Tuesday, November 12, 2019
Employee Resourcing and Development Essay
Employee resourcing and development is essential to all organisations and highly contributes towards the organisations success. Employee resourcing is ââ¬Ëthe part of human resource management which focuses on the recruitment and release of individuals from organisationââ¬â¢ and ââ¬Ëthe management of their performance and potential while employed by the organisationââ¬â¢ (Pilbeam & Corbridge, 2010). Employee development is ââ¬Ëthe process & facilitation of learning and knowledge that support business goals, develop individual potential and respect and build on diversityââ¬â¢ (Harrison, R., 2009). Employee resourcing and development can significantly add value to an organisation and help to cement the HR business partnership, and this essay will critically analyse the extent to which resourcing and development activities do so. Absence Management Employee absence levels can have substantial negative impacts on organisations; and therefore it is becoming increasingly common to see organisations introducing new, or revising existing, absence management programmes. A study from CIPD found that the ââ¬Ëannual median cost of absence per employee was à £595ââ¬â¢ (CIPD, 2013); costing the UK economy à £17 billion per year (ACAS, 2010). If an employee is absent from work it is highly likely that the organisation will be faced with both direct and indirect costs. Direct costs being those associated with the hiring of, and paying for, temporary staff while the particular employee(s) are absent (ACAS, 2010); Statutory Sick Pay if the employee is absent for 4 or more days in a row; occupational sick pay, if it is part of the particular organisations terms and conditions (GOV.UK, 2013). Secondly, indirect costs are those related to low morale amongst remaining colleagues, who may be expected to take on extra responsibilities as a result of the absence; decreased customer satisfaction, if temporary members of staff are not adequately knowledgeable in particular areas of customer interest; reduced reputation with both customers and potential employees, potentially affecting future business; decreased performance and productivity, as a result of demotivation of remaining colleagues and lack of staff in relation to workload. All of which can significantly impact upon organisational efficiency and effectivenessà (Pilbeam & Corbridge, 2009). Efficient absence management can reduce the detrimental effects that employee absence can have on an organisation, and can also be seen to contribute towards added value. The study carried out by CIPD found that ââ¬Ëreturn-to-work interviews and trigger mechanismsâ⬠¦ are ranked among the most effective approaches for managing short-term absenceââ¬â¢ (CIPD, 2013). A return-to-work interview is a crucial part of an absence management programme ââ¬â welcoming empl oyees back to work following their absence and checking that the employee is well enough to return to work (ACAS, 2010). If an employee returns to work before being fully recovered there is the chance that the employee will take longer to return to full health, reducing productivity and potentially resulting in them being absent again in the near future, and possibly for a longer period. There is also the risk that they could pass on their illness to other colleagues resulting in further absences (Robson, 2006) and further impacts on productivity. Read more: Essay on Developing and Assessing Employees The return-to-work interview also allows organisations to identify the cause of the employeeââ¬â¢s absence and to assess whether their absence was work-related (ACAS, 2010). This then enables the organisation to take steps to prevent the same employee, or other employees, being absent for similar reasons in the future; this may include training updates in health and safety for example. The cost of such changes will be potentially outweighed by the benefits, by reducing employee absence levels in the long-term. A return-to-work interview may also outline the underlying reasons for absence, such as the employee having to take care of an elderly relative (ACAS, 2010). In these circumstances an organisation may decide to develop different working arrangements with that particular employee, for example flexible working. Flexible working allows the organisation to fit around the employeeââ¬â¢s schedule, potentially reducing the number of days that the employee needs to take off work unexpectedly as a result of their circumstances; thus reducing the negative impact that unexpected absences can have on productivity and associated costs. It also enables organisations to plan ahead ââ¬â if they know that a particular employee is going to be off work then they can recruit temporary/part-time staff to fill in on these days; reducing the impact that the extra workload could have on colleagues stress levels and allows the organisation to maintain levels of productivity. The effectiveness of flexible working and the extent to whichà it adds value, however, relies heavily on whether or not it is valued by the employees themselves (Hodge, 2009); therefore this should be investigated prior to it being implemented. As previously mentioned trigger mechanisms, such as the Bradford Factor is also found to have an ââ¬Ëoverwhelmingly positive impact on absenceââ¬â¢ (CIPD, 2013, p. 31). The Bradford Factor is a ââ¬Ëmechanism for weighting frequency of sickness absenceââ¬â¢ (Pilbeam & Corbridge, 2009 p. 340). Such management techniques of monitoring absence increase productivity and reduce levels of absenteeism; which in the long-term will reduce organisational costs, resulting in increased profit. A study looking into the impact of positive intervention in absence management found that trigger mechanisms reduced absenteeism, especially if sick pay was withdrawn or there was the threat of disciplinary action (Baker-McClearn, et al., 2010). However , this was also found to ââ¬Ëcontribute to low morale, lack of commitment to work, stress and anxietyââ¬â¢ (Baker-McClearn, et al., 2010), all of which could potentially lead to reduced productivity resulting in increased costs. There was also a close link found between the use of trigger mechanisms and increasing levels of presenteeism (Baker-McClearn, D. et al., 2010). Presenteeism can be used to describe people ââ¬Ëwho, despiteâ⬠¦ ill healthâ⬠¦ are still turning up at their jobââ¬â¢ (Unison. 1999, as cited in Baker-McClearn, et al., p. 311). For example, employees would come into work feeling unwell as, one, they couldnââ¬â¢t afford to remain absent if not receiving sick pay and two, they were frightened of the consequences disciplinary action would bring. This has severe impacts upon productivity, with findings showing that ââ¬Ëproductivity drops from 75% on ââ¬Ënormal daysââ¬â¢ to 55% on ââ¬Ësick daysââ¬â¢Ã¢â¬â¢ (Newcombe, T., 2013). Ther efore, although the Bradford Factor is effective in reducing absenteeism, it is questionable whether the benefits of this outweigh the negative impacts on the employee and the impacts that presenteeism can have on the organisation. As previously mentioned, HR aims to improve employee productivity through absence management. This consequently improves employee performance, which contributes towards organisational objectives, such as improving performance ââ¬â potentially leading to increased profit margins. Therefore the alignment of the HR practitionerââ¬â¢s objectives with the business managerââ¬â¢s objectives helps to reinforce the business partnership; with both partners working together toà achieve organisational objectives. Employee Well-Being Employee well-being has been defined by CIPD as ââ¬Ëcreating an environment to promote a state of contentment which allow employees to flourish and achieve their full potential for the benefit of themselves and their organisationââ¬â¢ (Pilbeam & Corbridge, 2009, p. 416). It is becoming increasingly common to see organisations adopting measures designed to promote employee health and well-being; as organisational researchers have found that dysfunctional employee well-being can have widespread costs for the organisation (Wright & Chuang, 2012). For instance, employee well-being strategies aim to create a healthier workforce which consequently leads to reduced absence levels. Therefore, as a result, this then leads to a reduction in the significant financials costs related to employee absence (Bevan, S., 2010). Employee well-being also aims to target long-term absence related to depression and anxiety; both of which prove to be ââ¬Ëmore complex and costly to manage, and have m ore significant consequences for employersââ¬â¢ (Bevan, S., 2010, p. 11). Therefore, it is likely that the costs of implementing such well-being policies will be outweighed by the significant savings and increased added value that will be seen as a result. These measures have not only been found to positively influence an employeeââ¬â¢s health and well-being, but also to add value to an organisation through improved employee productivity and commitment (Bevan, S., 2010). As previously mentioned, well-being can have a positive impact on absence levels which as a result improves employee productivity. Macdonald (2005) also suggested that well-being strategies contributed towards employee morale, increased levels of productivity and employee retention (Pilbeam, & Corbridge, 2009). Research has also gone onto to find that there is a significant link between employee well-being and job performance, workplace accidents, customer engagement, quality defects and profitability. Job per formance has been found to be highly correlated with employee well-being in a number of organisational studies (Thomas, et al, 2012). Absence management is one way in which performance can be improved within all organisations, particularly within the domiciliary care sector. With government cut backs and managements time being constrained, absence management schemes can often be overlooked, resulting in high levels of absenteeism. As previously mentioned, the Bradford factor has been found toà have an ââ¬Ëoverwhelmingly positive impact on absenceââ¬â¢ (CIPD, 2013, p. 31) and is one way that domiciliary care businesses could monitor absence effectively and efficiently, without taking up too much of managementââ¬â¢s time and without incurring substantial costs. Return-to-work interviews will also enable management to identify the key reasons behind the absence, allowing management to take steps to potentially prevent absence of the same reason occurring again. Both techniques will in theory reduce absenteeism as employees will be aware that their absence is being monitored, and so they will be less likely to be absent from work as frequently; therefore overall increasing organisational performance. Recruitment and Selection Recruitment is ââ¬Ëthe process of generating a pool of capable people to apply for employment to an organisationââ¬â¢ and selection is ââ¬Ëthe process by which managers and others use specific instruments to choose from a pool of applicants a person or persons more likely to succeed in the job(s)ââ¬â¢ (Braton and Gold, 2007, as cited by French & Rumbles, 2010). The recruitment and selection process is ââ¬Ëfundamental to the functioning of an organisationââ¬â¢ (Pilbeam & Corbridge, 2006, p. 155), and it is also said that ââ¬Ëthe success of an organisation depends on having the right number of staff, with the right skills and abilitiesââ¬â¢ (ACAS, 2010, p. 3). Therefore, the right recruitment and selection procedures are crucial to an organisation finding the best candidate for the job. Recruitment The recruitment process is extremely important when it comes to adding value to an organisation in the long-term. Poor recruitment processes ââ¬â which result in the wrong candidate being selected for the job ââ¬â can be very expensive for an organisation in terms of employee turnover, organisational costs and employee morale (ACAS, 2010). Good recruitment can ââ¬Ësignificantly contribute to effective organisational performance, to good employee relations, and to a positive public imageââ¬â¢ (Pilbeam & Corbridge, 2010, p. 156). The first step in the recruitment process is to create an effective job description and job specification. It