Forensic Audit Building a World Class Program

Similar documents
Types of Fraud and Recent Cases. Developing an Effective Anti-fraud Program from the Top Down

How To Understand And Understand Forensic Accounting

Deloitte Forensic Fraud Risk Management

Fraud Prevention, Detection and Response. Dean Bunch, Ernst & Young Fraud Investigation & Dispute Services

Fraud Prevention Policy

Antifraud program and controls assessment grid*

KEYS TO AN EFFECTIVE DIRECTOR CORPORATE COMPLIANCE AND INTERNAL AUDIT MULTICARE HEALTH SYSTEM TACOMA, WA

ISOLATE AND ELIMINATE FRAUD THROUGH ADVANCED ANALYTICS. BENJAMIN CHIANG, CFE, CISA, CA Partner, Ernst and Young Advisory Singapore

We believe successful global organisations can confront fraud, corruption and abuse PwC Finland Forensic Services

1/17/2013 FRAUD RISK MANAGEMENT PROGRAM SESSION OBJECTIVE AND OUTLINE

Mental Health Resources, Inc. Mental Health Resources, Inc. Corporate Compliance Plan Corporate Compliance Plan

FRAUD PREVENTION STRATEGIES FOR HEALTH CARE A FORENSIC ACCOUNTANT S PERSPECTIVE

Corporate Resiliency Managing g the Growing Risk of Fraud and Corruption

MEDICAID COMPLIANCE POLICY

Policy-Standard heading. Fraud and Corruption Policy

A Framework for Managing Crime and Fraud

Managing the Risk of Fraud in Outsourcing. Fernando Cancino, CFE, CIA

Fraud Risk Management providing insight into fraud prevention, detection and response

Fraud Risk Management and Internal Audting

FEI Canada. Fraud Prevention. Presented by: Matthew McGuire and Leigh Beijer. Date:

Fraud Prevention and Deterrence

DCAA Audits of Compliance Systems and the Implications of Changes in the False Claims Act for Universities

The SEC's New Whistleblower Program: What It Means for Companies and How to Respond. July 22, 2011

Fraud Prevention and Deterrence

Aligning Compliance Program Priorities with Business Objectives

For Private circulation only Creative. Clear. Focused. Forensic Services

Riverside Community College District Policy No Human Resources

Fraud Risk Management

BDO NORDIC. Investigation, fraud prevention and computer forensics. You can guess. You can assume. Or you can know. And knowing is always better.

AUDIT COMMITTEE BEST PRACTICES CHECKLIST

6 TH ANNUAL JOINT ACFE & IIA FRAUD CONFERENCE The Whistleblower Programs. April 17, Presented by:

Fraud-Related Compliance

Fraud-Related Compliance

Due Diligence Primer Registered Investment Advisers and Broker-Dealers

RESPONDING TO SEC AND DOJ INVESTIGATIONS

by: Scott Baranowski, CIA

Fraud Risk Management Procedures

LANTHEUS HOLDINGS, INC. Foreign Corrupt Practices Act and Anti-Bribery Compliance Policy

SAMPLE FRAMEWORK FOR A FRAUD CONTROL POLICY

Puerto Rican Family Institute, Inc.

WHISTLE BLOWING POLICY & PROCEDURES

Forensic Accounting: An Introduction

The Compliance and Ethics Essentials Toolkit

February Audit committee performance evaluation

UNIVERSITY COMPLIANCE PLAN

Establishing An Effective Corporate Compliance Program Joan Feldman, Esq. Vincenzo Carannante, Esq. William Roberts, Esq.

WHISTLEBLOWING POLICY NUS policies adopted and adapted by Yale-NUS College

Five-Year Strategic Plan

PHI Air Medical, L.L.C. Compliance Plan

THE FCA INSPECTOR GENERAL: A COMMITMENT TO PUBLIC SERVICE

Fraud Prevention Checklist for Small Businesses

Internal Controls and Fraud Detection & Prevention. Harold Monk and Jennifer Christensen

Forensic Services. kpmg.hu

Making Your Fraud Vision 20 / 20. Thomas R. Strause, CIA, CFE, CBA, CISA, CFSA, CICA Partner FOS tstrause@fosaudit.

