IN BRIEF
Fraud risk management has become increasingly important in the current business environment. How CPAs can best apply their expertise to this task remains a question requiring further investigation. This article surveyed CPAs about the importance of specific fraud risk management practices drawn from professional guidance and analyzed the results to provide insights into benchmarks CPAs can use when advising businesses.
***
The importance of effective fraud risk management is underscored by recent cases: Take, for example, the January 2025 indictment of Alexander Charles Beckman, founder and former CEO of GameOn, Inc. According to the US Attorney’s Office for the Northern District of California (2025), Beckman and his wife defrauded investors by issuing fabricated bank statements and audit reports to validate fraudulent financial statements (“Founder and Former CEO of San Francisco Technology Company and Attorney Indicted for Years-Long Fraud Schemes,” News release, January 23, 2025, https://tinyurl.com/yurpmsem). Acting with-out their permission, Beckman also used the names and signatures of real people to create falsified documents, in all enabling the couple to raise more than $60 million from investors.
Such cases highlight the continuing need for organizations—and the CPAs who advise them—to establish strong programs of fraud risk management. The Fraud Risk Management Guide [FRM Guide (2023)], co-published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and the Association of Certified Fraud Examiners (ACFE), outlines comprehensive principles and practices designed to deter, detect, and prevent fraud. Yet questions remain as to which specific practices CPAs view as most important and how CPAs can evaluate those practices in a client’s program of fraud risk management.
To explore these questions, the authors surveyed CPAs to assess the perceived importance of 16 practices of fraud risk management drawn from the FRM Guide (2023). Respondents rated each practice on a five-point scale of importance, and the resulting data was used to identify those practices most valued by CPAs. The analysis produced a limited model of fraud risk management that includes at least one highly rated practice for each COSO internal control component. In addition, a qualitative model of rating practices of fraud risk management was developed.
This article addresses two questions:
- Which fraud risk management practices do CPAs view as most important within and across the COSO internal control components?
- How can qualitative measures be applied to fraud risk management practices to help CPAs evaluate internal control systems and advise on program improvements?
These questions guided the survey design and analysis with the goal of identifying practical benchmarks CPAs can use when evaluating internal control systems and advising clients on fraud risk management. The following provides background on fraud risk management practices, summarizes the research methodology, and presents and discusses the research results with a conclusion.
Background
The FRM Guide (2023) includes five fraud risk management principles that align with COSO’s five internal control components: control environment, risk assessment, control activities, information and communication, and monitoring activities. The following discussion focuses on this guidance and other supporting literature.
Control environment. The FRM Guide (2023) contains the following fraud risk management principle regarding COSO’s control environment component:
The organization establishes and communicates a Fraud Risk Management Program that demonstrates the expectations of the board of directors and senior management, and their commitment to high integrity and ethical values regarding managing fraud risk.
Three key topics within the control environment included in this survey are: ethics program, awareness training, and executive oversight.
Ethics Program. Training in ethics helps to confirm that employees understand expectations. This training should occur as a part of employee orientation and be consistently highlighted at meetings (C. Andrews and B. LeBlanc, “Fraud Hotlines: Don’t Miss That Call,” Journal of Accountancy, August 2013, https://tinyurl.com/ynk4r3rs).
Awareness Training. In their 2021 Fraud Awareness Training Benchmarking Report (14-16), the ACFE noted a survey of its members showed training most frequently covered topics such as the red flags of fraud, ethics, fraud reporting procedures, and organizational anti-fraud policies. The three highest-ranked training objectives were: “(1) informing employees about general fraud issues and risks, (2) covering material and content relevant to their organization, and (3) specifying actions employees can take to prevent or detect fraud.”
Executive Oversight. Accountability should be established by having a member of executive management assigned overall responsibility for the fraud risk management program. This person should periodically report to the board regarding the functioning of the program [FRM Guide (2023)].
Risk assessment. The FRM Guide (2023) contains the following fraud risk management principle regarding COSO’s risk assessment component:
The organization performs comprehensive fraud risk assessments to identify specific fraud schemes and risks, assess their likelihood and significance, evaluate existing fraud control activities, and implement actions to mitigate residual fraud risks.
Three key topics within risk assessment included in this survey are: brainstorming, likelihood/significance, and residual risk.
