ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD

Published  . 0 views
↓ Download
ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD
1 / 1
ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 1 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 2 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 3 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 4 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 5 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 6 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 7 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 8 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 9 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 10 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 11 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 12 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 13 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 14 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 15 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 16 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 17 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 18 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 19 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 20 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 21 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 22 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 23 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 24 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 25 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 26 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 27 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 28 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 29 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 30 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 31 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 32 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 33 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 34 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 35 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 36 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 37 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 38 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 39 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 40 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 41 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 42 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 43 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 44 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 45 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 46 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 47 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 48 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 49 of 50 ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD - slide 50 of 50
Description: ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD EXAMINATION FORENSIC AUDIT, PROFESSIONAL OPPORTUNITIES Criminology and Ethics Meaning of Cyber Laws Cyber law is otherwise called Digital Law or Internet Law. Cyber law India is the zone of

Related Topics

Download Presentation

"ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. ETHICAL CONSIDERATIONS, CODE OF CONDUCT IN FRAUD EXAMINATION & FORENSIC AUDIT, PROFESSIONAL OPPORTUNITIES<br>
slide2. Criminology and Ethics<br>
slide3. Meaning of Cyber Laws Cyber law is otherwise called Digital Law or Internet Law. Cyber law India is the zone of law that manages the Internet’s relationship to technology, innovative and electronic components, including computers, programming, equipment, data frameworks and Information System (IS).
Web law or Cyber law India is a term that exemplifies the legitimate issues identified with utilization of the Internet. It is less an unmistakable field of law than licensed innovation or agreement law, as it is a space covering numerous zones of law and guidelines.
In this manner Cyber law India can consider as a piece of the general lawful framework that manages the Internet, E-trade, advanced agreements, electronic proof, the internet, and their particular lawful issues.<br>
slide4. Cyber Ethics Cyber ethics is the philosophic study of ethics pertaining to computers, encompassing user behavior and what computers are programmed to do, and how this affects individuals and society. For years, various governments have enacted regulations while organizations have defined policies about cyber ethics.
Commandments of Computer Ethics
Thou shalt not use a computer to harm other people.
Thou shalt not interfere with other people's computer work.
Thou shalt not snoop around in other people's computer files.
Thou shalt not use a computer to steal.
Thou shalt not use a computer to bear false witness.
Normal stories highlighted in the media on PC wrongdoing or computer crimes incorporate points covering hacking to infections, webcam-jackers, to web paedophiles, here and there precisely depicting occasions, here and there misinterpreting the job of innovation in such exercises. Increment in digital crime percentage has archived in the news media.<br>
slide5. Cyber laws in India Information Technology (IT) Act, 2000: Laws against cybercrimes in India have been laid down in the Information Technology (IT) Act 2000. They are as follows:
Hacking and Data Theft: Sections 439 (h) and 66 of the IT Act punish various exercises going from hacking into a computer organize, information burglary, presenting and spreading infections through computer systems, harming computers or computer systems or computer programs, disturbing any PC or PC framework, denying an approved individual access to a PC or PC organize, harming or pulverizing data dwelling in a computer and so on. The greatest discipline for the above offenses is detainment of up to 3 years or a fine or Rs. 5,00,000 or both.
Tampering with Computer Source Document: Section 65 of the IT Act provides punishment for tampering with computer source documents and says that any person who knowingly or intentionally conceals, destroys or changes or intentionally or knowingly causes another to conceal, destroy, or change any computer source code (i.e. a listing of programmes, computer commands, design and layout and programme analysis of computer resource in any form) used for a computer, computer programme, computer system or computer network, when the source code is required to be kept or maintained by law for the nonce effective, shall be punishable with imprisonment for up to 3 years or with a fine which can reach Rs. 3,00,000 or with both.<br>
slide6. Cyber laws in India Receipt of Stolen Property: Section 66 B of the IT Act provides punishment for untrustworthy accepting any stolen PC asset or communication device. The discipline for this offense under Section 66B of the IT Act is detainment of up to 3 years or a fine of up to Rs.1,00,000 or both.
