risk after existing controls, against the organisation’s fraud risk tolerance Above tolerance
Decide the response Accept within tolerance; or add controls (principle 3): segregation, independent vendor-master approval, analytics for duplicate bank details and round-sum invoices Segregate access; add bank-detail matching analytic; quarterly vendor-master review by someone outside AP
Assign and document Owner, date, evidence AP manager; Q4; access change ticket and analytic output

Scheme categories the assessment should cover

The Guide’s expanded scheme list — each scheme hyperlinked in the second edition to a description of how it is carried out — covers generic schemes that can victimise any organisation and industry-specific ones. A complete assessment considers at least:

  • Fraudulent financial reporting — revenue recognition manipulation, reserve manipulation, improper capitalisation, disclosure fraud, management override of controls.
  • Misappropriation of assets — cash skimming and larceny, billing schemes (fictitious vendors, personal purchases), payroll (ghost employees, falsified hours), expense reimbursement, cheque and payment tampering, inventory and asset theft.
  • Corruption — bribery, kickbacks, conflicts of interest, illegal gratuities, economic extortion.
  • Other — identity theft, cyber-enabled fraud (business email compromise, payment diversion), procurement fraud, grant and programme fraud, and the industry-specific schemes for healthcare, financial services, government and others the Guide lists.

Management override is assessed separately and always: it is the scheme that defeats every other control, and COSO’s internal control framework treats controls over override as entity-level. Our guide to entity-level controls covers where those sit; whistleblowing policy covers the reporting channel principle 4 depends on.

Data analytics in the second edition

The 2023 edition’s stated purpose includes addressing “more recent anti-fraud developments” and adding “important information related to technology developments — specifically data analytics”, and it describes analytics as integral to each principle rather than a separate topic. For the assessment that means two things. Analytics informs the likelihood and significance ratings — duplicate payments found, vendor-employee address matches, round-sum invoices, journal entries posted at unusual times are evidence of exposure, not hypotheses. And analytics is a control response under principle 3: the detective control that closes the residual gap in the worked row above is an analytic that runs, is reviewed, and whose exceptions are investigated. An assessment that rates a scheme “low” without looking at the data is guessing.

Fraud risk assessment errors

  1. Generic risks. “Fraud in procurement — medium” is not a scheme. The Guide’s principle 2 says “specific fraud schemes”.
  2. Likelihood rated with controls in place. Inherent likelihood first; existing controls evaluated separately; residual risk derived. Collapsing the three produces “low” everywhere.
  3. No tolerance. Residual risk cannot be judged against nothing; the board’s fraud risk tolerance is a principle 1 output the assessment needs.
  4. Controls listed, not evaluated. A control that exists on paper and a control that would detect the scheme are different; precision matters, as it does for any detective control.
  5. Management override ignored, because it is uncomfortable to assess the people who commissioned the assessment.
  6. Done once. New systems, new markets, remote working, an acquisition and a downturn each change the schemes; the Guide’s “dynamic and iterative” is a cadence, not a description.
  7. Not connected to the investigation record. Every incident and every hotline report is a data point on likelihood; an assessment that ignores them is rating what the organisation would like to be true.

Frequently asked questions

What is a fraud risk assessment?
A structured evaluation, scheme by scheme, of how fraud could be committed against the organisation and by whom, how likely and significant each scheme is, what controls already address it, and what residual risk remains against the organisation’s tolerance. It is principle 2 of the COSO/ACFE Fraud Risk Management Guide and the way COSO principle 8 is satisfied.

How often should it be performed?
The Guide describes it as dynamic and iterative: a full refresh at least annually and an update whenever the business, systems, people or environment change materially. Investigation results and hotline reports feed it continuously.

Who performs it?
A cross-functional team — finance, internal audit, compliance, IT, operations, HR — under a named owner with board oversight, with the people who know how each process actually works in the room. Assessing management override needs independence from the management being assessed.

What is the difference between the five fraud principles and COSO’s 17?
The 17 principles are the internal control framework; the five fraud risk management principles are the Guide’s application of the five components to fraud specifically, one per component, with the fraud risk assessment as the risk-assessment principle.

What changed in the second edition?
Released 2 May 2023 by COSO and the ACFE, it addresses recent anti-fraud developments, revises terminology, expands the scheme list with linked descriptions, and adds substantial content on data analytics as integral to each principle.

Where this leaves you

Run the fraud risk assessment the way the Guide’s second principle is written: specific schemes, specific perpetrators, likelihood and significance rated inherently, existing controls evaluated for whether they would actually catch the scheme, residual risk against a tolerance the board has set, and a response with an owner — refreshed when the business changes and fed by what the data and the hotline are already telling you.

References

More on COSO

The fraud risk assessment workbook with the scheme library, the fraud risk management policy, the control evaluation matrix, the investigation procedure and the board reporting template are in the COSO ERM & Internal Control Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.