is vital that the skills and competencies outlined within the person specification are accurate inà relation to the needs of the job. If this is not the case then there is the chance that an individual will be employed with false expectations, potentially resulting in them not performing as well as was originally intended (ACAS, 2010). In worse cases, the employee may lose faith in the organisation and leave to work for potential competitors, taking with them the training they have received. Not only is this is a waste of an organisations time, money and resources ââ¬â all of which can be potentially avoided if an organisation has an effective recruitment procedure in place ââ¬â but it can also have an impact on existing employees morale. For example, it can be demotivating for existing employees to see new employees coming and going within a short space of time. The process of recruiting and training new employees can also be lengthy, in which time colleagues will potentially be expected to take on extra responsibilities; possibly impacting upon employee productivity and overall organisational performance. Over recent years online recruitment has become increasingly popular. Online recruitment shortens the recruitment cycle (Pilbeam & Corbridge, 2010), which can be of great benefit to some organisations w ho find that their lengthy recruitment process can result in them losing potential candidates (CIPD, 2013). A survey carried out by Chapman and Webster (2003) also found that most organisations (within the USA) that used technology based recruitment and selection techniques, did so because they found that they added value in terms of improved efficiency, reduced costs and increased the number of potential candidates. This improved efficiency and reduced costs will potentially allow organisations to increase their profit margins, and by widening the applicant pool the organisation has a greater chance of finding the ââ¬Ërightââ¬â¢ candidate for the job. However, although this method of recruitment generates a high volume of candidates, it does not necessarily mean that these candidates possess the relevant skills or attitudes required for the job. It is also particularly important that the recruitment and selection process is fair. The employer must recognise that it has a lega l obligation to make sure that they do not unlawfully discriminate against potential candidates during the recruitment and selection process (ACAS, 2010). In ensuring this, an organisation reduces its risk of facing legal costs that may be incurred if it were to be seen to demonstrate unlawful recruitment and selection procedures; improving the organisations reputationà and therefore adding value. For example, if an organisation is seen to operate ethically and value equality then it is likely that the organisation will see an increase in their customer base and also in the number of candidates wanting to work for the organisation ââ¬â increasing the likelihood of the organisation finding the right person for the job. Selection ââ¬ËInappropriate selection decisions reduce organisational effectiveness, invalidate reward and development strategies, are frequently unfair on the individual recruit and can be and can be distressing for managers who have to deal with unsuitable employeesââ¬â¢ (Pilbeam & Corbridge, 2010, p. 155). Therefore, it is important that the selection process is carried out effectively, ensuring the ââ¬Ëbestââ¬â¢ candidate is chosen for the job. The selection process not only produces a shortlist of applicants for the interviewing stage, but it also provides the organisation with feedback in regards to their job advertising and the application form. This will help improve the organisations future recruitment and selection procedures, making the process of finding the ââ¬Ërightââ¬â¢ candidate more effective; therefore saving organisational time and reducing any potential costs associated with ineffective selection procedures. It is essential that the selection process gains the commitment of managers and supervisors, by involving them in the process of selecting a candidate (ACAS, 2010). The managers and supervisors will have first-hand knowledge and experience and therefore will know what it is they need in future employees, making the process of selecting the ââ¬Ëbestââ¬â¢ person for the job more effective. This again will add value to the organisation, as if the right person is selected for the organisation then it is highly likely that they will perform well, potentially improving organisational performance overall. The involvement of the managers and supervisors will also help settle the new employee into the organisation, making them feel comfortable within their new role; potentially reducing employee turnover levels and the costs associated with this. The involvement between HR and business managers throughout recruitment and selection also helps to reinforce the business partnership. This involvement ensures that recruitment and selecti on is carried out in line with the organisations strategy ââ¬â ensuring that the candidate selectedà contributes to organisational objectives. Recruitment and selection can be an issue within a lot of organisations, in particular those within the domiciliary care sector. Domiciliary care tends to involve very demanding work, and due to ineffective selection techniques the wrong candidates are selected for the jobs; therefore resulting in high levels of employee turnover. Psychometric testing is one selection technique that would allow domiciliary care businesses to assess the personalities of potential candidates; improving decision-making and allowing managers to ââ¬Ëdevelop more informed and accurate perceptions about the ability and potential of individualsââ¬â¢ (CIPD, 2009, as cited in Pilbeam & Corbridge, 2010, p. 202). This will help ensure the ââ¬Ërightââ¬â¢ candidate is chosen; reducing employee turnover and any associated costs, and improving employee mora le and productivity ââ¬â therefore enhancing overall organisational performance within this sector. Talent Management Talent management is ââ¬Ëthe systematic attraction, identification, development, engagement, retention and deployment of those individuals who are of particular value to an organisation.ââ¬â¢ These individuals ââ¬Ëmake a difference to organisational performance either through their immediate contribution or, in the longer-term, by demonstrating the highest levels of potentialââ¬â¢ (CIPD, 2013). Talent management has become an increasingly common practice within a lot of organisations, due to a weakening economic climate which has put pressure on organisations to cut costs and increase efficiency and productivity (CIPD, 2013). In the current climate ââ¬Ëhaving a rigorous, cyclical, ongoing process around Talent Management [can] be a key differentiator between success and failureââ¬â¢ (Couch, 2012). Talent has been seen to add value to organisations, particularly as talent management has become ââ¬Ëintegral in engaging employees in the organisationââ¬â¢, if prac ticed effectively (Morton, 2005, p. 11, as cited in Hughes & Rog, 2008, p. 746). Engaged employees are committed to the organisation and therefore will be less likely to leave; this as a result minimises employee turnover and any associated costs. Towers Perrin (2003) supports this idea, as he found that 66 percent of highly engaged employees plan to stay with their current employers, compared to only 12 percent of disengaged employees. It is alsoà more likely to see higher levels of performance from engaged employees; potentially improving customer service and productivity, as well as increasing sales and profits (Hughes, J. C. & Rog, E., 2008). Effective talent management also ensures organisations can successfully attract and retain talent, reducing the risk of talent leaving the organisation or being employed by a competitor ââ¬â thus allowing organisations to gain a competitive advantage. Organisations that focus on retaining talented individuals are also able to add value through reduced recruitment and training costs as a result of not having to recruit talent externally, or develop talent internally. Retention of talent also reduces the negative impact employee turnover can have on organisational productivity and employee morale; which in turn can potentially have a consequential effect on profit margins (Chitakasem, N., 2011). There is evidence, however, to suggest that talent management doesnââ¬â¢t always add value to organisations. Lewis and Heckman (2006) argued that ââ¬Ëimprovements in bottom line results [prove] to be temporary, despite an ongoing commitment to talent in the organisationââ¬â¢ (as ci ted in Hughes & Rog, 2008, p. 745). Therefore, it is important organisations evaluate the effectiveness of their talent management scheme as this can contribute highly to its success, enabling them to maximise their return on investment (CIPD, 2009). Also, a focus on external recruitment and retention of ââ¬Å"high talentâ⬠employees could: increase competition amongst internal candidates, consequently discouraging teamwork; lead to existing employees feeling undervalued, resulting in increased turnover; redirect training and development from those employees who may be struggling to those who are capable, reduce performance of those who donââ¬â¢t receive training; and ignore fixing cultural or other systematic issues which hinder employee performance (Hughes & Rog, 2008). Whelan & Carcary (2001) also say that those employees who are not seen to be ââ¬Ëkey talentââ¬â¢ can become demotivated as a result of them feeling unappreciated within the organisation; leading to f alls in productivity and potentially negatively affecting profit margins. Therefore, in some cases, talent management may not always add value; the extent to which talent management adds value can depend on how well the organisation manages those employees who are not seen to be ââ¬Ëkey talentââ¬â¢. Organisations implementing talentà management programmes may also experience resistance from some employees; as talent management makes their performance more visible to employers and creates a direct link between future career opportunities within the organisation and rewards (Little, B. 2010). Resistance from employees will likely have a knock on effect on productivity, resulting in profit margins being affected; again affecting the extent to which talent management can add value to an organisation. Overall, talent management, if managed effectively, can significantly add value to an organisation. Maximising employee performance and productivity, improving employee retention, a nd increasing the flexibility of employees etc. all contribute towards an organisations success. However, the business partnership plays a significant role in the extent to which talent management can add value within an organisation. A survey carried out by the Corporate Executive Boardââ¬â¢s Corporate Leadership Council (CLC) discovered that ââ¬ËHR must effectively partner with business line management to drive talent outcomesââ¬â¢ (Martin, 2010). It is important that line managerââ¬â¢s work with HR practitioners so as to ensure that talent management is directed in the right areas of the organisation and that it is aligned with strategic goals. The HR practitioner must also be knowledgeable of the organisations objectives so as to implement talent management programmes that will contribute towards achieving these goals. As a result, this will potentially help to reinforce the business partnership, encouraging HR to work in partnership with the business leaders to improve its performance and future success. Talent management can be beneficial for many organisations in terms of developing and retaining talented employees so as to improve organisational performance. The domiciliary care, as previously mentioned, has problems with employee retention and therefore talent management could be one way of addressing this issue. Appraisals could be used to assess employeesââ¬â¢ performance, and allow managers to identify talent within the organisation, and the training needs (Pilbeam & Corbridge, 2010). Managers can then support and mentor talented employees through further training programmes (CIPD, 2013), such as National