Identity Theft and Cheating by Personation: Section 66C of the IT Act provides punishment for identity theft and provides that anyone fraudulently or deceivingly making use of the electronic signature, password or any other special identifying feature of some other person shall be imprisoned for a term which may extend to 3 years and shall also be liable to fine which may extend to Rs.1,00,000.
Section 66D of the IT Act provides punishment for ‘cheating by personation by using computer resource’ and provides that any person who by means of any communication device or computer resource cheats by personation, shall be punished with imprisonment for a term which may extend to 3 years and fine which may extend to Rs.1,00,000.<br>
slide7. Cyber laws in India Violation of Privacy: Section 66E of the IT Act provides punishment for violation of privacy and provides that any person who intentionally or knowingly captures, publishes or transmits private images of a person without his or her consent thereby violating the privacy of that person, shall be punished with imprisonment of upto 3 years or with fine not exceeding Rs.2,00,000 or with both.
Obscenity: Sections 67, 67A and 67B of the IT Act provides punishment for publishing or transmitting, in electronic form: obscene things or material containing sexually explicit content, etc
Cyber Terrorism: Section 66F of the IT Act provides punishment for cyber terrorism.
Email Spoofing: Email spoofing refers to email that seems to originate from one source but is sent from another source. Email spoofing can also lead to monetary damage.<br>
slide8. Cyber laws in India Indian Penal Code (IPC) On Cybercrimes
Sec 503 – Sending of threatening messages by emails.
Sec 499 – Sending defamatory messages by emails
Sec 463 – Forgery of electronic records
Sec 420 – Bogus websites, cyber frauds
Sec 463 – Email spoofing
Sec 383 – Web- jacking
Sec 500 – Email abuse
Sec 292 – Pornography
Sec 354D – Cyber Stalking<br>
slide9. Cyber laws in India Internet Time Thief: It is nothing but a way of cheating, where the web is a tool for committing this crime. This
type of cyber-crime was unheard until the victim reported it. This will note the usage by an unauthorized person
of the web hours purchased for by another person.

Web Jacking: The term is coined from “web hijacking”. Once a website is web jacked the owner of the site tend to lose all control over it. The person getting such kind of an access is called a hacker who may even alter or destroy any information on that site.
Salami Attack: This is basically associated with finance and thus the most victims of this crime are the financial institutions. This attack features a unique quality that the alteration is so insignificant that during a single case it might go completely unnoticed. E.g., a bank employee inserts a program whereby a meagre sum of Rs.3 is deducted from customers’ account. Such a small amount will not be noticeable at all. However, such deduction from all the account holders collect huge amounts. This is purely a criminal breach of contract.<br>
slide10. Cyber laws in India Email Bombing: Email bombing means sending a huge number of mails to the victims as a result of which their account or mail server crashes. This is one kind of mischief, where the account or server is subject to destruction.
Virus Attack: Virus is a program that attaches itself to a computer or a file and then circulates to other files and to other computers on a network. They usually affect the data on a computer, either by altering or by deleting it.
Other Cyber Laws in India
The Bankers` Book Evidence Act, 1891.
The Reserve Bank of India Act, 1934.
Various laws relating to IPRs.
The Information Technology (Securities Procedure) Rules, 2004.<br>
slide11. Measures to Curb Cybercrimes under Cyber Laws and Cyber Ethics The main objective of the technology is to provide a sense of security to the users. Some measures to curb cybercrimes via cyber law and ethics are as follows:
Synchronised Passwords: Passwords are meant for one`s security. The password synchronised on the card changes after every 30-60 seconds which makes it valid for one-time log-on sessions only. Other methods providing security are fingerprint identification, signature, voice, retinal identification and biometric recognition etc. to impute password and pass phrases.
