* More than 80% of company frauds in the study were committed by individuals in accounting, operations, sales, executive/upper management, customer service or purchasing
We can’t seem to get far from data/identity governance issues this month. Dave McKee, from Aveksa (he’s actually director, senior media strategy at Schwartz Communications doing PR for Aveksa) just sent me a link to a new survey from the Association of Certified Fraud Examiners (ACFE) entitled “Who is Most Likely to Commit Fraud at Your Company? Profile of a Fraudster Drawn from ACFE Survey of Experts.”
The ACFE’s 2010 Report to the Nations on Occupational Fraud and Abuse is based on data compiled from a study of 1,843 cases of occupational fraud that occurred worldwide between January 2008 and December 2009.
10 woeful tales of data gone missing
The report is only available to members, but McKee did share some interesting highlights that call out the need for access controls, including:
* More than 80% of the frauds in the study were committed by individuals in one of six departments: accounting, operations, sales, executive/upper management, customer service or purchasing.
* More than 85% of fraudsters in the study had never been previously charged or convicted for a fraud-related offense.
* Organizations tend to over-rely on audits. External audits were the control mechanism most widely used by the victims in the survey, but they ranked comparatively poorly in both detecting fraud and limiting losses due to fraud. Audits are clearly important and can have a strong preventative effect on fraudulent behavior, but they should not be relied upon exclusively for fraud detection.
*A lack of internal controls, such as segregation of duties, was cited as the biggest deficiency in 38% of the cases.
I find the first point, about the departments housing fraud perpetrators, very interesting. For the past 25 years, the most frequent question I’ve been asked is how to control the sys admin/network admin’s access to sensitive/proprietary data. Yet IT isn’t even in the top six of the departments where fraudsters were found. Of course, it could be that IT types cover their tracks better.
I can’t emphasize more that audits, while necessary, are of little value in stopping fraud. Audits tend to discover last year’s (or even earlier) fraud, not what’s happening today. Only good data/identity governance apps can do that.
What are you doing in that area?




