Introduction to Forensic Audit Applicable Laws &

Published  . 0 views
↓ Download
Introduction to Forensic Audit Applicable Laws &
1 / 1
Introduction to Forensic Audit Applicable Laws & - slide 1 of 62 Introduction to Forensic Audit Applicable Laws & - slide 2 of 62 Introduction to Forensic Audit Applicable Laws & - slide 3 of 62 Introduction to Forensic Audit Applicable Laws & - slide 4 of 62 Introduction to Forensic Audit Applicable Laws & - slide 5 of 62 Introduction to Forensic Audit Applicable Laws & - slide 6 of 62 Introduction to Forensic Audit Applicable Laws & - slide 7 of 62 Introduction to Forensic Audit Applicable Laws & - slide 8 of 62 Introduction to Forensic Audit Applicable Laws & - slide 9 of 62 Introduction to Forensic Audit Applicable Laws & - slide 10 of 62 Introduction to Forensic Audit Applicable Laws & - slide 11 of 62 Introduction to Forensic Audit Applicable Laws & - slide 12 of 62 Introduction to Forensic Audit Applicable Laws & - slide 13 of 62 Introduction to Forensic Audit Applicable Laws & - slide 14 of 62 Introduction to Forensic Audit Applicable Laws & - slide 15 of 62 Introduction to Forensic Audit Applicable Laws & - slide 16 of 62 Introduction to Forensic Audit Applicable Laws & - slide 17 of 62 Introduction to Forensic Audit Applicable Laws & - slide 18 of 62 Introduction to Forensic Audit Applicable Laws & - slide 19 of 62 Introduction to Forensic Audit Applicable Laws & - slide 20 of 62 Introduction to Forensic Audit Applicable Laws & - slide 21 of 62 Introduction to Forensic Audit Applicable Laws & - slide 22 of 62 Introduction to Forensic Audit Applicable Laws & - slide 23 of 62 Introduction to Forensic Audit Applicable Laws & - slide 24 of 62 Introduction to Forensic Audit Applicable Laws & - slide 25 of 62 Introduction to Forensic Audit Applicable Laws & - slide 26 of 62 Introduction to Forensic Audit Applicable Laws & - slide 27 of 62 Introduction to Forensic Audit Applicable Laws & - slide 28 of 62 Introduction to Forensic Audit Applicable Laws & - slide 29 of 62 Introduction to Forensic Audit Applicable Laws & - slide 30 of 62 Introduction to Forensic Audit Applicable Laws & - slide 31 of 62 Introduction to Forensic Audit Applicable Laws & - slide 32 of 62 Introduction to Forensic Audit Applicable Laws & - slide 33 of 62 Introduction to Forensic Audit Applicable Laws & - slide 34 of 62 Introduction to Forensic Audit Applicable Laws & - slide 35 of 62 Introduction to Forensic Audit Applicable Laws & - slide 36 of 62 Introduction to Forensic Audit Applicable Laws & - slide 37 of 62 Introduction to Forensic Audit Applicable Laws & - slide 38 of 62 Introduction to Forensic Audit Applicable Laws & - slide 39 of 62 Introduction to Forensic Audit Applicable Laws & - slide 40 of 62 Introduction to Forensic Audit Applicable Laws & - slide 41 of 62 Introduction to Forensic Audit Applicable Laws & - slide 42 of 62 Introduction to Forensic Audit Applicable Laws & - slide 43 of 62 Introduction to Forensic Audit Applicable Laws & - slide 44 of 62 Introduction to Forensic Audit Applicable Laws & - slide 45 of 62 Introduction to Forensic Audit Applicable Laws & - slide 46 of 62 Introduction to Forensic Audit Applicable Laws & - slide 47 of 62 Introduction to Forensic Audit Applicable Laws & - slide 48 of 62 Introduction to Forensic Audit Applicable Laws & - slide 49 of 62 Introduction to Forensic Audit Applicable Laws & - slide 50 of 62 Introduction to Forensic Audit Applicable Laws & - slide 51 of 62 Introduction to Forensic Audit Applicable Laws & - slide 52 of 62 Introduction to Forensic Audit Applicable Laws & - slide 53 of 62 Introduction to Forensic Audit Applicable Laws & - slide 54 of 62 Introduction to Forensic Audit Applicable Laws & - slide 55 of 62 Introduction to Forensic Audit Applicable Laws & - slide 56 of 62 Introduction to Forensic Audit Applicable Laws & - slide 57 of 62 Introduction to Forensic Audit Applicable Laws & - slide 58 of 62 Introduction to Forensic Audit Applicable Laws & - slide 59 of 62 Introduction to Forensic Audit Applicable Laws & - slide 60 of 62 Introduction to Forensic Audit Applicable Laws & - slide 61 of 62 Introduction to Forensic Audit Applicable Laws & - slide 62 of 62
Description: Introduction to Forensic Audit Applicable Laws Regulatory Environment Course Introduction, Business Fraud, Scenario, and Fraudster Profile. Forensic Audit A forensic audit is an analysis and review of the financial records of a company or