Vocational Qualifications (NVQââ¬â¢s). This support will contribute towards employees feeling valued within the organisation, and this along with the increased knowledge and motivation will help to improve employee performance; which as a result willà potentially improve employee retention and the overall performance of the organisation. In conclusion, absence management, recruitment and selection, and talent management, if effectively managed and implemented, can improve organisational performance. Absence management was found to reduce the negative costs associated with absenteeism, and improve employee morale and productivity. Effective recruitment and selection was found to improve the chances of finding the ââ¬Ërightââ¬â¢ person for the job; therefore increasing employee performance and reducing employee turnover. Finally, talent management was found to increase employee engagement and motivation through mentoring, and improve employee performance and retention through development. Therefore all three resourcing and development activities contribute towards improving organisational performance, consequently adding value to the organisation. Finally, the aim of human resources to achieve organisational goals through these resourcing and development activities helps to contribute towards cementing the busine ss partnership. References GOV.UK. (2013). Statutory Sick Pay (SSP). Accessed 17th November 2013 https://www.gov.uk/statutory-sick-pay Newcombe, T. (23 May 2013). Stress and presenteeism ââ¬Å"sapping UK productivityâ⬠, says research. HR Magazine. Retrieved from http://www.hrmagazine.co.uk/hro/news/1077290/stress-presenteeism-sapping-uk-productivity-research Baker-McClearn, D. et al. (2010). Absence management and presenteeism: the pressures on employees to attend work and the impact of attendance on performance. Human Resource Management Journal. 20 (3), 311ââ¬â328. doi: 10.1111/j.1748-8583.2009.00118.x Robson, F. (2006). How toâ⬠¦ manage absence effectively. CIPD. Retrieved from http://www.cipd.co.uk/pm/peoplemanagement/b/weblog/archive/2006/08/88/howtomanageabsence-2006-08.aspx Hemsley, S. (2011). Absence: How does it affect the workplace and what can employers do about it? HR Magazine. Retrieved from http://www.hrmagazine.co.uk/hr/features/1019816/absence-how-affect-workplace-employers Howart h, J. (2005). Absence management. Strategic Direction, 21
Sunday, November 10, 2019
Fraud Risk Management
Fraud risk management A guide to good practice 1 This guide is based on the fi rst edition of Fraud Risk Management: A Guide to Good Practice. The fi rst edition was prepared by a Fraud and Risk Management Working Group, which was established to look at ways of helping management accountants to be more effective in countering fraud and managing risk in their organisations. This second edition of Fraud Risk Management: A Guide to Good Practice has been updated by Helenne Doody, a specialist within CIMA Innovation and Development.Helenne specialises in Fraud Risk Management, having worked in related fi elds for the past nine years, both in the UK and other countries. Helenne also has a graduate certifi cate in Fraud Investigation through La Trobe University in Australia and a graduate certifi cate in Fraud Management through the University of Teeside in the UK. For their contributions in updating the guide to produce this second edition, CIMA would like to thank: Martin Birch FCMA, MBA Director ââ¬â Finance and Information Management, Christian Aid.Roy Katzenberg Chief Financial Offi cer, RITC Syndicate Management Limited. Judy Finn Senior Lecturer, Southampton Solent University. Dr Stephen Hill E-crime and Fraud Manager, Chantrey Vellacott DFK. Richard Sharp BSc, FCMA, MBA Assistant Finance Director (Governance), Kingston Hospital NHS Trust. Allan McDonagh Managing Director, Hibis Europe Ltd. Martin Robinson and Mia Campbell on behalf of the Fraud Advisory Panel. CIMA would like also to thank those who contributed to the fi rst edition of the guide. About CIMACIMA, the Chartered Institute of Management Accountants, is the only international accountancy body with a key focus on business. It is a world leading professional institute that offers an internationally recognised qualifi cation in management accounting, with a full focus on business, in both the private and public sectors. With 164,000 members and students in 161 countries, CIMA is committed to upho lding the highest ethical and professional standards of its members and students. à © CIMA 2008. All rights reserved.This booklet does not necessarily represent the views of the Council of the Institute and no responsibility for loss associated to any person acting or refraining from acting as a result of any material in this publication can be accepted by the authors or publishers. Acknowledgements Fraud risk management: a guide to good practice 2 Contents Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Fraud ââ¬â its extent, patterns and causes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 1. 1 What is fraud? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 1. 2 The scale of the problem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1. 3 Which businesses are affected? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 1. 4 Why do people commit fraud? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 1. 5 Who commits fraud? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 1. 6 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 Risk management ââ¬â an overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 2. 1 Wh at is risk management? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 2. 2 Corporate governance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 2. 3 The risk management cycle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 2. 4 Establish a risk management group and set goals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 2. 5 Identify risk areas . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 2. 6 Understand and assess the scale of risk . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 2. 7 Develop a risk response strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2. 8 Implement the strategy and allocate responsibilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2. 9 Implement and monitor suggested controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2. 10 Review and refi ne and do it again . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2. 11 Information for decision making . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2. 12 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23 Fraud prevention . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 3. 1 A strategy to combat fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 3. 2 Developing a sound ethical culture . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 3. 3 Sound internal control systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 3. 4 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 Fraud detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 4. 1 Detection methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 4. 2 Indicators and warnings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 4. 3 Tools and techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41 4. 4 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 Responding to fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 5. 1 Purpose of the fraud response plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 5. 2 Corpor ate policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 5. 3 Defi nition of fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 5. 4 Roles and responsibilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 5. 5 The response . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47 5. 6 The investigation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 5. 7 Organisationââ¬â¢s objectives with respect to dealing with fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 5. 8 Follow-up action . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 5. 9 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 1 2 3 4 5 3 Appendices Appendix 1 Fraud and the law . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 Appendix 2 Examples of common types of internal fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57 Appendix 3 Example of a risk analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60 Appendix 4 A sample fraud policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61 Appendix 5 Sample whistleblowing policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62 Appendix 6 Examples of fraud indicators, risks and controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 Appendix 7 A 16 step fraud prevention plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67 Appendix 8 Outline fraud response plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 Appendix 9 Example of a fraud response plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69 Appendix 10 References and further reading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77 Appendix 11 Listed abbreviations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80 Figures Figure 1 Types of internal fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Figure 2 The fraud triangle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Figure 3 The CIMA risk management cycle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Figure 4 Anti-fraud strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 Figure 5 Ethics advice/services provided . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 Figure 6 Meth ods of fraud detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Case Studies Case study 1 Fraud doesnââ¬â¢t involve just money . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Case study 2 Size really doesnââ¬â¢t matter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 Case study 3 A breach of trust . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 Case study 4 Management risk . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 Case study 5 A fi ne warning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 Case study 6 Vet or regret? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 Case study 7 Tipped off . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 Case study 8 Risk or returns . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42 Case study 9 Reporting fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 Case study 10 TNT roots our fraud . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 4 5 Periodically, the latest major fraud hits the headlines as other organisations sit back and watch, telling themselves that ââ¬Ëit couldnââ¬â¢t happen here. ââ¬â¢ But the reality is that fraud can happen anywhere. While only relatively few major frauds are picked up by the media, huge sums are lost by all kinds of businesses as result of the high number of smaller frauds that are committed. Surveys are regularly carried out in an attempt to estimate the true scale and cost of fraud to business and society. Findings vary, and it is diffi cult to obtain a complete picture as to the full extent of the issue, but these surveys all indicate that fraud is prevalent within organisations and remains a serious and costly problem. The risks of fraud may only be increasing, as we see growing globalisation, more competitive markets, rapid developments in technology, and periods of economic diffi culty. Among other fi ndings, the various surveys highlight that: organisations may be losing as much as 7% of their annual turnover as a result of fraud â⬠¢ corruption is esti mated to cost the global economy about $1. 