Mitigating fraud by utilizing the COSO framework and Fraud Risk Management Guide

A proactive approach to strengthen internal controls and address emerging risk

Key takeaways

The COSO framework helps organizations proactively assess and manage evolving fraud risks.

 Line Illustration of direction arrows

The framework’s integrated approach embeds fraud deterrence into organizations’ entire culture.

Independent assessments reveal hidden vulnerabilities and strengthen fraud defenses.

#
Financial investigations Financial consulting Dispute advisory

Occupational fraud is not just a persistent threat—it’s likely the most costly form of financial crime worldwide, according to John Warren, CEO of the Association of Certified Fraud Examiners, who recently observed that fraud’s annual impact is estimated “in the trillions of dollars.”

Management of organizational fraud risk continues to be a critical challenge for companies. The rapid pace of technological change and adoption of artificial intelligence are transforming the sophistication and variation of fraud schemes, bringing enhanced risks of significant financial losses, regulatory violations, and the loss of customer and investor confidence.

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) established the Internal Control—Integrated Framework in 1992 to provide an approach to managing risk that has become the globally recognized blueprint for establishing, implementing and assessing internal control. The framework, and the related Fraud Risk Management Guide, initially published in 2016 and updated in 2023, enables organizations to take a proactive approach to prevention and provides a structured methodology for the detection of fraud risk.

COSO: An enduring model for evolving fraud risk

In many cases, fraud occurs because companies lack a comprehensive understanding of their specific vulnerabilities. Although staff may be close to processes and familiar with existing controls, they may not see where gaps have developed over time due to organizational changes or a lack of understanding of the latest fraud schemes and technology risks. They may not have insight into emerging threats occurring at peer organizations or be aware of novel instances of fraud in their industry.

The strength of the COSO framework is that it provides the structure for an independent, objective fraud risk assessment and a model to remediate controls through its five integrated components.

An effective system of internal control requires that all five components and their underlying 17 principles are incorporated, functioning and operating together. This integrated approach creates an environment where fraud deterrence isn't relegated to a single department but is embedded across the organization’s culture and processes. The five components include:

Tools

Control environment: The foundation of ethical conduct

An organization’s control environment forms the bedrock of fraud prevention. Its principles require a commitment to integrity and ethical values and require the board of directors to exercise oversight independent of management.

checklist

Risk assessment: Explicitly targeting fraud

The risk assessment is arguably the most important component of fraud prevention. COSO Principle 8 requires that the organization consider “the potential for fraud in assessing risks to the achievement of objectives." This codification elevates the consideration of fraud risk from a purely compliance and control activity to an entity-wide concern to be systematically identified and analyzed.

COSO’s approach of systematically identifying risk and vulnerabilities allows the organization to holistically consider its risk appetite across all areas of its operations and design proportionate and targeted controls to manage risk accordingly.

Control activities: Designing specific fraud controls

The development of both preventive and detective controls can include a range of processes and technologies that allow flexibility to address an evolving threat environment.

In some cases, a traditional approach, adapted to a new fraud scheme, can be effective. In others, a fresh perspective and innovative thinking may be required. The framework allows for either approach.

Line Illustration of a robot

 Information and communication: Enabling timely reporting

Effective fraud risk management relies heavily on the workforce, customers, third parties and others being informed and able to recognize increasingly sophisticated threats. Timely and relevant information and communication are vital in building lines of defense against fraud schemes.

Line Illustration of a binoculars filled
Multicolor icon

Monitoring activities: Continuous oversight and adaptation

Monitoring activity on an ongoing basis, and continually adapting controls to those activities and identified deficiencies, will result in a fraud risk program that is adaptable and relevant to the organization, its markets and its interactions.

Fraud Risk Management Guide

Application of the COSO framework to address fraud risk was codified in the Fraud Risk Management Guide published in 2023 by COSO and the Association of Certified Fraud Examiners. The guide’s principles align with the COSO framework and provide a granular approach to the prevention, detection and investigation of instances of fraud.

The five fraud risk management principles rationalize the COSO framework principles into tangible areas of focus for management to consider in building their anti-fraud program.

The value of an independent perspective

When developed in collaboration with business leaders, an independently led fraud risk assessment can apply industry-specific data analytics and forensic investigative techniques to stress-test fraud defenses and controls. An experienced external advisor can shed light on emerging fraud threats and risks within your industry, while also identifying company-specific fraud vulnerabilities based on business segment, geographic operations, government interactions and supply chain, as well as other critical factors.

Professionals experienced in implementing the COSO framework can ultimately deliver significant value, successfully establishing a consistent fraud risk identification and mitigation approach across the organization.

The takeaway

The latest fraud trends suggest that organizations can’t simply rely on their existing control environment to protect them from evolving fraud risk. The COSO framework and the Fraud Risk Management Guide provide an enduring approach to thinking about and responding to fraud risk. In the hands of experienced practitioners, they form the bedrock of your organization’s anti-fraud program—one that is effective and can adapt to ever more sophisticated threats.

Related insights

Uncover financial misconduct. Act with confidence.

When suspicious activity surfaces, speed matters. RSM’s financial investigations team helps you identify, analyze and resolve complex issues—minimizing disruption and protecting your reputation.