A performance assessment of existing fraud controls starts with a detailed review of relevant policies and procedures applied to prevent fraudulent activities. This includes checking those controls for adequacy and relevance as well as whether they are able to detect and prevent fraud. An organisation should perform an independent assessment of internal processes to identify whether controls are sufficiently reliable and to update them promptly in response to evolving risks.
An important aspect is the collection and analysis of data on past fraud incidents, if any, or on cases when controls could not have operated as intended. This can also include employee feedback on their experience of using the existing controls in practice. Regular tests of control procedures can identify weaknesses and prompt further improvements. An analysis of such data enables to adapt and streamline control tools, improving their effectiveness and adequacy for relevant challenges and risks.
We help organisations assess the effectiveness of the existing controls to prevent fraud by carrying out comprehensive independent audits and tests of control procedures. We analyse adequacy and relevance of current policies, help identify weaknesses and provide recommendations for improvement.
Three dimensions of control effectiveness
1. Design Effectiveness: Is the control designed correctly to prevent or detect a specific risk?
What we check:
Example: The Company has a control requiring an approval of all payments above UAH 50 thousand by CFO.
2. Operating Effectiveness: Is the control performed as designed, systematically and reliably?
What we check:
Example: The policy requires reconciling bank statements on a monthly basis.
3. Control adaptability: Does the control remain relevant in response to business changes?
What we check:
How we assess controls:
1. We analyse formal documentation: Policies and procedures, authority matrices, job descriptions, approval schemes, risk maps.
What we look for:
2. Sampling – we take a representative sample of transactions and check them for the following:
The size of the sample typically depends on the risk type.
3. Walkthrough testing – We walk through the entire process end-to-end – selecting a real transaction and tracing all steps from initiation to completion. We check whether controls work at each stage and identify any ‘grey areas’ where control is lacking.
Example: We trace procurement from order to payment:
Order → Approval → Sourcing → Contracting → Arrival of goods → Invoice → Payment.
At each stage, we check who performs, who controls and what is documented.
4. Interviews with responsible individuals performing controls: Do they understand what this control is for? What do they do if they encounter an issue? What challenges arise in performance of controls? How do they act in emergencies?
5. Analytical procedures – we rely on the data analysis to identify any outliers.
6. Red Team Testing – we attempt overriding controls, e.g.:
Important from the ethical standpoint: We do this with management’s permission, in controlled conditions and without any real financial losses.
Prioritisation of control improvements
Not all the weaknesses identified are equally critical. We help prioritise control improvements depending on the level of risk and potential financial impact. Examples of priority categories are provided below:
Critical (address immediately):
High priority (address over several months):
Medium priority (address over 6 months):
A control assessment is a regular process. We recommend conducting a full-scope assessment at least once every several years and annually for high-risk areas.
We perform an independent assessment of existing controls, policies and procedures to identify vulnerabilities that may be missed in-house. With our experience, we propose adapted best practices from other sectors, providing innovative fraud risk mitigation solutions.