5 trillion each year â⬠¢ only a small percentage of losses from fraud are recovered by organisations â⬠¢ a high percentage of frauds are committed by senior management and executives â⬠¢ greed is one of the main motivators for committing fraud â⬠¢ fraudsters often work in the fi nance function â⬠¢ fraud losses are not restricted to a particular sector or country â⬠¢ the prevalence of fraud is increasing in emerging markets. Introduction Despite the serious risk that fraud presents to business, any organisations still do not have formal systems and procedures in place to prevent, detect and respond to fraud. While no system is completely foolproof, there are steps which can be taken to deter fraud and make it much less attractive to commit. It is in assisting organisations in taking such steps that this guide should prove valuable. The original guide to good practice was based on the work of CIMAââ¬â¢s Fraud and Ri sk Management Working Group that was established as part of the Instituteââ¬â¢s response to the problem of fraud. Since the publication of the original guide, we have continued to see high rofi le accounting scandals and unacceptable levels of fraudulent behaviour. This second edition of the guide includes updates to refl ect the many changes in the legal environment and governance agenda in recent years, aimed at tackling the ongoing problem of fraud. The guide starts by defi ning fraud and giving an overview of the extent of fraud, its causes and its effects. The initial chapters of the guide also set out the legal environment with respect to fraud, corporate governance requirements and general risk management principles. The guide goes on to discuss the key components of an anti-fraud strategy nd outlines methods for preventing, detecting and responding to fraud. A number of case studies are included throughout the guide to support the text, demonstrating real life problems th at fraud presents and giving examples of actions organisations are taking to fi ght fraud. Fraud risk management: a guide to good practice Management accountants, whose professional training includes the analysis of information and systems, can have a signifi cant role to play in the development and implementation of anti-fraud measures within their organisations. This guide is intended to help management accountants in that role and will also be seful to others with an interest in tackling fraud in their organisation. The law relating to fraud varies from country to country. Where it is necessary for this guide to make reference to specifi c legal measures, this is generally to UK law, as it would be impossible to include references to the laws of all countries where this guide will be read. It is strongly advised that readers ensure they are familiar with the law relating to fraud in their own jurisdiction. Although some references may therefore not be relevant to all readers, the general principles of fraud risk management will still apply and rganisations around the world are encouraged to take a more stringent approach to preventing, detecting and responding to fraud. 6 7 Defi nition of fraud The term ââ¬Ëfraudââ¬â¢ commonly includes activities such as theft, corruption, conspiracy, embezzlement, money laundering, bribery and extortion. The legal defi nition varies from country to country, and it is only since the introduction of the Fraud Act in 2006, that there has been a legal defi nition of fraud in England and Wales. Fraud essentially involves using deception to dishonestly make a personal gain for oneself and/or create a loss for another. Although defi nitions vary, ost are based around these general themes. Fraud and the law Before the Fraud Act came into force, related offences were scattered about in many areas of the law. The Theft Acts of 1968 and 1978 created offences of false accounting, and obtaining goods, money and services by decept ion, and the Companies Act 1985 included the offence of fraudulent trading. This remains part of the Companies Act 2006. There are also offences of fraud under income tax and value-added tax legislation, insolvency legislation, and the common law offence of conspiracy to defraud. The Fraud Act is not the only new piece of legislation.Over the last few years there have been many changes to the legal system with regard to fraud, both in the UK and internationally. This guide focuses mainly on UK requirements, but touches on international requirements that impact UK organisations. In the UK, the Companies Act and the Public Interest Disclosure Act (PIDA) have been amended and legislation such as the Serious Crimes Act 2007 and the Proceeds of Crime Act 2002 (POCA) have been introduced. Internationally the Sarbanes-Oxley Act 2002 (Sarbox) has been introduced in the United States (US), a major piece of legislation that affects not only companies in the US ut also those in the UK and othe rs based all over the globe. Further information on these pieces of legislation can be found in Appendix 1. As well as updating the legislation in the UK, there have been, and will continue to be, signifi cant developments in the national approach to combating fraud, particularly as we see implementation of actions resulting from the national Fraud Review. Appendix 1 gives further information on the Fraud Review. There are also many law enforcement agencies involved in the fi ght against fraud in the UK, including the Serious Fraud Offi ce, the Serious Organised Crime Agency SOCA), the Financial Services Authority (FSA), and Economic Crime Units within the police force. Different types of fraud Fraud can mean many things and result from many varied relationships between offenders and victims. Examples of fraud include: â⬠¢ crimes by individuals against consumers, clients or other business people, e. g. misrepresentation of the quality of goods; pyramid trading schemes â⬠¢ em ployee fraud against employers, e. g. payroll fraud; falsifying expense claims; thefts of cash, assets or intellectual property (IP); false accounting â⬠¢ crimes by businesses against investors, consumers and employees, e. g. i nancial statement fraud; selling counterfeit goods as genuine ones; not paying over tax or National Insurance contributions paid by staff â⬠¢ crimes against fi nancial institutions, e. g. using lost and stolen credit cards; cheque frauds; fraudulent insurance claims â⬠¢ crimes by individuals or businesses against government, e. g. grant fraud; social security benefi t claim frauds; tax evasion â⬠¢ crimes by professional criminals against major organisations, e. g. major counterfeiting rings; mortgage frauds; ââ¬Ëadvance feeââ¬â¢ frauds; corporate identity fraud; money laundering â⬠¢ e-crime by people using computers and technology to commit crimes, e. . phishing; spamming; copyright crimes; hacking; social engineering frauds. 1. 1 Wh at is fraud? 1 Fraud: its extent, patterns and causes Figure 1 Types of internal fraud Cash Non-cash Financial Non-fi nancial Confl icts of interest Bribery and extortion Asset misappropriation Fraudulent statements Corruption Internal fraud Fraud risk management: a guide to good practice 8 The fi nal of the three fraud categories is corruption. This includes activities such as the use of bribes or acceptance of ââ¬Ëkickbacksââ¬â¢, improper use of confi dential information, confl icts of interest and collusive tendering. These types of internal fraud are summarised n Figure 1. Surveys have shown that asset misappropriation is the most widely reported type of fraud in UK, although corruption and bribery are growing the most rapidly. Further information on common types of internal fraud, and methods by which they may be perpetrated, is included in Appendix 2. This guide focuses on fraud against businesses, typically by those internal to the organisation. According to the Associa tion of Certifi ed Fraud Examiners (ACFE), there are three main categories of fraud that affect organisations. The fi rst of these is asset misappropriations, which involves the theft or misuse f an organisationââ¬â¢s assets. Examples include theft of plant, inventory or cash, false invoicing, accounts receivable fraud, and payroll fraud. The second category of fraud is fraudulent statements. This is usually in the form of falsifi cation of fi nancial statements in order to obtain some form of improper benefi t. It also includes falsifying documents such as employee credentials. 9 1. 2 The scale of the problem There have been many attempts to measure the true extent of fraud, but compiling reliable statistics around fraud is not easy. As one of the key aspects of fraud is deception, it can be diffi cult to identify and urvey results often only refl ect the instances of fraud that have actually been discovered. It is estimated that the majority of frauds go undetected and, even wh en a fraud has been found, it may not be reported. One reason for this may be that a company that has been a victim of fraud does not want to risk negative publicity. Also, it is often hard to distinguish fraud from carelessness and poor record keeping. Although survey results and research may not give a complete picture, the various statistics do offer a useful indication as to the extend of the problem. There can be no doubt that fraud is prevalent within organisations nd remains a serious issue. PricewaterhouseCooperââ¬â¢s Global Economic Crime Survey (PwCââ¬â¢s survey) in 2007 found that over 43% of international businesses were victims of fraud during the previous two years. In the UK, the fi gures were higher than the global average, with 48% of companies having fallen victim to fraud. Some surveys put the fi gures much higher. For example, during 2008, Kroll commissioned the Economist Intelligence Unit (EIU) to poll nearly 900 senior executives across the world. The EIU found that 85% of companies had suffered from at least one fraud in the past three years1. This fi gure had risen from 80% in a imilar poll in 2007. KPMGââ¬â¢s Fraud Barometer, which has been running since 1987, has also shown a considerable increase in the number of frauds committed in the UK in recent years, including a 50% rise in fraud cases in the fi rst half of 2008. According to the UK report of PwCââ¬â¢s survey, the average direct loss per company over a two year period as a result of fraud has risen to ? 1. 75 million, increasing from ? 0. 8 million in the equivalent 2005 survey. These fi gures exclude undetected losses and indirect costs to the business such as management costs or damage to reputation, which can be signifi cant. Management costs lone were estimated to be on average another ? 0. 75 million. Participants of the ACFE Report to the Nation 2008 (ACFE report) estimated that organisations lose 7% of their annual revenues to fraud. It is diffi cult to put a total cost on fraud, although many studies have tried to. For example an independent report by the Association of Chief Police Offi cers (the ACPO) in 2007 revealed that fraud results in losses of ? 20 billion each year in the UK. The World Bank has estimated that the global cost of corruption and bribery is about 5% of the value of the world economy or about $1. 5 trillion per year. It is thought that these stimates are conservative, and they also exclude other types of fraud such as misappropriation of assets. While it may be impossible to calculate the total cost of fraud, it is said to be more signifi cant than the total cost of most other crimes. According to the Attorney General in the UK, fraud is an area of crime which is second only to drug traffi cking in terms of causing harm to the economy and society2. 