Related Topics

Download Presentation

"Introduction to Forensic Audit Applicable Laws &" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Introduction to Forensic Audit Applicable Laws & Regulatory Environment<br>
slide2. Course Introduction, Business Fraud, Scenario, and Fraudster Profile.<br>
slide3. Forensic Audit A forensic audit is an analysis and review of the financial records of a company or person to extract facts, which can be used in a court of law. Forensic auditing is a speciality in the accounting industry, and most major accounting firms have a department forensic auditing.<br>
slide4. Reasons for Conducting a Forensic Audit Forensic audit investigations may expose, or confirm, various kinds of illegal activities. Normally, instead of a normal audit, a forensic audit is used if there is a possibility that the evidence gathered would be used in court.<br>
slide5. Functions of Forensic Audit Function A forensic audit comprises the following steps:
Planning the Investigation
Collecting Evidence
Reporting
Court Proceedings<br>
slide6. Need of Forensic Audit Function An entity should direct for forensic audit due to occurrence of following:
Theft of business information or where business systems have been hacked.
Issues identified by Whistle Blowers
Reconciliations resulted in unidentified material differences
Suspicious of fraud or illegal activity.
Turnover has occurred and balances are showing negative results.<br>
slide7. Forensic Audit Procedures Since the forensic audit is more of investigation and collection of evidences, it is of great importance that the audit should be conducted with an attitude of professional scepticism. These procedures are more specific towards detecting possible material misstatements in the financial records that result into fraudulent activities.<br>
slide8. Investigation Methodology of Forensic Audit The forensic audit investigation is the utilization of specialized investigation skills to conduct the forensic audit engagements in such a manner that the outcome can be presented in court of law as evidence. An auditor can follow a nine-step methodology for fact finding in case of forensic audit engagements:
Accept the forensic audit engagement.
Evaluate the allegations or suspicions.
Conduct due diligence background notes.
Complete the preliminary stage of investigation.
Check the prediction assuming that there will be a litigation.
Begin with external investigation.
Gathering the required proofs and evidences.
Preparing report on findings; and
Court proceedings.<br>
slide9. Common Areas of Forensic Audit Some of the common areas that are to be detected in forensic audit are:
Asset Misappropriation.
Instances of Corruption.
Extortion.
Financial Statement fraud.
Conflict of interest.<br>
slide10. Business Frauds Corporate fraud consists of illegal or unethical and deceptive actions committed either by a company or an individual acting in their capacity as an employee of the company. Corporate fraud schemes are often extremely complicated and, therefore, difficult to identify. It often takes an office full of forensic accountants’ months to unravel a corporate fraud scheme in its entirety.<br>
slide11. Why Does Corporate Frauds Happen? The Desire or Perceived need to attract or Retain Investors
Problems or defects with a Company’s Products
Major Corporate Fraud Cases in the World:
Enron
Waste Management
ZZZZ Best:
Wirecard
Wells Fargo<br>
slide12. Fraudster Profile One of the many threats that organisations face, is to risk complacency. To begin with, there are many ways in which frauds can be perpetrated and the deliberate nature of fraud can make it difficult to detect. The profile of a typical fraudster in 2020:
Males committed 72% of reported frauds and caused higher losses; nearly three times more than females.
Occupational fraudsters who had been with their companies at least 6 years caused twice the loss of employees who had been in their roles for 5 years or less.
Most occupational frauds were committed by employee-level (41%) or manager-level (35%) personnel.
More than three-quarters of all occupational frauds were committed by employees from 8 business units, with those in operations causing 15% of all incidents.
64% of occupational fraudsters had a university degree or higher and the average loss caused by them was almost double those without one.<br>
slide13. Frauds related Basic Concepts<br>
slide14. Basic Concepts of Frauds Fraud is a deliberate act (or failure to act) with the intention of obtaining an unauthorized benefit, either for oneself or for the institution, by using deception or false suggestions or suppression of truth or other unethical means, which are believed and relied upon by others.
Examples of fraudulent acts include:
Embezzlement.
Forgery or alteration of documents.
Unauthorized alteration or manipulation of computer files.
Fraudulent financial reporting.
Authorization or receipt of unearned wages or benefits.
Conflict of interest, ethics violations.<br>
slide15. What is a Fraud Triangle? Employees who commit fraud generally are able to do so because there is opportunity, pressure, and rationalization.<br>
slide16. What is a Fraud Triangle? Opportunity is generally provided through weaknesses in the internal controls.
Some examples include inadequate or no:
✓ Supervision and review.
✓ Separation of duties.
✓ Management approval.
✓ System controls.

