A fraud risk assessment identifies the specific fraud schemes an organization is exposed to, rates each one for likelihood and significance, maps the controls already in place against it, and assigns a response to whatever risk is left over. COSO and the ACFE frame it as Principle 2 of a five-principle Fraud Risk Management Program, but it stands on its own as a deliverable. A cross-functional team identifies inherent fraud risk across three categories, fraudulent financial reporting, misappropriation of assets, and corruption, rates likelihood as remote, reasonably possible, or probable and significance as inconsequential, significant, or material, then tests whether existing controls actually close the gap. What is left after controls are mapped is residual risk, and every material residual risk gets an assigned response before the assessment is done.
A fraud risk assessment is a structured analysis that identifies the fraud schemes an organization is exposed to, rates each for likelihood and significance, maps the controls in place against it, and assigns a response to the risk that remains. A general risk assessment addresses what could go wrong; a fraud risk assessment addresses what someone inside or connected to the organization might cause to go wrong deliberately and then conceal. That distinction, intent, is why COSO and the Association of Certified Fraud Examiners (ACFE) treat fraud risk assessment as a discrete exercise rather than a line item within general risk management, and why a client engaging a consultant for one expects a different form of scrutiny than a standard risk review provides.
This article covers the conduct of a fraud risk assessment for a client: where it sits inside the broader COSO/ACFE framework, the composition of the assessment team, the identify, assess, and respond method the current framework and its predecessor both build on, the working grid that constitutes the engagement's core deliverable, and the failure patterns that lead a board or an examiner to reject an assessment.
Where the assessment fits in a fraud risk management program
COSO and the ACFE organize fraud risk management into five principles, published as the Fraud Risk Management Guide, Second Edition in 2023. Fraud risk assessment is Principle 2, sitting between governance and the control activities it justifies.
| Principle | What it covers |
|---|---|
| 1. Governance | Board and senior-management commitment to a documented fraud risk management program. |
| 2. Fraud Risk Assessment | Identify schemes, assess likelihood and significance, map controls, respond to residual risk. This guide. |
| 3. Control Activities | Preventive and detective controls, deployed to stop fraud or catch it in progress. |
| 4. Information & Communication | A reporting channel and a coordinated investigation and corrective-action process. |
| 5. Monitoring Activities | Ongoing evaluation confirming the other four principles stay present and functioning. |
An engagement can run this Principle 2 assessment as a standalone deliverable, scoped and priced on its own, or as the diagnostic phase of a full fraud risk management program build. Either way, the method below does not change.
The case for a dedicated fraud risk pass
Where fraud is folded into a general risk assessment, the questions asked ordinarily stop at process failure: where a control could break down. A fraud risk assessment asks where someone could deliberately break a control and then conceal the break. An organization that omits the dedicated pass may never examine incentives, pressures, and the specific opportunities an insider has to override or bypass a control, because that adversarial framing was not built into the general exercise. Running fraud risk assessment as its own exercise, even where the results are later merged into the broader risk register, preserves the intent-focused lens and produces a control structure evaluated against deliberate circumvention. The same logic is why a BSA/AML risk assessment stays a distinct exercise in a financial institution rather than getting absorbed into enterprise risk management: a risk category defined by someone actively working to evade detection needs its own dedicated pass.
Before the assessment itself starts, the engagement carrying it should already be scoped the way any consulting engagement is: risk screened, independence cleared, and terms signed in writing, the sequence covered in how to plan a compliance audit engagement.
The five steps of the assessment
Both the current framework and its 2008 predecessor build the assessment around the same sequence: assemble the team, identify inherent risk before considering any controls, assess the identified risks for likelihood and significance, map controls, then respond to what remains.