1 Kroll Global Fraud Report, Annual Edition 2008/2009 2 Attorney Generalââ¬â¢s interim report on the governmentââ¬â¢s Fraud Review, March 2006 Fraud risk managemen t: a guide to good practice 10 Case study 1 Fraud doesnââ¬â¢t just involve moneyCounterfeiting is one example of fraud that can have extremely serious consequences. Technology is ever improving, making it easier for counterfeiters to produce realistic looking packaging and fool legitimate wholesalers and retailers. Counterfeiting is a potentially lucrative business for the fraudster, with possibilities of large commercial profi ts, and it is a problem affecting a wide range of industries including wines and spirits, pharmaceuticals, electrical goods, and fashion. However, there are often many victims affected by such a fraud and not just the business that has been duped or had their brand exploited.For some, the outcome of counterfeiting goes way beyond fi nancial losses and can even be fatal: â⬠¢ In late 2006, 14 Siberian towns declared a state of emergency due to mass poisonings caused by fake vodka. Around 900 people were hospitalised with liver failure after drinking indu strial solvent that was being sold as vodka. This is not a one off problem and sales of fake alcohol have been known to kill people. â⬠¢ Also in 2006, a counterfeit product did result in more tragic consequences. At least 100 children died after ingesting cough syrup that had been mixed with counterfeit glycerine.The counterfeit compound, actually a dangerous solvent, had been used in place of more expensive glycerine. The manufacturing process had been sourced to China and the syrup passed through trading companies in Beijing and Barcelona before reaching its fi nal destination in Panama. The certifi cate attesting to the productââ¬â¢s purity was falsifi ed and not one of the trading companies tested the syrup to confi rm its contents along the way. It is thought that the number of deaths is likely to be much higher than the 100 cases that have been confi rmed. Fraud is often mistakenly considered a victimless rime. However, fraud can have considerable social and psychologic al effects on individuals, businesses and society. For example, when a fraud causes the collapse of a major company, numerous individuals and businesses can be affected. In addition to the companyââ¬â¢s own employees, employees of suppliers can be affected by the loss of large orders, and other creditors, such as banks, can be indirectly affected by huge losses on loans. Consumers have to pay a premium for goods and services, in order to compensate for the costs of fraud losses and for money spent on investigations and additional security.Taxpayers also suffer due to reduced payments of corporation tax from businesses that have suffered losses. Fraud drains resources, affects public services and, perhaps of more concern, may fund other criminal and terrorist activity. According to the Fraud Review, fraud is a major and growing threat to public safety and prosperity. Case study 1 demonstrates just how much of a threat fraud can be to public safety and that there truly are victims of fraud. 11 1. 3 Which businesses are affected? Fraud is an issue that all organisations may face regardless of size, industry or country. If the rganisation has valuable property (cash, goods, information or services), then fraud may be attempted. It is often high profi le frauds in large multi-national organisations that are reported on in the media and smaller organisations may feel they are unlikely to be a target of fraudsters. However, according to the ACFE report, small businesses (classifi ed as those with less than 100 employees) suffer fraud more frequently than large organisations and are hit by higher average losses. When small companies are hit by large fraud losses, they are less likely to be able to absorb the damage han a larger company and may even go out of business as a result. The results of PwCââ¬â¢s survey showed that companies reporting fraud were spread across many industries, with at least a quarter of the respondents in any one industry suffering from f raudulent incidents. Industries suffering the highest average losses were insurance and industrial manufacturing. Losses in the fi nancial services industry, a sector frequently in the press and one with which fraud is often associated, were actually below average. Even not-for-profi t organisations are not immune to fraud, with government institutions nd many charities falling victim to unscrupulous fraudsters. As one director working in the international development and aid sector has pointed out, ââ¬ËIn my sector, fraud is not a possibility, it is a reality and we are always dealing with a number of suspicious incidents on a more or less permanent basis. ââ¬â¢ PwCââ¬â¢s survey also revealed that incidences of fraud were highest in companies in North America, Africa and Central and Eastern Europe (CEE), where more than half of the companies reported fraud. It was lowest in the Western European region, although the UK was uch higher than the average for this region, with l evels of fraud similar to those in CEE. The EIU poll commissioned by Kroll in 2007 found that respondents in countries such as India and China have seen a signifi cant increase in the prevalence of corporate fraud in the last three years and this trend is likely to increase in businesses operating in emerging markets3. Although fraud is prevalent across organisations of all sizes and in all sectors and locations, research shows that certain business models will involve greater levels of fraud risk than others. The control environment hould be adjusted to fi t with the degree of risk exposure. Further guidance on risk assessment and controls is given in later chapters. 3 Kroll Global Fraud Report, Annual Edition 2007/2008 Fraud risk management: a guide to good practice 12 Case study 2 Size really doesnââ¬â¢t matter From a family affairâ⬠¦ A member of a small family business in Australia committed a $2m fraud, costing profi ts, jobs and a great deal of trust. The business owner s became suspicious when they realised that their son in law used the company diesel card to buy petrol for his own car.On closer scrutiny, they soon uncovered a company cheque for $80,000 made payable to the son in lawââ¬â¢s personal account. BDOââ¬â¢s Brisbane offi ce discovered that the cheque and the fuel were just the tip of a vast iceberg. The companyââ¬â¢s complex accounts system allowed the son in law to disguise cheques payable to himself as creditor payments. He then became a signatory and took ever larger cheques. He claimed that the poor cash fl ow was due to losses in one particular division which the family therefore closed, creating redundancies and losing what was in truth a successful business.The costs of ineffi cient accounting systems and undue trust can be massive. Every business should protect itself with thorough controls and vigilance. Adapted from ââ¬ËFraudTrack 5 Fraud: A Global Challengeââ¬â¢ published by BDO Stoy Hayward â⬠¦ to a major corporate scandal WorldCom fi led for bankruptcy protection in June 2002. It was the biggest corporate fraud in history, largely a result of treating operating expenses as capital expenditure. WorldCom (now renamed MCI) admitted in March 2004 that the total amount by which it had misled investors over the previous 10 years was almost US$75 billion (? 2 billion) and reduced its stated pre-tax profi ts for 2001 and 2002 by that amount. WorldCom stock began falling in late 1999 as businesses slashed spending on telecom services and equipment. A series of debt downgrades raised borrowing costs for the company, struggling with about US$32 billion in debt. WorldCom used accounting tricks to conceal a deteriorating fi nancial condition and to infl ate profi ts. Former WorldCom chief executive Bernie Ebbers resigned in April 2002 amid questions about US$366 million in personal loans from the company and a federal probe of its accounting practices.Ebbers was subsequently charged with conspir acy to commit securities fraud and fi ling misleading data with the Securities and Exchange Commission (SEC) and was sentenced to 25 years in prison. Scott Sullivan, former Chief Financial Offi cer, pleaded guilty to three criminal charges and was sentenced to fi ve years in prison. Ultimately, losses to WorldCom shareholders were close to US$180 billion and the fraud also resulted in the loss of 17,000 jobs. The SEC said that WorldCom had committed ââ¬Ëaccounting improprieties of unprecedented magnitudeââ¬â¢ ââ¬â proof, it said, of the need for reform in the regulation of corporate ccounting. Adapted from CIMA Offi cial Learning System, Management Accounting Risk and Control Strategy 13 1. 4 Why do people commit fraud? There is no single reason behind fraud and any explanation of it needs to take account of various factors. Looking from the fraudsterââ¬â¢s perspective, it is necessary to take account of: â⬠¢ motivation of potential offenders â⬠¢ conditions unde r which people can rationalise their prospective crimes away â⬠¢ opportunities to commit crime(s) â⬠¢ perceived suitability of targets for fraud â⬠¢ technical ability of the fraudster expected and actual risk of discovery after the fraud has been carried out â⬠¢ expectations of consequences of discovery (including non-penal consequences such as job loss and family stigma, proceeds of crime confi scation, and traditional criminal sanctions) â⬠¢ actual consequences of discovery. A common model that brings together a number of these aspects is the Fraud Triangle. This model is built on the premise that fraud is likely to result from a combination of three factors: motivation, opportunity and rationalisation. Motivation In simple terms, motivation is typically based on either reed or need. Stoy Haywardââ¬â¢s (BDO) most recent FraudTrack survey found that greed continues to be the main cause of fraud, resulting in 63% of cases in 2007 where a cause was cited. Other causes cited included problems from debts and gambling. Many people are faced with the opportunity to commit fraud, and only a minority of the greedy and needy do so. Personality and temperament, including how frightened people are about the consequences of taking risks, play a role. Some people with good objective principles can fall into bad company and develop tastes for the fast life, which empts them to fraud. Others are tempted only when faced with ruin anyway. Opportunity In terms of opportunity, fraud is more likely in companies where there is a weak internal control system, poor security over company property, little fear of exposure and likelihood of detection, or unclear policies with regard to acceptable behaviour. Research has shown that some employees are totally honest, some are totally dishonest, but that many are swayed by opportunity. Rationalisation Many people obey the law because they believe in it and/or they are afraid of being shamed or rejected by eople the y care about if they are caught. However, some people may be able to rationalise fraudulent actions as: â⬠¢ necessary ââ¬â especially when done for the business â⬠¢ harmless ââ¬â because the victim is large enough to absorb the impact â⬠¢ justifi ed ââ¬â because ââ¬Ëthe victim deserved itââ¬â¢ or ââ¬Ëbecause I was mistreated. ââ¬â¢ Figure 2 The fraud triangle Motivation Opportunity The fraud triangle Rationalisation Fraud risk management: a guide to good practice 14 Case study 3 A breach of trust A good example of the fraud triangle in practice is the highly publicised case of the secretary that stole over ? . 3 million from her bosses at Goldman Sachs. Motivation There were some suggestions that Joyti De-Laurey originally started down her fraudulent path because of fi nancial diffi culties she found herself in before starting work at the investment bank. De-Laurey had previously run her own sandwich bar business, but it was closed down due to ins uffi cient fi nances. According to her defence, De-Laureyââ¬â¢s ââ¬Ëfi rst bitter experience of fi nancial turmoil coincided with a novel introduction to a Dallas-type world where huge, unthinkable amounts of money stared her in the face, day in and day out. The motive behind the fraud was primarily greed though, with De-Laurey spending her ill gotten gains on a luxury lifestyle, including villas, cars, jewellery, designer clothes and fi rst class holidays. De-Laurey has even admitted that she did not steal because she needed to, but because she could. She explained that she fi rst started taking money simply to fi nd out if she could get away with it. She says that it then became ââ¬Ëa bit addictiveââ¬â¢ and that she ââ¬Ëgot a huge buzz from knowing they had no idea what I was doing. ââ¬â¢ Opportunity In terms of opportunity, De-Laureyââ¬â¢s bosses trusted her and held her in high regard.She had proved herself indispensable, on both business and personal fronts , and was given access to their cheque books in order to settle their domestic bills and personal fi nances. A little over a year after starting at Goldman Sachs, De-Laurey began forging her bossesââ¬â¢ signatures on personal cheques to make payments into her own accounts. Realising she had got away with it, De-Laurey continued to steal money by issuing forged cheques and making false money transfers. Before long she was forging signatures on a string of cash transfer authorities, siphoning off up to ? 