GOV-008 Fraud Risk Assessment
Description
A fraud risk assessment exists that enumerates the fraud scenarios the organisation is exposed to, including misuse of system access and other insider scenarios. Each scenario carries a likelihood and impact rating and a link to the preventive or detective control that addresses it, or a recorded treatment decision where no control does. The assessment carries a review date within the defined interval and is revisited after a significant change to the business, its systems or its workforce.
Rationale
Fraud risk is not operational risk. It is intentional, committed by people who hold legitimate access and who know which controls look for them, so the scenarios have to be written down before a control can be designed against them. GOV-005 holds the general risk assessment and GOV-006 the risk tolerance; GOV-009 holds segregation of duties, one of the preventive controls this assessment points to. The programme that acts on the insider scenarios is HRS-012.
Applicability (9 profiles)
Framework Mappings (3)
| 5.3 | Segregation of duties | informative |
| PM-12 | Insider Threat Program | informative |
| CC3.3 | COSO Principle 8: Assesses Fraud Risk | full |
Evidence (2)
Fraud risk assessment report documenting identified fraud scenarios, insider threat considerations, and resulting control recommendations.
Example: Fraud Risk Assessment Report or risk register extract (GRC platform / Google Drive), dated within the last 12 months, with sections covering misuse of system access, insider threat scenarios, likelihood and impact ratings, and detective/preventive control gaps identified.
Test: Request the most recent fraud risk assessment. Verify: (1) the assessment is dated within the defined interval, (2) insider threat and misuse-of-access scenarios are explicitly addressed, (3) likelihood and impact are rated, (4) control recommendations are documented, (5) assessment findings are traceable to the risk register or a remediation plan.
Documented anti-fraud or insider threat policy referencing the fraud risk assessment process and the controls designed in response.
Example: Insider Threat or Fraud Risk Management Policy (Confluence), approved by management, referencing: the assessment schedule, responsible roles, and the categories of preventive and detective controls required.
Test: Request the anti-fraud or insider threat policy. Verify: (1) fraud risk assessment is referenced as a required activity, (2) detective controls (e.g. access logging, anomaly detection) are listed, (3) the policy has a named approver and approval date within the last 12 months.
Questions (3)
Does a documented fraud risk assessment exist?
A fraud risk assessment should document insider threat and access-misuse scenarios with likelihood and impact ratings and link findings to detective and preventive controls.
Which of the following controls has your organisation implemented in direct response to identified fraud risk?
The link between the fraud risk assessment findings and the controls designed in response should be documented.
Which of the following does the fraud risk assessment record?
Options run from the most commonly recorded to the least. Insider scenarios are the ones a fraud assessment written from a financial-controls template tends to miss, because the loss path runs through system access rather than through a payment.