Pressure (or motive) can be imposed due to:
✓ Personal financial problems; unforeseen expenses.
✓ Personal vices / addictions such as gambling, drugs, shopping, etc.
✓ Unrealistic deadlines and performance goals.<br>
slide17. What is a Fraud Triangle? Rationalization occurs when the individual develops a justification for their fraudulent activities. The rationalization varies by case and individual.
Some examples include:
✓ "I really need this money and I'll pay it back when I get my pay check."
✓ "Other people are doing it."
✓ "I didn't get a raise. The University owes me."<br>
slide18. Red Flags for Fraud Managers and employees responsible and should be aware of the red flags for fraud. These are warning signs that may indicate that fraud risk is higher. Examples of red flags include, but are not limited to, the following:
Employee Red Flags
Employee lifestyle changes
Significant personal debt and credit problems.
High employee turnover, especially in those areas which are more vulnerable to fraud.
Refusal to take vacation or sick leave.
Lack of segregation of duties in a vulnerable area.
Management Red Flags:
Management frequently overrides internal controls.
Management decisions are dominated by an individual or small group.
Policies and procedures are not documented or enforced.
Weak internal control environment.<br>
slide19. Red Flags for Fraud Management Red Flags:
✓ Accounting personnel are lax or inexperienced in their duties.
✓ Decentralization without adequate monitoring.
✓ Excessive number of bank accounts; frequent changes in banking accounts.
✓ Excessive number of year end transactions; unnecessarily convoluted transactions.
✓ High employee turnover rate; low employee morale.
✓ Refusal to use serial numbered documents (receipts).
✓ Compensation program that is out of proportion.
✓ Photocopied or missing documents.
✓ Reluctance to provide information to, or engage in frequent disputes with, auditors.<br>
slide20. What Organization Do if they Suspect Fraud or Misconduct? Any employee who suspects that dishonest, unethical, or fraudulent activity is occurring should not attempt to personally contact the suspected individual in an effort to determine facts, conduct investigations or interviews / interrogations. Care must be taken to avoid mistaken accusations or alerting suspected individuals.<br>
slide21. Fraud as per Section 447 of Companies Act 2013.<br>
slide22. Frauds – Companies Act, 2013 The Companies Act, 2013, is the legislation which focusses on issues related to corporate frauds. Fraud in relation to affairs of a company or any corporate body as defined in S.447 of the Companies Act 2013, includes any act, omission, concealment of any fact or abuse of position committed by any person or any other person with the connivance in any manner, with intent to deceive, to gain undue advantage from, or to injure the interests of the company or its shareholders or its creditors or any other person, whether or not there is any wrongful gain or wrongful loss.
The Companies Act of 2013, unlike its previous predecessor Act of 1956 have tried to list out various provisions or instances wherein Section 447, that exclusively deals with defining Fraud and its punishment, has to be referred to and they are as following:<br>
slide23. Frauds – Companies Act, 2013 Section 7: Deals with documents to be file with concerned Registrar of Companies (RoC) for incorporating a company.
Penal consequences: Sub-Section (5): If a person furnishes false information or incorrect particulars or suppresses material information then the person is liable for action under Section 447.
Section 8: Deals with Charitable Companies.
Penal consequences: Sub-Section (II): Every officer in default shall be liable for action under Section 447 if it is proved that the affairs of the company were conducted fraudulently.
Section 34: Deals with Criminal liability for mis-statement in Prospectus.
Penal consequences: Sub-Section (II): Every person who has authorized the issue of a prospectus carrying misstatement shall be liable under this provision.
Section 36: Deals with punishment for fraudulently inducing persons to invest money.
Penal Consequences: Sec. 447 can be invoked.<br>
slide24. Frauds – Companies Act, 2013 Section 38: Deals with punishment for personation for acquisition of securities.
Penal Consequences: Sec. 447 can be invoked; also, court has the power to pass order for disgorgement of gains, and maximum punishment here can go upto 10 years in jail.
Section 56: Deals with transfer and transmission of shares.
Penal Consequences: Sub-Section (7): Punishment under Section 447 for intentional fraudulent transfer of shares by a depository or depository participant.
Section 86: Deals with punishment for furnishing incorrect or suppressing material information.
Penal Consequences: Sub-Section (7): To be liable u/s 447, if despite aware of the same, a person wilfully provides for false information or suppress material information.
Section 90: Deals with punishment for wilful suppression w.r.t register of significant beneficial owners of the company.
Penal Consequences: Penal Consequences: Same as there in Section 86.<br>
slide25. Frauds – Companies Act, 2013 Section 206: Deals with power of Registrar of Companies (RoC) to call for information, inspect books and conduct inquiries.
Penal Consequences: If the information collected by the registrar or the inspection reveals that the business of the company has been conducted for a fraudulent or unlawful purpose, then every officer of the company who is in default shall be punishable for fraud as per Section 447.
Section 251: Deals with fraudulent application for removal of name.
Penal Consequences: “If an application has been made by the company with a fraudulent intent to evade the liabilities of the company or to defraud its creditors or other persons then the person in charge of the management of the company shall be liable for action under Section 447.”
Section 339: Deals with liability for fraudulent conduct of business.
Penal Consequences: Sub-Section (3): Punishment can be invoked u/s 447.<br>
slide26. Extract of Section 447 of Companies Act, 2013-Notified Date of Section: 12/09/2013 Punishment for Fraud. Any person who is found to be guilty of fraud under section 447 1[involving an amount of at least ten lakh rupees or one per cent. of the turnover of the company, whichever is lower] shall be punishable with imprisonment for a term which shall not be less than six months but which may extend to ten years and shall also be liable to fine which shall not be less than the amount involved in the fraud, but which may extend to three times the amount involved in the fraud.<br>
slide27. Extract of Section 447 of Companies Act, 2013-Notified Date of Section: 12/09/2013 Section 447 of the Act provides for a maximum imprisonment for 10 years. The standard of proof is ‘beyond reasonable doubt’. Recently, the SC in the matter of Latesh v. State of Maharashtra explained the term ‘reasonable doubt’ as “a mean between excessive caution and excessive indifference to a doubt, further it has been elaborated that reasonable doubt must be a practical one and not an abstract theoretical hypothesis…”
Conditions for Grant of Bail:
Section 212 of the Act provides for investigation into affairs of the company by SFIO.
Section 212(6) of the Act provides that a person accused of offence covered under Section 447 of the Act shall not be released on bail till the following conditions are satisfied:
1. The public prosecutor has been given opportunity to oppose his release and where the public prosecutor opposes the application,

