13.07.2015 Views

Fighting Fraud in Smaller Public Companies.pdf - Lord & Benoit

Fighting Fraud in Smaller Public Companies.pdf - Lord & Benoit

Fighting Fraud in Smaller Public Companies.pdf - Lord & Benoit

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

"FIGHTING FRAUD <strong>in</strong><strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>”What are the Top <strong>Fraud</strong> andF<strong>in</strong>ancial Ethics Threats?Please turn on computer speakers to hear presenter© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org1


"FIGHTING FRAUD <strong>in</strong><strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>”Presenter is now speak<strong>in</strong>g. Please turn on computerspeakers to hear presenterWhat are the Top <strong>Fraud</strong> andF<strong>in</strong>ancial Ethics Threats?If you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-6072


Cont<strong>in</strong>u<strong>in</strong>g Professional EducationPlease turn on computer speakers to hear presenterThere will be <strong>in</strong>structions at the end of this sem<strong>in</strong>ar on obta<strong>in</strong><strong>in</strong>gCPE credit* for this web<strong>in</strong>ar.To qualify you must attend at least 50 m<strong>in</strong>utes of this web<strong>in</strong>ar.* Please note: State Boards of Accountancy have f<strong>in</strong>al authority on theacceptance of <strong>in</strong>dividual courses for CPE credit.• <strong>Lord</strong> & <strong>Benoit</strong> is not registered with NASBA.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org3


DisclaimerThe literature conta<strong>in</strong>ed here<strong>in</strong> is not <strong>in</strong>tended tosubstitute authoritative literature published by therespective regulatory agencies. Professionals areadvised to consult with legal and account<strong>in</strong>gauthorities on all matters before implement<strong>in</strong>gprofessional standards.If you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-6074


Biographies and IntroductionsBob <strong>Benoit</strong>Please turn up your computer speakers to hear presenterIf you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-607© Copyright 2008 : <strong>Lord</strong> & <strong>Benoit</strong>, LLC www.Section404.org5


<strong>Lord</strong> & <strong>Benoit</strong> helps “<strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>”<strong>Lord</strong> & <strong>Benoit</strong> releaseslead<strong>in</strong>g edge SOXeducation and research.For <strong>in</strong>stance, “Impact ofSOX on the Manufactur<strong>in</strong>gIndustry”.© 2009 <strong>Lord</strong> & <strong>Benoit</strong>, LLCwww.section404.org


<strong>Lord</strong> & <strong>Benoit</strong> helps “<strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>”CCH “F<strong>in</strong>ancial Restatements” researchRIA Thomson “Investment Research” sectionRIA Thomson/Southwest Learn<strong>in</strong>g "Checks on Internal Controls Pay Off"BNA "Sarbanes-Oxley and Small Bus<strong>in</strong>ess"Counsel of Institutional Investors "Letter to Chairman SEC and Chairman PCAOB"ADP "HR's Role <strong>in</strong> Ensur<strong>in</strong>g Compliance and Driv<strong>in</strong>g Cultural Change”Oracle “GRC Strategy”Oracle: Best Practices for World Class I/T GovernanceOracle: Help<strong>in</strong>g You Compete and W<strong>in</strong> <strong>in</strong> a Flat WorldSAP "Governance, Risk and Compliance Management"Top 40 Account<strong>in</strong>g Firms "The SOX Act"If you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-6077


<strong>Lord</strong> & <strong>Benoit</strong> helps “<strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>”• Do You Know the Facts? Latest Section 404(a) Requirements for <strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>• SOX TV: Top Ten Compliance Threats TV <strong>in</strong>terview discuss<strong>in</strong>g major areas of compliance forsmaller public companies• SOX TV: How Do You Conduct a Virtual SOX Assessment?• Delay-Detect 10A-Delist: Facts about Section 404(a) for <strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>• Impact of Account<strong>in</strong>g for Income Taxes on SOX 404• ComplianceOnl<strong>in</strong>e: 10 Threats to SOX Compliance for <strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>• Metric Stream Web<strong>in</strong>ar: SOX Essentials for Small <strong>Public</strong> <strong>Companies</strong>• Leverage Entity-Level Controls and Virtual SOX• SME Capital Markets: SEC Guidance on Internal Controls over F<strong>in</strong>ancial Report<strong>in</strong>g (SOX 404)--Impacts CPA's Attorneys, Officers and Directors• ComplianceOnl<strong>in</strong>e: New SEC Guidance on Sarbanes-Oxley Section 404• Help<strong>in</strong>g Foreign Based SB-2 Registrants and 10KSB Filers Achieve SOX Compliance• Small Filers Plann<strong>in</strong>g for the Transition to 404 Compliance• MSCPA Conference: A Sarbanes-Oxley Update• SME Capital Markets: Virtual SOX Compliance Frameworks for SB-2 and 10KSB Filers• AICPA Web Sem<strong>in</strong>ar: Virtual SOX• CBI Research: 2nd Annual Pharmaceutical/Biotech Conference on Sarbanes-Oxley and 404Compliance• ComplianceOnl<strong>in</strong>e: 10 Pre-SOX Tips for <strong>Smaller</strong> <strong>Public</strong> <strong>Companies</strong>• Sarbanes-Oxley Risk Assessment for Pharma/Bio/Life Science Industries• ComplianceOnl<strong>in</strong>e: Virtual SOX Compliance• State Society of CPA’s: Arizona, Nevada, New Jersey, Ohio: C<strong>in</strong>c<strong>in</strong>nati, Cleveland, Columbus,Texas: Dallas, Houston, Wiscons<strong>in</strong>If you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-6078


