-->
Showing posts with label investigation. Show all posts
Showing posts with label investigation. Show all posts

Monday, October 17, 2016

The first steps that management should take when Suspicions or Allegations of Fraud becomes known

Initial Response to Suspicions or Allegations of Fraud

 
 
Suspicions of Fraud

 When responding to suspected and detected incidents of fraud, time is critical. Management and fraud examiners must be prepared to address a number of issues in a short amount of time, sometimes under stressful conditions.
Initially, when a suspicion or allegation of fraud arises, management must respond quickly. The failure to act quickly against suspicions of fraud could result in litigation, enhanced penalties, and enforcement actions by government regulators. The appropriate response varies depending on the facts, such as the underlying evidence, who is implicated, how the evidence came about (e.g., internal sources, civil lawsuit, investigation by the government), and so on. But generally, when evidence of fraud arises, management should respond by engaging in the following actions:
  • Activate the response team.
  • Engage legal counsel, if necessary.
  • Consider contacting the insurance providers.
  • Address immediate concerns.
  • Conduct an initial assessment.
  • Document the initial response.

Activate the Response Team:

When evidence of fraud arises, management must activate the fraud response team—the group of people tasked with responding to incidents of fraud. When activated, the response team should seek to answer the following questions:
  • Is a formal investigation necessary?
  • If a formal investigation is necessary, who will lead it?
  • Is there a need for immediate police involvement?
  • Is there an immediate need for legal assistance or advice?
  • Is there a need for external support (e.g., forensics specialists)?
  • Is there a need for additional support (e.g., access to IT facilities or a secure room, support from administration)?
  • Is there a need to devise a media strategy to deal with the issue?
  • Is there a need to report the issue to an external third party?
  • Should the audit committee be informed?

Engage Legal Counsel:

Because incidences of fraud are riddled with legal uncertainties, management should consult with internal and possibly external local legal counsel before making any decisions or taking any action concerning the suspected conduct. Typically, the general counsel should be made aware of any significant fraud that might result in legal action.
 

Consider Contacting the Insurance Provider:

When evidence of fraud arises, it is generally impossible to know whether the incident will result in an insurance claim, but even so, many insurance policies require timely notice of potential claims. Therefore, an organisation should consider putting its insurer on notice to preserve a potential insurance claim.

Address Immediate Concerns:

Also, when evidence of fraud arises, management and the response team should address immediate concerns. Immediate concerns will vary, but they might include:
  • Preserving relevant documents
  • Identifying who should be informed

Preserving Relevant Documents:

When evidence of fraud arises, management should seek to preserve all relevant documents, especially those that an employee might want to hide or destroy. In a fraud investigation context, the term documents typically refers to, but is not limited to, contracts, invoices, correspondence, memoranda, weekly reports, presentations, telephone messages, emails, reports, performance reviews, performance improvement plans, medical records, and other written or recorded material.
 
When evidence is misplaced, lost, or destroyed, it becomes more difficult to conduct an investigation. Thus, the response team and management must take action to preserve evidence as soon as the decision to investigate is made. There are a number of steps that management should take to preserve relevant documents. For one thing, management should work with legal counsel to issue a litigation hold to notify employees to suspend the destruction of potentially relevant records.
 
Furthermore, management should suspend the organisation’s record retention policy temporarily to avoid a piece of evidence accidentally being destroyed.
Also, management could lockdown access to emails or digital files that employees might want to conceal or destroy. Digital information can be found in virtually any type of media, and it is more fragile than tangible evidence. Therefore, employees can destroy this type of information if it is not protected properly. Often, when fraudsters become aware of an investigation, they try to destroy evidence in their computers or sabotage other evidence that could be used against them. Accordingly, it is a good idea to have IT personnel involved in this process each time the organisation decides to conduct an investigation.
 
The failure to preserve documents could have several adverse consequences. First, the failure to preserve documents could result in the government’s questioning of the integrity of any fraud investigation. Second, documents destroyed when litigation is expected, or in progress, might give rise to claims of spoliation of evidence, which, if proven, could lead to monetary fines and sanctions, adverse inference jury instruction sanctions, or dismissal of claims or defences. Spoliation is broadly defined as the act of intentionally or negligently destroying documents relevant to litigation.
 In today’s digital environment, digital spoliation is a major concern for organisations involved in litigation. When compared to the spoliation of tangible documents, digital spoliation carries additional risks. Management often lacks sufficient knowledge of the inventory of digital information, and electronic data might only be available for an evanescent time. Additional concerns include business practices designed to free up storage space by deleting digital information and the fact that electronic data can reside in numerous locations, as well as the fact that identifying relevant electronic data within today’s large and complex data systems can be challenging and costly.
 