Encryption: This is an important tool to protect data in transit. Plain content (readable) can hence be changed over to cipher text (coded language) by this technique and the beneficiary of the information can decode it by changing over it into plain content again by utilizing private key. With the exception of the beneficiary whose holder of the private key unscramble the information, nobody can access sensitive data.<br>
slide12. Measures to Curb Cybercrimes under Cyber Laws and Cyber Ethics Firewalls: It divides between the framework and potential interlopers or intruders to shield the arranged archives from spilled or got to. It would just give the information to stream access PCs which in this way are perceived and confirmed by one’s framework. Therefore, it just allows access to the framework to ones previously registered with the PC.
Digital Signatures: Advanced or Digital Signature made by utilizing methods for cryptography by applying algorithms. This has its unmistakable use in the matter of banking where client’s mark is accordingly distinguished by utilizing this technique.<br>
slide13. Ethics Ethics is a code by which society lives, and leads, successful lives. Ethics are considered to be the recognized guidelines of behaviour for reputable groups or institutions, but usually does not stop there. Any individual acting in a professional manner should also live by, and conduct the business by, a code of ethics. Every researcher conducting business either in a scientific or a criminological capacity would also adopt a code of ethics, no matter where the research is conducted.
According to the Encarta Electronic dictionary, ethics can be defined as the study of moral standards and how they affect conduct or a system of moral principles governing the appropriate conduct for a person or group.<br>
slide14. Introduction to Ethics in Research Ethics is something that must be taken very seriously when it comes to research, and protecting the subject or subject matter of the research. A researcher must be above reproach when conducting the research. It requires the researcher to be able to view the subject matter with an objective point of view, not putting a particular opinion in the research itself, just gathering data and reporting the facts. The role of the researcher is one that must determine whether the presence of one more person will affect the desired results of the study. Should the researcher sit on the side-lines and observe, or would it be okay to interact with the subject that is being studied. If the researcher has to disregard the rules in order to get the desired result of the study, then that researcher needs to find a different way in which to gather the data, or change the reason of the study.
Ethics also fall under leadership capabilities and the ability to work on one’s own merit. When a newly appointed criminal justice researcher starts work, the work must be monitored closely for a period of time to accuracy and validity.<br>
slide15. Why Ethics are Important The code of ethics in an important way to keep researchers honest, because usually those that have signed the written consent acknowledging the code will think twice before straying from the code.
It is extremely important that the ethical decision is always made, and not tossed aside with disregard so that a researcher or scientists can obtain the desired results of a study. Ethics must be taken very seriously in order for the moral attitude of this country to stay on track. Ethics is what keep people honest in all aspects of work, not just science and medicine. It is how a civilized society lives.
Ethics are not just important in criminal justice research, but in all aspects of criminal justice.
Those conducting research into criminal misconduct which incarcerates innocent men for lack of conducting proper investigations will show unethical behaviour, and in turn must report the findings, regardless of the repercussions.<br>
slide16. The Use of Ethics in Criminal Justice Research When studying certain subject matter or certain personnel, it must be made quite plain to them that the privacy ethics will remain tightly in place. Never, at any time, should a participant in a study feel as if personal data has been compromised. And, in the event that the information has leaked out, such as someone hacking into the system and personal data availed, those individuals participating must be told immediately. If a participant is told their identity will remain anonymous, then it must remain so, even if damaging information comes out about that individual.
