-->
Showing posts with label investigation. Show all posts
Showing posts with label investigation. Show all posts

Monday, October 17, 2016

The first steps that management should take when Suspicions or Allegations of Fraud becomes known

Initial Response to Suspicions or Allegations of Fraud

 
 
Suspicions of Fraud

 When responding to suspected and detected incidents of fraud, time is critical. Management and fraud examiners must be prepared to address a number of issues in a short amount of time, sometimes under stressful conditions.
Initially, when a suspicion or allegation of fraud arises, management must respond quickly. The failure to act quickly against suspicions of fraud could result in litigation, enhanced penalties, and enforcement actions by government regulators. The appropriate response varies depending on the facts, such as the underlying evidence, who is implicated, how the evidence came about (e.g., internal sources, civil lawsuit, investigation by the government), and so on. But generally, when evidence of fraud arises, management should respond by engaging in the following actions:
  • Activate the response team.
  • Engage legal counsel, if necessary.
  • Consider contacting the insurance providers.
  • Address immediate concerns.
  • Conduct an initial assessment.
  • Document the initial response.

Activate the Response Team:

When evidence of fraud arises, management must activate the fraud response team—the group of people tasked with responding to incidents of fraud. When activated, the response team should seek to answer the following questions:
  • Is a formal investigation necessary?
  • If a formal investigation is necessary, who will lead it?
  • Is there a need for immediate police involvement?
  • Is there an immediate need for legal assistance or advice?
  • Is there a need for external support (e.g., forensics specialists)?
  • Is there a need for additional support (e.g., access to IT facilities or a secure room, support from administration)?
  • Is there a need to devise a media strategy to deal with the issue?
  • Is there a need to report the issue to an external third party?
  • Should the audit committee be informed?

Engage Legal Counsel:

Because incidences of fraud are riddled with legal uncertainties, management should consult with internal and possibly external local legal counsel before making any decisions or taking any action concerning the suspected conduct. Typically, the general counsel should be made aware of any significant fraud that might result in legal action.
 

Consider Contacting the Insurance Provider:

When evidence of fraud arises, it is generally impossible to know whether the incident will result in an insurance claim, but even so, many insurance policies require timely notice of potential claims. Therefore, an organisation should consider putting its insurer on notice to preserve a potential insurance claim.

Address Immediate Concerns:

Also, when evidence of fraud arises, management and the response team should address immediate concerns. Immediate concerns will vary, but they might include:
  • Preserving relevant documents
  • Identifying who should be informed

Preserving Relevant Documents:

When evidence of fraud arises, management should seek to preserve all relevant documents, especially those that an employee might want to hide or destroy. In a fraud investigation context, the term documents typically refers to, but is not limited to, contracts, invoices, correspondence, memoranda, weekly reports, presentations, telephone messages, emails, reports, performance reviews, performance improvement plans, medical records, and other written or recorded material.
 
When evidence is misplaced, lost, or destroyed, it becomes more difficult to conduct an investigation. Thus, the response team and management must take action to preserve evidence as soon as the decision to investigate is made. There are a number of steps that management should take to preserve relevant documents. For one thing, management should work with legal counsel to issue a litigation hold to notify employees to suspend the destruction of potentially relevant records.
 
Furthermore, management should suspend the organisation’s record retention policy temporarily to avoid a piece of evidence accidentally being destroyed.
Also, management could lockdown access to emails or digital files that employees might want to conceal or destroy. Digital information can be found in virtually any type of media, and it is more fragile than tangible evidence. Therefore, employees can destroy this type of information if it is not protected properly. Often, when fraudsters become aware of an investigation, they try to destroy evidence in their computers or sabotage other evidence that could be used against them. Accordingly, it is a good idea to have IT personnel involved in this process each time the organisation decides to conduct an investigation.
 
The failure to preserve documents could have several adverse consequences. First, the failure to preserve documents could result in the government’s questioning of the integrity of any fraud investigation. Second, documents destroyed when litigation is expected, or in progress, might give rise to claims of spoliation of evidence, which, if proven, could lead to monetary fines and sanctions, adverse inference jury instruction sanctions, or dismissal of claims or defences. Spoliation is broadly defined as the act of intentionally or negligently destroying documents relevant to litigation.
 In today’s digital environment, digital spoliation is a major concern for organisations involved in litigation. When compared to the spoliation of tangible documents, digital spoliation carries additional risks. Management often lacks sufficient knowledge of the inventory of digital information, and electronic data might only be available for an evanescent time. Additional concerns include business practices designed to free up storage space by deleting digital information and the fact that electronic data can reside in numerous locations, as well as the fact that identifying relevant electronic data within today’s large and complex data systems can be challenging and costly.
 

Identifying Who Should Be Informed:

Management and the response team should identify whom to inform. Depending on the facts, several departments should be interested in fraud, including legal, human resources, internal audit, security, risk management, and loss prevention or security. When responding to an allegation of fraud, it is important to consider the interests of each of these departments. This is necessary to ensure that designated employees are notified immediately to enable a prompt response. Information about incidences, however, should be shared only on a need-to-know basis.
 Human resources (HR) personnel address issues involving unfair treatment, discrimination, harassment, substance abuse, or concerns about corporate policies. Therefore, the HR department should be informed of fraud that affects any such areas.
Both the HR and legal departments should be involved to ensure that the right people receive information in a timely manner. Also, other departments, such as loss prevention and risk management, audit, and security might need to be involved. Although the development of information distribution rules requires the participation of several departments, it is best to have these rules set before investigation protocols are in place.
 
Another department that needs to be involved is the information technology (IT) department. The IT department might need to be part of an investigation to safeguard data until it can be analysed. IT personnel can also help identify what data are available and where, and they might be able to function as forensic investigators if licensed to do so.
Again, management must restrict access to certain pieces of information on a need-to-know basis.

Conduct an Initial Assessment to Determine the Appropriate Response:

Usually, when an allegation of fraud arises, there are not enough known and verified facts to begin a formal investigation; therefore, management and the response team should conduct an initial assessment to determine if an investigation is needed and what steps, if any, are required to respond in an appropriate manner. This is perhaps the most critical question that management must answer when an allegation of fraud arises.
 
An initial assessment should be quick and, unless complications arise, completed within a few days. Ideally, action should be taken within three days of learning about an incident.
The initial assessment should be a limited fact-finding analysis focused on the specific allegation or incident. It does not require an investigation plan or report, unlike a formal investigation. Thus, the initial assessment should seek to:
  • Determine if fraud occurred.
  • Identify the status of the fraud (e.g., When did it begin? Was it internal or external? Is it still occurring? If it is no longer occurring, when did it stop?).
  • Identify potential claims and offences.
To conduct an initial assessment and determine the appropriate response, those responsible should take the following steps:
  • Understand the context.
  • Review any applicable policies and procedures.
  • Investigate the allegations.
  • Document the reasons for the decision.

Understand the Context:

Next, those responsible should gain an understanding of all of the circumstances leading up to the current situation. Often, the context is necessary to determine the best approach to dealing with a tip or suspicion, and it can provide clues that are helpful in other areas.
 
Efforts to understand the context should seek to obtain the initial facts and circumstances about:
  • The manner in which the suspicions became known
  • The date suspicions became known
  • The areas to which the suspicions pertain
  • The source of the information
  • The allegations at issue

Review Any Applicable Policies and Procedures:

Those involved in the initial assessment must also review any applicable internal controls and organisational policies, including any anti-fraud auditing and testing policies and procedures, to determine the best method and processes for continuing the investigation.
 