U.S. Department of Justice Office of the Inspector General. Improving the Grant Management Process

Department of Veterans Affairs Office of Inspector General Strategic Plan FY

Preventing Fraud: Assessing the Fraud Risk Management Capabilities of Today s Largest Organizations

BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL

PROPOSAL GRADUATE CERTIFICATE IN FORENSIC ACCOUNTING FRAUD INVESTIGATION TO BE OFFERED AT PURDUE UNIVERSITY CALUMET

7/22/2014. From Treadway To the Cube ( ) So, Who is COSO? What Does COSO Do?

ASAE s Job Task Analysis Strategic Level Competencies

COMPLIANCE PROGRAM GUIDANCE FOR MEDICARE FEE-FOR-SERVICE CONTRACTORS

MASTER OF JURISPRUDENCE AND GRADUATE CERTIFICATE PROGRAMS COURSE DESCRIPTIONS

Sharon Kurek, CPA, CFE Director of Internal Audit

GUIDANCE FOR MANAGING THIRD-PARTY RISK

Leveraging Big Data to Mitigate Health Care Fraud Risk

Credit Union Liability with Third-Party Processors

Anti-bribery and Fraud Protection Policy

UBS presentation Key remediation actions

COUNCIL TAX REDUCTION, DISCOUNT & EXEMPTION ANTI- FRAUD POLICY

STATEMENT FROM THE CHAIRMAN

TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER

Assessment for Establishing a Whistleblower Hotline:

Governance, Risk & Compliance Management. Julian Hunn, Operations Manager Professional Standards

Misplaced Trust: Vendor Fraud. IIA/ACFE Conference Patrick Mitchell, Managing Director Sharon Delgado, Senior Manager

Office of the Inspector General

BAPTIST HEALTH CORPORATE COMPLIANCE PLAN

Proactive Fraud Detection with Data Mining Fear not the computer You play ball with it and it will play ball with you

Fraud and Role of Information Technology. September 2008

Fraud-Related Compliance

ACCOUNTING RECORDS: HOW THEY ARE USED TO CONCEAL FRAUD. ROSANNE TERHART, CFE, CA Senior Manager BDO Canada LLP Vancouver, British Columbia Canada

APEC General Elements of Effective Voluntary Corporate Compliance Programs

Fraud Prevention and Detection in a Manufacturing Environment

Sobel & Co. s Nonprofit and Social Services Group presents. Your Organization is Vulnerable: The Facts About Nonprofits and Fraud

Advanced Data Analytics, the Fraudsters Worst Enemy

Competency Requirements for Executive Director Candidates

Title: False Claims Act & Whistleblower Protection Information and Education

KAREN KINCAID BALMER, CPA, CFF, CFE, CrFA

Transcription:

Forensic Audit Building a World Class Program PAUL E. ZIKMUND DIRECTOR GLOBAL INTEGRITY AND FORENSIC AUDIT 1 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Why the Need for Forensic Audit Program In response to a crisis Concern from the Board or Audit Committee External Auditors or Consultant s recommendations Sarbanes Oxley Benchmarking Internal need to enhance existing antifraud programs and controls Increase in fraud cases Target of external investigation Centralized function to address fraud risk management programs and controls 2 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Recipe for Success Sponsorship ROI Staffing Building the Network Execution & Results 3 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Sponsorship & Support Organizational policies and procedures Hotline Ethics and Compliance programs Code of Conduct Executive sponsorship Visibility to Board/Audit Committee Engagement by Business Segments/OpCo s Respect from Legal & Human Resources Clear understanding of roles and responsibilities Assignment of costs 4 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Staffing Proper background and experience Recruit internally and externally Combined set of skills (CFE, CIA, CPA, M.B.A.) Invest in training Previous corporate investigative experience a plus Law enforcement versus auditing Proper headcount Strong external relationships Well networked Data Analytics & Computer Forensics skills a plus 5 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Execution & Results High-quality results Build a brand (think like a consultant) Regionally based Training and awareness programs Be proactive Think beyond investigations (Compliance, Internal Controls, ERM, etc.) Avoid territorialism Solicit feedback (example: have legal review your reports) Network, network, & network 6 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Build the Network Litigation Support Audit Committee presentations Executive Management visibility Regional awareness of the team Attend training and awareness programs ERM Corporate Compliance Information Systems Think Big! Temporary assignments (rotation program) Develop policies and procedures 7 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Return on Investment Recovery of assets Remediation of losses Internal controls/root cause analysis feedback Informal feedback on people and processes Increased transparency of reporting fraud and misconduct Reduction in fraud Greater credibility from external agencies (DOJ, Auditors) Stronger control environment Audit Committee assurance Consistent approach to managing fraud risk 8 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Roadblocks Lack of policies and procedures Lack of a champion or executive management support and sponsorship Improperly positioned/located within the organization Improperly staffed (headcount & skillsets) No budget Failure to embed AFPC within organizational framework Fear of travel Myopic thinking Failure to network Being reactive 9 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Proactive Risk Management Approach 1. Prevention Programs 12. Proactive Auditing 2. Incident (Fewer) 11. Training 3. Incident Reporting 10. Testing For Compliance 4. Investigation 9. Implementation of Controls 5. Action 8. Publication 6. Resolution 7. Analysis 11 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Anti- Roles & Responsibilities Management Board of Directors Internal Auditors Audit Committee External Auditors AFPC Compliance 12 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