Other areas in which research professionals need to be aware of is the need to quickly publish a paper to stay in competition for certain positions within the community. One should never be made to feel pressure to publish anything, as this will certainly lead to unethical behaviour on the part of the researcher. Those conducting research must also stay away from any study that could be deemed harmful to human participants, no matter how enticing the end results may look like. No one’s safety or well-being is worth harming someone in the name of science.<br>
slide17. Ethical Hacking<br>
slide18. What is ethical hacking? Ethical Hacking sometimes called as Penetration Testing is an act of intruding/penetrating into system or networks to find out threats, vulnerabilities in those systems which a malicious attacker may find and exploit causing loss of data, financial loss or other major damages. The purpose of ethical hacking is to improve the security of the network or systems by fixing the vulnerabilities found during testing. Ethical hackers may use the same methods and tools used by the malicious hackers but with the permission of the authorized person for the purpose of improving the security and defending the systems from attacks by malicious users.<br>
slide19. Origins of Ethical Hacking The term hacking first started to appear in the 1960s in connection with activities at the Massachusetts Institute of Technology and referred to applying creative engineering techniques to “hack” machinery and make it operate more efficiently.
Later on Hackers realized computer programming languages could be used to manipulate telecommunications systems and complete long-distance calls for free, a practice dubbed phreaking.
The 1983 film War Games, in which a student inadvertently cracks into a war-gam supercomputer run by the U.S. military, helped to highlight the vulnerabilities of large computing systems.
In the 2000s, compliance regulations, such as the Health Insurance Portability and Accountability Act, that govern the storage and security of digitized medical and business data have elevated the role of ethical hackers within the realm of cybersecurity.
The coronavirus pandemic created new avenues of pursuit for
cybercriminals.<br>
slide20. What do ethical hackers do? Ethical hackers can help organizations in a number of ways, including the following:
Finding vulnerabilities: Ethical hackers help companies determine which of their IT security measures are effective, which need updating and which contain vulnerabilities that can be exploited.
Demonstrating methods used by cybercriminals: These demonstrations show executives the hacking techniques that malicious actors could use to attack their systems and wreak havoc on their businesses.
Helping to prepare for a cyber-attack: Ethical hackers understand how threat actors operate, and they know how these bad actors will use new information and techniques to attack systems.
Ethical hacking vs. penetration testing: Ethical hackers routinely test IT systems looking for flaws and to stay abreast of ransomware or emerging computer viruses. Their work often entails pen tests as part of an overall IT security assessment. Pen testers seeks to accomplish many of the same goals, but their work is often conducted on a defined schedule. Pen testing is also more narrowly focused on specific aspects of a network, rather than on ongoing overall security.<br>
slide21. How to become an ethical hacker? There are no standard education criteria for an ethical hacker, so an organization can set its own requirements for that position. Those interested in pursuing a career as an ethical hacker should consider a bachelor’s or master’s degree in infosec, computer science or even mathematics as a strong foundation. Other technical subjects-including programming, scripting, networking and hardware engineering-can help those pursuing a career as ethical hackers by offering a fundamental understanding of the underlying technologies that form the systems they will be working on.<br>
slide22. Ethical hacking techniques Ethical hackers generally use the same hacking skills that malicious actors use to attack enterprises. Some of these hacking techniques include the following:
Scanning ports to find vulnerabilities with port scanning tools, such as Nmap, Nessus, Wireshark etc.
Scrutinizing patch installation processes.
Performing network traffic analysis and sniffing by using appropriate tools.
Attempting to evade intrusion detection systems, intrusion prevention systems, honeypots (An intentionally compromised computer system allows attackers to exploit vulnerabilities so you can study them to improve your security policies) and Firewalls..
Testing methods to detect Structured Query Language injection to ensure malicious hackers can’t introduce security exploits that expose sensitive information contained in SQL-based relational databases.<br>
slide23. Certified Ethical Hackers There are a number of ethical hacking certifications and related IT security certifications that help ethical hackers demonstrate their subject matter expertise.
Three programs by CompTIA: Cybersecurity Analyst (CySA+), Advanced Security Practitioner (CASP+) and PenTest+. CySA+ teaches students to apply behavioral analytics to improve network security. The CASP+ certification “issues related to enterprise security operations and architecture. The PenTest+ certification is geared to IT professionals engaged in pen testing and assessing vulnerabilities.