Brainstorming. Beasley and Jenkins describe how auditors can avoid difficulties inherent to brainstorming sessions (M. Beasley and G. Jenkins, “A Primer for Brainstorming Fraud Risks,” Journal of Accountancy, December 2003, https://tinyurl.com/58xuated). Their recommendations include the following:
- Assign homework—inform participants before the meeting that they will be discussing fraud risks so that they can begin to consider how and where the organization is vulnerable.
- Establish ground rules—common ground rules for a session include not being critical of others’ ideas, letting everyone speak, and trying to build on each other’s ideas.
Likelihood/Significance and Residual Risk. Exhibit 1 presents an example of a fraud risk management assessment matrix that can be used to document the risk assessment process.
After listing identified fraud risks and schemes in column 1 of the matrix, users assess the risks in terms of likelihood (column 2) and significance (column 3). The FRM Guide (2023) states organizations can categorize likelihood and significance of potential frauds in as many gradations as is reasonably needed. It suggests the following categories: Likelihood—remote, reasonably possible, and probable; Significance—inconsequential, more than inconsequential, and material.
This is followed by listing the personnel/departments involved (column 4) and then a consideration of any existing fraud control activities associated with the risk (column 5) and the effectiveness of those existing control activities (column 6). It is necessary to understand the meaning of inherent risk to understand the concept of residual fraud risks (column 7). Fraud risks identified in the matrix are listed on an inherent risk basis. Inherent risk is the amount of risk assuming there are no internal controls in place to properly address the fraud risk. When a specific fraud risk has a high level of both likelihood and significance, it is considered to have a high inherent risk and therefore deserves more in terms of fraud controls. The residual fraud risks column includes risks that are not controlled or risks that remain after the application of some form of existing control activities. An appropriate fraud risk response (column 8) should be based upon residual risk. Grove and Clouse (Grove, H. and Clouse, M. “Financial and Non-Financial Risk Assessment,” Journal of Forensic and Investigative Accounting, 2020, v. 12, no. 3, p.424, https://tinyurl.com/3yzd88za) provide a description of potential fraud risk responses:
- Accept the risk if the combined probability of occurrence (i.e., likelihood) and potential impact of loss (i.e., significance) indicate a low over-all level of risk exposure.
- Avoid risk by removing an asset or discontinuing an activity. This approach may be desirable when risk control measures are too costly.
- Mitigate the risk by implementing preventive and detective controls to reduce the overall level of risk exposure to a low level.
- Transfer some or all of the risk of loss to an insurance company by purchasing a fidelity bond or fidelity insurance.
Control activities. The FRM Guide (2023) defines a fraud control activity as “a specific procedure or process intended to either prevent fraud from occurring or to detect fraud quickly in the event that it occurs.” The guide contains the following fraud risk management principle regarding COSO’s control activities component:
The organization selects, develops, and deploys preventive and detective fraud control activities to mitigate the risk of fraud events occurring or not being detected in a timely manner.
Four key topics within control activities included in this survey are: directly linked, preventive/detective, management override, and data analytics.
Directly Linked. It is important that an organization’s fraud control activities are directly linked to its fraud risk assessment. This ensures that the fraud risks and schemes identified in the fraud risk management assessment matrix (see Exhibit 1) are appropriately addressed [FRM Guide (2023)].
Preventive/Detective. Bwerinofa-Petrozzello describes preventive and detective controls and provides some examples (“Preventing Fraud with Internal Controls: A Refresher,” Journal of Accountancy, August 2023, https://journalofaccountancy.com/issues/2023/aug/preventing-fraud-with-internal-controls-a-refresher.html). Preventive controls are valuable because they attempt to stop fraud from happening. Examples of preventive controls include:
- Segregation of duties so that no one person can exploit the organization system on their own.
- Physical controls over assets so that access to physical areas of the organization is limited to what someone needs to do their job.
Since some people are continuously working to get around an organization’s preventive controls, it is also necessary to have detective controls to discover fraud should it occur. Some examples of detective controls include:
- Physical inventory checks to ensure that the inventory recorded in the records exists.
- Account reconciliations such as reconciling general ledger balances to subsidiary ledgers, supporting schedules, or third-party records such as a bank account balance.