2. million at a time from supposedly secure New York investments. Rationalisation De-Laurey was able to rationalise her actions by convincing herself that she had earned the money she stole. De-Laurey believed that she deserved the plundered amounts as a just reward for her dedication, discretion and loyalty, and claims that she had the consent of her bosses to take money in return for her ââ¬Ëindispensable servicesââ¬â¢. The fact that they were so rich they did not even noti ce the money was missing, only served to fuel De-Laureyââ¬â¢s fraudulent activities. She justifi ed her actions through the belief that her bosses had cash to spare.According to De-Laurey; ââ¬ËThey could afford to lose that money. ââ¬â¢ Caught out After four years of siphoning off vast amounts of money, De-Laurey was eventually caught when her boss at the time decided to make a six-fi gure donation to his former college. He took a look at his bank accounts to see if he could cover the donation and was surprised to fi nd the balance on the accounts so low. He investigated further and realised that large sums had been transferred to an unknown account. De-Laurey was the obvious suspect. By this time, De-Laurey had actually stolen around ? 3. 3 million from this particular boss.De-Laurey was the fi rst woman in the UK to be accused of embezzling such a large sum and, after a long and high profi le trial in 2004, she was sentenced to seven years imprisonment. Various sources in cluding The Guardian, The Times, The Independent and the BBC News 15 One of the most effective ways to tackle the problem of fraud is to adopt methods that will decrease motive or opportunity, or preferably both. Rationalisation is personal to the individual and more diffi cult to combat, although ensuring that the company has a strong ethical culture and clear values should help. These methods and principles are developed further in later hapters of this guide. 1. 5 Who commits fraud? Different types of fraudster Fraudsters usually fall into one of three categories: 1 Pre-planned fraudsters, who start out from the beginning intending to commit fraud. These can be short-term players, like many who use stolen credit cards or false social security numbers; or can be longer-term, like bankruptcy fraudsters and those who execute complex money laundering schemes. 2 Intermediate fraudsters, who start off honest but turn to fraud when times get hard or when life events, such as irritation at being passed over for promotion or the need to pay for care for a family ember, change the normal mode. 3 Slippery-slope fraudsters, who simply carry on trading even when, objectively, they are not in a position to pay their debts. This can apply to ordinary traders or to major business people. In 2007, KPMG carried out research on the Profi le of a Fraudster (KPMG survey), using details of fraud cases in Europe, India, the Middle East and South Africa. The ACFE carried out similar research on frauds committed in the US. These surveys highlight the following facts and fi gures in relation to fraudsters: â⬠¢ perpetrators are typically college educated white male most fraudsters are aged between 36 and 55 â⬠¢ the majority of frauds are committed by men â⬠¢ median losses caused by men are twice as great as those caused by women â⬠¢ a high percentage of frauds are committed by senior management (including owners and executives) â⬠¢ losses caused by managers are ge nerally more than double those caused by employees â⬠¢ average losses caused by owners and executives are nearly 12 times those of employees â⬠¢ longer term employees tend to commit much larger frauds â⬠¢ fraudsters most often work in the fi nance department, operations/sales or as the CEO. The ACFE report also found that the type of person ommitting the offence depends on the nature of the fraud being perpetrated. Employees are most likely to be involved in asset misappropriation, whereas owners and executives are responsible for the majority of fi nancial statement frauds. Of the employees, the highest percentage of schemes involved those in the accounting department. These employees are responsible for processing and recording the organisationââ¬â¢s fi nancial transactions and so often have the greatest access to its fi nancial assets and more opportunity to conceal the fraud. Fraud risk management: a guide to good practice 16 Case study 4 Management riskIn 2007, a major British construction fi rm suffered from extensive fraud committed by management at one of its subsidiaries. Accounting irregularities dating back to 2003 were said to include systematic misrepresentation of production volumes and sales by a number of senior fi gures at the division. Management at the subsidiary attempted to cover their behaviour by selling materials at a discounted price and the fraud went undetected for several years despite internal and external audits. The irregularities were eventually uncovered by an internal team sent to investigate a mismatch between orders and sales.Following an initial internal investigation, a team of external experts and the police were brought in to identify the full extent of malpractice. The investigation found that the organisation was defrauded of nearly ? 23 million, but the fraud was said to cost the company closer to ? 40 million due to the written down value of the business and factoring in the cost of the investigation. The managing director of the subsidiary was dismissed, another manager faced disciplinary action and fi ve others left before disciplinary proceedings could be commenced. Civil proceedings were ruled out on the basis that osses were unlikely to be recovered. Operations at the centre of the incident had to be temporarily closed and more than 160 jobs were cut at the business. In addition to individual fraudsters, there has also been an increase in fraud being committed by gangs of organised criminals. Examples include false or stolen identities being used to defraud banks, and forms of e-fraud exploiting the use of internet by commercial businesses. SOCA is responsible for responding to such threats, with the support of the victim organisations. 1. 6 Summary A major reason why people commit fraud is because they are allowed to do so.There are a wide range of threats facing businesses. The threat of fraud can come from inside or outside the organisation, but the likelihood that a frau d will be committed is greatly decreased if the potential fraudster believes that the rewards will be modest, that they will be detected or that the potential punishment will be unacceptably high. The main way of achieving this must be to establish a comprehensive system of control which aims to prevent fraud, and where fraud is not prevented, increases the likelihood of detection and increases the cost to the fraudster. Later chapters of this guide set out some of the easures which can be put in place to minimise fraud risks to the organisation. Before looking specifi cally at fraud risk, the guide considers risk management in general. Risk management is defi ned as the ââ¬Ëprocess of understanding and managing risks that the entity is inevitably subject to in attempting to achieve its corporate objectivesââ¬â¢ (CIMA Offi cial Terminology, 2005). For an organisation, risks are potential events that could infl uence the achievement of the organisationââ¬â¢s objectives. Risk management is about understanding the nature of such events and, where they represent threats, making positive plans to mitigate them. Fraud s a major risk that threatens the business, not only in terms of fi nancial health but also its image and reputation. This guide is primarily focused on managing the risk of fraud, but fi rst, this chapter looks at more general aspects of risk management and corporate governance. 17 2 Risk management ââ¬â an overview Risk management is an increasingly important process in many businesses and the process fi ts in well with the precepts of good corporate governance. In recent years, the issue of corporate governance has been a major area for concern in many countries. In the UK, the fi rst corporate governance report and code of best practice s considered to be the Cadbury Report in 1992, which was produced in response to a string of corporate collapses. There have been a number of reports since, covering provisions around areas such as exec utive remuneration, non-executive directors, and audit committees. The principles of these various reports have been brought together to form the Combined Code on Corporate Governance (Combined Code). The Combined Code was fi rst introduced in 1998 and among other matters, calls for boards to establish systems of internal control and to review the effectiveness of these systems on a regular basis. UK isted companies are required to provide a statement in their annual reports confi rming that they comply with the Combined Code, and where they do not, they must provide an explanation for departures from it (the ââ¬Ëcomply or explainââ¬â¢ principle). The assessment of internal controls should be included in the report to shareholders. The Combined Code is reviewed regularly and the most recent version was published in June 2008. Following the original introduction of the Combined Code, the Turnbull Committee was set up to issue guidance to directors on how they should assess and report on their review of internal controls. TheTurnbull Committee made it clear that establishment of embedded risk management practices is key to effective internal control systems. The Turnbull guidance was fi rst published in 1999 and revised in 2005. In the revised report (sometimes referred to as Turnbull 2) there is now a requirement for directors to give explicit confi rmation that any signifi cant failings or weaknesses identifi ed from the review of effectiveness of internal controls have been, or are being, remedied. 2. 1 What is risk management? 2. 2 Corporate governance Fraud risk management: a guide to good practice 18 The Financial Reporting Council is responsible for aintaining and reviewing the Combined Code, although the Combined Code is annexed to the rules of the UK Listing Authority, which is part of the FSA. The FSA is responsible for ensuring that listed companies provide the appropriate ââ¬Ëcomply or explainââ¬â¢ statement in their annual report. While the guidance is generally applicable to listed companies, the principles are relevant to all organisations and have been widely used as a basis for codes of best practice in the public and not-for-profi t sectors. Fraud risk management practices are developing along the same lines. Many other countries have also produced reports on orporate governance, usually accompanied by codes of best practices. For example, South Africa has had the King Report (version I and now II) since 1994, Malaysia has had its Code of Corporate Governance in place since 2000 and Sri Lanka issued the Rules on Corporate Governance as part of its Listing Rules in January 2007. Corporate governance requirements in the US are now largely set out within the Sarbox legislation, further details on which are provided at Appendix 1. As previously mentioned, these requirements extend beyond the US, capturing any company that is SEC listed and its subsidiaries. Some other countries have lso introduced a statutory appr oach to corporate governance, such as that in the US, although none are currently as comprehensive. A number of international organisations have also launched guidelines and initiatives on corporate governance, including the Organisation for Economic Co-operation and Development (OECD) and the European Commission. An example of a growing area of corporate governance is IT governance, which has developed in light of rapid and continuing advances in information technology. The following box gives more information on IT governance. IT Governance IT governance is about ensuring that the rganisationââ¬â¢s IT systems support and enable achievement of the organisationââ¬â¢s strategies and objectives. It encompasses leadership, organisational structures, businesses processes, standards and compliance. There are fi ve specifi c drivers for organisations to adopt IT governance strategies: â⬠¢ regulatory requirements e. g. IT governance is covered by the Combined Code and Turnbull gu idance in the UK â⬠¢ increasing intellectual capital value that the organisation has at risk â⬠¢ alignment of technology with strategic organisational goals â⬠¢ complexity of threats to information security â⬠¢ increase in the compliance requirements of nformation and privacy-related regulation. A key benefi t of an effective, integrated IT governance framework is the integration of IT into the strategic and overall operational approach of an organisation. There are a series of international Information Security (IS) standards that provide guidance on implementing an effective IT governance framework, known as the ISO 27000 series. For example, ISO/IEC 27001 defi nes a set of IS management requirements in order to help organisations establish and maintain an IS management system. The standards apply to all types of organisation regardless of size or sector.They are particularly suitable where the protection of information is critical to the business, for example in t he fi nance, health and public sectors, and for organisations which manage information on behalf of others, such as IT outsourcing companies. ISACA also offers a series of IS standards and certifi cation. ISACA is a leading global association in the IT governance and control fi eld. With a network across more than 160 countries, its IS standards are followed by practitioners worldwide. Figure 3 The CIMA risk management cycle Controls assurance Controls assurance is the process whereby controls are eviewed by management and staff. There are various ways to conduct these exercises, from highly interactive workshops based on behavioural models at one end of the spectrum to pre-packaged self audit internal control questionnaires at the other. These models all include monitoring and risk assessment among their principal components. 