1. Assemble a cross-functional assessment team
The method calls for a cross-functional team rather than a single assessor on either the consultant's or the client's side: accounting and finance, an operations or business-unit representative, risk management, to keep the fraud assessment integrated with the client's broader enterprise risk process rather than running parallel to it, legal and compliance, internal audit, and, where the client's internal bench is thin on a specific fraud typology, an external specialist. Senior management, business-unit leaders, and the process owners closest to the risk participate directly. They own the controls being assessed, and they carry ultimate accountability for whether the resulting program operates.
The consultant's own role appears on the team chart explicitly. A consultant leading the assessment supplies the structured method and, frequently, the fraud-specific expertise the client's internal team lacks, while the client's personnel hold the institutional knowledge of where risk sits; an assessment built without them omits risk that surfaces only from that knowledge.
2. Identify inherent fraud risk across three categories
The full population of fraud risks that could apply to the client is gathered before any existing control narrows the list. The sources are external, comprising regulator guidance, industry-specific fraud data, and COSO and ACFE publications, and internal, comprising structured interviews, a cross-functional brainstorming session, a review of what the whistleblower hotline has logged, and analytical procedures run against the client's own transaction data. Every scheme identified sorts into one of three categories.
| Category | What it covers | Representative schemes |
|---|---|---|
| Fraudulent financial reporting | Intentional misstatement of financial or non-financial results. | Fictitious or prematurely recognized revenue, concealed liabilities, backdated agreements, misstated asset values. |
| Misappropriation of assets | Theft of tangible or intangible assets by employees, customers, vendors, or former employees. | Cash skimming and lapping, false expense reimbursement, ghost employees on payroll, inventory theft, IP or customer-list theft. |
| Corruption | Misuse of position for personal gain, involving another party. | Bribery and kickbacks, embezzlement via false accounting entries, undisclosed conflicts of interest, bid rigging. |
IT-specific fraud risk does not form a fourth category; it is recorded under whichever of the three it enables: unauthorized access to accounting systems, an override of application controls, or misuse of customer data for a fraudulent credit application all belong under the category the resulting scheme would fall into on its own.
3. Assess likelihood and significance for each risk
Every identified risk is scored on two independent scales before any control is credited. Likelihood sorts into three levels: remote, reasonably possible, or probable. Significance sorts into three levels as well: inconsequential, significant, or material.
Significance is not measured by dollar figure alone. Operational disruption, reputational exposure, and legal or regulatory liability are weighed alongside the direct monetary loss a scheme would cause. A scheme carrying a small recoverable loss but triggering a mandatory regulatory notification, or a customer-facing data exposure, can rate as material notwithstanding the limited immediate financial effect.
4. Map existing controls and test their effectiveness
For each identified risk, the anti-fraud controls bearing on it are inventoried, with a record of whether each has been tested by internal audit, tested by management, or not yet tested at all. A control that exists on paper but was never tested does not get credited as effective, and a mapping that skips this distinction cannot support the residual-risk determination that comes next.
5. Determine residual risk and assign a response
The exposure remaining unaddressed after controls are mapped is residual risk. Three responses are available for material residual risk: add a control, design a proactive fraud-auditing or data-analytics procedure targeted at the specific scheme, or accept and monitor the risk, typically because the cost of a further control would exceed the exposure it closes. A response of "no action needed" is defensible only when residual risk is explicitly rated as already adequately mitigated, never as a default for a risk nobody got around to addressing.
Adversarial reasoning about each control
A generic control review asks whether a control exists and whether its operation can be evidenced. A fraud risk assessment asks a further question of the same control: how a person intending to commit the specific scheme would circumvent it, and what that person would do afterward to conceal the act. Working through each identified risk in that form, rather than confirming that a control is documented, is the strategic reasoning step both the current and predecessor guides call for, and it distinguishes a fraud risk assessment from a routine controls review. For every control in the mapping, three questions are put: how the control could be overridden, who holds authority to override it without a second signature, and what concealment would look like. Management override, by a person senior enough to bypass a control that would stop anyone else, carries its own line of questioning in every category; it is the risk factor both guides call out by name.