2. The court is satisfied that there are reasonable grounds for believing that he is not guilty of such offence and that he is not likely to commit any offence while on bail. (Twin Conditions)<br>
slide28. Extract of Section 447 of Companies Act, 2013-Notified Date of Section: 12/09/2013 The Twin Conditions are almost impossible to satisfy – they are identical to the conditions under Section 45 of the Prevention of Money Laundering Act, 2002 (PMLA) for grant of bail to an accused. In a landmark judgment delivered by the SC in Nikesh Tarachand Shah v. Union of India, Section 45 of the PMLA was struck down as unconstitutional for being violative of Articles 14 and 21 of the Constitution. Surprisingly, despite the striking-off of an identical section, not only are arrests being made under Section 447 of the Act but bails are also denied using the Twin Conditions. It is interesting to note that the SC in SFIO v. Nitin Johari cancelled the bail granted by the Delhi High Court and took a view that economic offences constitute a class apart and need to be visited with a different approach in the matter of bail.<br>
slide29. Extract of Section 447 of Companies Act, 2013-Notified Date of Section: 12/09/2013 SEBI has amended the SEBI (LODR-Listing Obligations Diclosure Requirements) Regulations, 2015 with effect from October 08, 2020 to provide that in case of initiation of forensic audit, (by whatever name called), the following disclosures shall be made to the stock exchanges by the listed entities:
1. The fact of initiation of forensic audit along-with name of entity initiating the audit and reasons for the same, if available;
2. Final forensic audit report (other than for forensic audit initiated by regulatory / enforcement agencies) on receipt by the listed entity along with comments of the management, if any.

