Fraud Risk Assessment Flashcards
7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Fraud Risk Assessment flashcards as text
Which of the following is a key limitation of relying solely on past fraud losses to assess current fraud risk?
Answer: Past losses reflect detected frauds only and may miss undetected schemes
Historical fraud loss data only captures detected and reported incidents, leaving undetected frauds — which may represent the majority — entirely unmeasured.
In fraud risk assessment terminology, 'risk tolerance' refers to:
Answer: The amount of residual fraud risk an organization is willing to accept
Risk tolerance defines the level of residual fraud risk that the board and management consider acceptable given the cost of controls.
Which of the following best illustrates 'segregation of duties' as a fraud prevention control?
Answer: The employee who approves vendor invoices is different from the one who processes payment
Segregation of duties requires that no single individual control all phases of a transaction, so that approval and payment functions are separated.
A fraud risk assessment reveals that an organization's anonymous hotline has received zero reports over three years. A fraud examiner should interpret this finding as:
Answer: Potentially indicating low awareness of the hotline or fear of retaliation rather than absence of fraud
Zero reports on a hotline may reflect poor awareness, lack of trust, or fear of retaliation rather than an absence of fraud.
Which of the following fraud schemes would a fraud risk assessment focused on the revenue cycle most likely identify as a key risk?
Answer: Fictitious sales recorded to inflate revenue
Fictitious or premature revenue recognition is the primary financial statement fraud risk in the revenue cycle.
When conducting fraud risk interviews with process owners, which question type is MOST effective at uncovering hidden fraud risks?
Answer: Open-ended questions asking what could go wrong in their area and how
Open-ended questions encourage process owners to think creatively about vulnerabilities and often surface risks that structured questionnaires miss.
According to the ACFE's fraud risk management principles, what should happen after a fraud risk assessment is completed and risks are prioritized?
Answer: Management should design or enhance anti-fraud controls and responses for the highest-priority risks
After prioritization, management is responsible for developing or strengthening controls and other responses targeted at the highest-rated fraud risks.