This scheme is a load of manure and more
Read Time: 3 mins
Written By:
Anna Brahce, CFE
The ACFE's "2006 Report to the Nation" pins the median financial statement misstatement at $2 million, which occurred in 10.6 percent of the study's reported cases. When looking at some of the recent large-scale frauds, such as WorldCom, management override around the journal entry process was the key contributing factor.1 This is to be expected because the easiest route to changing the books and records is for executive management to post a top-side journal entry. Though it's always possible to make the adjustments in the sub-ledgers (for example, fixed assets, sales journals, etc.), this requires more collusion with other organizational departments. So the top-side entry is still the best way to commit the financial statement fraud.
Companies have spent much time documenting, testing, and otherwise fine-tuning their journal entry processes for Sarbanes-Oxley. Standard-setters like the AICPA have even issued guidance to companies on ways to prevent management override. (See www.aicpa.org/audcommctr/spotlight/achilles_heel.htm.) However, none of this documentation, testing, or standards can prevent the one-off entry in the middle of the night. Executive management can beat the system with a few keystrokes.
Therefore, journal entry testing requirements have been specifically promulgated for external auditors with the AICPA's Statement of Auditing Standard (SAS) 99 - Consideration of Fraud in a Financial Statement Audit. The standard states that "the auditor should design procedures to test the appropriateness of journal entries recorded in the general ledger and other adjustments (for example, entries posted directly to financial statement drafts) made in the preparation of the financial statements." More specifically, SAS 99 requires the auditor, in all audits, to (a) obtain an understanding of the entity's financial reporting process and controls over journal entries and other adjustments, (b) identify and select journal entries and other adjustments for testing, (c) determine the timing of the testing, and (d) inquire of individuals involved in the financial reporting process about inappropriate or unusual activity relating to the processing of journal entries or other adjustments.
This SAS was followed by the AICPA's Practice Alert 2003-02 (http://media.cpa2biz.com/Publication/pralert _03_02.pdf) with the purpose of providing auditors additional guidance regarding the design and performance of journal entry audit procedures to fulfill the responsibilities outlined in SAS 99. Rightly or wrongly, the auditor is still perceived as a valid line of defense against fraud, material and immaterial, and therefore, needs to detect as much fraud as possible.
DATA ANALYSIS IS A KEY TO MEETING THE REQUIREMENTS
Auditors and fraud examiners shouldn't rely on just manually reviewing the general ledger because it's just too large and they will miss some irregularities. Even though an auditor's or fraud examiner's judgment is still valuable, relying only on manual means is obsolete. As highlighted in the AICPA's Practice Alert 2003-02, "Journal entries and other adjustments oftentimes exist only in electronic form, which requires extraction of the desired data for any quality analysis. In an IT environment, it might be necessary for the auditor to employ computer-assisted audit techniques (for example, report writers, software or data extraction tools, or other systems based techniques) to identify the journal entries and other adjustments to be tested." The Practice Alert further describes various journal-entry tests that would be difficult or impossible to complete for most client engagements without a computer. The practical reality is that financial statement fraud lives in the 1 percent of digital transactions and, hence, needs improved tools for detection. Data analysis can provide that superb defense against management override by performing a more extensive search for unusual ledger activity.
TESTS TO PERFORM
Per SAS 99, fraudulent adjustments often have certain unique identifying characteristics, which might include entries (a) made to unrelated, unusual, or seldom-used accounts, (b) made by individuals who typically don't make journal entries, (c) recorded at the end of the period or as post-closing entries that have little or no explanation or description, (d) made either before or during the preparation of the financial statements that don't have account numbers, (e) containing round numbers or a consistent ending number, or (f) applied to accounts that contain transactions that are complex or unusual in nature, contain significant estimates and period-end adjustments, have been prone to errors in the past, haven't been reconciled on a timely basis or contain unreconciled differences, contain inter-company transactions, or are otherwise associated with an identified risk of material misstatement due to fraud.
While the above is helpful guidance, let's list some precise computerized journal entry tests and organize them into the five Ws:
Who
What
When
Where
Why (unusual activity)
The above test, "Extract journal entries to general ledger accounts known to be problematic or complex based on past issues ..." could be made specific to an organization by reviewing past audits or inquiring of management to determine past issues. (Generally, companies tend to have misstatement issues in revenue recognition and capitalization of expenses.)
Another approach is for a company's auditors and fraud examiners to track any issues identified in internal control reviews or past audits in a small database of their own. (It could be as simple as a Microsoft Excel list.) For an industry perspective, check AuditAnalytics.com; the site has a database of all Securities and Exchange Commission filings that you can use to identify trends in company misstatements based on a given industry or size of a company.
WAYS TO DO SOME OF THESE TESTS
You can perform some simple procedures in Microsoft Excel and easily apply them to any data analysis product you're using in your organization.
For unusual times of day, obtain the time-stamp field for analysis or obtain a date field and then use the WEEKDAY() function. For instance, WEEKDAY(A1) will convert a date field cell A1 into the day of the week (1 is a Monday and 7 is Sunday). Then by selecting the top of the column containing the WEEKDAY() functions, the Auto Filter feature (under the Data menu item in Excel) can be used to filter all WEEKDAY(Date_Field) values that are equal to 6 or 7.
For identifying round numbers, use the MOD() function, which divides the number by a provided divisor and then lists the resulting value that isn't divisible by the divisor. For example, say that $10,422 is in cell A1 and the function MOD(A1,1000) is placed in cell B1. The result in B1 would be $422 because this would be the remainder after dividing $10,422 by $1,000. Or if cell A2 had $100,000 in it then MOD(A1,1000) would result in a zero value, which would indicate a round number. Once you use this MOD() function for every amount posted in the journal entry, you can filter all zero items using the AutoFilter feature. Note that the function would be written as MOD(A2, 10000) for round multiples of $10,000.
BENEFITS OF AUTOMATED JOURNAL ENTRY TESTING
If you're serious about stopping financial statement fraud, consider using effective journal entry controls and automated tests. Here are the benefits:
In the January/February column, I'll explain additional journal entry tests based on the tests I describe here.
[Some source links referenced in this article are no longer available. — Ed.]
Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.
Read Time: 3 mins
Written By:
Anna Brahce, CFE
Read Time: 20 mins
Written By:
Paul Kilby, CFE
Read Time: 13 Mins
Written By:
Vincent M. Walden, CFE, CPA
Eric Johnson
Read Time: 3 mins
Written By:
Anna Brahce, CFE
Read Time: 20 mins
Written By:
Paul Kilby, CFE
Read Time: 13 Mins
Written By:
Vincent M. Walden, CFE, CPA
Eric Johnson