Certified Ethical Hacker (CEH). This is a vendor-neutral certification from the International Council of Electronic Commerce Consultants (EC-Council), one of the leading certification bodies. This security certification, which validates how much an individual knows about network security, is best suited for a pen tester role.<br>
slide24. Certified Ethical Hackers Certified Information Systems Auditor (CISA). This certification is offered by ISACA, a nonprofit, independent association that advocates for professionals involved in infosec, assurance, risk management and governance.
Certified Information Security Manager (CISM). CISM is an advanced certification offered by ISACA that provides validation for individuals who have demonstrated the in-depth knowledge and experience required to develop and manage an enterprise infosec program.
GIAC Security Essentials (GSEC). This certification created and administered by the Global Information Assurance Certification organization is geared toward security professionals who want to demonstrate they are qualified for IT systems hands-on roles with respect to security tasks.<br>
slide25. Types of Hackers Green hat hackers are generally aspiring hackers who lack the technical acumen but display aptitude and interest in learning how to successfully hack computer machinery. Green hat hackers may include people involved in hacktivism (the act of hacking into a computer system, for politically or socially motivated purposes
Blue hat hackers comprise two different types of hackers. The first type is a person skilled enough with malware to compromise computer systems. The second type refers to someone asked to participate in Microsoft’s invitation-only Blue Hat security conference.<br>
slide26. Types of Hackers Red hat hackers are ethical hackers who specialize in cracking Linux-based systems.
White Hat Hackers: White hat hackers choose to use their powers for good rather than evil.
Black Hat Hackers: They are also responsible for writing malware, which is a method used to gain access to these systems.
Grey Hat Hackers: Grey hat hackers are a blend of both black hat and white hat activities.<br>
slide27. Types of Ethical Hacking Hacktivists: This is the technique through which a hacker is hacking into any computer system illegally for any reason may be social or political.
Cyber Warrior: Cyber warrior is a kind of hacker who is being hired by an organization or by an individual to creep into the system or computer network. Cyber warrior will act as a wicked hacker will try to find out the vulnerabilities or weaknesses in the present system.
White Box Penetration Testers: White box penetration testers are also called as white box hackers. White box testers are working in the same way as cyber warriors are working the only difference is that cyber warriors do not have knowledge of the system or computer network of the organization or of individual whereas white box hackers are having full knowledge of the system or computer network of the target.
Certified Ethical Hacker / Licensed Penetration Tester: As the name says itself that certified ethical hacker, who are responsible to look into the system and networks to find out the vulnerabilities and weaknesses.<br>
slide28. Types of Attacks Nontechnical assaults: Exploits that include controlling individuals, end clients and even the best vulnerability inside any computer or network foundation.
Network-foundation assaults: Here are a few cases of network- foundation assaults:
Connecting into a network through a maverick Modem connected to a computer behind a firewall.
Exploiting shortcomings in network transport components, for example, TCP/IP and NetBIOS.
Flooding a network with excessively numerous solicitations, making a denial of service (DoS) for honest to goodness demands.<br>
slide29. Hacking Protection Techniques Security Infrastructure: One among the principal basic frameworks for forcing information security is that the firewall, that goes for forbidding the access of approaching and leaving movement through setup of control sets.
Intrusion Detection System: It shields a network by gathering information form a spread of framework and network supply, so examining the information for potential security issues. There are a unit 2 styles of IDS, particularly Network Intrusion Detection System (NIDS) screens various devices by looking at network activity at the network limits and Host Intrusion Detection System (HIDS) will screen one host by breaking down application logs, recording framework adjustment like word document and access administration records.
Code Review: For any self-created applications like internet applications, AN independent code audit on the projects should be led severally from the apparatus advancement in order to ensure no security blemish is uncovered from the codes that territory unit unmistakable to the overall population, and legitimate mistake handling and information approval are executed inside the code.
