Ironclad your internal fraud investigations
Despite a robust system of internal controls and governance, no organisation can stake claim to be immune from fraud. In fact, even the coso guidance suggests that 'collusion' and \'management override of controls' are few of the limitations of an internal control framework. These limitations mean that management is capable of overriding internal controls and perpetrate fraud and that personnel can avoid or skip internal controls to engage in collusive behaviour.
The Associate of Certified Fraud Examiners (ACFE) 2024 Report to the Nations on occupational fraud also states that more than half of occupational frauds occur due to lack of internal controls or an override of existing internal controls and also states that 43% of occupational frauds were detected by a tip (whistleblower complaints / WB complaints).Organisations faced with dealing with WB complaints are often faced with various conundrums on the best approach of dealing with these matters.On one hand, there are organisations who do not hesitate from engaging the best of the external forensic experts and lawyers to help him navigate these matters while on the other hand, certain organisations prefer to deal with these matters in-house either with support from their internal specialist teams (such an internal audit / investigation units) or representatives chosen from their business units.
For organisations in the latter category, this choice may be driven by various factors such as need to balance the cost of investigation, maintaining confidentiality by limiting circulation of information outside the organisation, making the best use of the knowledge residing within the organisation etc.In case cases, given the potential reliance on the results of such investigation by external bodies/ agencies such as statutory auditors or law enforcement authorities, it is vital that common potholes encountered while investigating these matters internally are effectively managed.
Forensic Accounting Investigation Standards (FAIS) 110 defines an investigation as \'a critical examination of facts, records, documents and other forms of evidence for a specific purpose, such as an alleged legal, ethical or contractual violation with respect to transactions or event.The purpose of the Investigation is to examine facts and circumstances and gather evidence to prove or disprove hypotheses formulated regarding alleged legal violations, unethical conduct or the possibility of a fraud by suspected individuals.
Where the mandate requires the need to gather and evaluate evidence for a specific purpose, such as to help establish possible fraudulent intent, or to identify possible suspects of fraud, the concept of Investigation shall apply.
This article does not go into the merits of the decision whether to outsource the investigation or to perform it with help internal experts.It is the responsibility of the organisation to evaluate the pros and cons of each approach and decide the best course of action in the organisation\'s interests.The purpose of this article is to put forth few of the aspects to be considered by the organisation in the course of their decision making should the organisation decide to pursue the matter internally.As with all such matters which can potentially impact the financial statements, more importantly in relation to fraud, organisations should engage in proactively keeping their statutory auditors informed of the incident and the organisations proposed approach.
Management has the primary responsibility for preventing and detecting fraud in an organization.Accordingly, although investigation of whistle-blower complaints is the responsibility of management and should be owned up by them, it is always recommended that inputs from the statutory auditors (audit firm/ auditor) may also be sought in relation to the scope of investigation and the proposed work steps to avoid any misgivings at a later date which can potentially delay the audit closure process.As part of the scoping exercise, the auditor may also be able to provide valuable suggestions to the organisation based on his experience in dealing with such matters on other audits which also helps in meeting the auditor\'s requirements.At times, this can also make the organisation\'s investigation process more robust.
Additionally, statutory auditors have certain obligations in relation to fraud under the Standards on Auditing and Companies Act and ensuring that the auditors are timely informed of such matters assists the organisation in supporting the auditor to sufficiently meet the obligations enforced upon them under the law and under the applicable auditing standards.More specifically, reporting obligations cast on the auditor under section 143(12) of the Companies Act and form ADT-4, require the auditor to comment whether he is \'satisfied with the steps taken by management\' in relation to frauds.It is in the interest of the organisation that the investigation approach should be agreed with the auditor considering these reporting requirements and he should be satisfied with the steps taken.Any conclusion by the auditor to the contrary will likely be detrimental since the matter may invoke additional scrutiny from the regulator (e.g. Ministry of Corporate Affairs) upon filing of the ADT-4 form by the auditor.A harmonious and collaborative approach with the auditor as opposed to being siloed or adversarial, will be beneficial to the organisation.
Based on evaluation of the facts and circumstances, should the auditor express any concerns with regard to investigating the matter internally, the organisation should endeavour to address these concerns with suitable steps and responses.
Effective governance in whistleblower investigations is critical for maintaining organizational integrity and addressing management override of controls.The inherent tension between oversight bodies, such as the Board of Directors and Audit Committee, and management can complicate the adherence to FATE principles: Fairness, Accountability, Transparency, and Explainability.
To mitigate these challenges, organizations should adopt several key structural safeguards:
- Direct Reporting Lines: Establish a direct reporting line for investigators to an independent board sub-committee to ensure unbiased oversight.
- Dedicated Budget: Allocate a specific budget for whistleblower investigations that is controlled by the Audit Committee, ensuring that resources are available without management interference.