Investigate the Allegations:

An initial assessment should be a limited, fact-finding analysis, and it should focus on investigating the specific allegation or incident. More specifically, to determine the appropriate response, the assessment should, if possible, seek to answer a number of questions, including:
  • Is the allegation credible?
  • Who is the subject of the allegation, and what is his relationship to the company?
  • When did the alleged misconduct occur, and how often did it occur?
  • What was the business purpose of the activity related to the allegation?
  • How serious is the allegation?
  • What levels of employees are alleged to be involved, if any, in the misconduct (i.e., officers, directors, or managers)?
  • What individuals might have pertinent information about the matter that would tend to support or refute the complainant’s position, and what facts do these individuals purportedly know?
  •  Did any third parties receive any direct or indirect benefit from the misconduct, and if so, who are they?
  • If a third party is involved, is the third party a government official?
  •  How was the matter recorded on the company’s books and records, if applicable?
  • Can it be determined if the person in question acted with fraudulent intent?
  • Is it possible that the issue might be larger than expected?
  • Were there any whistleblowers, and if so, how should they be dealt with?
  • What measures should the company take to document how the initial evidence of wrongdoing was handled?
  • Is the government already involved, and if not, is it likely that the government will become involved?
  • Is it likely that the matter will have significant negative impact on shareholder value?
These questions are important because the response should be proportional to the potential scale of the fraud in terms of its value, frequency, potential damage, the individuals involved, the number of people involved, and so on.
 
In addition, the decision as to the appropriate response might be influenced by other factors.
As with any business decision, the cost of conducting the investigation must be considered, and management might also consider whether an investigation will interrupt business activity.
 
Generally, the investigation portion of the initial assessment will involve:
  • Contacting the source, if the investigation was triggered by a report or complaint
  • Interviewing key individuals
  • Reviewing key evidence

CONTACTING THE SOURCE:

If the evidence came in through a tip from an identified source, those responsible should contact the source to find out additional information and confirm the source’s willingness to help throughout the investigation. When contacting the source, the interviewer should encourage the complainant to provide a narrative description of the report. After the source provides the narrative, the interviewer should ask clarifying questions and then summarise the key points.
An interview with the source should seek to determine:
  • What does the individual know?
  • How did the individual get the information?
  • Who were the key individuals involved?
  • When did the alleged events occur (e.g., dates, times, and locations)?
  • What are the details (e.g., who, what, when, where, why, and how much) of the allegations?
  •  What are the dates (or period) of the key events?
  • What evidence exists to corroborate the alleged events, where is the evidence located, and how can the evidence be accessed?
  • What witnesses can corroborate the alleged events?
  • Which individuals might have pertinent information about the matter that would tend to support or refute the complainant’s position, and what facts do these individuals purportedly know?
  • What was the motivation behind the alleged events?
  • Why were the alleged actions improper?
  • If the scheme is ongoing, do the subjects know of the complainant’s report?
  • What is the complainant’s motivation for making the report (e.g., What prompted you to report this?)?
When interviewing the source, the interviewer should seek to determine if there is any reason to suspect the complainant’s credibility. Also, if there are any weaknesses in the complainant’s information, the interviewer should ask the complainant to explain what he expects the subject would say in defence of the allegations and ask the complainant to explain why such a response is not sufficient to dispose of the matter. Additionally, the interviewer should ask the source what he wants the organisation to do about the complaint. The response to such an inquiry will help the team focus its efforts.

INTERVIEWING KEY INDIVIDUALS:

Those responsible should interview key individuals for information about the suspicious conduct and the subject(s). Interviewing individuals with personal knowledge is critical. Also, they should interview witnesses as early as possible because it will limit the harm arising from loss of memory, witnesses becoming unavailable, and inadvertent loss or destruction of key evidence.
 

REVIEWING THE EVIDENCE:

Those responsible should review relevant documents and files, which might include personnel files, the organisation’s employee handbook, accounting records, vendor activity reports, budget reports, fixed asset records, expense reimbursements records, leasing documents, rental agreements, payroll records, purchasing requisitions, purchase contracts, inventory records, shipping/receiving reports, emails, telephone records, and so on.
Obtaining and reviewing these documents will assist in understanding the chronology of events and might put the responsible parties on notice as to certain strengths or weaknesses of the investigation.

Document the Reasons for the Decision:

To avoid any real or perceived downplay of the matter’s significance and to avoid any attempts at wilful blindness, those responsible should document their actions and findings.
In addition, management must document its decisions and the reasons behind them. Thus, if management decides against conducting an investigation, it must document the reasons why.
 
Again, management should document the organisation’s initial response in an incident report log that serves as a record of the organisation’s response efforts. Once a suspicion of fraud arises, the issue should be recorded and detailed in the log. As the issue progresses, the log should be modified and, ultimately, it should contain details of actions taken and conclusions reached.
The incident report log should contain all information relevant to or created during the initial response that is used to support management’s decision making.
Read More

Tuesday, October 11, 2016

Key Components to Develop a fraud prevention strategy

Fraud prevention strategy

 fraud prevention strategy
 
To help ensure that an organisation responds to suspicious fraud-related activity efficiently, management should have a fraud prevention strategy in place that outlines how to respond to such issues. When evidence of misconduct arises, management must respond in an appropriate and timely manner. During the initial response, time is critical.
A fraud prevention strategy outlines the actions that members of an organisation will take when suspicions of fraud have arisen. Because every fraud is different, the fraud prevention strategy should not outline how a fraud examination should be conducted. Instead, fraud prevention strategy should help organisations manage their responses and create environments to minimise risk and maximise the potential for success.
Additionally, a fraud prevention strategy will allow management to respond to suspected and detected incidents of fraud in a consistent and comprehensive manner. By having a fraud prevention strategy in place, management will send a message that it takes fraud seriously.
More specifically, the fraud prevention strategy should guide the necessary action when potential fraud is reported or identified.
Also, a fraud prevention strategy should not be unduly complicated; for a response plan to work in high-pressure and time-sensitive situations, it must be simple to understand and administer.
While the appropriate response will vary based on the event, management should include a range of scenarios in the fraud prevention strategy.
Organisations without a fraud prevention strategy might not be able to respond to issues properly, and will likely expend more resources and suffer greater harm than those that have such a plan in place. Conversely, having a fraud prevention strategy puts an organisation in the best position to respond promptly and effectively.
The elements of a fraud prevention strategy include:
  • Reporting protocols
  • A response team responsible for conducting an initial assessment
  • Factors used to decide on the course of action
  • Litigation hold procedures
  • Principles for documenting the response plan
  • A template or form to report fraud incidents

Reporting Protocols :

One of the first steps when developing a fraud prevention strategy is to establish reporting protocols for tips, matters, allegations, and other indicators of improper activity. Reporting protocols are necessary to ensure that designated individuals are notified immediately to enable a prompt response.
 
Reporting protocols should outline notification principles and escalation triggers that vary depending on the nature and severity of the allegations. That is, they should indicate how to communicate the incidents to the appropriate level of management. For example, a fraud prevention strategy might instruct employees to report suspicions of fraud to their manager (if possible), a designated human resources (HR) or compliance officer, or the head of audit and enforcement.
Next, the issue should be reported to the party or parties responsible for conducting an initial assessment to determine how to respond and whether a full investigation is necessary.
Additionally, organisations should provide multiple channels for reporting concerns about fraud.
 

