Skip to main content
Deploying Internal Audit as a Fraud Control LayerFraud Detection Analytics
6 min readFor Fraud Risk Managers

Deploying Internal Audit as a Fraud Control Layer

An estimated 70% of fraud is committed by insiders, yet many organizations haven't clearly defined what their internal audit function should do when fraud surfaces. Your team might be asking too much of your auditors or not enough, creating risk.

This guide helps you build a defensible internal audit framework for fraud risk management. You'll define scope, establish reporting lines, and create protocols that position internal audit as an effective control layer without turning your auditors into fraud investigators.

The Problem: Misaligned Expectations Create Control Gaps

Your internal audit department likely sits between two conflicting expectations. Management wants auditors to act as fraud detectives, proactively hunting for schemes and investigating incidents. Meanwhile, professional standards position internal auditors as independent evaluators who assess controls but don't operate them.

This tension isn't theoretical. When auditors spend time investigating individual fraud cases, they're not evaluating whether your anti-fraud framework works across the organization. When they're embedded in operational decisions about fraud prevention, they lose the independence needed to assess whether those decisions were sound.

The consequence: you get neither effective fraud detection nor reliable control assurance. Your audit function becomes reactive, chasing incidents instead of identifying systemic weaknesses.

What You Need Before Starting

Before restructuring your internal audit fraud role, gather these components:

Organizational clarity on the three lines model:

  • First line: Business units own and operate controls
  • Second line: Risk and compliance functions set policy and oversee
  • Third line: Internal audit provides independent assurance

Current state documentation:

  • Your internal audit charter (what the Board Audit Committee authorized)
  • Existing fraud response procedures
  • List of who currently handles fraud investigations
  • Internal audit's current involvement in fraud cases over the past 24 months

Stakeholder availability:

  • Chief Audit Executive (CAE)
  • Board Audit Committee chair
  • CFO or controller
  • Head of fraud risk management (if separate from audit)
  • Legal counsel

Technical resources:

  • Access to your fraud risk assessment
  • Documentation of fraud detection controls (transaction monitoring rules, access reviews, reconciliation processes)
  • Ethics hotline or whistleblower system configuration

Step-by-Step Implementation

Step 1: Define Internal Audit's Fraud Mandate

Schedule a working session with your Board Audit Committee and CAE. Draft language for your internal audit charter that explicitly addresses fraud responsibilities. Use this structure:

Internal audit SHALL:

  • Evaluate the design and operating effectiveness of fraud prevention and detection controls
  • Assess fraud risk assessment processes annually
  • Test key anti-fraud controls as part of the audit plan
  • Report fraud control deficiencies to the Board Audit Committee

Internal audit SHALL NOT:

  • Conduct fraud investigations as primary investigators
  • Design or implement fraud prevention controls
  • Make operational decisions about fraud case disposition
  • Serve as the primary fraud reporting channel for employees

Get Board approval for this charter language. This creates a defensible boundary when management asks auditors to step outside their role.

Step 2: Establish the Fraud Investigation Protocol

Document who investigates when fraud is suspected. A workable model:

For suspected fraud involving amounts below your materiality threshold (typically $10,000-$50,000):

  • Business unit management investigates with HR or security support
  • Internal audit receives investigation summary for control gap analysis
  • CAE reviews findings quarterly

For material fraud or executive-level involvement:

  • Legal counsel leads investigation
  • External forensic specialists engaged if needed
  • Internal audit provides process documentation and control testing on request
  • Internal audit does NOT participate in evidence gathering or interviews

For ethics hotline reports:

  • Route non-fraud ethics issues to HR or compliance
  • Route fraud allegations to legal or designated fraud coordinator
  • CAE receives all fraud-related reports but doesn't triage or investigate
  • Internal audit assesses control environment after case resolution

Document this protocol and publish it to management. Include a decision tree showing who handles what.

