Most fraud risk assessment frameworks ask teams to assign precise-sounding labels to subjective judgments. When your fraud risk register classifies a threat as "reasonably possible" (35% to 65% likelihood) versus "unlikely" (10% to 35%), what evidence supports that distinction? In most cases, none.
This false precision creates two problems. First, it gives boards and senior management false confidence in resource allocation decisions. Second, it obscures the actual variables that determine whether fraud occurs, making it harder to design effective controls.
What the Data Shows
Organizations typically assess fraud likelihood using categorical scales borrowed from enterprise risk management frameworks. The likelihood of fraud is evaluated based on past incidents, industry prevalence, internal controls, available resources, fraud prevention efforts, ethical standards, unexplained losses, and customer complaints.
Frequency classifications range from "very frequent" (daily or multiple times per day) to "rare" (once over several years). Likelihood categories span from "almost certain" (more than 90% chance) to "remote" (less than 10% chance).
The assessment process itself reveals the problem: relevant data or information that accurately predicts the likelihood of particular fraud risks typically isn't available to the organization conducting the evaluation.
Key Findings
Historical incident data creates selection bias. Your past fraud incidents only reflect the schemes you detected. The fraud you haven't caught yet doesn't appear in your likelihood calculations. If your transaction monitoring catches structuring attempts but misses trade-based money laundering, your risk assessment will systematically underweight the latter.
Industry prevalence data lacks context. Knowing that payment card skimming affects X% of merchants in your sector doesn't tell you whether your specific checkout flow, vendor management practices, or JavaScript security posture make you more or less vulnerable than that baseline. Generic industry statistics can't account for your control environment.
Frequency and impact don't align with your categorical scales. The framework treats "very frequent" low-impact fraud (daily cash pocketing at counters) and "rare" high-impact fraud (coordinated cyber-attacks on confidential information) as distinct risk categories. But a scheme that occurs daily with $50 impact creates $18,250 annual exposure, while a "rare" incident might never materialize during your planning horizon. Your resource allocation should follow expected loss, not categorical frequency.
Subjective percentages mask control gaps. When you classify a fraud risk as "reasonably possible" (35% to 65% likelihood), you're really saying "we don't have enough detective controls to know." That percentage range is too wide to drive meaningful decisions. The honest assessment would be: "We can't measure this risk's likelihood because we lack visibility into the process."
Management-level assessments introduce organizational bias. When department managers conduct fraud risk assessments for their own areas and share results with the Board of Directors, they face conflicting incentives. Acknowledging high fraud likelihood in your department suggests control failures. This structure discourages the candid risk identification that makes assessments useful.
What This Means for Your Team
Stop treating fraud likelihood assessment as a measurement exercise. You're not measuring an observable phenomenon; you're making informed judgments about future events based on incomplete information. The framework should acknowledge that uncertainty rather than hide it behind precise-sounding percentages.
Your fraud risk assessment should answer three questions:
Do we have visibility into this process? If you can't detect when the fraud occurs, you can't assess its likelihood. A cash handling process with no reconciliation controls and no exception reporting doesn't have "low likelihood" fraud risk; it has unmeasured fraud risk. Document the visibility gap, not a fabricated likelihood score.
What control failures would this scheme exploit? Instead of assigning a percentage to "vendor invoice fraud," map the control points: segregation of duties in accounts payable, vendor master file access controls, invoice matching logic, payment authorization workflows. Rate your confidence in each control, not the fraud's likelihood.
What's our expected annual loss from this risk category? Combine your best estimate of frequency (informed by historical data where available) with impact to calculate exposure. A daily $50 theft and a quarterly $6,000 embezzlement both create roughly $18,000 annual exposure, even though your categorical framework would classify them differently.
Action Items by Priority
Replace likelihood percentages with control confidence ratings. For each fraud risk, assess your confidence that existing controls would prevent or detect the scheme: High Confidence, Moderate Confidence, Low Confidence, or No Coverage. This framing is honest about what you're actually evaluating.
Separate measurement capability from risk severity. Create a two-dimensional risk matrix: one axis for expected loss (calculable where you have data), one axis for measurement uncertainty (acknowledging where you lack visibility). High-loss, high-uncertainty risks demand investment in detective controls before you can assess them properly.
Build fraud scenario libraries by control failure mode. Instead of listing fraud types ("cash theft," "invoice fraud"), document the control combinations that would need to fail for fraud to succeed undetected. This approach reveals common vulnerabilities across multiple fraud scenarios.
Require evidence citations for all likelihood assessments. When a manager classifies a risk as "unlikely," require them to cite the specific historical data, industry benchmark, or control testing result that supports that judgment. If they can't, the assessment defaults to "insufficient data."
Implement continuous control monitoring for high-exposure processes. For processes where even moderate-frequency fraud creates material exposure (cash handling, treasury operations, payment authorization), deploy automated monitoring that generates daily or weekly metrics. Replace annual subjective assessments with objective control performance data.
The goal isn't to eliminate judgment from fraud risk assessment; judgment is unavoidable when you're evaluating future events. The goal is to stop pretending that subjective judgments are precise measurements, and to focus your assessment process on the factors you can actually observe: control design, control performance, and process visibility.