A Response Team :

 No single person can effectively address every fraud-related issue. Therefore, the fraud prevention strategy must identify key individuals who might be required to respond to a particular fraud. The response team members will vary depending on the facts and the potential severity of the suspected fraud, but the team might include:
  • Legal counsel
  • A representative of management
  • A Fraud Examiner
  • The finance director
  • General counsel
  • A representative of internal audit
  • Audit committee members
  • A C-level executive
  • Information technology (IT) personnel
  • A representative of human resources (HR)

Factors Used to Decide on the Course of Action :

Again, the response team should determine the appropriate course of action when fraud is suspected. In general, if an allegation of fraud-related misconduct arises, management should conduct an investigation, but there are other courses of action it might decide to take. To help decide the best course of action, management should identify a list of factors it will use to make this decision. Identifying such factors will help the response team determine whether to escalate an incident into an investigation.
Each organisation will have different criteria for deciding whether allegations/suspicions qualify for a formal investigation, but common ones include:
  • Credibility of the allegation
  • Type of incident
  • The subject of the allegation
  • The business purpose of the activity at issue
  • Seriousness or severity of the allegation
  • Potential negative impact
  • Likelihood that the incident will end up in court
  • The ways in which prior, similar incidents were handled

Litigation Hold Procedures :

If an organisation does not already have litigation hold procedures in place, management should institute them immediately. A litigation hold refers to the steps an organisation takes to notify employees to suspend the destruction of potentially relevant records when the duty to preserve information arises.
Litigation hold procedures are necessary to ensure that potentially responsive documents are not destroyed once evidence of misconduct arises. The failure to preserve relevant evidence could have several adverse consequences, including, but not limited to, the government’s questioning of the integrity of any fraud investigation, monetary fines and sanctions, adverse inference jury instruction sanctions, or dismissal of claims or defences.
To establish litigation hold procedures, management should:
  • Identify the scope of litigation hold procedures (i.e., the locations that the litigation hold procedures will cover).
  • Examine how information moves through the organisation.
  • Determine how to identify relevant documents.
  • Develop a process to ensure such information is preserved.
Litigation hold procedures should apply to individual communications (e.g., email, chat messages, voice recordings), data on shared devices (e.g., network folders), system backup files, and archived data.
In general, litigation hold policies should be developed so the organisation can:
  • Promptly notify employees who might possess relevant documents.
  • Issue a preliminary hold order to all individuals and employees who might possess relevant information.
  • Promptly notify information technology (IT) personnel and get their involvement if electronic data is at issue.
  • Notify employees and IT personnel of their duty to preserve.
  • Suspend any deletion protocols.
  • Prohibit the destruction, loss, or alteration of any potentially relevant documents.
  • Prohibit employees from destroying, hiding, or manipulating documents.
  • Alert employees as to the risk to the company and the employees if they fail to heed the litigation hold request.
Moreover, establishing litigation hold procedures will help those involved in an investigation identify the relevant sources of information quickly, and it will help them understand the technology options available for searching, analysing, and reviewing data.
Even though litigation holds should apply to both electronic data and physical documents, electronic data contains certain attributes that make executing a timely litigation hold more difficult. Specifically, electronic data might only be available for a temporary period, business practices are often designed to free up storage space by deleting this type of information, electronic data can reside in numerous locations, and identifying relevant electronic data within today’s large and complex data systems can be challenging and costly.
 
Moreover, if an organisation operates internationally, it is more difficult to execute a timely hold. In such cases, management should consider retaining an outside expert to help with the data search and preservation.
A key objective of a litigation hold is to stop any automatic document deletion programmes or rules that might be in place.
Read More

Thursday, August 4, 2016

What is the the real forgery definition to detect fraud

Forgery definition 

forgery meaning
 

A forgery definition is any writing prepared with the intent to deceive or defraud. Thus, forgery meaning occurs when an individual, with intent to defraud, makes or alters a document apparently capable of defrauding another.

A document is not a forgery crime just because it contains a false representation. To constitute a  forgery definition, the writing as a whole must have apparent legal significance. In addition, forgery crime occurs not only when an entire writing or instrument is created, but also when there is any material alteration that affects the legal significance of the document or whenever a signature on a writing is fraudulently procured from a person who does not know what he is signing. Furthermore, the forgery definition is committed even if no one is actually defrauded.

Forged Maker Schemes in forgery definition

Forgery definition can include not only the signing of another person’s name to a document such as a cheque (check forgery) with a fraudulent intent, but the forgery crime is also the fraudulent alteration of a genuine instrument.

This forgery definition is so broad that it would encompass all cheque tampering schemes. For the purposes of this post, the forgery definition has been narrowed to fit the fraud examiner’s needs. To properly distinguish the various methods used by individuals to tamper with cheques, the concept of “forgery crime” will be limited to those cases in which an individual signs another person’s name on a cheque.

The person who signs a cheque in forgery definition is known as the “maker” of the cheque. A forged maker scheme can thus be defined as a cheque tampering scheme in which an employee misappropriates a cheque and fraudulently affixes the signature of an authorised maker thereon. Frauds that involve other types of cheque tampering, such as the alteration of the payee or the changing of the dollar amount, are classified separately.

To forge a cheque, an employee must have access to a blank cheque, be able to produce a convincing forgery meaning of an authorised signature, and be able to conceal his crime.

Concealment is a universal problem in cheque tampering schemes; the methods used are basically the same whether one is dealing with a forged maker scheme, an intercepted cheque scheme, or an authorised maker scheme. 


Obtaining the Cheque for the forgery definition

EMPLOYEES WITH ACCESS TO COMPANY CHEQUES

One cannot forge a company cheque unless one first possesses a company cheque. Most schemes of forgery meaning are committed by accounts payable clerks, office managers, bookkeepers, or other employees whose duties typically include the preparation of company cheques. These are people who have access to the company chequebook on a regular basis and are therefore in the best position to steal blank cheques.


EMPLOYEES LACKING ACCESS TO COMPANY CHEQUES

If perpetrators do not have access to the company chequebook through their work duties, they will have to find other means of forgery definition and misappropriating a cheque. The method by which a person steals a cheque depends largely on how the chequebook is handled within a particular company. In some circumstances, the chequebook is poorly guarded and left in unattended areas where anyone can get to it. In other companies, the cheque stock might be kept in a restricted area, but the perpetrator might have obtained a key or combination to this area, or might know where an employee with access to the cheques keeps his own copy of the key or combination. An accomplice might provide blank cheques for the fraudster in return for a portion of the stolen funds. Perhaps a secretary sees a blank cheque left on a manager’s desk or a custodian comes across the cheque stock in an unlocked desk drawer.

In some companies, cheques are computer-generated. When this is the case, an employee who knows the password for preparing and issuing cheques can usually obtain as many unsigned cheques as he desires and commit a forgery definition. There are an unlimited number of ways to steal a cheque, each dependent on the way in which a particular company guards its blank cheques. In some instances, employees go as far as to produce counterfeit cheques.
 
forgery crime
 


To Whom Is the Cheque Made Payable in forgery definition?

TO THE PERPETRATOR

Once a blank cheque has been obtained, the perpetrator must decide to whom it should be made payable. In most instances forged cheques are made payable to the perpetrator himself so that they can be easily converted to the forgery definition. Cancelled cheques that are payable to an employee should be closely scrutinised for the possibility of fraud and forgery meaning.

If the perpetrator owns his own business or has established a shell company, he will usually write fraudulent cheques to these entities rather than himself. These cheques are not as obviously fraudulent on their faces as cheques made payable to an employee. At the same time, these cheques are easy to convert because the perpetrator owns the entity to which the cheques are payable.
 

