What Can a CIO Do to Prevent Fraud?

When you become CIO, it turns out that you'reCertified Fraud Examiners (ACFE) revealed that
going to have a lot more on your mind than justcompanies may be losing up to 7% of their annual
how to use the latest and greatest technology torevenues due to employee fraud. Now that's a big
help the company run faster. You've got anumber!
problem that starts with "F" and rhymes withThere's lots of ways that IT staff along with the
"Baud" and that stands for Fraud...rest of the business can commit fraud. However,
Bad Times Make Fraud More Likelyif we had to group them together, they'd all fall
When things get tough at a company, peopleinto one of three different buckets. These
start to feel the pressure to deliver results nogroupings are: asset misappropriation, corruption,
matter what. Some recent studies by behavioraland financial statement fraud. It turns out that
psychologists have revealed a trait that all of usasset misappropriation is the most common and
have called "reframing". This occurs when in orderaverages roughly $150,000 per event. On the
to get away with cheating, we adjust theother end of the spectrum, financial statement
definition of cheating so that it excludes ourfraud is the least common but the most
actions. Neat trick, eh?expensive - it costs the company $2M on
What this means for you soon-to-be-CIOs is thataverage every time it occurs.
just about anyone working for the company isHow To Stop Fraud
capable of committing fraud. Hard times broughtSo how does the CIO fit into all of this you may
on by, oh say, a global recession, can boost thebe asking yourself? The answer is actually very
chances that someone will cross that line thatsimple: good leadership. The goal of every CIO
should never be crossed.should be to prevent IT staff from making bad
The Fraud Trianglejudgement calls before they become fraud. A CIO
Look, you're going to become the company's CIOwho establishes clear standards for the IT
and unfortunately that's not going to suddenlydepartment to follow has gone a long way in
equip you with magical mind-reading abilities.preventing fraud from occurring in the first place.
Instead you are going to have to be aware ofOf course, we're talking about the IT department
what is called the "fraud triangle" and keep youhere and so there has to be a second level of
eyes open both within and without the ITeffort - fraud detection. The CIO has access to
department.the entire company's data and it's electronic tools.
The fraud triangle has (of course) 3 sides to it:He / she is best suited to working with the CEO
pressure, opportunity, and that ability to rationalizeand CFO to implement the IT sensors that will
your actions that we've already talked about. Anyalert them if something unusual starts to happen.
one of these by itself probably isn't enough toWhat All Of This Means For You
push one of your staff to do something that theFraud is, unfortunately, all too common in modern
entire company might regret, but put all three ofcompanies. A CIO has a key role to play in both
them together and you've got the makings of apreventing fraud from occurring within the IT
serious problem.department and detecting it when it happens in
3 Categories Of Fraudother parts of the business.
So how big is this fraud thing? Well first you needUnderstanding that anyone can end up committing
to understand that study after study have shownfraud given the right set of circumstances is the
that people will cheat if they think that they cankey to preventing it. CIOs need to establish clear
get away with it. What makes this even morestandards that make sure that everyone knows
amazing is that they will cheat no matter whatwhat is and is not acceptable behavior within the
their background is (Ivy Leaguers do it too) andcompany.
they'll cheat even if they really don't have all thatIn the end, it's the tone set by the CIO that will
much to gain by cheating.be communicated down to the rest of the IT
This is a big deal for companies. A 2007-2008staff. Preventing fraud is something that a CIO
survey that was done by the Association ofcan do by leading by example.