GIFA - Risk Management Process Deterrence Policies & Procedures Risk Assessment Anti- Culture Detection Forensic Audit Techniques CAATs Detective Processes & Controls Investigation Investigation Guides Evidence Management Reporting Remediation Root Cause Analysis Recovery of Assets Internal Controls Review 13 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

GIFA - Deterrence Sub-Process Deterrence Detection Policies & Procedure s Forensic Audit Technique s Risk Assessme nt CAATs Anti- Culture Detective Processes & Controls Investigation Investigati on Guides Evidence Managem ent Reporting Remediation Root Cause Analysis Recovery of Assets Internal Controls Review Policies & Procedures Code of Conduct Response Policies Human Resources Policies Risk Assessment Identify Risk Factors Define Schemes & Scenarios Determine Residual Risk Anti- Culture Whistleblower Hotline Control Environment Employee Surveys 14 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

GIFA - Detection Sub-Process Deterrence Detection Policies & Procedure s Forensic Audit Technique s Risk Assessme nt CAATs Anti- Culture Detective Processes & Controls Investigation Investigati on Guides Evidence Managem ent Reporting Remediation Root Cause Analysis Recovery of Assets Internal Controls Review Forensic Audit Techniques Analytical Procedures Interviewing Analysis of Financial Transactions CAATs ACL / IDEA software Continuous Controls Monitoring Event-Driven CAATs Detective Controls Segregation of Duties Monitoring & IT Controls Safeguarding Company Assets 15 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

GIFA - Investigation Sub-Process Deterrence Detection Policies & Procedure s Forensic Audit Technique s Risk Assessme nt CAATs Anti- Culture Detective Processes & Controls Investigation Investigati on Guides Evidence Managem ent Reporting Remediation Root Cause Analysis Recovery of Assets Internal Controls Review Investigative Guidelines Processes & Flowcharts Response Team Defined Roles & Responsibilities Evidence Management Document Reviews & Labeling Computer Forensics Chain of Custody Reporting Report Guidelines Attorney-Client Privilege Presentation of Findings 16 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