TO AN ACCOMPLICE

If a fraudster is working with an accomplice, he can make the forged cheque payable to that person. The accomplice then cashes the cheque and splits the money with the employee fraudster. Because the cheque is payable to the accomplice in his true identity, it is easily Converted and the forgery definition is done. An additional benefit to using an accomplice is that a cancelled cheque payable to a third-party accomplice is not as likely to raise suspicion as a cancelled cheque to an employee. The obvious drawback to using an accomplice in a scheme is that the employee fraudster usually has to share the proceeds.


TO “CASH”

The perpetrator might also write cheques payable to “cash” to avoid listing himself as the payee. Cheques made payable to cash, however, must still be endorsed. The perpetrator will have to sign his own name or forge the name of another to convert the cheque. Cheques payable to “cash” are usually viewed more sceptically than cheques payable to persons or businesses. Some institutions might refuse to cash cheques made payable to “cash” to avoid forgery definition.

TO VENDORS

Not all fraudsters forge company cheques to obtain cash. Some employees use forged maker schemes to purchase goods or services for their own benefit. These fraudulent cheques are made payable to third-party vendors who are uninvolved in the fraud. For instance, the forgery definition is done if an employee might forge a company cheque to buy a computer for his home. The computer vendor is not involved in the fraud at all. Furthermore, if the victim organisation regularly does business with this vendor, the person who reconciles the company’s accounts might assume that the cheque was used for a legitimate business expense.
 
forgery meaning
 
 

Forgery definition by Forging the Signature

After the employee has obtained and prepared a blank cheque, he must forge an authorised signature to convert the cheque. The most obvious method, and the one that comes to mind when one thinks of the word forgery definition, is to simply take pen in hand and sign the name of an authorised maker.

 

FREE-HAND forgery definition

The difficulty a fraudster encounters when physically signing the authorised maker’s name is in creating a reasonable approximation of the true signature. If the forgery definition appears authentic, the perpetrator will probably have no problem cashing the cheque. In truth, the forged signature might not have to be particularly accurate. Many fraudsters cash forged cheques at liquor stores, grocery stores, or other institutions that are known to be less than diligent in verifying signatures and identification. Nevertheless, a poorly forgery definition by forged signature is a clear red flag of fraud. The maker’s signature on cancelled cheques should be reviewed for forgery meaning during the reconciliation process.


PHOTOCOPIED forgery definition

To guarantee an accurate forgery definition, some employees make photocopies of legitimate signatures. The signature of an authorised signer is copied from some document (such as a business letter) onto a transparency and then the transparency is laid over a blank cheque so that the signature copies onto the maker line of the cheque. The result is a cheque with a perfect signature of an authorised maker.
 
forgery
 

Forgery definition by AUTOMATIC CHEQUE and SIGNING MECHANISMS

Companies that issue a large number of cheques sometimes use automatic cheque-signing mechanisms in lieu of signing each cheque by hand. Automated signatures are produced with manual instruments, such as signature stamps, or they are printed by computer. Obviously, a fraudster who gains access to an automatic cheque-signing mechanism will have no trouble forging the signatures of authorised makers. Even the most rudimentary control procedures should severely limit access to these mechanisms.

The same principle applies to computerised signatures. Access to the password or programme that prints signed cheques should be restricted, specifically excluding those who prepare cheques and those who reconcile the bank statement.


Converting the Cheque in forgery definition

To convert the forged cheque, the perpetrator must endorse it. The endorsement is typically made in the name of the payee on the cheque. Since identification is typically required when one seeks to convert a cheque, the perpetrator usually needs fake identification if he forges cheques to real or fictitious third persons. As discussed earlier, cheques payable to “cash” require the endorsement of the person converting them. Without a fake ID the perpetrator will likely have to endorse these cheques in his own name. An employee’s endorsement on a cancelled cheque is obviously a red flag.


 Endorsement Schemes in forgery definition


Forged endorsements are those cheque tampering schemes in which an employee intercepts a company cheque intended to pay a third party and converts the cheque by endorsing it in the third party’s name. In some cases the employee also signs his own name as a second endorser. 

A fraudster’s main dilemma in a forged endorsement scheme (and in all intercepted cheque schemes, for that matter) is gaining access to a cheque after it has been signed. The fraudster must either steal the cheque between the point where it is signed and the point where it is delivered, or he must re-route the cheque, causing it to be delivered to a location where he can retrieve it. The manner used to steal a cheque depends largely upon the way the company handles outgoing disbursements. Anyone who is allowed to handle signed cheques might be in a good position to intercept them.


Forgery definition by Intercepting Cheques Before Delivery


EMPLOYEES INVOLVED IN DELIVERY OF CHEQUES

Obviously, the employees in the best position to intercept signed cheques are those whose duties include the handling and delivery of signed cheques. The most obvious example is a mailroom employee who opens outgoing mail containing signed cheques and steals the cheques. Other personnel who have access to outgoing cheques might include accounts payable employees, payroll clerks, and secretaries.


POOR CONTROL OF SIGNED CHEQUES

Unfortunately, employees are often able to intercept signed cheques because of poor internal controls. For instance, many employees simply find signed cheques left unattended in the work areas of the individuals who signed them or the people charged with their delivery. In these cases it is easy for the perpetrator to steal the cheque. Another common breakdown occurs when the person who prepares a cheque is also involved in the delivery of that cheque once it has been signed.

 In addition to the preceding example, secretaries or clerks who prepare cheques for their bosses to sign are often responsible for mailing those cheques. It is very simple for those employees to make out a fraudulent cheque and obtain a signature, knowing that the boss will give the signed cheque right back to them. This scheme is indicative of the key problem with occupational fraud: trust. For an office to run efficiently, high-level employees must be able to rely on their subordinates. Yet this reliance is precisely what puts subordinates in a position to defraud their employer.


forgery definition by Theft of Returned Cheques

Cheques that have been mailed and are later returned to the victim for some reason, such as an incorrect address, are often targeted for theft by fraudsters. Employees with access to incoming mail are able to intercept these returned cheques and convert them by forging the intended payee’s endorsement.


Forgery definition by Re-Routing the Delivery of Cheques

Employees might also misappropriate signed cheques by altering the addresses to which those cheques are mailed. These perpetrators usually replace the payee’s legitimate address with an address where the employee can retrieve the cheque, such as the employee’s home or a PO Box the employee controls. In other instances, the perpetrator might purposely misaddress a cheque so that it will be returned as undeliverable. The employee steals the cheque after it is returned to the victim organisation.

 Obviously, proper separation of duties should preclude anyone who prepares disbursements from being involved in their delivery. Nevertheless, the person who prepares a cheque is often allowed to address and mail it as well. In some instances where proper controls are in place, employees are still able to cause the misdelivery of cheques.


Forgery definition by Converting the Stolen Cheque

Once a cheque has been intercepted, the perpetrator can cash it by forging the payee's signature, hence the term forged endorsement scheme. Depending on where he tries to cash the cheque, the perpetrator may or may not need fake identification at this stage. If a perpetrator is required to produce identification to cash his stolen cheque, and if he does not have a fake ID in the payee’s name, he might use a dual endorsement to cash or deposit the cheque. In other words, the perpetrator forges the payee’s signature as though the payee had transferred the cheque to him, and then the perpetrator endorses the cheque in his own name and converts it. When the bank statement is reconciled, dual endorsements on cheques should always raise suspicions, particularly when the second signer is a company employee. 
Read More

Saturday, July 2, 2016

Use of Digital forensics jobs in fraudd cases

Conducting an Investigation Involving digital forensics jobs:


 computer forensics jobs

Fraud examiners must be prepared to address the myriad issues related to examinations involving digital forensics jobs and computer forensics jobs.

