{"description":"Runs ON an audit item (an existing engagement). Assesses fraud risks across the fraud triangle and management override, maps anti-fraud controls to those risks, validates and characterizes the journal-entry population for the period, selects entries by pattern flag plus a reproducible random draw from the unflagged remainder, tests every selected entry for support, approval and business purpose, and raises every unsupported anomaly as an issue linked to its FSLI and control. Hands off to engagement reporting for issue disposition and reporting.","edges":[{"id":"e-assess-fraud-risks-conclude","source":"assess-fraud-risks","target":"conclude"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["audit-testing"],"controlVerbs":{"UC-AUDIT-12":"operates","UC-AUDIT-13":"operates","UC-AUDIT-14":"operates"},"controls":["UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-14"],"department":"internal-audit","domains":["audit"],"kind":"fraud-risk-je-testing","library":{"aliases":[{"source":"assureplugin","sourceTemplateId":"fraud-risk-je-testing"}],"canonicalUrl":"https://workflow-library.com/all/?w=fraud-risk-je-testing","contentDigest":"sha256:79c63b355999a79e044c279a7bd312e4a60f76cfc83b7c13d70a490b0b253a56","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted step documents and native step results retaining source files, review notes and final conclusions.","id":"workpapers"}],"roles":[{"contribution":"expertise","description":"Approves the procedure, scope and precommitted testing or monitoring criteria.","id":"audit-supervisor","nodeIds":["assess-fraud-risks"]},{"contribution":"approval","description":"A reviewer other than the preparer; ITGC reviewers must also be independent of control operation.","id":"independent-reviewer","nodeIds":["conclude"]}],"status":"declared"},"provenance":[{"source":"assureplugin/skills/audit-fraud-je/workflows/fraud-risk-je-testing.json","sourceTemplateId":"fraud-risk-je-testing"}],"releaseId":"sha256:79c63b355999a79e044c279a7bd312e4a60f76cfc83b7c13d70a490b0b253a56","schemaVersion":1,"sourceTemplateId":"workflow-library:fraud-risk-je-testing"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"fraud-risk-je-testing","source":"coworkcanvas-gallery","standards":["iia-2024","sox","coso-ic"],"teams":["internal-audit"]},"name":"Fraud Risk Assessment & JE Testing","nodes":[{"data":{"controls":["UC-AUDIT-12","UC-AUDIT-13"],"instructions":"**Objective** — Challenge the fraud assessment and approve a risk-responsive journal-entry selection.\n\n**Inputs** — The Audit engagement, significant FSLIs, prior findings, authorized interviews, controls and complete JE extract.\n\n**Procedure**\n1. Assess incentives and pressures, opportunity, rationalization and management override at entity and significant-FSLI level. Treat override as a distinct risk regardless of assessed integrity; record evidence and uncertainty without inventing a risk for a quota. Link risks to the Audit and relevant FSLIs, and map existing anti-fraud controls. Management owns control design and implementation; record gaps for management response rather than designing controls as the auditor.\n2. Freeze the source extract with source system, extraction query and parameters, entity, period and timestamp. Reconcile row counts or value to an independent source; inspect query filters and report completeness and accuracy, or cite approved current-period reliance on the same report and parameters. Profile columns, date boundaries, nulls, numeric ranges and totals. Validate an empty population and record not applicable/no occurrences; draw no sample and make no effectiveness claim.\n3. Profile leading digits only where Benford analysis is suitable. For digits 1–9 compute expected proportion log10(1+1/d), observed proportions, absolute deviations and the declared screening threshold; exclude zeros and document handling of negatives. A deviation is a screening signal, never proof of fraud or population completeness.\n4. Flag round amounts using a declared currency threshold; weekend postings using the relevant calendar; postings in the declared period-end window; self-approval; adjust/override/reclass/plug keyword hits; preparers or approvers with at most two entries unless another threshold is approved; and manual, post-close or top-side source values or documented description matches. Record every flag definition, count and input column. Treat Benford as a population-level screen, not an entry-level flag.\n5. Use the engagement-approved sampling methodology. The source method uses this nonstatistical baseline for occurrence populations: at most 50 items, round up 10% with a floor of 5 capped at the population; 51–250 items, round up 15%; above 250, 25/40/60 for low/moderate/high risk. Increase for prior deficiencies, changed controls, sole safeguards, elevated risk or external reliance. This baseline does not establish statistical assurance; document the assurance objective, materiality, tolerable error and any statistical design separately. Choose random for homogeneous populations, systematic for temporal coverage, monetary-unit sampling for positive monetary exposure, and documented targeted strata as a supplement. Record the algorithm/version, input row order, seed, population SHA-256, size and date so another tester can reproduce the draw.\n6. Select every flagged entry plus a reproducible random draw from the unflagged remainder, sizing that draw from the remainder’s count and assessed risk. Deduplicate the union by JE identifier and retain all reasons. Commit the exception policy before testing.\n\n**Record in AssureSwarm** — Record fraud rationale, control gaps, profiling and selection criteria in the result; attach the frozen extract, profile, Benford result, flags and sample. Link Audit, Risk, FSLI and Control records using native relationships.\n\n**Exit criteria** — The engagement lead provides expertise and variance: the assessment addresses management override, the population basis is supported and flagged plus unflagged selections trace to the approved criteria.","label":"Approve fraud risks and JE selection","requiredApprovals":1},"id":"assess-fraud-risks"},{"data":{"controls":["UC-AUDIT-13","UC-AUDIT-14"],"instructions":"**Objective** — Decide whether testing supports the fraud-risk assessment or requires escalation.\n\n**Inputs** — Approved risk/selection plan, each entry’s source support, approval and documented business purpose.\n\n**Procedure**\n1. For every selected entry inspect invoice, contract, calculation or other source evidence; agree amount/account and record evidence dates. Compare preparer and approver, approval timing and authority to policy. Investigate self-approval or delegation explanations using corroboration. Test business purpose and override rationale; disposition every flag as resolved or unresolved.\n2. Precommit an exception policy before seeing results: expand once by a stated increment or stop and evaluate. Preserve the original exception after expansion. Replace only demonstrably out-of-scope, voided or duplicate rows using the same method and seed lineage; missing evidence is an exception. Prefer reperformance and inspection to observation and inquiry; investigate contrary evidence and distinguish an observed failure from an unsupported representation.\n3. Record supported or exception per entry, including both flagged and random selections. Raise every unsupported anomaly as a linked Issue: exception for a testing failure, finding for a broader gap, with severity reflecting magnitude and context. Link to the Audit, FSLI and relevant Control.\n4. Summarize flag counts and the Benford screening result; state for each assessed fraud risk whether evidence corroborates or elevates the rating or supplies no new information. Preserve residual control gaps, unresolved anomalies and limitations. Deliver the reviewed workpaper and Issue register to engagement reporting.\n\n**Record in AssureSwarm** — Attach source support and per-entry dispositions; record the risk conclusions in the step result and proposed Risk field updates. Capture human sign-off in native approvals.\n\n**Exit criteria** — An independent audit reviewer provides expertise and approval: all selected entries are tested, exceptions have owners and links, and analytics are not described as proof of fraud.","label":"Review JE evidence and fraud conclusions","requiredApprovals":1},"id":"conclude"}],"sourceTemplateId":"workflow-library:fraud-risk-je-testing"}