Security Patches: A few service providers, together with bundle merchants and bundle providers bargain with security fixes once their shortcoming of the bundle or bundle was found. The establishment of progressive defensive patches is staggeringly crucial since these shortcomings’ region unit some of the time noted to the overall population.<br>
slide30. Threats to Ethical Conduct<br>
slide31. What Are Ethical Issues in Business? Ethical issues in business encompass a wide array of areas within an organization’s ethical standards. Fundamental ethical issues in business include promoting conduct based on integrity and trust, but more complex issues include accommodating diversity, empathetic decision-making, and compliance and governance that is consistent with the organization’s core values.
To manage the ethical issues in business, first need to develop a thorough understanding of what those issues can look like. Understanding how to detect and, most importantly, deter these issues before they become a problem can ensure to focus stays on business growth and success instead of remediation.
Avoiding ethical issues in business always starts with top management. Providing clearly written policies and processes that ensure those policies are both acknowledged and adhered to, can ensure transparency and ethical business practices are applied.<br>
slide32. Harassment and Discrimination in the Workplace Harassment and discrimination are arguably the largest ethical issues that impact business owners today which results catastrophic for organization both financially and reputationally. Every business needs to be aware of the anti-discrimination laws and regulations that exist to protect employees from unjust treatment.
As per regulations stipulated by the Occupational Safety and Health Administration (OSHA), employees have a right to safe working conditions.
However, health and safety concerns should not be limited to physical harm. Factors such as job insecurity, high demands, effort-reward imbalance, and low autonomy, were all found to contribute to health-related behavioural risks, including sedentary lifestyles, heavy alcohol consumption, increased cigarette smoking, and eating disorders.<br>
slide33. Whistleblowing or Social Media Rants The widespread nature of social media has made employees conduct online a factor in their employment status. The question of the ethics of firing or punishing employees for their online posts is complicated.
Business owners must be able to respect and not penalize employees who are deemed whistle-blowers to either regulatory authorities or on social media. This means that employees should be encouraged, and cannot be penalized, for raising awareness of workplace violations online.<br>
slide34. Ethics in Accounting Practices Any organization must maintain accurate bookkeeping practices. “Cooking the books”, and otherwise conducting unethical accounting practices, is a serious concern for organizations, especially in publicly traded companies.
An infamous example of this was the 2001 scandal with American oil giant Enron, which was exposed for inaccurately reporting its financial statements for years, with its accounting firm Arthur Andersen signing off on statements despite them being incorrect. The deception affected stockholder prices, and public shareholders lost over $25 billion because of this ethics violation. Both companies eventually went out of business, and although the accounting firm only had a small portion of its employees working with Enron, the firm’s closure resulted in 85,000 jobs lost.<br>
slide35. Nondisclosure and Corporate Espionage Many employers are at risk of current and former employees stealing information, including client data used by organizations in direct competition with the company. When intellectual property is stolen, or private client information is illegally distributed, this constitutes corporate espionage. Companies may put in place mandatory nondisclosure agreements, stipulating strict financial penalties in case of violation, in order to discourage these types of ethics violations.<br>
slide36. Technology and Privacy Practices Under the same umbrella as nondisclosure agreements, the developments in technological security capability pose privacy concerns for clients and employees alike. Employers now have the ability to monitor employee activity on their computers and other company-provided devices, and while electronic surveillance is meant to ensure efficiency and productivity, it often comes dangerously close to privacy violation.<br>
slide37. Key steps for reducing ethics risk Honestly assess needs and resources: Successful businesses start with a good plan. So do successful ethics and compliance programs. To create a relevant and meaningful plan, It’s important to know :
What ethics challenges are common in the work we do? In our workplace?
Where are our greatest areas of risk?
What values are important to our company and its employees?
Strong Foundation: Written Standards of Ethical workplace conduct:
Training on the standards.
Performance evaluations of ethical conduct.
Systems to discipline violators.
Develop a Culture of Integrity: There are several things’ leaders should do to help promote a strong ethics culture:
Talk about the importance of ethics.