The increasing usage of the Internet and other technology in all aspects of life has created new opportunities for technology to be used in perpetrating almost every type of fraud, and in most fraud cases, investigators gather some type of digital evidence by digital forensics jobs.

Digital forensics jobs are investigations that involve relevant digital data processed or stored by digital devices, devices that process data in the form of numbers (digits). Digital devices can be used to communicate with others, create documents, access data online, enter data online, store information, and so on. An investigator leading a digital forensics jobs into a crime that involves a digital device is not necessarily, and in most cases, should not be, the forensic examiner.

Conversely, digital forensics jobs encompasses the recovery and investigation of material found in digital devices.

 Hiring experts of computer forensics jobs :

When conducting an examination involving computer forensics jobs, fraud examiners should determine whether a digital forensics jobs expert is needed. digital forensics jobs experts are individuals who specialize in identifying, recovering, collecting, preserving, processing, and producing digital data for use in investigations and litigation. Some organisations have their own in-house personnel whom they have trained and outfitted with the proper equipment and software tools to conduct the examination and analyse digital evidence, while others might prefer the use of an outside examiner who will be able to conduct a digital forensics jobs, prepare a proper report, and deliver expert testimony if needed in legal proceedings.
Sometimes retrieving digital data in digital forensics jobs is as easy as searching the target computer’s hard drive, but other times retrieval requires a thorough knowledge of computers to conduct a computer forensics jobs. For example, many fraudsters delete or hide incriminating files, and in these instances, efforts must be made to recover or find such data. There are, in fact, a variety of ways in digital forensics jobs of recovering deleted or hidden data from a target computer, and digital forensics jobs experts are specially trained for such tasks.
Specifically, digital forensics jobs experts are capable of analysing digital media at the hexadecimal level, which means that such experts can view every sector, and all the bytes in those sectors, on a system. Thus, digital forensics jobs experts can recover data from deleted files, both those that have been purposefully deleted and those that were accidentally deleted.
Deleted files are recoverable in digital forensics jobs until they are overwritten because data is not erased from a computer’s hard drive until it is overwritten. A deleted file will remain present on a hard drive until the operating system overwrites all or some of the file. So, deleted files that have been overwritten generally are not recoverable by digital forensics jobs.
digital forensics jobs experts can also recover temporary auto-save files, print-spool files, deleted emails, and deleted link (shortcut) files, and they can work with data at the hexadecimal level.
The hexadecimal level contains various items found in restore points and registry files that define hardware, such as external drives and websites visited, in addition to the document revisions and files created and maintained by the user.
Computer forensics jobs and specialists can recover, among other things, the following types of information from computer systems:
  • Deleted files and other data that has not been overwritten (e.g., deleted documents, images, link or shortcut files, and email messages);
  • Files deleted through computer-automated processes;
  • Temporary auto-save files;
  • Print-spool files;
  • Websites visited, even where the browser history and cache have been deleted;
  • Communications sent via chat or instant messenger;
  • Financial-based Internet transactions;
  • Documents, letters, and images created, modified, or accessed, even if the data was not saved on the computer in some situations;
  • Data that has been copied, corrupted, or moved;
  • The time and date information about files (e.g., when files were created, accessed, modified, installed, deleted, or downloaded);
  • Data from a drive that has been defragmented or reformatted.
The increased sophistication of hardware and operating systems allows computer systems to store more information about how people use their computers, and therefore, the digital forensics jobs are able to uncover a large amount of data that relates to the use of a computer, what is or has been stored on it, and the details about the computer’s user.

Moreover, digital forensics jobs have special tools and software designed to facilitate a thorough and legally sufficient analysis of items that contain digital evidence. It is important to allow a trained digital forensics jobs expert to conduct a proper seizure and examination on a piece of evidence so the investigator will have the best chance of using that evidence in a legal proceeding.
Read More

Wednesday, June 29, 2016

Using Certified check definition in fraud cases

What is Certified check definition ?

Certified check

Certified check definition is customer's cheques stamped with the paying bank's guarantee that the maker's signature is genuine and that there is enough money available in the older’s account to cover the amount to be paid. Certified check definition is liabilities of the bank and, when paid, are kept by the bank. These Certified cheques are immediately charged against the customer's account by debit memorandums. Some bank certified check permit customers to retrieve the original cheques by surrendering the debit memorandum.

Another certified check definition is also called cashier’s cheques. Certified check definition are cheques that have been issued and certified by a bank with itself as the drawer. These items are called treasurer’s cheques when issued by a trust company. Cashier's cheques are frequently an excellent lead to other bank accounts, stock, real property, and other assets. Because certified check definition can be held indefinitely, subjects sometimes purchase cashier's cheques instead of keeping large amounts of currency on hand.

To reconstruct a subject’s transactions with certified check definition, the fraud examiner must be sure that all Certified cheques are accounted for because subjects sometimes exchange previously purchased Certified cheques for new ones.

Bank cheques, such as cashier’s cheques, certified cheques, can be extremely time-consuming and expensive to locate unless the fraud examiner knows the date and number of the cheque. However, if the subject has deposited a bank certified cheques into his account or purchased a bank cheque using a certified check definition from his account, copies of bank certified cheques are much easier to obtain because the subject’s account records will reveal the date and number of the bank cheque.
Read More

Monday, June 27, 2016

The Importance of benefit fraud reporting

Benefit fraud reporting:


fraud report


Writing benefit fraud reporting is a critical skill for fraud examiners. A thorough investigation or keen analysis will often do little good if the fraud examiner cannot convey the information in a written format and benefit fraud reporting. Fraud examiners must be flexible in their writing technique because benefit fraud reporting should generally be tailored to the situation, as well as to the needs of the party requesting the report. Even so, many aspects of good writing; such as accuracy, relevancy, and clarity; are universal to all benefit fraud reporting.

Types of reports:

The two most common types of reports fraud examiners are engaged to create are fraud examination reports and expert reports:
  •  Fraud Examination Reports:

A fraud examination report documents the results of a fraud examination and is generally created by one or more critical members of the fraud examination team. fraud reporting is a particularly important function in fraud examinations. This fraud report conveys all evidence necessary to evaluate the case, and it can be used to corroborate previously known facts. An accurate fraud report will add credibility to the fraud examination and to the fraud examiner's work. Additionally, requiring a benefit fraud reporting will force the fraud examiner to consider his actions during an investigation by requiring that he documents his process. And a well- benefit fraud reporting will omit irrelevant information, thereby allowing pertinent facts to stand out. A first-rate fraud examination report is based on a first-rate fraud examination.
  •  Expert Reports:

Many fraud cases benefit from the assistance of an expert witness, who (unlike most witnesses) may provide technical opinions through his testimony. Typically, fraud examiners who serve as expert witnesses in litigation are tasked with providing an expert fraud report, which requires them to provide particular information about their qualifications, their opinions, the bases of those opinions, and various other pieces of information. The purpose of an expert fraud report is to inform the parties, the judge, and the jury (if applicable) about the expert’s opinion of the case, as well as his credibility for commenting on such issues.

The content of the report is highly dependent on the needs of the situation. For example, the expert witness might provide an expert opinion on an organisation’s auditing practices. If the expert used a benefit fraud reporting as part of the basis of forming the opinion, the benefit fraud reporting would likely need to be attached to the expert report.