<strong>Lord</strong> & <strong>Benoit</strong> helps “PCAOB CPAs”o All Big 4 CPA firms and most second-tier firms’ havereferenced <strong>Lord</strong> & <strong>Benoit</strong>’s research.o Almost all PCAOB-registered CPA firms worldwide,use the <strong>Lord</strong> & <strong>Benoit</strong> e-newsletter as a source forSOX research <strong>in</strong>formation.If you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-6079


Web<strong>in</strong>ar Course Outl<strong>in</strong>e1. Regulatory Environment, Guidance1. SEC2. PCAOB3. AICPA4. COSO5. SOX Sections 404(a) and (b)2. Top <strong>Fraud</strong> and F<strong>in</strong>ancial Ethics Risks3. Questions and AnswersIf you cannot hear from yourcomputer speakers please call:(312) 878-0211Access Code: 671-626-122Web<strong>in</strong>ar ID: 787-396-60710


Regulatory Environment• SEC• PCAOB• AICPA• The times (bankruptcies, tight fund<strong>in</strong>g, changes <strong>in</strong>Congress, new President, bank failures, fraud, overallneed for governance)• COSO© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org11


COSO (Committee Of Sponsor<strong>in</strong>g Organizationsof the Treadway Commission)www.COSO.ORG© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org12


Guidance, Guidance and More GuidanceCOSOSEC GuidancePCAOB GuidanceAICPA Standards© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org13


SOX Section 404(a) Requirements?The Sarbanes-Oxley Act of 2002, Section 404(a)requires smaller public companies (non-acceleratedfilers) with fiscal years end<strong>in</strong>g after December 15,2007 to document a Management Assessment of theirInternal Controls over F<strong>in</strong>ancial Report<strong>in</strong>g (ICFR).Non-accelerated filers are companies with public floatunder $75 million.IPO’s© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org14


SOX Section 404(b) Requirements?Section 404(b) for non-accelerated filers(the auditor attestation) was extendeduntil years beg<strong>in</strong>n<strong>in</strong>g after December 15,2008© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org15


SEC Interpretive Guidance“Management’s evaluation of the risk ofmisstatement should <strong>in</strong>cludeconsideration of the vulnerability of theentity to fraudulent activity.”© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org16


Top <strong>Fraud</strong> Risks© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org17


Check Sign<strong>in</strong>g• The number one fraud risk was the abilityto sign checks and enter account<strong>in</strong>gtransactions.• This opens the door to ongo<strong>in</strong>g, perpetualfraud without be<strong>in</strong>g caught.• For example, a bookkeeper who has thefreedom to write checks to himself andcover it up by book<strong>in</strong>g a transaction or <strong>in</strong>the bank reconciliation.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org18


Wire Transfers• A similar fraud risk is lack of segregationof duties with electronic fund transfers.• People who do not even have checksign<strong>in</strong>gauthority have EFT or ACHauthority.• EFT and ACH is an even quicker way toembezzle funds than checks.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org19


Account<strong>in</strong>g Systems• Account<strong>in</strong>g systems that do not haveadequate access controls.• For example, certa<strong>in</strong> off-the-shelfaccount<strong>in</strong>g software lets users revisetransaction dates and amounts withoutleav<strong>in</strong>g an audit trail.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org20


Payroll• Payroll is not reviewed by anyone otherthan the person do<strong>in</strong>g it.• Such personnel can create fictitiousemployees, give themselves or othersraises, make adjustments to payroll andpay people after they've been term<strong>in</strong>ated.• Hav<strong>in</strong>g outside payroll services does not<strong>in</strong>sulate companies from this fraud risk.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org21


Cash Application• Another top fraud risk was when checkswere received by those with access toaccounts receivable records.• In this scenario, personnel can set upcommercial enterprises with similarnames, and deposit checks <strong>in</strong> bogusaccounts while issu<strong>in</strong>g credits as if thechecks were deposited.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org22


