Fraud risk assessment engine following the COSO Fraud Risk Management Guide. Builds fraud risk universes, maps anti-fraud controls, identifies red flags, designs data analytics detection programs, and evaluates anti-fraud program maturity. USE THIS SKILL when the user mentions fraud risk, anti-fraud controls, fraud detection, red flags, whistleblower program, fraud investigation, Benford's law, fraud triangle, fraud schemes, asset misappropriation, financial statement fraud, corruption, cyber fraud, or anti-fraud program assessment. Covers the full anti-fraud lifecycle from prevention through investigation readiness.
インストール
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
Fraud risk assessment engine following the COSO Fraud Risk Management Guide. Builds fraud risk universes, maps anti-fraud controls, identifies red flags, designs data analytics detection programs, and evaluates anti-fraud program maturity. USE THIS SKILL when the user mentions fraud risk, anti-fraud controls, fraud detection, red flags, whistleblower program, fraud investigation, Benford's law, fraud triangle, fraud schemes, asset misappropriation, financial statement fraud, corruption, cyber fraud, or anti-fraud program assessment. Covers the full anti-fraud lifecycle from prevention through investigation readiness.
Fraud Risk Assessment
Required Inputs
Organization: Company name, industry, size (revenue, employees), and organizational structure.
Business Processes: Key revenue, procurement, payroll, treasury, and financial reporting processes.
Control Environment: Existing internal controls, segregation of duties, approval authorities.
Prior Fraud History: Known fraud incidents, investigation outcomes, losses incurred.
Assess organizational exposure through the lens of fraud motivation theory.
Fraud Triangle Factors
Factor
Definition
Assessment Questions
Risk Level
Pressure / Motivation
Financial or personal pressure to commit fraud
Financial pressure on employees
Are employees under financial stress? Aggressive incentive targets?
[High/Med/Low]
Organizational pressure
Are there unrealistic financial targets? "Make the numbers" culture?
[High/Med/Low]
External pressure
Industry downturns? Competitive pressure? Covenant compliance?
[High/Med/Low]
Opportunity
Ability to commit and conceal fraud
Weak internal controls
Are there gaps in segregation of duties, approvals, reconciliations?
[High/Med/Low]
Override capability
Can management override controls without detection?
[High/Med/Low]
Inadequate monitoring
Is there limited oversight of transactions, access, behavior?
[High/Med/Low]
Complex transactions/structures
Are there complex related-party transactions, off-book entities?
[High/Med/Low]
Rationalization
Ability to justify fraudulent behavior
Tone at the top
Do leaders model ethical behavior? Is there a "rules don't apply to me" attitude?
[High/Med/Low]
Organizational justice
Do employees perceive fair treatment, compensation, recognition?
[High/Med/Low]
Ethical culture
Is there a strong code of conduct? Is it enforced consistently?
[High/Med/Low]
Extended Pentagon Factors (Beyond the Triangle)
Factor
Definition
Assessment Questions
Risk Level
Capability
Skills and position to execute fraud
Technical knowledge
Does the individual understand systems well enough to exploit them?
[High/Med/Low]
Authority level
Does the position carry sufficient authority to override or conceal?
[High/Med/Low]
Coercion ability
Can the individual pressure others to assist or remain silent?
[High/Med/Low]
Arrogance
Belief that rules do not apply
Entitlement
Does the culture tolerate "star performers" who bend rules?
[High/Med/Low]
Ego / overconfidence
Do key individuals believe they are too smart to be caught?
[High/Med/Low]
3. COSO Fraud Risk Management Guide Application
Apply the 5 COSO principles for fraud risk management.
COSO Fraud Risk Management Principles Assessment
Principle
Description
Current Maturity (1-5)
Evidence
Gap
Principle 1: Fraud Risk Governance
Organization establishes and communicates a fraud risk management program that demonstrates expectations of the governing body and senior management and their commitment to high integrity and ethical values.
[1-5]
[Evidence]
[Gap]
Principle 2: Fraud Risk Assessment
Organization performs comprehensive fraud risk assessments to identify specific fraud schemes and risks, assess their likelihood and significance, evaluate existing fraud risk management activities, and implement actions to mitigate residual fraud risks.
[1-5]
[Evidence]
[Gap]
Principle 3: Control Activities
Organization selects, develops, and deploys preventive and detective fraud control activities to mitigate the risk of fraud events occurring or not being detected in a timely manner.
[1-5]
[Evidence]
[Gap]
Principle 4: Investigation and Corrective Action
Organization establishes a communication process to obtain information about potential fraud and deploys a coordinated approach to investigation and corrective action to address fraud appropriately and in a timely manner.