- Protected Communication Channels: Implement secure channels for whistleblowers to report concerns without fear of retaliation.
- Concurrent Reporting: Require concurrent reporting of findings to external auditors and regulators to enhance transparency.
- Dual-Key Decision System: Utilize a \"dual-key\" system for critical decisions in investigations to prevent unilateral actions that could compromise integrity.
- Documentation Protocols: Maintain clear documentation protocols to ensure all investigative steps and findings are recorded systematically.
Additionally, modern technology can further reinforce these principles through various controls:
- Automated Audit Trails: Implement automated audit trails and system-generated logs to track all actions taken during investigations.
- Immutable Records: Use tamper-evident evidence trails to ensure data integrity.
- Access Control Matrices: Utilize access control matrices and version control systems to manage who can view or alter investigation-related documents.
- Blockchain Documentation: Leverage blockchain secure and transparent technology for documentation of reports and findings.
- System Metadata: Employ system-generated metadata and automatic backup systems to protect data integrity.
- Privileged Access Management (PAM): Implement PAM systems for real-time alerts on unauthorized access attempts.
- Security Information and Event Management (SIEM): Use SIEM platforms for comprehensive logging of activities related to investigations.
Now that we have laid out the broad background and context of this article, as you may have guessed by the title, now let us explore some aspects which can help us plug some gaps or in other words \'ironclad\' your internal fraud investigations.By no means this is an exhaustive list and learned members who are more experienced may possibly have a much tighter iron lock around their internal investigations!
Areas of Focus
- Board or Audit Committee mandate
- Investigation team composition
- Evaluation of allegation
- Confidentiality
- External experts
- Investigation report
- Face finding
- Conclusion
i. Obtain mandate from Board or Audit Committee
Matters in relation to whistleblower complaints are by no means easy to deal with.It is difficult for any such investigation being handled internally to be successful without a supportive tone at the top and the concurrence of those charged with governance (TCWG) namely the Board of Directors and the Audit Committee (if any).Internal investigations require composition of the right team with the appropriate skill sets as well as support from various functions in the organisation to provide the necessary data/information (e.g. electronic data which needs to be provided by the information technology team, copies of documents/vouchers which needs to be provided by the finance team, copies of legal contracts which needs to be given by the legal team, ability to summon individuals for interviews etc).In order to garner timely support from these various functions, a clear mandate from TCWG with regard to the internal investigation will be vital.Such mandate may be provided for each investigation or an omnibus approval depending on the TCWG\'s preference.Without such support, power and authority to conduct the investigation, the investigation team will be akin to a toothless tiger!
In large organisations, investigation are handled internally by investigation units which are likely directly under the purview of TCWG hence this condition is met.
ii. Composition of the investigation team
Competence and objectivity are paramount qualities for an internal investigation team.Competence is important since without the right skill sets and experience, the entire investigation process will turn out to be infructuous as the matter will not be properly investigated with the merit that it deserves.Objectivity simply means that the individuals should not be biased while conducting the investigation.When it comes to internal investigations, various biases can creep in and when it comes to maintaining objectivity, at times perception may matter more than reality!
What could be some of the biases that could creep in? Consider a situation where the members of the investigation team are from the same department that the alleged individuals are working in.In case of highly technical matters, having some member of the same department who has the relevant competence and expertise may possibly have its merits, this approach is also fraught with the perils of the likely favouritism that can creep in while investigating the matter.Another example could be how close are present or past informal relationships between the alleged individuals and the investigation team members.There are no bright lines in this evaluation, and it would all depend on observation and perception by various people in the organisation.As a corollary, is there any informal evidence that the alleged individuals and the investigation team members have a bone to pick with each other?In both such cases, it will be difficult to argue that the matter is being handled in an objective manner.
Another important aspect of competence is also to be able to identify whether there are any areas where the investigation team members do not have the skill sets needed to investigate.If there is such a case, then the organisation may need to consider supplementing the team with support from external agencies having specialised skill sets.Refer section f) for more on this topic.
iii. Evaluating Allegations: A Structured Framework
Once the investigation team is formed, it\'s time to get down to the brass tacks.
To effectively evaluate allegations while protecting whistleblowers and maintaining organizational integrity, a structured framework is essential.This framework should include initial assessment protocols, whistleblower protection measures, information gathering processes, allegation validation methods, technology infrastructure, and resource and timeline management.
Initial Assessment Protocol
The initial assessment should clarify the subject matter and specificity of the allegations.A preliminary risk assessment should categorize allegations based on potential impact and credibility, documenting any initial red flags or corroborating evidence.
Whistleblower Protection Framework
Establish secure communication channels, anonymous reporting mechanisms, and clear confidentiality and non-retaliation policies.Create information firewalls, monitor for retaliation, and designate a Whistleblower Protection Officer separate from the investigation team.