This new requirement to report is without any materiality thresholds, which could cause high level of anxiety to the Audit Committee and Boards as any such disclosure could have a profound impact on the stock price of the company. In addition, a speculative reporting by the media may also create panic among the investor community.<br>
slide30. Some Common Threads in the Frauds Poor corporate governance practices.
Board of directors consisting of unquestioning or silent yes man directors.
Centralisation of decision-making powers in hands of promoters or a few top management officials.
Lack of effective internal controls and systems, Including IT control and internal audit system.
Lack of effective oversight and monitoring mechanism.
Absence or lack of MIS systems.
Non- adherence to systems and controls.
Ambitious expansion in non- core area funded through overleveraging of Balance Sheet.
Imprudent bank / NBFC lending practices.
Absence of effective whistle blower mechanism.<br>
slide31. Commonly used Mechanisms to Commit Frauds Fake sales invoice.
Revenue recognition without delivery of goods or transfer of control and ownership of goods.
Double accounting of sales.
Not accounting of sales returns, credit notes on account of discount, promotional expenses etc.
Sale of non-existent scrap or at lower-than-normal value.
Fake purchases of material and capital purchases, without receiving goods or without transfer of ownership to the company.
Over invoicing of imports and transfer of differential value to fraudsters by round tripping/money laundering.<br>
slide32. Commonly used Mechanisms to Commit Frauds Accounting of fake expenses, without incurring expenses or overstatement of costs.
Common items of expenses are-sales promotion and marketing’s, commission, payments to dummy contracted or regular staff, travelling and conveyance, freight and transportation, fuel costs, administration costs etc.
Deliberate under provisioning of expenses, debtors, loans, advances and liabilities.
Under provisioning on account of impairments of tangible and intangible assets, current assets, over estimation of realisable value of stocks, scraps etc.
Actual liability disclosed as contingent liabilities.
Valuation of non-existing stocks or non - moving/non-saleable stocks.<br>
slide33. Fraud Triangle, Types, Sector Classification.<br>
slide34. Frauds – Triangle The three elements of the Fraud Triangle are:
Opportunity
Pressure
Rationalization<br>
slide35. The Fraud Diamond Capability: The Fraud Diamond, a newer theory of fraud proposed by David T. Wolfe and Dana R. Hermanson, asserts that the fraudster's capability must also be taken into account. The fraudster, it is said, must have the required traits (e.g., greed, weakness of character, excessive pride, dishonesty, etc.) and abilities (e.g., knowledge of processes and controls) to actually commit the fraud.
10-80-10 Rule: The 10-80-10 Rule supports the general assumption of capability by breakdown of the population and the likelihood of fraud occurrences.
Essentially:
10 percent of the population will NEVER commit fraud.
80 percent of the population might commit fraud given
the right combination of opportunity, pressure, and rationalization.
10 percent of the population are actively looking
at systems and trying to find a way to commit fraud.<br>
slide36. Types of Frauds There are following types of Fraud as described below:
Payroll fraud
Asset misappropriation / skimming
Invoice Fraud Schemes
Financial statement fraud
Tax fraud
Data, Intellectual Property and Identity Theft Insurance and Banking Fraud
Money Fraud
Return Fraud
Bribery and corruption<br>
slide37. Types of Frauds Payroll fraud can manifest in a variety of ways. An employee could lie about their productivity, sales or hours worked to get a higher pay. Some may request for a pay advance without any intention of paying it back. Others may even take it a step further by enlisting a co-worker to manipulate their attendance records by clocking in and out for them.
According to most studies, payroll fraud disproportionately affects small businesses because they are less likely to have anti-fraud measures and systems.
How to avoid it: Do background checks on every potential employee. Have managers closely monitor time sheets and use secure automated payroll services.<br>
slide38. Types of Frauds Asset misappropriation / skimming is one of the most common types of business fraud, but it is also one of the easiest to spot. Watching out for forged checks, missing inventory and accounts that simply don’t add up is key to identifying asset misappropriation. Fall victim to skimming, which is the act of taking money from either a customer or the company without recording the transaction.
How to avoid it: Rotate cash-handling staff and do not entrust all financial tasks to one employee.
Invoice Fraud Schemes, this type of fraud happens when the fraudster (often an employee in sales or accounting) creates fake invoices to steal money from the business. This could mean invoicing for products and services that were never bought, creating a fake supplier / shell company to funnel the money to, or awarding over-inflated contracts to personal friends and family.
How to avoid it: Cross-check every invoice with actual goods and services purchased. Do comprehensive background checks before approving a new supplier.<br>
slide39. Types of Frauds Financial statement fraud involves fudging important numbers like sales, revenues, assets and liabilities. Usually, this is done to dupe investors or the public, manipulate stock or increase bonuses. While this is one of the rarer kinds of business fraud, it is also one of the most damaging.
How to avoid it: Delegate different accounting functions to different employees. Closely examine financial statements for inconsistencies or inaccurate information before publishing.
Tax fraud (also known as tax evasion) is a type of fraud that happens when an individual or company’s earnings and expenses are misreported to the IRS, often to take advantage of lower tax brackets and special exemptions.
How to avoid it: Do not over-report expenses or under-report earnings. File taxes completely, accurately and on time.<br>
slide40. Types of Frauds Data, Intellectual Property and Identity Theft, A lot of businesses handle sensitive information, whether personal data or intellectual property (IP). IP theft can damage business if an employee leaks trade secrets and patents to competitors. Identity theft can hurt reputation due to lower customer trust.
How to avoid it: Restrict access to high-level documents. Have a security policy in place for the classification and handling of sensitive information.
Insurance and Banking Fraud, most companies offer health insurance or workers' compensation to their employees. Sadly, there are employees who try to profit off insurance by filing false claims or lying about injuries and illnesses, resulting in higher premiums and more out-of-pocket expenses for small business owners.
How to avoid it: Be strict about the requirements for filing insurance claims/workers' compensation. Check all submitted documents to ensure they’re real.<br>
slide41. Types of Frauds Money Fraud is a type of fraud where a customer uses fake bills to make a real purchase. If don’t check regularly, won’t notice the notes are counterfeit until it’s too late.
How to avoid it: Train cash-handling employees on how to check for counterfeit bank notes. Invest in a counterfeit money detector if handle large amounts of cash regularly.
Return Fraud, many retail businesses have some sort of return, refund or exchange policy that allows customers to send back defective items. Some people take advantage of this by lying about purchases, returning stolen goods, stealing receipts, or using items and then returning them before the return period is up to get their money back.
How to avoid it: Require receipts for all returns and exchanges. In the case of refunds, give store credit instead of cash.
Bribery and corruption encompass a variety of practices such as skimming/getting kickbacks from projects, using money to influence major company decisions, and manipulating contracts to favour some people over others.
How to avoid it: Implement stricter compliance programs and gifting guidelines. Conduct due diligence with all employees, management and third-party vendors.<br>
slide42. Sector Classification The courts classify fraud under two major types: criminal and civil. Civil fraud is when the fraud is an intentional misrepresentation of facts. Criminal fraud is when theft is involved in the fraud.
For example, lying on income taxes is a type of civil fraud. Civil fraud is punishable by fines or restitution, which involves paying the victim back. If lie on income tax return and get caught, will be required to pay a large fine to fix this wrong.
An example of criminal fraud is that of identity theft. Identity theft, as the name implies, involves theft. Criminal fraud is usually punished as a felony crime. Penalties can be jail time, probation, and fines.<br>
slide43. Sector Classification Common Fraud: Subtypes: in spite of two major types of fraud, there are many different subtypes.
• Mail fraud, such as creating fake invoices.