Identifying Who Should Be Informed:

Management and the response team should identify whom to inform. Depending on the facts, several departments should be interested in fraud, including legal, human resources, internal audit, security, risk management, and loss prevention or security. When responding to an allegation of fraud, it is important to consider the interests of each of these departments. This is necessary to ensure that designated employees are notified immediately to enable a prompt response. Information about incidences, however, should be shared only on a need-to-know basis.
 Human resources (HR) personnel address issues involving unfair treatment, discrimination, harassment, substance abuse, or concerns about corporate policies. Therefore, the HR department should be informed of fraud that affects any such areas.
Both the HR and legal departments should be involved to ensure that the right people receive information in a timely manner. Also, other departments, such as loss prevention and risk management, audit, and security might need to be involved. Although the development of information distribution rules requires the participation of several departments, it is best to have these rules set before investigation protocols are in place.
 
Another department that needs to be involved is the information technology (IT) department. The IT department might need to be part of an investigation to safeguard data until it can be analysed. IT personnel can also help identify what data are available and where, and they might be able to function as forensic investigators if licensed to do so.
Again, management must restrict access to certain pieces of information on a need-to-know basis.

Conduct an Initial Assessment to Determine the Appropriate Response:

Usually, when an allegation of fraud arises, there are not enough known and verified facts to begin a formal investigation; therefore, management and the response team should conduct an initial assessment to determine if an investigation is needed and what steps, if any, are required to respond in an appropriate manner. This is perhaps the most critical question that management must answer when an allegation of fraud arises.
 
An initial assessment should be quick and, unless complications arise, completed within a few days. Ideally, action should be taken within three days of learning about an incident.
The initial assessment should be a limited fact-finding analysis focused on the specific allegation or incident. It does not require an investigation plan or report, unlike a formal investigation. Thus, the initial assessment should seek to:
  • Determine if fraud occurred.
  • Identify the status of the fraud (e.g., When did it begin? Was it internal or external? Is it still occurring? If it is no longer occurring, when did it stop?).
  • Identify potential claims and offences.
To conduct an initial assessment and determine the appropriate response, those responsible should take the following steps:
  • Understand the context.
  • Review any applicable policies and procedures.
  • Investigate the allegations.
  • Document the reasons for the decision.

Understand the Context:

Next, those responsible should gain an understanding of all of the circumstances leading up to the current situation. Often, the context is necessary to determine the best approach to dealing with a tip or suspicion, and it can provide clues that are helpful in other areas.
 
Efforts to understand the context should seek to obtain the initial facts and circumstances about:
  • The manner in which the suspicions became known
  • The date suspicions became known
  • The areas to which the suspicions pertain
  • The source of the information
  • The allegations at issue

Review Any Applicable Policies and Procedures:

Those involved in the initial assessment must also review any applicable internal controls and organisational policies, including any anti-fraud auditing and testing policies and procedures, to determine the best method and processes for continuing the investigation.
 

Investigate the Allegations:

An initial assessment should be a limited, fact-finding analysis, and it should focus on investigating the specific allegation or incident. More specifically, to determine the appropriate response, the assessment should, if possible, seek to answer a number of questions, including:
  • Is the allegation credible?
  • Who is the subject of the allegation, and what is his relationship to the company?
  • When did the alleged misconduct occur, and how often did it occur?
  • What was the business purpose of the activity related to the allegation?
  • How serious is the allegation?
  • What levels of employees are alleged to be involved, if any, in the misconduct (i.e., officers, directors, or managers)?
  • What individuals might have pertinent information about the matter that would tend to support or refute the complainant’s position, and what facts do these individuals purportedly know?
  •  Did any third parties receive any direct or indirect benefit from the misconduct, and if so, who are they?
  • If a third party is involved, is the third party a government official?
  •  How was the matter recorded on the company’s books and records, if applicable?
  • Can it be determined if the person in question acted with fraudulent intent?
  • Is it possible that the issue might be larger than expected?
  • Were there any whistleblowers, and if so, how should they be dealt with?
  • What measures should the company take to document how the initial evidence of wrongdoing was handled?
  • Is the government already involved, and if not, is it likely that the government will become involved?
  • Is it likely that the matter will have significant negative impact on shareholder value?
These questions are important because the response should be proportional to the potential scale of the fraud in terms of its value, frequency, potential damage, the individuals involved, the number of people involved, and so on.
 