Information Gathering Process
Use structured templates to capture allegation details and explore discussions with the whistleblower if possible.Provide multiple communication channels with security measures, clear documentation protocols, and a secure storage system with restricted access.
Allegation Validation Framework
Use an evidence assessment checklist to verify basic facts and assess internal controls.Review historical patterns and cross-reference with existing compliance data.
Technology Infrastructure
Implement a secure case management system with audit trails, automated logging, and data analytics tools.Use a secure document management system with version control and access control matrices.Ensure regular backup and archiving protocols.
Resource Planning and Timeline Management
Identify dependencies, potential challenges, and resource availability.Create a detailed investigation timeline with milestones and a resource allocation matrix.Develop contingency plans for resource constraints.
FATE Principles Implementation
- Fairness: Use standard evaluation criteria, document decision-making, and apply protection measures equally.
- Accountability: Assign responsibilities clearly, report status regularly, and document key decisions.
- Transparency: Maintain clear communication, provide regular updates, and document evidence methodology.
- Explainability: Document evaluation criteria, explain decisions clearly, and provide regular status reports.
Trust Preservation Measures
Share information on a \"need-to-know\" basis, communicate with affected departments without compromising the investigation, and establish protocols for handling false allegations.Maintain documentation standards and provide confidentiality training.
Quality Control Measures
Conduct peer reviews of investigation planning, assess progress regularly, and ensure independent reviews of critical decisions.Perform documentation quality checks and provide regular updates to relevant stakeholders.
iv. Sufficient and appropriate procedures
A proper scope of work document along with planned procedures should be prepared by the investigation team.The planned procedures should be in sufficient detail and should be mapped to each of the allegations.This mapping will ensure that all facets of the highlighted concerns are suitably addressed.This activity will also help the investigation team ascertain potential reliance on any external experts where the relevant skillsets are not available with the investigation team.See section on \'Relying on external experts for specialised areas\'
FAIS 330 suggests some indicative list of work procedures that can be referred to.For example:
- Identify the nature of evidence required to confirm the allegations/possible violation.
- Collect various data, information, facts and documents pertaining to the subject matter.
- Look for fraud indicators (\"red flags\") such as any unusual or suspicious circumstances, suspicious transactions, unusual trends or patterns, etc.
- Collect available evidence using a regular \"masked audit\" approach.
- Conduct discreet enquiries to corroborate evidence and identify those involved.
- Evaluate allegations and segregate opinions from verifiable facts.
- Perform basic financial analysis to quantify the extent of loss/damage.
FAIS 320 may also be relevant in this regard which highlights that evidence gathered in the investigation should be both reliable and relevant.
v. Maintain confidentiality
Unlike in the case of investigations outsourced to external agencies, for investigations handled internally there are special considerations regarding ensuring confidentiality.When matters are handled by external agencies, the relevant data is essentially handed over them and all analysis is performed by the agencies on their electronic devices or at their offices.On the contrary, when this is done in-house, all relevant data gathered and analysed for the investigation is stored on the team member\'s official computers or organisations repositories.Relevant communications may be shared via the official email communication channels.You may agree that any leakage of information prior to the completion of investigation may jeopardise the situation and compromise on various elements.There could be malafide attempts to delete data or cohesive attempts to not participate in meetings.Considering this, it becomes important to assess the relevant access controls around storage and access of the information analysis, documents containing interim findings, internal notes or confidential minutes of discussion etc.Some aspects which can be considered in this regard are:
- Have the team members been sensitised of the requirements for maintaining confidentiality?
- Have they been sufficiently guided and coached on the good practices in this regard?
- Are they comfortable in following in these practices and have they clearly understood the implications of not complying?
- Are the team members storing any investigation related findings on any common drive?
- What are the access controls surrounding this common drive?
- Even if the team members are not storing any data on common folders, are there any automated backup mechanisms on shared repositories which get triggered at periodic intervals and can potentially compromise the access controls?
- Who has access to these backup data?
- In case the investigation team comprises any senior members, are their emails handled by their assistants and is there a risk of information compromise at their end?
With the advent of social media, it not too difficult to validate aspects of the competence of the experts via public domain information.In addition, the organisation may consider asking for credentials and references if needed.Background checks can also be performed in case any of the above options do not yield satisfactory results.
All these aspects need to be evaluated upfront and if there is an increased risk of leakage of information, these potential weaknesses should be plugged suitably.Many of these challenges may vary in severity and impact depending on the manner in which the operational aspects of the investigation are conducted and various policies and procedures around information security.
vi. Relying on external experts for specialised areas
FAIS 230 defines an \'Expert\' as an individual or a person representing an entity, possessing special skills or domain expertise, along with relevant experience and expertise in a particular area, field or discipline.