However, each benefit fraud reporting in this scenario is a separate document with its own structure. In some situations, the person who wrote the fraud examination report might also be called as an expert witness, so it is important to keep in mind the different purposes of each benefit fraud reporting.

The Trial-Ready Standard:

A guiding principle for writing benefit fraud reporting is: "Would I be able to defend this report in a judicial proceeding?" Most fraud cases will not be presented in such proceedings, but the purpose of the benefit fraud reporting is to give an objective and reliable account and analysis of the facts of a case. A court or administrative hearing is the ultimate test of a report, because the judge or the opposing parties will thoroughly scrutinise it. Therefore, even when litigation is unlikely, a written benefit fraud reporting that can withstand scrutiny in a judicial proceeding is the gold standard. Fraud examiners should always know what reliable evidence is available to back up each statement expressed in the benefit fraud reporting and make sure that case analysis is of professional quality.
Read More

Report phone scams in fraud investigation

Using Report phone scams to detect fraud:

Report fraud
There are many types of public and nonpublic records like Report phone scams that can aid a fraud examiner's efforts. Nonpublic records ,financial or otherwise, might be needed to prove fraud or to provide leads in a fraud examination. It include information about a person or business considered to be private and confidential.
 The telephone records and report phone scams can provide valuable insight into fraud examinations. For example, report phone scams might provide contacts with real estate brokers or sellers, identify charge calls from holiday spots or contacts with coconspirators, or provide other leads to assets and expenditures.
Generally, a person's private phone lines, such as home phone and personal mobile devices, will be considered private. Therefore, the records for these lines will usually require consent from the subject about report fraud, a warrant or subpoena, or other legal order to produce the records.
However, some phone records and report phone scams might be accessible. For example, if a fraud examiner is conducting an internal investigation and the employer keeps business report phone scams, the fraud examiner might not have to obtain permission or a legal order to access these records.
Whether the records are private will depend on the laws of the relevant jurisdiction. Often, the expectation of privacy regarding business report fraud can be eliminated by having the employee sign a document upon being hired that acknowledges that phone calls, other electronic communications, and metadata may be recorded and reviewed by the employer and made as report phone scams. However, in some jurisdictions this might be prohibited, so employers should consult with legal counsel.
In another way, as a result of the proliferation of smart phones, report phone scams have become an essential element of most civil and criminal investigations. Report phone scams refers to techniques used to gather data from smart phones so that the data will be admissible in court. Organisations use report phone scams to determine whether a company device has been used in violation of its use policies.
There are many companies that provide report phone scams services, and there are numerous off-the-shelf tools available that can extract information from the hardware, microchips, and software of mobile phones. Generally, off-the-shelf forensic tools employ various ways to extract data from mobile devices to report phone scams, and in many investigations, it is best to use a combination of methods when gathering evidence by report phone scams. The main areas for recovering data on mobile devices to report phone scams are as follows:
  • Logical:

This includes the logical storage objects that reside on a logical store (e.g., a file system partition). The actual data that can be retrieved to report phone scams using a logical examination will vary, depending on the type of device, but the retrievable information could include text messages, multi-media messages, call registers, contacts, tasks, images, audio, videos, calendar entries, and so on;
  •  File system:

This includes information in the logical extraction and hidden information such as deleted information and operating system files.
  •  Physical:

This includes information on a physical store to report phone scams (e.g., flash memory or memory chip). But unfortunately, due to the vast array of mobile devices available, there is no single report fraud that will cover the range of devices used in today’s world.
 To complicate things further, report phone scams use methods different from traditional computer forensics because, among other things, mobile devices store data to report phone scams in various unique formats that prevent mobile devices from being copied in the same ways that computer hard drives can be imaged. But regardless of the differences, it is essential that report fraud procedures maintain the integrity of any data collected. For example, the Association of Chief Police Officers (ACPO) provides four principles report phone scams that investigators should adhere to when dealing with digital evidence. Those four principles are summarised as follows:
  
Investigators should not perform any action to report fraud that will change data contained on digital devices or storage media that might subsequently be relied upon in court. Individuals accessing original data for report phone scams must be competent to do so and have the ability to explain their actions.
  
When examining a mobile device to report fraud, an audit trail or other record of applied processes, suitable for replication of the results by an independent third party, must be created and preserved to accurately document each investigative step.
 The person in charge of the investigation using report phone scams should have overall responsibility for ensuring the aforementioned procedures are followed and in compliance with governing laws.
Read More

Predication definition in fraud careers

The importance of Predication definition


define predication


Fraud examiners should not conduct or continue fraud examinations without proper predication definition; Data analytics is instrumental in helping a fraud examiner define predication. Predication definition is the totality of circumstances that would lead a reasonable, professionally trained, and prudent individual to believe a fraud has occurred, is occurring, and/or will occur.

Define predication is the basis upon which a fraud investigation begins. Internal fraud investigations should not be conducted without define predication.

Suppose someone has submitted a tip that gives the fraud examiner reason to believe a particular fraud has occurred. Before accusing someone of wrongdoing, the fraud examiner must perform some preliminary work, such as data analysis, to determine predication definition; however, he must do this carefully to avoid defamation.

To illustrate this predication definition, imagine a bull's eye representing a particular fraud. The fraud examiner must stay on the outside of the bull's eye during the predication check. That means he should avoid conducting any interviews or making accusatory statements and instead use data analytics techniques that do not infringe upon anyone's rights. Because the investigation of fraud deals with the individual rights of others, an investigation must be conducted only with adequate cause or predication definition.
Read More

What is chain of custody definition in fraud cases?

What is chain of custody definition for the fraud examiner:


what is chain of custody


Establish what is chain of custody definition in fraud cases in fraud cases is important. If evidence is subject to change over time, or is susceptible to alteration, the offering party might need to establish that the evidence has not been altered or changed from the time it was collected through its production in court. This is done by establishing and define chain of custody. Thus, the chain of custody definition can be an important factor in establishing authenticity.

To clarify what is chain of custody, the chain of custody definition is both a process and a document that memorializes:


1) Define chain of custody by who has had possession of an object?

2) Define chain of custody by what they have done with it.

