An internal auditor is explaining fraud risk management to a newly appointed team member who keeps confusing it with the work done after a fraud is discovered. Which statement best describes what fraud risk management involves?
- AIt is the process of gathering legal evidence to establish that a named individual committed a fraud that has already taken place.
- BIt is a periodic exercise performed by the external auditors to certify that the financial statements are free from any fraud.
- CIt is an ongoing process to identify, assess, and respond to the risk of fraud occurring across the organisation. Correct
- DIt is the internal audit function taking ownership of the operating controls that prevent fraud within the business units.
Why A is wrong: This is tempting because it sounds like serious anti-fraud work, but it describes fraud investigation, which responds to a suspected event, rather than the ongoing management of fraud risk.
Why B is wrong: External auditors do consider fraud risk, but this wrongly hands the whole activity to them and treats it as a one-off certification rather than an ongoing organisational process.
Why C is correct: Correct: fraud risk management is the continuous identification, assessment, and response to fraud risk, mirroring the wider risk management cycle applied to the specific threat of fraud.
Why D is wrong: This is tempting because internal audit evaluates fraud controls, but owning and operating those controls is a management responsibility, and taking it on would impair independence.