19 The risk management cycle is an interactive process of identifying risks, assessing their impact, and prioritising actions to control and reduce risks. A n umber of iterative steps should be taken: 1 Establish a risk management group and set goals. 2 Identify risk areas. Understand and assess the scale of risk. 4 Develop a risk response strategy. 5 Implement the strategy and allocate responsibilities. 6 Implement and monitor the suggested controls. 7 Review and refi ne the process and do it again. 2. 3 The risk management cycle Identify risk areas Review and refi ne process and do it again Implementation and monitoring of controls Implement strategy and allocate responsibilities Understand and assess scale of risk Develop risk response strategy Information for decision making Establish risk management group and set goals Fraud risk management: a guide to good practice 20 2. Establish a risk management group and set goals A risk management group should be established whose task it is to facilitate and co-ordinate the overall risk management process. Possible members of the group could include a chief risk offi cer, a non executive direc tor, fi nance director, internal auditor, heads of planning and sales, treasurer and operational staff. Depending on the size and nature of the organisation, the risk management group may be in the form of a committee who meet from time to time. The risk management group will promote the understanding and assessment of risk, and facilitate the evelopment of a strategy for dealing with the risks identifi ed. They may also be responsible for conducting reviews of systems and procedures to identify and assess risks faced by the business, which include the risk of fraud, and introducing the controls that are best suited to the business unit. However, line managers and their staff may also be involved in the risk identifi cation and assessment process, with the risk management group providing guidance. 2. 5 Identify risk areas Each risk in the overall risk model should be explored to identify how it potentially evolves through the organisation.It is important to ensure that the risk is c arefully defi ned and explained to facilitate further analysis. The techniques of analysis include: â⬠¢ workshops and interviews â⬠¢ brainstorming â⬠¢ questionnaires â⬠¢ process mapping â⬠¢ comparisons with other organisations â⬠¢ discussions with peers. Once risks have been identifi ed, an assessment of possible impact and corresponding likelihood of occurrence should be made using consistent parameters that will enable the development of a prioritised risk analysis. In the planning stage, management should agree on the most appropriate defi nition and number of categories to be used when ssessing both likelihood and impact. The assessment of the impact of the risk should not simply take account of the fi nancial impact but should also consider the organisationââ¬â¢s viability and reputation, and recognise the political and commercial sensitivities involved. The analysis should either be qualitative or quantitative, and should be consistent to allow compa risons. The qualitative approach usually involves grading risks in high, medium and low categories. Impact The assessment of the potential impact of a particular risk may be complicated by the fact that a range of possible outcomes may exist or that the risk may occur number of times in a given period of time. Such complications should be anticipated and a consistent approach adopted which, for example, may seek to estimate a worst case scenario over, say, a 12 month time period. Likelihood of occurrence The likelihood of a risk occurring should be assessed on a gross, a net and a target basis. The gross basis assesses the inherent likelihood of the event occurring in the absence of any processes which the organisation may have in place to reduce that likelihood. The net basis assesses the likelihood, taking into account current conditions and processes to mitigate he chance of the event occurring. The target likelihood of a risk occurring refl ects the risk appetite of the organisa tion. 2. 6 Understand and assess the scale of risk 21 Where the net likelihood and the target likelihood for a particular risk differ, this would indicate the need to alter the risk profi le accordingly. It is common practice to assess likelihood in terms of: â⬠¢ high ââ¬â probable â⬠¢ moderate ââ¬â possible â⬠¢ low ââ¬â remote. An example of a risk analysis is contained in Appendix 3. The resulting document is often referred to as a risk register. The overall risk registers at organisational nd operational levels should include the risk of fraud being perpetrated. Some organisations also prepare detailed fraud risk registers that consider possible fraudulent activity. The fraud risk register often directs the majority of proactive fraud risk management work undertaken by an organisation. Analysing fraud risks Fraud risk is one component of operational risk. Operational risk focuses on the risks associated with errors or events in transaction processing or ot her business operations. A fraud risk review considers whether these errors or events could be the result of a deliberate act designed to benefi t the perpetrator.As a result, fraud risk reviews should be detailed exercises conducted by teams combining in depth knowledge of the business and market with detailed knowledge and experience of fraud. Risks such as false accounting or the theft of cash or assets need to be considered for each part of the organisationââ¬â¢s business. Frequently, businesses focus on a limited number of risks, most commonly on thirdparty thefts. To avoid this, the risks should be classifi ed by reference to the possible type of offence and the potential perpetrator(s). Fraud risks need to be assessed for each area and process of the business, for example, cash payments, ash receipts, sales, purchasing, expenses, inventory, payroll, fi xed assets and loans. Fraud risk management: a guide to good practice 22 2. 7 Develop a risk response strategy Once the ri sks have been identifi ed and assessed, strategies to deal with each risk identifi ed can be developed by line management, with guidance from the risk management group. Strategies for responding to risk generally fall into one of the following categories: â⬠¢ risk retention (e. g. choosing to accept small risks) â⬠¢ risk avoidance (e. g. stopping sale of certain products to avoid the risk to occurring) â⬠¢ risk reduction (e. g. hrough implementing controls and procedures) â⬠¢ risk transfer (e. g. contractual transfer of risk; transferring risks to insurers). Before strategies are developed, it is necessary to establish the risk appetite of the organisation. Risk appetite is the level of risk that the organisation is prepared to accept and this should be determined by the board. The appetite for risk will infl uence the strategies to be developed for managing risk. It is worth noting that a boardââ¬â¢s risk appetite may vary for different types of risk and over tim e. For example, the board may have a low risk tolerance on compliance and egulatory issues, but be prepared to take signifi cant strategic risks. The board may also reduce their risk appetite as the external environment changes, such as in times of recession. 2. 8 Implement the strategy and allocate responsibilities The chosen strategy should be allocated and communicated to those responsible for implementation. For the plan to be effective it is essential that responsibility for each specifi c action is assigned to the appropriate operational manager and that clear target dates are established for each action. It is also important to obtain the co-operation of those esponsible for the strategy, by formal communication, seminars, action plans and adjustments to budgets. The chosen strategy may require the implementation of new controls or the modifi cation of existing controls. Businesses are dynamic and the controls that are in place will need to be monitored to assess whether or n ot they are succeeding in their objectives. The risk management group should be empowered to monitor the effectiveness of the actions being taken in each specifi c area, as these can be affected by internal and external factors, such as changes in the marketplace or the introduction of new computer systems. . 10 Review and refi ne and do it again All of the elements outlined above form part of an iterative cycle where risk management is continually reviewed and developed. As the cycle continues, risk management should increasingly become embedded in the organisation so that it really becomes part of everyoneââ¬â¢s job. 2. 11 Information for decision making Risk management should form a key part of the organisationââ¬â¢s decision-making process. Information is gathered at all stages of the risk management cycle and this information should be fed into the decision-making mechanisms. For more information on risk management, please refer o CIMAââ¬â¢s publication Risk Management : A guide to good practice. 2. 9 Implement and monitor suggested controls 23 There are risks in most situations. Risk management is an important element of corporate governance and every organisation should review their risk status and develop their approach as described in the CIMA Risk Management Cycle in 2. 3 to 2. 11 above. Managing the risk of fraud is the same in principle as managing any other business risk. First, the potential consequences of fraud on the organisation need to be understood, using the principles set out in this chapter. The risks should then be reduced by developing nd implementing an anti-fraud strategy across the organisation. This is best approached systematically, both at the organisational level, for example by using ethics policies and anti-fraud policies, and at the operational level, through introduction of controls and procedures. The following chapters expand on the fraud risk management process in the context of an antifraud strategy. 2. 12 Summar y Fraud risk management: a guide to good practice Given the prevalence of fraud and the negative consequences associated with it, there is a compelling argument that organisations should invest time and resources towards tackling fraud.There is, however, sometimes debate as to whether these resources should be committed to fraud prevention or fraud detection. Fraud prevention Based on the earlier discussion aroun
Thursday, November 7, 2019
African Americans in media Essays
