A procurement audit is scoped for contract compliance. During walkthroughs, you learn that one buyer sets up vendors, approves invoices, and releases payments, and that three vendors share a bank account. Nothing in your original scope covers fraud. Your scope now has to change.
Fraud is an intentional act involving deception to obtain an unjust or illegal advantage. The intent element is what separates it from error. An error is a mistake; fraud is a choice, and a choice made by someone who is actively working to stay hidden. That concealment is why recognizing fraud risks when planning an engagement is its own step: ordinary procedures designed to detect unintentional misstatement will not find someone who is hiding.
Internal audit's role is bounded. You evaluate whether the organization's controls address fraud risk, and you stay alert to fraud indicators during every engagement. You are not primarily responsible for preventing or detecting fraud; management owns that.
KEY: The exam almost never asks "did the auditor find the fraud?" It asks "did the auditor consider fraud risk when planning, and adjust the engagement when the risk was...
Common mistakes
- Treating fraud consideration as optional when controls look strong. Management override is an inherent risk in every engagement; strong design does not remove the planning obligation.
- Investigating after finding indicators. Once a specific fraud indicator surfaces, the auditor preserves evidence and escalates to the chief audit executive rather than expanding procedures.
- Claiming detection responsibility. Internal audit evaluates fraud controls and stays alert to indicators. Management owns prevention and detection.
Bottom line
- Fraud requires intent; that concealment is why standard error-focused procedures do not surface it.
- Fraud risk is assessed during planning, before objectives and procedures are fixed.
- The fraud triangle is pressure, opportunity, and rationalization; only opportunity is control-driven.
- Management override is an inherent fraud risk in every engagement, regardless of control design quality.
Exam shortcut
Sort every fraud stem into one of two buckets before reading the answers. Bucket one is "risk exists": weak segregation, cash handling, override capability, incentive pressure, no actual anomaly yet. The answer expands procedures and reports the weakness. Bucket two is "something happened": altered documents, shared bank accounts, transactions structured under a limit, a whistleblower tip. The answer preserves evidence and escalates to the chief audit executive.
The full lesson (about 2,020 words, 13 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 2
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.