Management override. The FRM Guide (2023) recommends implementing controls to mitigate fraudulent financial reporting. Such controls are necessary to deter management from manipulating financial statements, for example, through top-side adjustments, biased accounting estimates, or by pressuring subordinates to engage in inappropriate activities. Radin (“A Practical Approach to Finding Management Override,” The CPA Journal, October 2008, pp. 6–9) points out that businesspersons often have a good understanding of what auditors do, as many people in financial management positions have either previously worked as auditors or at least have taken courses in auditing, making it easier for such managers to override controls in a manner that can get around an auditor.
Data analytics. Allen (A.G. Allen, “Audit Tools Help Enhance Fraud Risk Assessments,” Internal Auditor, Feb. 21, 2022, https://tinyurl.com/mvjhjmwv) feels that data analytics can serve as one of an organization’s greatest forms of anti-fraud controls. Allen describes an example of using data analytics to identify fraudulent vendors. Auditors can begin this process by ensuring vendor information is complete. Analytic tools can be used to isolate vendors with missing information, especially those with missing phone or tax identification numbers.
Information and communication. The FRM Guide (2023) contains the following fraud risk management principle regarding COSO’s information and communication component:
The organization establishes a communication process to obtain information about potential fraud and deploys a coordinated approach to investigation and corrective action to address fraud appropriately and in a timely manner.
Three key topics within information and communication included in this survey are: anonymity, response plan, and reporting.
Anonymity. Andrews and LeBlanc (2013) point out that third-party tip lines have become a common option for companies to receive allegations of fraud. They note that anonymity and ongoing confidentiality are important features, as more than half of tips generally come from employees.
Response Plan. The FRM Guide (2023) states the board should ensure “that the organization develops a system for prompt, competent, and confidential evaluation, investigation, and resolution of allegations and complaints involving potential fraud or misconduct.”
Reporting. The results of investigations should be reported to the appropriate internal authority and external parties, if necessary [FRM Guide (2023)]. Internal investigation reports should be accurate, clear, impartial, and objective. In addition, they should be prepared and delivered in a timely manner to people within the organization, such as senior management, directors, or legal counsel, who have oversight regarding the investigation [FRM Guide (2023)].
Monitoring activities. The FRM Guide (2023) contains the following fraud risk management principle regarding COSO’s Monitoring Activities component:
The organization selects, develops, and performs ongoing evaluations to ascertain whether each of the five principles of fraud risk management is present and functioning and communicates Fraud Risk Management Program deficiencies in a timely manner to parties responsible for taking corrective action, including senior management and the board of directors.
Three key topics within monitoring activities included in this survey are: measurement criteria, other fraud, and improvements.
Measurement Criteria. Effective monitoring of a fraud risk management program should include establishing clear measurement criteria to evaluate a program’s effectiveness. Some examples of measurement criteria include:
- How long it takes to detect fraudulent activity.
- The number of issues identified in employee background checks compared to how many checks were performed [FRM Guide (2023)].
Other Fraud. Monitoring should also involve a consideration of known fraud schemes and newly discovered and reported frauds in other organizations, and an assessment of their likelihood of occurrence to evaluate whether current controls could prevent or detect them if they were to occur [FRM Guide (2023)].
Improvements. Overall responsibility for the Fraud Risk Management Program should be assigned to a member of senior management. In addition, responsibility for certain fraud risk management principles and associated fraud control activities can be separately assigned to senior members of management. Each of these individuals should do the following:
- Follow appropriate channels to promptly report concerns and obtain approval for revisions to fraud risk management processes and related control activities that fail to reduce the residual fraud risk to a level that is acceptable with the risk tolerance of the organization.
- Make and document any necessary changes to the processes of fraud risk management and corresponding control activities [FRM Guide (2023)].
Research Methodology
The present survey asked how CPAs would rate the importance of 16 practices of fraud risk management, developed on the basis of practices of fraud risk management published in the FRM Guide (2023), as detailed above. A physical mail survey was created and distributed to 300 CPAs listed in the 2025 Alabama State Board of Public Accountancy Annual Register of Certified Public Accountants and Public Accountants. Only CPAs associated with public accounting firms were selected. A total of 44 responses were received from CPAs across the State of Alabama, representing an overall response rate of 14.7%. A total of 43 of the responses addressed the demographics included in the survey.