[1-5]
[Evidence]
[Gap]
Principle 5: Fraud Risk Management Monitoring
Organization selects, develops, and performs ongoing evaluations to ascertain whether each of the five principles of fraud risk management is present and functioning and communicates fraud risk management program deficiencies in a timely manner to parties responsible for taking corrective action, including senior management.
[1-5]
[Evidence]
[Gap]
Maturity Scale for COSO Principles
Level
Definition
1 - Initial
No formal program. Fraud risk addressed reactively.
2 - Developing
Some elements exist but not comprehensive. Limited documentation.
3 - Defined
Formal program with policies, procedures, and assigned responsibilities.
4 - Managed
Program actively monitored with metrics. Regular assessments conducted.
Overpayment recovery; System access termination; Law enforcement referral
Expense reimbursement
Written expense policy with limits; Pre-approval for expenses > threshold; Receipt requirements
Duplicate expense detection; Benford's law analysis on amounts; Supervisor review of all claims; Analytics for round numbers, weekend dates, split transactions
Immediate bank notification and recall; Law enforcement (FBI IC3); Insurance claim
Bribery / Corruption
FCPA/anti-bribery policy; Third-party due diligence; Gift and entertainment policy with pre-approval; Compliance training
Third-party payment analytics (round amounts, unusual destinations); Gift and entertainment log review; Whistleblower reports; Travel expense anomaly detection
Investigation protocol; Self-disclosure analysis (DOJ/SEC); Remediation and enhanced controls
Conflicts of interest
Annual COI disclosure requirement; Vendor relationship disclosure; Board member independence certification
COI disclosure vs. transaction analysis (undisclosed relationships); Related-party transaction review; Procurement award pattern analysis
Disclosure remediation; Recusal procedures; Contract renegotiation or termination
6. Red Flag Indicators by Fraud Type
Behavioral Red Flags (Applicable Across All Fraud Types)
Red Flag
Possible Indication
Follow-Up Action
Living beyond apparent means
Employee may be supplementing income through fraud
Discreet observation; if pattern persists, analytics on their transactions
Refusal to take vacation or share duties
Concealment risk — fraud may be discovered in their absence
Mandatory vacation enforcement; cross-training with job rotation
Unusually close relationship with vendor/customer
Potential conflict of interest or kickback scheme
COI disclosure review; transaction analysis
Excessive overtime without clear business reason
Time theft or concealment activity requiring extra hours
Workload review; access log analysis
Resentment or complaints about perceived unfairness
Rationalization factor; may justify fraudulent behavior
Management attention; engagement assessment
Defensiveness when questioned about work
May indicate concealment
Supervisory review of work products
Known financial difficulties (garnishments, bankruptcy)
Pressure factor in fraud triangle
Heightened transaction monitoring
Transactional Red Flags
Fraud Type
Red Flag
Detection Method
Billing fraud
Vendor with P.O. box only; same address as employee; round-dollar invoices; sequential invoice numbers from different vendors; invoices just below approval thresholds
Vendor master analytics, invoice analytics
Payroll fraud
Employees with same bank account; employees with no tax withholding changes; overtime outliers; commission rate anomalies
Total Fraud Cost is typically 2x-5x the direct loss amount
Industry benchmarks (ACFE Report to the Nations):
Median loss per fraud case: $117,000
Mean loss per fraud case: $1,783,000
Median duration before detection: 12 months
Estimated total fraud loss: 5% of annual revenue (ACFE estimate)
11. Industry-Specific Fraud Schemes
Financial Services
Scheme
Description
Key Controls
Rogue trading
Unauthorized trading positions exceeding limits
Position limits, independent P&L valuation, trade surveillance
Structured program with metrics; lessons learned integration
Best-in-class capability; proactive intelligence
Response
Inconsistent consequences
Documented disciplinary process
Consistent enforcement; recovery pursued; law enforcement referral criteria
Root cause analysis; control enhancement post-incident
Comprehensive remediation; industry sharing; regulatory cooperation
Monitoring
No program monitoring
Annual review by management
Regular KPIs; audit committee reporting
Benchmarking against peers; program effectiveness metrics
Independent program assessment; continuous improvement cycle
Maturity Score Calculation
Domain Score = Assessed Level (1-5)
Overall Maturity = Average of 7 Domain Scores
Target Maturity by Organization Profile:
Public company (SEC registrant): Level 4 minimum