Chain of custody definition is simply a means of establishing that there has not been a material change or alteration to a piece of evidence. Thus, define chain of custody for an item of evidence demonstrates its authenticity, and it shows that the item has not been altered or changed from the time it was collected through production in court.
In general, chain of custody definition consists of documenting each person who had control or custody of the evidence; what is chain of custody, how and when evidence was received; how it was maintained or stored while in each person’s possession; what changes, if any, it underwent in that person’s custody; and how it left that person’s custody. The end result of chain of custody definition is a chain of testimony that accounts for the movement and location of physical evidence from the time, it is obtained to the time it is proffered at trial. The goal of chain of custody definition is to show that access to the evidence was limited to those who testified in the Chain of custody definition and thereby demonstrate that the evidence has not been materially altered.
Gaps in the Chain of custody definition (e.g., when it is not clear what occurred with a set of records) or outright mishandling (e.g., a group of questioned documents was not properly sealed), can dishevel a case but not wreck it outright. Courts have found in some cases that even though there have been mistakes in the Chain of custody definition, the mistake affects the “weight”, though not the “admissibility”, of evidence. That is to say, the evidence will still be allowed into the record, but it is accompanied by a forthright description of any improprieties that have occurred in the Chain of custody definition. The jury and judge are supposed to consider the improprieties when they deliberate, “weighing” the case for guilt or innocence.
To define chain of custody in fraud cases, the array of physical evidence, all the paper documents, audio and video recordings, and information-processing equipment, such as computers, demands some close monitoring to define chain of custody.
The following are some general guidelines that will help fraud examiners define chain of custody. They will also help fraud examiners in authenticating obtained evidence to clarify the chain of custody definition :
  • If records are received via mail or courier-receipted delivery, keep copies of the postmarked envelope or the delivery receipts is important in chain of custody definition;
  • If a cover letter is included, make sure you keep it to define chain of custody;
  • If the cover letter or transmittal letter includes a list of the documents, check the package immediately to ensure all documents are there to ensure chain of custody definition. If something is missing, make a note in the file and notify the sender immediately;
  • If you receive documents in person, the Chain of custody definition make obligation to create a memo stating the date and time the documents were received, who gave you the documents, where that individual obtained the documents, and a complete list of the documents received;
  • If you obtained the documents yourself from the original source (desk, file cabinet, etc.), to define chain of custody, you have to create a memo describing the date, time, exact location of where the documents were found, and a complete list of the documents obtained.
The Chain of custody definition obligate to keep the originals of these memos or delivery receipts in the case file and keep a copy with the documents (it will be much easier to identify where the documents came from if you have the information with the documents).
Additionally, because digital evidence can be easily altered or destroyed, a Chain of custody definition must be maintained for all electronic evidence gathered and analysed in an investigation. At a minimum, the following Chain of custody definition and procedures should be followed:
  •  Identify each item that contains relevant information;
  • Document each item, who it was received from, who authorised its removal, the location of the item, and the date and time the item was received;
  • Maintain a continuous record of the item’s custody as it changes hands.
Read More

Tuesday, June 21, 2016

Benefit fraud cases: types of evidence in law

Types of evidence in law in Benefit fraud cases:

best evidence rule
In benefit fraud cases, the fraud examiner will usually obtain a great types of evidence in law when conducting fraud investigations. It is critical that the fraud examiner understand the relevance of this types of evidence in law and how it should be preserved and presented.
Fraud examiner jobs should always keep in mind what is evidence in law can either help or hurt a case, depending on which ones are presented and how they are presented as a best evidence rule. They should strive to make certain that all relevant documents and types of evidence in law are included and that all irrelevant documents are eliminated.
Many Fraud examiner jobs pay too much attention to documents as types of evidence in law. It is easy to get bogged down in detail when examining records and to lose sight of a simple fact: Documents do not make cases; witnesses make cases. The documents and best evidence rule make or break the witness. So-called paper cases often confuse and bore a jury.
Basic procedures in handling types of evidence in law are required for it to be accepted, or given much weight, by the court to become best evidence rule. Generally, proof must be provided that the types of evidence in law is relevant, material, and authentic.
The relevance of documents cannot be easily determined early in a case. For that reason, all possible relevant documents should be obtained. If they are not needed, they can always be returned. Here are a few general rules regarding the collection of types of evidence in law: 
  • Obtain original best evidence rule where feasible. Make working copies for review, and keep the originals segregated;
  • Do not touch originals types of evidence in law any more than necessary; they might later have to undergo forensic analysis;
  • Maintain a best evidence rule and a good filing system for the documents. This is especially critical when large numbers of documents are obtained. Losing a key of types of evidence in law is very problematic, and can damage the case. Documents can be stamped sequentially for easy reference.


Obtaining what is evidence in law:

Documentary types of evidence in law may be obtained in a number of ways. It is possible to obtain evidence by consent, if both parties agree. This is the preferred method and best evidence rule. In some cases, consent can be oral, but when information is obtained from possible adverse witnesses, or the target of the examination, it is recommended that the consent must be in writing to be one of types of evidence in law. In many cases, however, the fraud examiner jobs will not wish to alert the suspect to his intentions and other routes must be taken. Types of evidence in law is owned by and in the control of the party that requests the information (e.g., documents in an employee’s desk drawers at the office), then the investigator is usually able to obtain the best evidence rule as required.
Additionally, to understand what is evidence in law, certain kind of records can be obtained as types of evidence in law by consent only if the subject of the records consents in writing. Accessing a subject’s bank records from financial institutions, for instance, generally requires written consent. If no consent is given and types of evidence in law is held by other parties or in uncontrolled locations, specific legal action might be required. Most often, the legal process used takes the form of a subpoena or other court order to produce the documents and records (including electronic records). Other forms of court orders can be used to obtain some types of evidence in law like witness evidence and statements.
Under no circumstances should the investigator attempt to obtain the best evidence rule by other means, as this can lead to charges of theft, trespass, and other sanctions.

Types of evidence in law:

There are two basic types of evidence in law: direct or circumstantial.

1- Direct types of evidence in law :

It shows prima facie the facts at issue; it proves the fact directly. What constitutes direct evidence depends on the factors involved. For example, in a case involving possible kickbacks, direct types of evidence in law might be a cheque from the vendor to the suspect.

2- Circumstantial types of evidence in law :

It is evidence that tends to prove or disprove facts in issue indirectly, by inference. In the case of a kickback allegation against Collins, cash deposits of unknown origin deposited to suspect's account around the time of the suspect transaction could be considered circumstantial types of evidence in law.

Organization of types of evidence in law:

Keeping track of the amount of paper generated is one of the biggest problems in fraud cases. It is essential that documents obtained be properly organized early in examination, and that they be continuously reorganized as the case progresses and the best evidence rule. Remember, it is usually difficult to ascertain the relevance of the types of evidence in law early in the case. To maintain good organization in complex cases, fraud investigator jobs should use the following methods.

Segregate the Documents of types of evidence in law:

In general, documents should be segregated by witness or transaction. In the former method, the examiner takes the list of names, whether employee, associate, or witness, and begins assembling collected documents by witness. Alternatively, the fraud examiner might find it easier to organize the information by grouping types of evidence in law of the same or similar transactions together. During the evidence gathering stage of an investigation, organizing the documents chronologically is not the best evidence rule and not recommended because it will make searching for relevant information more difficult. It is generally better to organize them by transaction or by party.
The examination report often follows a chronological timeline to give a narrative of a fraud scheme, in which case displaying key documents chronologically often makes sense. But in the organization phase, there usually is too much clutter for chronological organization to be effective.

Make a Key Document File:

Fraud investigator jobs should make a key document file to assure what is evidence in law , a separate file that contains copies of certain important pieces of information for quick access, for easy access to the most relevant documents. Periodically review the key documents. Move the less important documents to backup files and keep only the most relevant documents in the main file.

Establish a Database types of evidence in law:

Establish a database early on in the investigation and code all documents if there is a large amount of information to process. This database can be manual or computerised and accessed by keywords or Bates Stamp numbering. The coding system should provide meaningful and comparable data; therefore, the database should, at a minimum, include the following fields of information: the date of the document, the individual from whom the document was obtained, the date obtained, a brief description, and the subject to whom the document pertains.