Survey respondents were drawn from public accounting firms offering a range of services. The most commonly reported services were tax preparation (95.3%), financial statement compilations (88.4%), financial statement reviews (79.1%), and private company audits (69.8%). Smaller percentages reported internal control reporting (48.8%), fraud investigation (41.9%), and public company audits (18.6%). In terms of years of experience in public accounting, 4.7% had 1–5 years, 7.0% had 6–10 years, 11.6% had 11–15 years, and 76.7% had more than 15 years. The survey also asked whether the respondents’ firms had engaged or employed the services of a Certified Fraud Examiner: 52.4% answered no, 33.3% answered yes, and 14.3% stated that they were uncertain.
For each of the fraud risk management practices presented in the survey, respondents were asked to indicate the level of importance they would place on the practice if evaluating an organization’s fraud risk management program, using a five-point scale of (1) unimportant, (2) slightly important, (3) moderately important, (4) important, and (5) very important.
Two alternative methods were evaluated to determine how best to rank the CPAs’ importance ratings: a strictly ordinal ranking and a key performance indicator (KPI) ranking. Although the ordinal method preserves strict adherence to measurement theory, the KPI approach was selected because it communicates the findings more effectively. Under the KPI approach, practices were ranked in descending order based primarily on the combined percentage of respondents selecting (4) important and (5) very important; where values were tied, median ratings and then the percentage selecting (5) very important, were used as tiebreakers whereas mean values were reported for descriptive purposes only.
To interpret the relative importance of the practices, each was classified into one of four qualitative categories—vital, crucial, valuable, or beneficial—based upon the percentage of CPAs rating it as (4) important or (5) very important. Because responses were highly concentrated in these two ratings, strict cutoffs were applied: vital (≥ 92.00%), crucial (80.00–91.99%), valuable (70.00–79.99%), and beneficial (< 70.00%). Vital practices are essential to an effective fraud risk management program; crucial practices support core objectives but are not indispensable; valuable practices contribute meaningfully but play a supporting role; and beneficial practices offer helpful enhancements but are not central to program operation.
Survey Results
The survey results show how CPAs prioritized 16 practices of fraud risk management across the five COSO components of internal control. Because responses were concentrated at the upper end of the fivepoint scale, the rankings were determined primarily by the combined percentage of CPAs selecting (4) important and (5) very important. As described above, each practice was assigned to one of four qualitative categories—vital, crucial, valuable, or beneficial—based on that same percentage measure. These classifications provide the framework for interpreting the relative importance of the practices presented in Exhibit 2.
Analysis
Four practices were classified as vital, reflecting their essential role in effective fraud risk management. Improvements emphasizes the importance of promptly addressing identified deficiencies and ensuring that controls adapt as conditions change. Management override highlights the importance of preventing and detecting actions by senior management that circumvent internal controls, including those involving top-side adjustments or accounting estimates. Anonymity emphasizes protecting individuals who report suspected fraud, recognizing that most tips originate from employees who may fear retaliation. Finally, likelihood/significance highlights the importance of assessing both the probability and potential impact of fraud risks to identify and prioritize those posing the greatest overall risk.
Anonymity emphasizes protecting individuals who report suspected fraud, recognizing that most tips originate from employees who may fear retaliation.
At the other end of the spectrum, measurement criteria and data analytics were rated beneficial, suggesting they are helpful but less important than other practices. Two possible explanations for these findings were developed by the authors with the assistance of ChatGPT (OpenAI 2025), suggesting that variations in program maturity and available resources may help explain the results. Measurement Criteria often help refine mature programs and may be less important in the initial phases of program development, while data analytics can be limited by technological capacity, especially in smaller organizations.
Some additional perspective can be gained by considering the types of services offered by the firms employing the responding CPAs, as described above. Many of those firms offer traditional accounting services such as tax preparation and financial statement compilations and reviews, however, less than half of respondents reported that their firms offer fraud investigation services apart from those performed in connection with an audit. It is possible that CPAs working in firms that do not offer such services may place less emphasis on data analytics as a fraud risk management practice.