• Insurance fraud, such as claiming more than what is really needed.

• Tax fraud, such as not reporting income truthfully.

• Check fraud, which involves writing fake checks.

• Internet sales fraud, such as selling fake items.

• Website misdirection, which are fake websites.<br>
slide44. Sector Classification Common Fraud: Subtypes: in spite of two major types of fraud, there are many different subtypes.
• Charity fraud, which occurs when charities never send the money to the people they claim to help.
• Pyramid schemes, for example buying a package about how to make money only to find out that now have to sell that same package to others.

• Work-from-home scams, such as work-from-home ads that ask to pay for more information.
Anybody can become a victim of fraud, as criminals and other fraud perpetrators get more and more creative in the methods, they use to defraud others. As an example, with the website misdirection fraud for that matter, can become a victim of fraud by visiting what seems to be a legitimate website and then being redirected to a look-alike site that aims to steal information for fraudulent purposes. If enter credit card information, then the people behind this fake website can then use credit card to make purchases for themselves.<br>
slide45. Sector Classification Classification of Frauds in Banking Sector:

Misappropriation and criminal breach of trust.

Fraudulent encashment through forged instruments

Unauthorised credit facilities extended for reward or for illegal gratification.

Negligence and cash shortages.

Cheating and forgery.

Irregularities in foreign exchange transactions<br>
slide46. Cyber-crime, Digital Incident Response Presented by
CA. Sanjay Kumar Gupta<br>
slide47. Defining Cybercrime Cybercrime is any criminal activity that involves a computer, networked device or a network. While most cybercrimes are carried out in order to generate profit for the cybercriminals, some cybercrimes are carried out against computers or devices directly to damage or disable them, while others use computers or networks to spread malware, illegal information, images or other materials.
The U.S. Department of Justice (DOJ) divides cybercrime into three categories:

Crimes in which the computing device is the target- For example to gain network access;

