At Kelston Manufacturing, internal audit is evaluating how well the organisation manages fraud risk. Management runs a documented annual fraud risk assessment and maintains anti-fraud controls, but the assessment has not been revisited even though the company has entered three overseas markets this year, each carrying different bribery and procurement-fraud exposures. How should the internal auditor characterise this situation?
- AThe fraud risk management process is adequate, because a documented annual fraud risk assessment and a set of anti-fraud controls are already in place and were completed on schedule this year.
- BThe fraud risk management process is not adequate, because the fraud risk assessment has not been updated to reflect the new fraud exposures created by the recent market expansion. Correct
- CThe internal auditor should personally re-perform the fraud risk assessment for the three new markets and hand management the completed assessment so the gap is closed before the engagement ends.
- DThe internal auditor should conclude that fraud is likely occurring in the new markets, because the exposures there were never assessed and uncontrolled fraud risk almost always results in actual fraud.
Why A is wrong: The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure; an assessment that ignores materially changed fraud risks is not adequate simply because it exists.
Why B is correct: Evaluating fraud risk management means checking that identification and assessment keep pace with changing exposure; a static assessment that misses new bribery and procurement risks leaves the response mismatched to the actual exposure.
Why C is wrong: Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility; taking it on would place internal audit in a first line role and impair later assurance over that work.
Why D is wrong: An unassessed exposure is a control weakness, not proof of fraud; concluding that fraud is occurring without evidence oversteps the auditor's role, which is to report the weakness in fraud risk management.