Further analysis was performed to evaluate whether respondents’ experience in public accounting influenced the importance placed on client use of data analytics. A Spearman rank correlation across four experience levels indicated no statistically significant relationship between experience level and responses to this item (Spearman correlation = .258, p = .094). In a separate two-group analysis, a Mann–Whitney U test comparing CPAs with 15 years or less experience to those with more than 15 years of experience also indicated no significant difference (p = .063), although the more experienced group reported slightly higher importance ratings. Although data analytics ranked lower relative to the other fraud risk management practices examined, respondents generally still viewed it as important (median = 4). This suggests that the relatively lower ranking of the importance of client use of data analytics was not primarily driven by years of experience in public accounting.
Developing a Limited Program of Fraud Risk Management
Businesses that are in the early stages of developing a fraud risk management program may request the assistance of CPAs in designing and implementing a limited program that can later be expanded. Two considerations are particularly important in developing such a limited program:
- Including a balance that represents each of the five COSO components, and
- Incorporating those practices identified as most important.
Exhibit 3 presents a model for establishing a limited program of fraud risk management, showing the COSO components together with the corresponding practices rated as having the highest level of importance for that component in this survey.
It is interesting to note that the four most highly rated practices in the survey represent four separate components of the COSO framework. The only exception is that the control environment is not represented as one of the VITAL categories. The highest rated Control Environment practice is awareness training which is ranked #8 and categorized as being CRUCIAL. This practice emphasizes training employees to recognize signs of fraud and their duty to report it.
Implications for CPA Engagements
CPAs typically assist clients with fraud risk management in two principal ways: 1) by evaluating existing programs as part of an internal control assessment or 2) by advising them on the design or enhancement of such programs. In either type of engagement, CPAs should ensure that, at a minimum, the foundational practices identified in Exhibit 3 are addressed so that each of the COSO components is represented within the client’s program.
Summary and Conclusions
The current survey examined how CPAs rate the importance of 16 fraud risk management practices derived from the COSO-ACFE’s Fraud Risk Management Guide (2023). Responses from 44 CPAs in Alabama public accounting firms showed strong consensus, with ratings concentrated at important and very important. Each fraud risk management practice received at least 61% of responses at these two levels, indicating that CPAs generally regard all of the practices as consistently important to effective fraud risk management.
Findings from the limited model highlight a foundational set of practices that CPAs considered essential for building and evaluating fraud risk management programs. Four practices—improvements, management override, anonymity, and likelihood/significance—were classified as vital, representing four COSO components and forming the foundation of the limited model. With the addition of the crucial control environment practice and awareness training, the model is completed—ensuring that all five COSO components are represented. This model provides a practical benchmark for CPAs advising clients on initial fraud risk management programs.
Consistent with the Fraud Risk Management Guide (2023), which notes that “there is no ‘one-size-fits-all’ approach to managing fraud risk,” the limited model and other surveyed practices—each ranked and categorized by relative importance—can guide CPAs in assessing controls and advising clients at different stages of program maturity. These benchmarks encourage programs that remain effective and scalable as conditions evolve, while allowing CPAs to add practices suited to each business’s unique environment. In doing so, CPAs can help organizations strengthen fraud resilience and maintain balance across the COSO components.
There are certain limitations that should be considered in interpreting the results of this survey. First, all survey participants were CPAs practicing in accounting firms located in the state of Alabama. Accordingly, the findings may not be representative of CPAs in other parts of the United States. Nevertheless, CPAs operate within a broadly similar professional environment, including a standardized certification examination, common auditing standards, similar professional education requirements, and shared regulatory expectations. Second, the survey did not collect information regarding the size of the firms in which respondents work. Differences in firm size could influence the resources available to implement technologies such as data analytics and other fraud risk management practices. Finally, the study was not designed to provide industry-specific comparisons, but rather to assess the overall importance that CPAs place on selected fraud risk management practices. Future research could examine whether perceptions of these practices vary across firms of different sizes, across industries with differing fraud risks and regulatory environments, and through more detailed analysis of experience-related differences among CPAs.
Note: One author used OpenAI’s ChatGPT (GPT-5, 2025) to assist in identifying appropriate analytical approaches for Likert-scale data, formulating plausible explanations for selected survey findings, and refining the clarity of certain passages. All data analysis, interpretation, and final conclusions are those of the authors.
The post Fraud Risk Management Practices appeared first on The CPA Journal.