The fraud risk assessment grid
The grid carries one row per identified scheme, with the same columns applied across all three categories. The example below follows the format used in the predecessor guide's illustrative appendix, spanning a scheme from each category.
| Risk / scheme | Category | Likelihood | Significance | Residual risk | Response |
|---|---|---|---|---|---|
| Backdated sales agreements to accelerate revenue recognition | Financial reporting | Reasonably possible | Material | Management override of the revenue-cutoff control | Data-analytics review of contract execution dates against system-entry dates |
| False or duplicate expense reimbursement claims | Misappropriation | Probable | Significant | Approval control not tested against duplicate submissions | Add an automated duplicate-detection rule to the reimbursement system |
| Undisclosed vendor kickback tied to a procurement decision | Corruption | Remote | Material | Vendor selection not independently reviewed | Add an independent second-reviewer sign-off above a dollar threshold |
A full assessment repeats this pattern across every material process the client runs, not just the three illustrative rows above.
What the deliverable includes
A completed fraud risk assessment delivers three components to the client: the populated grid, a narrative explaining which risks were judged material and on what basis, and a statement of the response assigned to each material residual risk. The deliverable feeds two downstream processes. It informs the control-activity design work, which determines the preventive and detective controls to build or strengthen, and, where the client maintains an ongoing self-assessment, it feeds the fraud prevention and detection scorecards ACFE publishes, which grade the resulting controls against a standard checklist. Neither of those falls within the scope of this deliverable. Its function is to state, specifically and defensibly, where the client's fraud exposure sits before any new control is designed. Where a material residual risk later requires an actual fix, the corrective action follows the same field-by-field discipline covered in how to write a corrective action plan. Where the fraud risk assessment surfaces alongside a broader compliance engagement, it typically runs as one leg of the diagnosis phase described in the five phases of a consulting engagement, and if a scheme it identifies is already suspected activity rather than a modeled risk, the deliverable that follows is closer to a SAR narrative than a risk grid.
Where a fraud risk assessment fails review
- No dedicated pass. Fraud risk folded into the general risk assessment loses the intent-focused lens and the adversarial-reasoning step.
- Risks assessed only against existing controls. Scoring likelihood after crediting controls collapses inherent and residual risk into one number, and a reviewer cannot tell which one they are looking at.
- Significance measured in dollars alone. A scheme with real regulatory or reputational exposure gets rated inconsequential because nobody totaled anything but the direct loss.
- Management override skipped. Every category requires an explicit answer to who could override the control and how the override would be concealed, in addition to whether the control exists.
- Residual risk left unassigned. A risk carrying no named response has not been accepted; it is unaddressed, and a reviewer treats the two states differently.
- The team was too narrow. An assessment run by finance alone, without operations, legal, and risk management in the room, misses risk categories those functions would have surfaced.
The same gap analysis that a fraud program's later phases run once controls are in place traces the same failure logic covered in AML program gap analysis: a control review conducted without a benchmark and without scoring produces an opinion rather than an assessment.
Primary sources
- Committee of Sponsoring Organizations of the Treadway Commission (COSO) & Association of Certified Fraud Examiners (ACFE), Fraud Risk Management Guide, Second Edition (2023): the current five-principle structure; a free executive summary is available from the guide's landing page.
- The Institute of Internal Auditors (IIA), American Institute of Certified Public Accountants (AICPA), & Association of Certified Fraud Examiners (ACFE), Managing the Business Risk of Fraud: A Practical Guide (2008): the predecessor guide that originated the three-step identify, assess, respond method, the fraud risk assessment grid, and the risk taxonomy this guide walks through.
- ACFE, Fraud Risk Management Tools: the current home for the fraud risk assessment templates and the prevention and detection scorecards that typically follow this assessment.
- COSO, Internal Control, Integrated Framework (2013): Principle 8, the organization considers the potential for fraud in assessing risks to the achievement of objectives, the internal-control principle the Fraud Risk Management Guide expands into a full standalone framework.