10.1 | Continual improvement | 0 |
10.2 | Nonconformity and corrective action | 0 |
2-3 | Normative references and terms | 0 |
4.1 | Understanding the organization and its context | 0 |
4.2 | Understanding the needs and expectations of interested parties | 0 |
4.3 | Determining the scope of the fraud control management system (FCMS) | 0 |
4.4 | Fraud control management system (FCMS) | 0 |
4.5 | Fraud risk assessment | 0 |
4.5.1 | General: the fraud risk assessment | 0 |
4.5.2 | Collaboration with other risk management functions | 0 |
5.1 | Leadership and commitment | 0 |
5.1.1 | Governing body | 0 |
5.1.2 | Top management | 0 |
5.2 | Fraud control policy | 0 |
5.3 | Roles, responsibilities and authorities | 0 |
5.3.1 | General: roles and responsibilities | 0 |
5.3.2 | Delegated decision-making to managers and organizational functions | 0 |
5.3.3 | Fraud control function | 0 |
5.3.4 | Information security management system function | 0 |
5.3.5 | Internal audit function | 0 |
6.1 | Actions to address risks and opportunities | 0 |
6.2 | Fraud control objectives and planning to achieve them | 0 |
6.3 | Planning of changes | 0 |
7.1 | Resources | 0 |
7.1.1 | General: resources | 0 |
7.1.2 | Information security management system function | 0 |
7.2 | Competence | 0 |
7.2.1 | General: competence | 0 |
7.2.2 | Employment process | 0 |
7.3 | Awareness | 0 |
7.3.1 | Awareness of personnel | 0 |
7.3.2 | Training for personnel | 0 |
7.3.3 | Training for business associates | 0 |
7.3.4 | Awareness and training programmes | 0 |
7.4 | Communication | 0 |
7.4.1 | General: communication | 0 |
7.4.2 | Promoting the FCMS | 0 |
7.5 | Documented information | 0 |
7.5.1 | General: documented information | 0 |
7.5.2 | Creating and updating documented information | 0 |
7.5.3 | Control of documented information | 0 |
7.5.4 | Record keeping and confidentiality of information | 0 |
8.1 | Operational planning and control | 0 |
8.2 | Preventing fraud | 0 |
8.2.1 | General: preventing fraud | 0 |
8.2.10 | Physical security and asset management | 0 |
8.2.2 | Developing and promoting an effective integrity framework | 0 |
8.2.3 | Managing conflicts of interest | 0 |
8.2.4 | Internal controls and the internal control environment | 0 |
8.2.5 | Pressure testing the internal control system | 0 |
8.2.6 | Managing performance-based targets | 0 |
8.2.7 | Personnel screening | 0 |
8.2.8 | Screening and management of business associates | 0 |
8.2.9 | Preventing technology-enabled fraud | 0 |
8.3 | Detecting fraud | 0 |
8.3.1 | General: detecting fraud | 0 |
8.3.2 | Post-transactional review | 0 |
8.3.3 | Analysis of management accounting reports | 0 |
8.3.4 | Identification of early warning indicators | 0 |
8.3.5 | Data analytics | 0 |
8.3.6 | Fraud reporting | 0 |
8.3.7 | Artificial intelligence systems | 0 |
8.3.8 | Complaint management | 0 |
8.3.9 | Exit interviews | 0 |
8.4 | Responding to fraud events | 0 |
8.4.1 | General: responding to fraud events | 0 |
8.4.10 | Fraud event register | 0 |
8.4.11 | Analysis and reporting of fraud events | 0 |
8.4.12 | External reporting | 0 |
8.4.13 | Recovery of stolen funds or property | 0 |
8.4.14 | Responding to fraud events involving business associates | 0 |
8.4.15 | Insuring against fraud events | 0 |
8.4.16 | Assessing internal controls, systems and processes post-detection of a fraud event | 0 |
8.4.17 | Impact of fraud on other interested parties | 0 |
8.4.18 | Disruption of fraud | 0 |
8.4.2 | Immediate actions in response to discovery of fraud | 0 |
8.4.3 | Digital evidence first response | 0 |
8.4.4 | Investigation of a detected fraud event | 0 |
8.4.5 | Consideration of grievances | 0 |
8.4.6 | Disciplinary procedures | 0 |
8.4.7 | Separation of investigation and decision-making processes | 0 |
8.4.8 | Crisis management following discovery of a fraud event | 0 |
8.4.9 | Internal reporting and escalation | 0 |
9.1 | Monitoring, measurement, analysis and evaluation | 0 |
9.2 | Internal audit | 0 |
9.2.1 | General: internal audit | 0 |
9.2.2 | Internal audit programme | 0 |
9.3 | External audit | 0 |
9.4 | Management review | 0 |
9.4.1 | General: management review | 0 |
9.4.2 | Management review inputs | 0 |
9.4.3 | Management review results | 0 |
A | Annex A (informative): Examples of fraud risks impacting global entities | 0 |
B | Annex B (informative): Models for fraud prevention, guidance | 0 |