Keep employees adequately informed about issues that impact them.
Acknowledge and reward ethical conduct & hold accountable those who violate standards<br>
slide38. Key steps for reducing ethics risk continue…. Keep a “Values Focus”: Ethics is about choices-big and small. Organizations with integrity keep their values at the forefront in both mundane and the extraordinary moments. Corporate values should come into play and be reflected in multiple processes that drive the everyday life of the company, including:
HR policies and their implementation.
Reward systems.
Performance management and evaluation.
Re-evaluate and Revise: Situations and needs will change. Employee need to know what is working, what isn’t, what new vulnerabilities have emerged, what progress made and where there’s work yet to be done. Be disciplined about regularly revisiting the state of ethics and compliance in the organization. Risk assessments, follow-up surveys and periodic or ongoing focus groups will allow to keep program relevant and minimize risk.<br>
slide39. Major Threats in Auditing Profession Self-Interest Threat: A self-interest threat exists if the auditor holds a direct or indirect financial interest in the company or depends on the client for a major fee that is outstanding.
Self-Review Threat: A self-review threat exists if the auditor is auditing his own work or work that is done by others in the same firm.
Advocacy Threat: An advocacy threat exists if the auditor is involved in promoting the client, to the point where their objectivity is potentially compromised.
Familiarity Threat: A familiarity threat exists if the auditor is too personally close to or familiar with employees, officers, or directors of the client company.
Intimidation Threat: An intimidation threat exists if the auditor is intimidated by management or its directors to the point that they are deterred from acting objectively.<br>
slide40. Primary challenges for implementing an effective ethics policy There are three primary challenges companies face when an implementing an effective ethics policy:
Resistance from employees: The first challenge is resistance from employees. Not because employees are inherently unethical or immoral, but when they are facing a new ethics policy, they may be made to feel that way. Companies should offer as much communication as possible to let employees know why the policy is being implemented and how it affects them. One way to ease the resistance is to make sure implementing a values-driven policy.
Costs of training and other implementation fees can be high: The cost of creating an ethics policy is minimal. However, the cost of implementing and maintaining an effective ethics policy is much higher.
Inability to determine ROI of the ethics policy: It is notoriously difficult for executives to demonstrate ROI in ethics programs. “ROI is hard to measure for a couple of reasons: it’s not easy to measure a lack of wrongdoing, and it’s not obvious what success looks like for some of the outcomes.<br>
slide41. Objectivity, Independence and Integrity<br>
slide42. Code of Professional Conduct Institute of Certified Forensic Accountants Code of Professional Conduct is structured on three principles:
Meeting the client’ s requirements;
Integrity, independence, objectivity;
Responsibility to the profession and to the Institute of Certified Forensic Accountants.
When applying these fundamental principles, Auditors must be aware that in order to retain public confidence they should conduct their activities in such a way that they can demonstrate that these principles are being applied.
Integrity: It is essential for Auditors to retain a reputation for integrity. This implies not merely honesty but trustworthiness, fair dealing and truthfulness.
Objectivity: Objectivity is exercised when Auditors make judgements, based upon all the available evidence, not depending on, or influenced by, personal opinions or prejudices, or by inappropriate pressure or influence.<br>
slide43. Code of Professional Conduct Competence and Due Care: Auditors should refrain from agreeing to perform professional services which they are not competent to carry out, whether in terms of skill or resources, unless competent advice and assistance is obtained so as to enable them satisfactorily to perform such services.
Professional competence may be divided into two separate but related parts:
Attainment of professional competence: The attainment of professional competence requires a high standard of general education followed by specific education, training and examination in professionally relevant subjects, and a period of work experience.
Maintenance of professional competence: The maintenance of professional competence requires a continuing awareness of developments in the accountancy profession including relevant national and international pronouncements on accounting, auditing and other relevant regulations and statutory requirements.