Acctg Application Adm<strong>in</strong>istrator• Hav<strong>in</strong>g account<strong>in</strong>g people who are also ITadm<strong>in</strong>istrators is also a high fraud risk.• Users may delete transactions, giveaccess control to others, ga<strong>in</strong> access toaccount<strong>in</strong>g systems outside their assignedresponsibilities.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org23


Journal Entries• <strong>Companies</strong> did not have a secondperson review<strong>in</strong>g journal entries,particularly non-recurr<strong>in</strong>g journal entries.• <strong>Fraud</strong>ulent report<strong>in</strong>g is surfaced throughgeneral ledger overrides• These are caused by <strong>in</strong>centives,pressures and rationalizations.• All entries should be proofread.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org24


Audit Committee Overlooked• Many audit committees of smaller publiccompanies were not regularly <strong>in</strong>formedabout <strong>in</strong>ternal control matters, eventhough these committees have ultimateoversight responsibility.• Without know<strong>in</strong>g the facts, thesecommittees lose their corporategovernance ability.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org25


Human Behavior• Although ethics tra<strong>in</strong><strong>in</strong>g was very high onthe COSO list of requirements, <strong>in</strong> practicalreality many smaller public companieshave no communication or monitor<strong>in</strong>g ofethical values throughout the organizationthrough employee handbooks, codes ofconduct, employee sign-offs or quizzes.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org26


Background Checks• Many smaller public companies did notbother with background checks, open<strong>in</strong>gthemselves up to greater fraud potentialand expensive lawsuits.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org27


No Fail Safe Mechanism• Many smaller public companies had nowhistleblower programs <strong>in</strong> place.• One of the first l<strong>in</strong>es of defense aga<strong>in</strong>stfraud is giv<strong>in</strong>g managers and employees asafe method of report<strong>in</strong>g potential fraud.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org28


Credit and Debit Cards• Inadequate follow-up and oversight ofcompany credit cards• Unlimited use of paypal accounts• Debit cards© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org29


Table of Authorities• Board of directors did not def<strong>in</strong>e andcommunicate authorities reta<strong>in</strong>ed at theboard level and those delegated tomanagement, such as by an approvalmatrix.• Some transactions, <strong>in</strong>vestments or cashaccounts were set up without Boardapproval.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org30


Lack of Board Participation• Board of directors did not actively evaluateand monitor risk of management overrideof <strong>in</strong>ternal control and consider risksaffect<strong>in</strong>g the reliability of f<strong>in</strong>ancialreport<strong>in</strong>g?© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org31


Lack of Board Participation• Audit committee did not actively monitorthe effectiveness of <strong>in</strong>ternal control overf<strong>in</strong>ancial report<strong>in</strong>g and f<strong>in</strong>ancial statementpreparation?© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org32


Lack of Board Participation• Audit committee did not meet privatelywith the <strong>in</strong>ternal auditors to discussrelevant matters?© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org33


Computer System Event Logs• Lack of adequate access control overautomated records, <strong>in</strong>clud<strong>in</strong>g controls overand review of computer systems eventlogs.© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org34


Other <strong>Fraud</strong> Risks• Management Incentives and Pressures© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org35


Other <strong>Fraud</strong> Risks• Account<strong>in</strong>g Opportunities© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org36


Other <strong>Fraud</strong> Risks• Attitudes/Rationalizations to MisstateF<strong>in</strong>ancial Statements and Report<strong>in</strong>g© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org37


Importance of Ethical Values• Accountability• Communication and Respect• Commitment to Customers• Fairness and Integrity• Human Relationship• Innovation• Stewardship© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org38


Importance of Ethical Valueswww.Section404.org© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org39


Cont<strong>in</strong>u<strong>in</strong>g Professional EducationIf you would like CPE credit* for this web<strong>in</strong>ar:1. Please email LizK@<strong>Lord</strong>andbenoit.com today.2. Be sure to <strong>in</strong>clude your full name <strong>in</strong> the email3. You will be asked to complete an Evaluation Form and a SurveyQuestionnaireWe will send you a1. Certificate of Completion form2. Copies of Slides• Please note: State Boards of Accountancy have f<strong>in</strong>al authority on theacceptance of <strong>in</strong>dividual courses for CPE credit.•As mentioned earlier, <strong>Lord</strong> & <strong>Benoit</strong> is not registered with NASBA40© Copyright 2008 : <strong>Lord</strong> & <strong>Benoit</strong>, LLC www.Section404.org


"FIGHTING FRAUD <strong>in</strong> <strong>Smaller</strong><strong>Public</strong> <strong>Companies</strong>”QuestionsContact Information:<strong>Lord</strong> & <strong>Benoit</strong>, LLCBob <strong>Benoit</strong>(800) 404-7794 x204BobB@<strong>Lord</strong>and<strong>Benoit</strong>.comwww.Section404.org© 2009 <strong>Lord</strong> & <strong>Benoit</strong> www.section404.org41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!