Crimes in which the computer is used as a weapon-For example, to launch a denial-of-service (DoS) attack;
Crimes in which the computer is used as an accessory to a crime-For example, using a computer to store illegally obtained data.<br>
slide48. How Cybercrime Works Cybercrime attacks can begin wherever there is digital data, opportunity and motive. Cybercriminals often carry out their activities using malware and other types of software, but social engineering is often an important component for executing most types of cybercrime. Phishing emails are another important component to many types of cybercrime but especially so for targeted attacks, like Business Email Compromise (BEC), in which the attacker attempts to impersonate, via email, a business owner in order to convince employees to pay out bogus invoices.<br>
slide49. Types of Cybercrime There are following types of Cybercrime described below:
Cyberextortion : A crime involving an attack or threat of an attack coupled with a demand for money to stop the attack. Here, the attacker gains access to an organization's systems and encrypts its documents and files- anything of potential value-making the data inaccessible until a ransom is paid. Usually, this is in some form of cryptocurrency, such as bitcoin.
Cryptojacking : An attack that uses scripts to mine cryptocurrencies within browsers without the user's consent.
Identity theft : An attack that occurs when an individual accesses a computer to glean a user's personal information ,which they then use to steal that person's identity or access their valuable accounts, such as banking and credit cards. Cybercriminals buy and sell identity information on darknet markets, offering financial accounts, as well as other types of accounts, like video streaming services, webmail, video and audio streaming, online auctions and more. Personal health information is another frequent target for identity thieves.<br>
slide50. Types of Cybercrime There are following types of Cybercrime described below:
Credit card fraud: An attack that occurs when hackers infiltrate retailers' systems to get the credit card and/or banking information of their customers.
Cyberespionage : A crime involving a cybercriminal who hacks into systems or networks to gain access to confidential information held by a government or other organization.
Software piracy : An attack that involves the unlawful copying, distribution and use of software programs with the intention of commercial or personal use.
Exit scam : The dark web, not surprisingly, has given rise to the digital version of an old crime known as the exit scam. In today's form, dark web administrators divert virtual currency held in marketplace escrow accounts to their own accounts-essentially, criminals stealing from other criminals.<br>
slide51. Common Examples of Cybercrime Some of the more commonly seen cybercrime attacks include Distributed DoS (DDoS) attacks, which are often used to shut down systems and networks.
Infecting systems and networks with malware are an example of an attack used to damage the system or harm users.
Phishing campaigns are used to infiltrate corporate networks.
A credentials attack is when a cybercriminal aims to steal or guess user IDs and passwords for the victim's systems or personal accounts.
Cybercriminals may also attempt to hijack a website to change or delete content or to access or modify databases without authorization.
Other common examples of cybercrime include illegal gambling, the sale of illegal items like weapons, drugs or counterfeit goods-and the solicitation, production, possession or distribution of child pornography.<br>
slide52. Effects of Cybercrime on Businesses Businesses suffer with disastrous consequences as a result of criminal cyberattacks are as follows:
Damage to investor perception after a security breach can cause a drop in the value of a company.
In addition to potential share price drops, businesses may also face increased costs for borrowing and greater difficulty in raising more capital.
Loss of sensitive customer data can result in fines and penalties for companies that have failed to protect their customers' data.
Damaged brand identity and loss of reputation after a cyberattack undermine customers' trust in a company
Businesses may also incur direct costs from a criminal cyberattack, including increased insurance premium costs and the cost of hiring cybersecurity companies to do incident response and remediation, as well as Public Relations (PR) and other services related to an attack.<br>
slide53. Effects of Cybercrime Cybercrimes may have public health and national security implications, making computer crime one of Department of Justice (DOJ's) top priorities. The Department of Homeland Security (DHS) sees strengthening the security and resilience of cyberspace as an important homeland security mission. USSS' Electronic Crimes Task Force (ECTF) investigates cases that involve electronic crimes, particularly attacks on the nation's financial and critical infrastructures. The Internet Crime Complaint Center (IC3), a partnership among the FBI, the National White-Collar Crime Center (NW3C) and the Bureau of Justice Assistance (BJA), accepts online complaints from victims of internet crimes or interested third parties.<br>
slide54. How to Prevent Cybercrime While it may not be possible to completely eradicate cybercrime and ensure complete internet security, businesses can reduce their exposure to it by maintaining an effective cybersecurity strategy using a defense-in-depth approach to securing systems, networks and data.<br>
slide55. Steps for reducing Cybercrime Risks Develop clear policies and procedures for the business and employees;

Create cybersecurity incident response management plans to support these policies and procedures;

Outline the security measures

Use two-factor authentication (2FA) apps or physical security keys;

Activate 2FA (Two Factor Authentication) on every online account when possible;

Create intrusion detection system (IDS) rules that flag emails with extensions similar to company emails;

Continually train employees on cybersecurity policies and procedures

Keep websites, endpoint devices and systems current with all software release updates or patches; and