African Americans in media Essays African Americans in media Essay African Americans in media Essay African Americans in media BY aman2525 Race and Mass Media Representation Race is a large part of American Society today, and the United States media plays a large factor in how people perceive African-American males and females both. There have been many surveys taken to see how people perceive the portrayals of African- Americans in the media, and these surveys do not always match up with the true statistics. These portrayals in media can directly affect the stereotypes people have on African-Americans, and these stereotypes can create racial differences that results n violence. African Americans are portrayed poorly in the mass media, and with early education on race and better representation in the media, these portrayals will no longer affect the stereotypes people have on African-Americans. There are many different reasons why the mass media representation of African Americans is poor in the United States. The mass media has separated the working class, and young African-American males are being stereotyped as drug dealers or gangsters. Mostly the media centers on the negative characteristics and actions of the African- American community. Characteristics and actions such as engaging in drug use, criminal activity, and welfare abuse (Sanders 20). This representation has affected African-American males ability to find future employment or promotions, and this can affect them for the rest of their lives. In Sanders online survey, 466 respondents were asked how African American males are generally portrayed in the media overall. Ninety-nine percent of the respondents stated they believe coverage in the media focused more heavily on topics that involve crime (Sanders 28). In addition, ninety-six ercent of the respondents believe that the media coverage is negative (Sanders 28). In a study done by Thomas Stevenson, media coverage was broken down into eight categories, and crime was the leading topic. Of the articles that included African- Americans, thirty-six percent of the articles center point was on crime (Stevenson 7). However, for television broadcast, sixty-four out of seventy-four stories that African American males were involved in focused on crime (Stevenson 7). These results go to show how much ones stereotype of another can be affected by the media. In reality, tatistics shows that there are more whites than African-Americans in prison, sixty percent to forty percent (Stevenson 12). This shows that the media portrayals are wrong and are affecting the stereotypes of African-American males strongly. African- American females are portrayed quite differently in mass media than males. They are portrayed as gold diggers, Jezebels, and baby mamas according to a survey with more than twelve hundred respondents done by Richard Prince. According to this survey, these were three different types of African-American females that are most ortrayed in the media. On the other side, there were six different descriptions of African-American females that there isnt enough portrayal of in the media. These being young phenoms, real beauties, individualists, community heroines, girls next door and modern matriarchs (Fujioka 58). Eighty-Five percent of respondents stated the media portrays African-American females as baby mamas. A baby mama is a term used to define an unmarried young woman who has had a child. In addition, only forty-one percent of the respondents stated that the media portrays African- Americans as real beauties (Fujioka 58). Again, eighty-five percent of respondents stated they feel the six descriptions above fit African-American females more than the baby mama, gold digger, or Jezebel descriptions. Most African-American women want to be looked at positively in the media, and want their children to grow up with positive images and role models. They should be able to turn on the television without worrying about the negativity that could possibly be said about their culture. These issues with mass media representation of African-Americans needs fixed, and t will not be easy. These issues with the portrayals of African-Americans in the media, and how it affects the stereotypes of African-Americans can be fixed. However, the fix can take a long time to take place. The first action that can be taken to help the problem is teaching equality among races, in this case African-Americans, early in childhood. If this is taught at a young age, then there would be less hate among races. With this less hate, there would be much less negative stereotypes in the media. In addition, with less negative stereotypes in the media, there would be less iolence as well. This less violence would also decrease negative stereotypes in the media. The second action that needs to take place is the media needs to do better at representing African-Americans. The media needs to present them for who they really are, instead of presenting only the negative aspects. This will all take time and effort, however if done, it will have a positive influence on American Society. Again, African-Americans are portrayed in mass media very negatively in the United States, and this directly influences the stereotypes on African-Americans. Not only do other races see this negativity towards African-Americans in the media, but African- Americans see this portrayal as well. This portrayal has a negative effect on society by causing more violence in the streets, and the media giving the wrong interpretation of African-Americans. However, with much effort and time, these stereotypes can become more positive and the media can portray African-Americans for who they really are. Fujioka, Yiki. Television portrayals and African-American stereotypes: Examination of television effects when direct contact is lacking. Journalism Mass Communication Quarterly 76. 1 (1999): 52-75. Print. Sanders, Meghan S. An Examination Of African Americans Stereotyped Perceptions of Fictional Media Characters. Howard Journal Of Communitcations 23. 1 (2012): 17- 39. Business Source Complete. Web. 18 Nov. 2013 Stevenson, Thomas H. A Six-Decade Study Of The Portrayal Of African Americans In Business Print Media: Trailing, Mirroring, Or Shaping Social Change?. Journal Of Current Issues Research In Advertising (CTC Press) 29. 1 (2007): 1-14. Business source complete. web. 25 NOV. 2013.
Tuesday, November 5, 2019
50 Writing Prompts for Elementary School Children
50 Writing Prompts for Elementary School Children Writing is a skill that every person needs in life, and developing that skill in children is an important part of elementary school studies. However, writing inspiration is not something that every student comes by easily. Like adults, many children tend to get stuck when it comes to thinking of writing ideas on their own. Weve all had writers block at one point or another in our lives, so its easy to understand the frustration students may experience. Just as athletes need to warm up their muscles, writers need to warm up their minds and creativity. Giving students writing prompts, or ideas and inspiration for writing topics, will ease their anxiety and allow them to write more freely. Elementary School Writing Prompts Allowing your students to choose a writing idea each day or each week from the 50 that are listed can provide inspiration for their creative writing.à To make this activity more challenging, encourage them to write without stopping for at least five minutes, increasing the number of minutes that they devote to writing over time. Remind your students that there is no wrong way to respond to the prompts and that they should simply have fun and let their creative minds wander. With prompts that pertain to writing about people, you might encourage students to write about multiple people, considering people in their lives and people they dont know personally. This encourages children to think more critically and consider unknown factors in the creation of their stories. You might also encourage students to think in terms of either the realistic or the fantastic. When the confines of realism are eliminated, students are free to think more creatively, which can encourage them to become more engaged in the project at hand. The person I admire the most is...à My biggest goal in life is...The best book I ever read was...The happiest moment in my life was when...When I grow up, I want to...The most interesting place I have ever been to was...Name three things you dont like about school and why.The strangest dream I ever had was...When I turn 16, I will...Who is the funniest member of your family and why?I get scared when...Five things I would do if I had more money are...What is your favorite sport and why?What would you do if you could change the world?Dear teacher, I would like to know...Dear President Washington, what was it like to be the first president?My happiest day was...My saddest day was...If I had three wishes, I would wish for...Describe your best friend, how you met, and why you are friends.Describe your favorite animal and why.Three things I like to do with my pet elephant are...The time a bat was in my house...When I become an adult, the first thing I want to do is...My best vacation was when I went to... The top three reasons that people argue are...Describe five reasons that going to school is important.What is your favorite television show and why?The time I found a dinosaur in my backyard...Describe the best present you ever received.Describe your most unusual talent.My most embarrassing moment was when...Describe your favorite food and why.Describe your least favorite food and why.The top three qualities of a best friend are...Write about what you would cook for an enemy.Use these words in a story: scared, angry, Sunday, bugs.Whats your idea of a perfect vacation?Write about why someone might be afraid of snakes.List five rules that you have broken and why you broke them.What is your favorite video game and why?I wish someone had told me that...Describe the hottest day you can remember.Write about the best decision youve ever made.I opened the door, saw a clown, and then...The last time the power went out, I...Write about five things you can do if the power goes out.If I were pre sident, I would... Create a poem using the words: love, happy, smart, sunny. The time my teacher forgot to wear shoes... If youre looking for more writing ideas, experiment with journal promptsà or ideas for writing about important people in history like Martin Luther King Jr.
Sunday, November 3, 2019
A Secure Workflow for E-Government Application Essay
A Secure Workflow for E-Government Application - Essay Example Governmental agencies are providing services to their citizens and Foreign Companies via dedicated websites. Foreign users require services from the local department such as renewals of licenses and purchasing tenders. Providing a single secure portal that acts as a window to the various services is beneficial not only to these government agencies but also to their foreign customers. To get the full advantage of a workflow management system governmental agencies need a customized solution that fully corresponds to business and industry specifics. That is, a scalable platform for different tasks: This paper presents an approach for designing a secure workflow management system for e-Government portal, In section 2, we discuss some studies which are related to my research. In section 3, we briefly describe the overview of WFMS.The tools that will be used to improve the efficiency of workflow management systems in e-government portals and the advantages of utilizing these secure portals is presented in section 4. The onion routing technique is displayed in section 5and the methodology is discussed in section 6. Section 7&8 present the solution architecture and solution security, availability and scalability. We end this paper with section 9 that include future work and conclusion. Vijay Atluri from Rutgers University has claimed that Most of the commercial workflow systems provide minimal security features such as user authentication, Although some commercial WFMSs such as Flow Mark, Lotus Notes, and Chan engine can support role-based access control, they do not provide support to specify and enforce separation of duties constraints. They have to be implemented in an ad- hoc manner through a script type language [3].
Subscribe to:
Posts (Atom)