Maintain a Chronology of types of evidence in law:

A chronology of events should be commenced early in the case. The purpose of maintaining a chronology is to establish the chain of events leading to the proof with best evidence rule. The chronology might or might not be made a part of the formal report; at a minimum, it can be used for analysis of the case and placed in a working paper binder. Keep the chronology brief and include only information necessary to prove the case. By making the chronology too detailed, you defeat its purpose. The chronology should be revised as necessary, adding new information and deleting irrelevant details.
Read More

Monday, June 20, 2016

Welfare fraud investigation process in the welfare fraud cases

 Definition of Welfare fraud investigation process:


Welfare fraud investigation process in the welfare fraud cases is a methodology of resolving signs or allegations of fraud meaning from inception to disposition. The welfare fraud investigation process establishes a uniform, legal process for resolving signs or allegations of fraud meaning on a timely basis. It provides that welfare fraud cases should move in a linear order, from the general to the specific, gradually focusing on the perpetrator through an analysis of types of evidence in law.



welfare fraud cases

welfare fraud penalties

 Welfare fraud investigation process involve efforts to resolve allegations or signs of fraud meaning when the full facts are unknown or unclear; therefore, welfare fraud investigation process seek to obtain facts and types of evidence in law to help establish what happened, identify the responsible party, and provide recommendations where applicable.


When conducting a welfare fraud investigation process to resolve signs or allegations of fraud, the fraud examiner jobs should assume litigation will follow, act on predication, approach welfare fraud cases from two perspectives, move from the general to the specific, and use the fraud theory approach.


 Assume Litigation and welfare fraud penalties Will Follow:

Each welfare fraud investigation process should begin with the proposition that the case will end in litigation and welfare fraud penalties.
Thus, when a fraud examiner jobs begins a welfare fraud investigation process, he must assume that the welfare fraud cases will end in litigation, and this assumption must be maintained and considered throughout the entire welfare fraud cases. If the fraud examiner jobs assumes that litigation will occur with welfare fraud penalties, he will conduct the examination in accordance with the proper rules of types of evidence in law and remain well within the guidelines established by the legal systems.


 Act on predication definition:

Fraud examiner jobs must adhere to the law; therefore, fraud examiners should not conduct or continue welfare fraud investigation process without proper predication definition. Predication definition is the totality of circumstances that would lead a reasonable, professionally trained, and prudent individual to believe that a fraud meaning has occurred, is occurring, and/or will occur. In other words, predication definition is the basis upon which an examination, and each step taken during the welfare fraud investigation process, is commenced.

A fraud examiner jobs acts on predication definition when he has a sufficient basis and legitimate reason to take each step in a welfare fraud investigation process.

Accordingly, fraud examinerjobs should begin welfare fraud investigation process only when there are circumstances that suggest fraud meaning has occurred, and they should not investigate beyond the available predication definition. If a fraud examiner jobs can't articulate a factual basis or good reason for an investigative step and welfare fraud investigation process, he should not do it. Therefore, a fraud examiner jobs should reevaluate the predication definition as the fraud examination proceeds. That is, as a welfare fraud investigation process progresses and new information emerges, the fraud examiner jobs should continually reevaluate whether there is adequate predication definition to take each additional step in the examination of welfare fraud cases. If a fraud examiner jobs acts without predication definition, he might expose both himself and his client or employer to liability.


The requirement for predication definition, however, does not bar fraud examiners from accepting other forms of engagements in circumstances where predication definition is lacking. For example, a fraud examiner jobs can conduct a fraud risk assessment for consulting purposes even if there is no reason to believe a fraud meaning has occurred.


 Approach from Two Perspectives:

Fraud examiner jobs should approach welfare fraud investigation process into fraud meaning from two perspectives:

1/ by seeking to prove that welfare fraud cases has occurred;

2/ by seeking to prove that welfare fraud cases has not occurred.

To prove that a welfare fraud cases has occurred, the fraud examiner jobs must seek to prove that fraud has not occurred. The reverse is also true. To prove welfare fraud cases has not occurred, the fraud examiner jobs must seek to prove that fraud has occurred. The reasoning behind this two perspective approach is that both sides of welfare fraud cases must be examined because under the law, proof of welfare fraud cases must preclude any explanation other than guilt leading to the welfare fraud penalties.


 Move from the General to the Specific:

Fraud examiner jobs start when the full facts are unknown or unclear; therefore, they should proceed from the general to the specific. That is, welfare fraud investigation process should begin with general information that is known, starting at the periphery, and then move to the more specific details.

To illustrate, consider the order of interviews in welfare fraud investigation process. In most examinations, fraud examiner jobs should start interviewing at the periphery of all possible interview candidates and move towards the witnesses who appear more involved in the matters that are the probable subject will have welfare fraud penalties. Thus, the usual order of interviews is as follows:


Neutral third-party witnesses, starting with the least knowledgeable and moving to those who are more knowledgeable about the welfare fraud cases at issue;

Parties suspected of complicity and welfare fraud penalties, starting with the least culpable and moving to the most culpable;
The primary suspect(s) of the welfare fraud investigation process use the Fraud meaning.


Use the fraud Theory approach :

When conducting welfare fraud investigation process, fraud examiner jobs should adhere to the fraud theory approach. The welfare fraud cases approach is an investigative tool designed to help fraud examiners organize and direct welfare fraud investigation process based on the information available at the time.
The welfare fraud cases theory approach provides that, when conducting welfare fraud investigation process into allegations or signs of fraud occurring a welfare fraud penalties, the fraud examiner jobs should make a hypothesis (or theory) of what might have
Occurred based on the known facts. Once the fraud examiner jobs has created a hypothesis, he should test it through the acquisition of new information (or correcting and integrating known information) to determine whether the hypothesis is provable. If, after testing a hypothesis, the welfare fraud investigation process determines that it is not provable and they won’t have welfare fraud penalties, he should continually revise and test his theory based on the known facts until it is provable to apply the welfare fraud penalties, he concludes that no welfare fraud cases is present, or he finds that the fraud meaning can't be proven.
Simply put, the welfare fraud investigation process involves the following steps:
 
  • Forensic data analysis;
  • Creating a hypothesis about the welfare fraud investigation process;
  • Testing the hypothesis about the welfare fraud investigation process;
  • Refining and amending the hypothesis about the welfare fraud investigation process.
 

Forensic data analysis:

Under the welfare fraud investigation process, fraud investigator jobs should begin by forensic data analysis, so he can create a preliminary hypothesis as to what has occurred.
Also, if those responsible determined that a forensic audit jobs of the entire purchasing function is warranted, the forensic audit jobs would be conducted at the time this determination is made. When conducting the forensic audit jobs, the internal auditors should keep in mind that there is a possibility that fraud meaning might exist.
 

Creating a Hypothesis about the welfare fraud investigation process:

Once fraud investigator jobs has finished the forensic data analysis in the welfare fraud investigation process, he should create a preliminary hypothesis as to what has occurred. The hypothesis should be a "worst-case" scenario. That is, based on the caller's statements, fraud investigator jobs should determine the worst possible outcome. Under these facts, the worst possible outcome would be that one of boss’s purchasing agents has been accepting kickbacks to steer business to a particular vendor.
Welfare fraud investigation process can create hypotheses for any specific allegation (e.g., a bribery or kickback scheme, embezzlement examples, conflict of interest, fraud transactions, or financial statement fraud).
 

Testing the Hypothesis about the welfare fraud investigation process:

Once fraud investigator jobs has created a hypothesis, he should test it through the acquisition of new information or by correcting and integrating known information.
 
Testing a hypothesis in welfare fraud investigation process involves creating a "what-if" scenario.
Refining and Amending the Hypothesis about the welfare fraud investigation process:
If, after testing a hypothesis, the fraud examiner jobs in the welfare fraud investigation process, determines that it is not provable, the fraud examiner jobs should continually revise and test it based on the known facts. For example, if the fraud examiner tests his hypothesis and determines that the facts do not fit the presence of a bribery scheme, it could be that no fraud is present or that the fraud cannot be proven by the welfare fraud investigation process.
Read More