Back up data and information regularly to reduce the damage in case of a ransomware attack or data breach.<br>
slide56. Cybercrime Legislation and Agencies Various U.S. government agencies have been established to deal specifically with the monitoring and management of cybercrime attacks. The FBI's Cyber Division is the lead federal agency for dealing with attacks by cybercriminals, terrorists or overseas adversaries. Within DHS is the Cybersecurity and Infrastructure Security Agency (CISA). Furthermore, the Cyber Crimes Center (C3) provides computer-based technical services that support domestic and international investigations included in the Homeland Security Investigations (HSI) portfolio of immigration and customs authorities. C3 includes the Cyber Crimes Unit (CCU), the Child Exploitation Investigations Unit (CEIU) and the Computer Forensics Unit (CFU).
Legislation dealing with cybercrime can be applicable to the general public, or it can be sector-specific, extending only to certain types of companies. For example, the Gramm-Leach-Bliley Act (GLBA) focuses on financial institutions and regulates the implementation of written policies and procedures that should improve the security and confidentiality of customer records, while also protecting private information from threats and unauthorized access and use.<br>
slide57. Cyber Security measures in India The Information Technology Act 2000 (the IT Act) read with the rules and regulations framed thereunder deal with cybersecurity and the cybercrimes associated therewith. The IT Act not only provides legal recognition and protection for transactions carried out through electronic data interchange and other means of electronic communication, but it also contains provisions that are aimed at safeguarding electronic data, information or records, and preventing unauthorised or unlawful use of a computer system. Some of the cybersecurity crimes that are specifically envisaged and punishable under the IT Act are hacking, denial-of-service attacks, phishing, malware attacks, identity fraud and electronic theft.
In accordance with the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules 2013 (the CERT Rules), the Computer Emergency Response Team (CERT-In) has been established as the nodal agency responsible for the collection, analysis and dissemination of information on cyber incidents and taking emergency measures to contain such incidents.<br>
slide58. Cyber Security measures in India Other relevant rules framed under the IT Act in context of cybersecurity include:
✓ the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules 2011 (the SPDI Rules), which prescribe reasonable security practices and procedures to be implemented for collection and the processing of personal or sensitive personal data;

✓ the Information Technology (Information Security Practices and Procedures for Protected System) Rules 2018 (the Protected System Rules), which require specific information security measures to be implemented by organisations that have protected systems, as defined under the IT Act. More information on protected systems is provided in ‘Scope and jurisdiction’; and

✓ the Information Technology (Intermediaries Guidelines) Rules, 2011 (the Intermediaries Guidelines), which require intermediaries to implement reasonable security practices and procedures for securing their computer resources and information contained therein. The intermediaries are also required to report cybersecurity incidents (including information relating to such incidents) to CERT-In<br>
slide59. Cyber Security measures in India Other laws that contain cybersecurity-related provisions include the Indian Penal Code 1860 (IPC), which punishes offences, including those committed in cyberspace (such as defamation, cheating, criminal intimation and obscenity), and the Companies (Management and Administration) Rules 2014 (the CAM Rules) framed under the Companies Act 2013, which requires companies to ensure that electronic records and security systems are secure from unauthorised access and tampering.

In addition to the above, there are sector-specific regulations issued by regulators such as the Reserve Bank of India (RBI), the Insurance Regulatory and Development Authority of India Act 1999 (IRDA), the Department of Telecommunication (DOT) and the Securities Exchange Board of India (SEBI), which mandate cybersecurity standards to be maintained by their regulated entities, such as banks, insurance companies, telecoms service providers and listed entities.<br>
slide60. Cyber Security measures in India With the rise of digital payments, cybercrimes involving payment transactions in the online space have significantly increased and become complex. While the RBI has been active in requiring companies operating payment systems to build secure authentication and transaction security mechanisms (such as 2FA authentication, EMV chips, PCI DSS compliance and tokenisation), given that these payment companies often offer real-time frictionless payments experiences to their consumers, it leaves less time for banks and other entities operating in the payment ecosystem to identify and respond to cyberthreats.

As per the CAM Rules, the managing director, company secretary, or any other director or officer of the company (as may be decided by the board) is responsible for the maintenance and security of electronic records.<br>
slide61. How to create a fraud Agonistic Organisation Prevention of frauds requires creation of a fraud agnostic and vigilant organisation, which has following essential ingredients:
Robust Internal control systems and process
Effective cyber risk management systems to protect the organisation against ever increasing threat of cyber-attacks.
Tone at top of the management drives organisation culture down the level and right messaging conveying integrity, transparency, right value systems, act as a deterrence to potential frauds.
Effective accounting, finance team and internal, statutory audit systems.
Extensive deployment of data analytics, Artificial intelligence, and other related tools to pick up early signals of fraud happening and minimising damage.
Ensuring that applicable accounting standards are rigorously followed
Delegation of power and authorities
Effective whistle blower mechanism.<br>
slide62. How to create a fraud Agonistic Organisation IND AS which are mandatorily applicable to certain class of companies, require determination of fair values of most of items of assets and liabilities stated in financial statements compared to historical cost accounting followed in Indian Standards. Estimation of fair values requires significant judgements, assumptions, and estimates. In some cases, estimation requires valuation by valuers.
This leaves significant scope for scrupulous management to misstate financial statements. A fraud agnostic organisation with above accounting systems and all the above ingredients, depending on facts of each case acts as an effective checks and balances mechanism and a preventive tool for minimising occurrence of frauds.
Indicators of potential fraud:
There are plenty of early warning signals and red flags, which if picked in time, can unearth frauds and minimise losses. It requires vigilance, monitoring and rigorous analysis of unusual variances in key performance indicators (KPI) of the company, compared to:
1. Peers.
2. Macroeconomic indicators.
3. abnormal spikes or fall compared to company’s normal performance.<br>