Step 3: Build the Annual Fraud Control Audit

Create a recurring audit focused on fraud control effectiveness, not fraud hunting. Structure it as:

Scope definition: Select 3-5 high-risk fraud scenarios based on your fraud risk assessment (e.g., payment diversion, expense reimbursement schemes, procurement kickbacks, insider trading on customer data).

Control identification: For each scenario, list the preventive and detective controls that should stop or catch it:

  • Segregation of duties in payment approval
  • Vendor master file change monitoring
  • Expense report sampling and analytics
  • Trading preclearance for employees with material non-public information

Testing approach:

  • Test design: Does the control address the fraud risk as documented?
  • Test operating effectiveness: Pull 25-40 samples per control and verify execution
  • Interview control owners: Do they understand the fraud risk they're mitigating?

Reporting: Rate each fraud scenario's control environment (Effective / Needs Improvement / Ineffective). Report control gaps to management with remediation timelines. Escalate material weaknesses to the Board Audit Committee.

Schedule this audit annually or after significant process changes.

Step 4: Configure the Advisory Role

Internal auditors shouldn't design controls, but they can advise. Set boundaries:

Acceptable advisory activities:

  • Reviewing proposed fraud controls before implementation (as a consultant, not approver)
  • Sharing fraud trends from industry sources or peer organizations
  • Facilitating fraud risk assessment workshops
  • Training management on control design principles

Document your involvement: When you provide fraud control advice, send a follow-up email confirming: "This was advisory input. Management remains responsible for control design and implementation. Internal audit will assess these controls independently during future audits."

This documentation protects your independence when you later audit those same controls.

Step 5: Create the Fraud Data Request Template

When fraud is detected and investigated by others, internal audit needs specific information to assess control gaps. Build a standard template you send to investigators:

  • Fraud type and scheme description
  • Amount and duration
  • Controls that failed to prevent or detect
  • Controls that eventually detected (if applicable)
  • Individuals involved and their access levels
  • Systems or processes exploited
  • Root cause analysis from investigator's perspective

You're not investigating the fraud; you're documenting the control failure for your next audit cycle.

Validation: How to Verify It Works

Test your framework's effectiveness quarterly:

Boundary test: Review the past quarter's fraud incidents or allegations. For each one, verify:

  • Internal audit was not the primary investigator
  • Internal audit received post-incident documentation
  • Control gaps were added to the audit plan

If auditors are investigating, your boundaries failed.

Coverage test: Compare your fraud risk assessment to your annual audit plan. Every high or medium fraud risk should map to either:

  • A specific audit testing that risk's controls, or
  • A documented rationale for why you're not testing it this year

Gaps indicate you're not covering the fraud control landscape.

Independence test: Pull your last three fraud-related audit reports. Check whether auditors:

  • Recommended specific control implementations (problematic)
  • Assessed whether management's controls were effective (appropriate)

If you're prescribing solutions rather than evaluating them, you've lost independence.

Stakeholder feedback: Interview your CFO and fraud risk manager. Ask: "Is it clear what internal audit does and doesn't do for fraud?" If they're uncertain, your messaging failed.

Maintenance and Ongoing Tasks

Quarterly:

  • Review fraud incidents and update your fraud risk assessment
  • Verify investigators are sending you post-incident documentation
  • Report fraud control themes to the Board Audit Committee

Annually:

  • Update your fraud control audit scope based on new risks
  • Review and refresh your investigation protocol
  • Train new managers on internal audit's fraud role
  • Benchmark your approach against professional standards (Institute of Internal Auditors guidelines on fraud)

After major fraud incidents:

  • Conduct a lessons-learned session with investigators
  • Assess whether the incident reveals control gaps in other areas
  • Consider adding unscheduled audit work if the control failure appears systemic

When organizational changes occur:

  • New CAE: Reconfirm the fraud mandate with the Board Audit Committee
  • New fraud risk function: Renegotiate the interface between audit and fraud teams
  • New ethics hotline vendor: Verify routing protocols still match your framework

The goal isn't to make internal auditors fraud experts. It's to position them where they add the most value: evaluating whether your anti-fraud framework actually works before the next insider scheme surfaces.

You Might Also Like