Confidentiality: Auditors have an obligation to respect the confidentiality of information about an employer’s or client’s affairs in the course of professional services. The duty of confidentiality continues even after the end of the relationship with the employer or client.<br>
slide44. Code of Professional Conduct Proper Conduct: Auditors must not engage in conduct, whether in pursuit of their profession or otherwise, which would discredit, be prejudicial to or likely to diminish public confidence in them in their professional capacity, or the accountancy profession. They should also promote the fundamental ethical principles through leadership and example.
If Auditors break the law, this diminishes public confidence. The severity and nature of the offence would have to be taken into account by determining its impact on the accountancy profession.<br>
slide45. Code of Conduct for Fraud Examiner<br>
slide46. Code of Professional Conduct Integrity and Objectivity:
Certified Fraud Examiners shall conduct themselves with integrity, knowing that public trust is founded on integrity.
Prior to accepting the fraud examination, Certified Fraud Examiners shall investigate for actual or potential conflicts of interest.
Certified Fraud Examiners shall maintain objectivity in discharging their professional responsibilities within the scope of the engagement.

Professional Competence :
Certified Fraud Examiners shall be competent and shall not accept assignments where competence is lacking.
Certified Fraud Examiners shall maintain the minimum program of continuing professional education required by the Association of Certified Fraud Examiners.<br>
slide47. Code of Professional Conduct Due Professional Care:
Certified Fraud Examiners shall exercise due professional care in the performance of their services. Due professional care requires diligence, critical analysis and professional skepticism in discharging professional responsibilities.
Conclusions shall be supported with evidence that is relevant, competent and sufficient.
Understanding with Client or Employer: At the beginning of a fraud examination, Certified Fraud Examiners shall reach an understanding with those retaining them (client or employer) about the scope and limitations of the fraud examination and the responsibilities of all parties involved.
Understanding with Client or Employer: Certified Fraud Examiners shall communicate to those who retained them (client or employer) significant findings made during the normal course of the fraud examination.
Confidentiality: Certified Fraud Examiners shall not disclose confidential or privileged information obtained during the course of the fraud examination without the express permission of a proper authority or the lawful order of a court.<br>
slide48. Standards of Examination Fraud Examinations:
Fraud examinations shall be conducted in a legal, professional and thorough manner.
Certified Fraud Examiners shall establish predication and scope priorities at the outset of a fraud examination and continuously re-evaluate them as the examination proceeds.
Certified Fraud Examiners shall be alert to the possibility of conjecture, unsubstantiated opinion and bias of witnesses and others.
Evidence:
Certified Fraud Examiners shall endeavour to establish effective control and management procedures for documents, data and other evidence obtained during the course of an examination.
Certified Fraud Examiners’ work product may vary with the circumstances of each fraud examination.<br>
slide49. Standards of Reporting General: Certified Fraud Examiners’ reports may be oral or written, including fact witness and/or expert witness testimony, and may take many different forms. There is no single structure or format that is prescribed for a CFE’s report; however, the report should not be misleading.
Report Content:
Certified Fraud Examiners’ reports shall be based on evidence that is sufficient and relevant to support the facts, conclusions, opinions and/or recommendations related to the fraud examination.
No opinion shall be expressed regarding the legal guilt or innocence of any person or party.<br>
slide50. Code of Ethics for Certified Fraud Examiners A Certified Fraud Examiner shall, at all times, demonstrate a commitment to professionalism and diligence in the performance of his or her duties.
A Certified Fraud Examiner shall not engage in any illegal or unethical conduct, or any activity which would constitute a conflict of interest.
A Certified Fraud Examiner shall, at all times, exhibit the highest level of integrity in the performance of all professional assignments.
A Certified Fraud Examiner will comply with lawful orders of the courts, and will testify to matters truthfully and without bias or prejudice.
A Certified Fraud Examiner shall continually strive to increase the competence and effectiveness of professional services performed under his or her direction.<br>