GIFA - Remediation Sub-Process Deterrence Detection Policies & Procedure s Forensic Audit Technique s Risk Assessme nt CAATs Anti- Culture Detective Processes & Controls Investigation Investigati on Guides Evidence Managem ent Reporting Remediation Root Cause Analysis Recovery of Assets Internal Controls Review Root Cause Analysis Internal Controls Review Issues Tracking System Management Accountability Program Recovery of Assets Civil / Criminal Action Disciplinary Action Insurance Claims Information & Communication Awareness Programs Policy & Procedure Updates Surveys & Certification Programs 17 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Global Integrity & Forensic Audit Policies & Procedures Overview GIA Charter Defines the purpose of GIA Provides authority to conduct audits GIA Charter Defines areas of responsibility Response Policy GIFA Investigation Guidelines Allegations Matrix Response Protocols Response Policy Details guiding principles for managing fraud risk Assigns responsibility for addressing complaints Response Protocols Defines principles for conducting internal Compliance/GIFA investigations of fraud and misconduct Details the 7-step protocol to address allegations or detection of fraud and/or misconduct Allegations Matrix Defines various types of allegations Prioritizes allegations in three separate levels (A,B,C) Identifies ownership for investigating the allegations GIFA Investigative Guidelines Serves as a guide and reference to enroll investigative procedures and processes during the collection of facts and evidence in matters where illegal, unethical or otherwise improper acts are alleged Defines GIFA s philosophy and core values 19 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Global Integrity & Forensic Audit - Vision & Mission Vision To ensure the development, implementation, and sustainability of a comprehensive fraud risk management process designed to reduce Bunge s risk of asset loss, reputational damage, and legal liability resulting from incidents of fraud and misconduct. Mission To develop comprehensive anti-fraud programs and controls designed to deter, detect, investigate, and remediate incidents of fraud and misconduct within Bunge, including but not limited to: Promptly respond to reports of illegal, unethical, or improper acts committed by company employees or non-employees who are engaged in company business, Conducting fraud awareness training for company employees, Completion of a fraud risk assessment, Enhanced fraud detection through data analytics and forensic audit techniques, Provide litigation support and forensic due diligence for legal and regulatory matters, and Collaborate with compliance and risk management teams to evaluate risks, review processes, and analyze trending. 20 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Global Integrity & Forensic Audit - Scope of Work (1 of 2) Investigation of, Abuse, and/or Misconduct Accounting Irregularities Occupational (Embezzlement, Skimming, Fictitious Invoices, T&E, etc.) Conflicts of Interest Bribery & Corruption Litigation Support Antitrust, Intellectual Property, Securities Trading Risk Assessment 21 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Global Integrity & Forensic Audit - Scope of Work (2 of 2) Proactive Awareness Training Internal Audit (forensic audit techniques) Operating Companies Functions (Finance, Sales, etc.) M&A Due Diligence Ethics & Integrity Case Studies IT Investigative Technology/Computer Forensics FCPA/Third-Party Compliance Third-Party Proactive Reviews Anti-bribery Audits Security Audits/Surveys/Reviews 22 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Scope of Work - Differentiation Compliance Function GIFA Security Function Compliance policies & procedures Ethics programs Compliance investigations oversight (FCPA) Allegations matrix Compliance reporting 3 rd -party compliance programs investigations Anti-fraud training & awareness Litigation support protocols & investigation guidelines Security audits M&A due diligence risk assessments Physical security programs (facilities, cargo, inventory, etc.) Personal security Travel security Security policies and procedures Security investigations (thefts, product tampering, etc.) 23 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Legal Counsel Legal advice Litigation support Attorney-client privilege Review reports for language Communication with the Board, Audit Committee, Senior Management Co-sponsored training 25 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Human Resources Investigative support Interviewing Prior disciplinary actions incidents Personnel files Report distribution Disciplinary action Employee surveys Staffing (compensation, career planning) 26 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Information Technology Electronic evidence collection Data retrieval where/when/how Email reviews Hard drive imaging Internet activity Log in/out data 27 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Security Support investigations Physical access documentation Interviewing skills Prior incidents Location background 28 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Outside Experts Investigative experience/expertise Interviewing skills Data-mining techniques Computer forensics Report-writing skills Forensic auditing expertise Expert witness render opinions 29 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Audit Control weaknesses review Root-cause analyses Data mining Document review Email/electronic evidence reviews Proactive forensic audits Resource pool Forensic rotation program training programs 30 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Audit Committee/Management Periodic updates Annual presentation Immediate notification of serious fraud issues Root-cause analysis Patterns of behavior Legal liability Oversight of investigative activity Sponsorship 31 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Management Findings Continuous Updates Knowledge of Business & People Remediation of Findings Process Improvements Cause & Root Cause Analysis Internal Control Recommendations Training & Awareness 32 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Questions 33 2012 ACFE ANNUAL FRAUD CONFERENCE ORLANDO, FL

Association of Certified Examiners, Certified Examiner, CFE, ACFE, and the ACFE Logo are trademarks owned by the Association of Certified Examiners, Inc. The contents of this paper may not be transmitted, re-published, modified, reproduced, distributed, copied, or sold without the prior consent of the author.