Large private company: Level 3 minimum
Mid-market company: Level 3 target
Small/startup: Level 2 minimum, Level 3 target within 2 years
Government / regulated entity: Level 4 minimum
Output Template
## Fraud Risk Assessment: [Organization]### Assessment Parameters
| Field | Detail |
|---|---|
| Organization | [Name] |
| Industry | [Industry] |
| Revenue / Size | [$X / # employees] |
| Assessment Date | [Date] |
| Methodology | COSO Fraud Risk Management Guide |
| Assessor | [Name/team] |
### Executive Summary
[Overall fraud risk profile, critical findings, top fraud risk scenarios,
anti-fraud program maturity score, priority recommendations]
### Fraud Triangle / Pentagon Assessment
| Factor | Risk Level | Key Drivers |
|---|---|---|
| Pressure | [High/Med/Low] | [Key drivers] |
| Opportunity | [High/Med/Low] | [Key drivers] |
| Rationalization | [High/Med/Low] | [Key drivers] |
| Capability | [High/Med/Low] | [Key drivers] |
| Arrogance | [High/Med/Low] | [Key drivers] |
### COSO Fraud Risk Management Maturity
| Principle | Score (1-5) | Key Gap |
|---|---|---|
| Principle 1: Governance | [1-5] | [Gap] |
| Principle 2: Risk Assessment | [1-5] | [Gap] |
| Principle 3: Control Activities | [1-5] | [Gap] |
| Principle 4: Investigation & Corrective Action | [1-5] | [Gap] |
| Principle 5: Monitoring | [1-5] | [Gap] |
### Fraud Risk Heat Map
| Risk Zone | Fraud Schemes | Residual Risk Score |
|---|---|---|
| Critical (20-25) | [Schemes] | [Scores] |
| High (13-19) | [Schemes] | [Scores] |
| Medium (7-12) | [Schemes] | [Scores] |
| Low (1-6) | [Schemes] | [Scores] |
### Anti-Fraud Control Gap Analysis
[Control mapping with identified gaps and remediation recommendations]
### Red Flag Monitoring Program
[Key red flags to monitor with detection methods and responsible parties]
### Data Analytics Program Design
[Recommended analytics tests with data requirements and implementation priority]
### Whistleblower Program Assessment
[Effectiveness scorecard with improvement recommendations]
### Investigation Readiness
[Readiness assessment with gaps and remediation plan]
### Anti-Fraud Program Maturity Scorecard
| Domain | Current Level | Target Level | Gap |
|---|---|---|---|
| Governance | [1-5] | [Target] | [Gap] |
| Risk Assessment | [1-5] | [Target] | [Gap] |
| Prevention | [1-5] | [Target] | [Gap] |
| Detection | [1-5] | [Target] | [Gap] |
| Investigation | [1-5] | [Target] | [Gap] |
| Response | [1-5] | [Target] | [Gap] |
| Monitoring | [1-5] | [Target] | [Gap] |
| **Overall** | [Avg] | [Target] | [Gap] |
### Remediation Roadmap
| Priority | Action | Owner | Timeline | Est. Cost |
|---|---|---|---|---|
| Immediate | [Action] | [Role] | 0-30 days | [$X] |
| Near-term | [Action] | [Role] | 30-90 days | [$X] |
| Medium-term | [Action] | [Role] | 90-180 days | [$X] |
| Long-term | [Action] | [Role] | 180-365 days | [$X] |
### Disclaimers> This fraud risk assessment provides a framework for identifying and> mitigating fraud risk. It does not guarantee the detection or prevention> of all fraud. No system of internal controls can provide absolute> assurance against fraud. This assessment should be updated annually or> when significant organizational changes occur.
Quality Checks
Fraud risk universe covers all 4 major categories (asset misappropriation, financial statement fraud, corruption, cyber fraud) with specific schemes relevant to the organization's industry.
Fraud triangle/pentagon analysis assesses pressure, opportunity, AND rationalization (plus capability and arrogance for pentagon) with specific organizational evidence.
COSO Fraud Risk Management Guide principles (all 5) are assessed with specific maturity scores and evidence.
Fraud risk assessment matrix maps specific schemes to specific business processes with scored likelihood and impact.
Anti-fraud controls are mapped as preventive, detective, AND corrective for each significant fraud scheme.
Red flag indicators include behavioral, transactional, AND analytical categories with specific detection methods.
Whistleblower program assessment covers all key elements (channels, independence, anonymity, non-retaliation, awareness, triage, investigation, feedback, metrics).
Data analytics program includes specific tests (Benford's law, duplicate detection, anomaly detection) with data requirements, not just general descriptions.
Investigation readiness framework includes both the readiness checklist and decision tree for investigation management.
Fraud loss quantification covers direct losses AND indirect costs (investigation, remediation, regulatory, reputational).
Industry-specific fraud schemes are included for the organization's industry.
Anti-fraud program maturity model scores all 7 domains on a 5-level scale with defined level descriptions.