In case the internal investigation team does not possess certain specialised skill sets for relevant aspects of the investigation and if such skills are not available with any other department inhouse, it can consider seeking assistance from external experts.Assistance from these experts could be taken for complex areas such as digital evidence review, cyber investigation, handwriting experts, forged documents review, interpretation of laws and regulations (legal experts) etc.Similar to the attributes expected from internal investigation team members that we examined in section b) of the article, these are also relevant for evaluation of suitability of external experts.For example, evaluation of competence and independence.In case of external experts, one should also consider whether the same agencies had previously worked under the direction of the alleged individuals on previous unrelated engagements for the organisation which may potentially impede their ability to conduct the review in an unbiased manner.
Irrespective of the professional competence of the external experts, it is always the organisations responsibility to evaluate the sufficiency and appropriateness of the work performed by the expert and ensure that it meets the requirements of the organisation.Using an expert is just an arrangement to manage the skill gap and does not in any way reduce the responsibilities of the organisation.
More often than not, the work done by the expert may culminate in deliverables in the form of a written report.Unless considered prejudicial to the interests of the organisation, a written report should be insisted from the expert.It should be ensured that the report is comprehensive and contains at a minimum, details of the agreed scope, procedures performed, evidence gathered, findings.A detailed review of the deliverables to ensure the following:
- that work performed is aligned to the agreed scope;
- limitations / caveats in the report do not impact the conclusion;
- assumptions on the basis of which work is performed are appropriate and agreed upfront;
- the work procedures performed are robust and comparable to industry standards;
- the report is clear, detailed and self-sufficient with all the relevant appendices containing details of the evidence that was relied upon.These may include screenshots, tables containing analysis, photos, minutes of interviews etc.
vii. Written investigation report
Similar to the aspects explored for an external expert, no investigation can be considered to be complete unless the facts are clearly laid out in a written report.This report is crucial since it will form an important part of the investigation and will be relied upon by various stakeholders.The pointers discussed above in point f) are also relevant for the investigation report drafted by the investigation team.The investigation report should be reviewed and adopted by TCWG.Often it is found that for investigations conducted internally the group investigation teams, there is reluctance from the group in sharing the results or findings with the local organisation.It is important that the TCWG of the organisation which is impacted should have unfettered access to the investigation results and these results should also be shared with local management.The Board and management are responsible for the financial statements and providing appropriate representations to auditors.Unless they are made aware of the results of the investigation, they will not be able to fulfil such responsibilities cast upon them under the laws and regulations.
viii. Ensure fact finding and stay clear from organisational influences
The purpose of an investigation is to ensure that relevant facts are clearly drawn out and the conclusions are based on these facts.It is common human behaviour to often allow inherent biases to influence the outcome or the way the same facts are interpreted.Even within an organisation, it is not unreasonable to expect that at times there could be pressure on the investigation team to dilute the findings in order to favour someone.The investigation team should be steadfast in their mandate and should not buckle to any pressure by anyone.Any interference in the investigation should not be taken lightly and should be completely discouraged.Any attempts to do so should be promptly highlighted by the investigation team to the sponsors (TCWG).The TCWG may be able to provide suitable guidance and advice to the team to be able to handle such situations.It is also at this stage that the role of an independent governing body in the organisation becomes important.TCWG (Audit Committee and the Board of Directors) supported by management can undertake the responsibility of interpreting the facts and coming to a conclusion with regard to the veracity of the allegations and culpability of the alleged individuals.The TCWG will thus be able to provide an independent interpretation of the facts and act as an effective mitigant against any potential management biases in concluding the allegations.
ix. Regulatory interventions
FAIS 240 explains that there are various laws and regulations which may apply in the course of an investigation.In case of bribery related matters, impact of non-compliance to the relevant anti-bribery laws may need to be examined.While Prevention of Corruption Act (PCA) or the Indian Penal Code (IPC) is applicable in India, among the prominent overseas acts in this regard are the Foreign Corrupt Practices Act (FCPA), UK Bribery Act (UKBA).Interpretation of these laws and regulations is a complex affair and more likely that the organisation may seek external assistance to help them navigate these turbulent waters.As a collateral damage, matters of these non-compliances may also involve regulatory inquiries or scrutiny involving submission of data or depositions.There could be regulatory scrutiny even otherwise for example in case of fraud involving significant sums of money, evasion of taxes, potential money laundering etc.The organisation may need to engage with legal experts or seek appropriate legal advice under their office of general counsel as deemed fit.
Conclusion
The author has tried to examine few key aspects which are helpful to consider in an internal investigation.However, dynamic as this area is, there are newer methodologies arising from time to time and every organisation has do its best to be one step ahead of the game and be at the forefront of preventing or detecting fraud within the organisation.