In addition, the decision as to the appropriate response might be influenced by other factors.
As with any business decision, the cost of conducting the investigation must be considered, and management might also consider whether an investigation will interrupt business activity.
 
Generally, the investigation portion of the initial assessment will involve:
  • Contacting the source, if the investigation was triggered by a report or complaint
  • Interviewing key individuals
  • Reviewing key evidence

CONTACTING THE SOURCE:

If the evidence came in through a tip from an identified source, those responsible should contact the source to find out additional information and confirm the source’s willingness to help throughout the investigation. When contacting the source, the interviewer should encourage the complainant to provide a narrative description of the report. After the source provides the narrative, the interviewer should ask clarifying questions and then summarise the key points.
An interview with the source should seek to determine:
  • What does the individual know?
  • How did the individual get the information?
  • Who were the key individuals involved?
  • When did the alleged events occur (e.g., dates, times, and locations)?
  • What are the details (e.g., who, what, when, where, why, and how much) of the allegations?
  •  What are the dates (or period) of the key events?
  • What evidence exists to corroborate the alleged events, where is the evidence located, and how can the evidence be accessed?
  • What witnesses can corroborate the alleged events?
  • Which individuals might have pertinent information about the matter that would tend to support or refute the complainant’s position, and what facts do these individuals purportedly know?
  • What was the motivation behind the alleged events?
  • Why were the alleged actions improper?
  • If the scheme is ongoing, do the subjects know of the complainant’s report?
  • What is the complainant’s motivation for making the report (e.g., What prompted you to report this?)?
When interviewing the source, the interviewer should seek to determine if there is any reason to suspect the complainant’s credibility. Also, if there are any weaknesses in the complainant’s information, the interviewer should ask the complainant to explain what he expects the subject would say in defence of the allegations and ask the complainant to explain why such a response is not sufficient to dispose of the matter. Additionally, the interviewer should ask the source what he wants the organisation to do about the complaint. The response to such an inquiry will help the team focus its efforts.

INTERVIEWING KEY INDIVIDUALS:

Those responsible should interview key individuals for information about the suspicious conduct and the subject(s). Interviewing individuals with personal knowledge is critical. Also, they should interview witnesses as early as possible because it will limit the harm arising from loss of memory, witnesses becoming unavailable, and inadvertent loss or destruction of key evidence.
 

REVIEWING THE EVIDENCE:

Those responsible should review relevant documents and files, which might include personnel files, the organisation’s employee handbook, accounting records, vendor activity reports, budget reports, fixed asset records, expense reimbursements records, leasing documents, rental agreements, payroll records, purchasing requisitions, purchase contracts, inventory records, shipping/receiving reports, emails, telephone records, and so on.
Obtaining and reviewing these documents will assist in understanding the chronology of events and might put the responsible parties on notice as to certain strengths or weaknesses of the investigation.

Document the Reasons for the Decision:

To avoid any real or perceived downplay of the matter’s significance and to avoid any attempts at wilful blindness, those responsible should document their actions and findings.
In addition, management must document its decisions and the reasons behind them. Thus, if management decides against conducting an investigation, it must document the reasons why.
 
Again, management should document the organisation’s initial response in an incident report log that serves as a record of the organisation’s response efforts. Once a suspicion of fraud arises, the issue should be recorded and detailed in the log. As the issue progresses, the log should be modified and, ultimately, it should contain details of actions taken and conclusions reached.
The incident report log should contain all information relevant to or created during the initial response that is used to support management’s decision making.
Read More

Tuesday, October 11, 2016

Key Components to Develop a fraud prevention strategy

Fraud prevention strategy

 fraud prevention strategy
 
To help ensure that an organisation responds to suspicious fraud-related activity efficiently, management should have a fraud prevention strategy in place that outlines how to respond to such issues. When evidence of misconduct arises, management must respond in an appropriate and timely manner. During the initial response, time is critical.
A fraud prevention strategy outlines the actions that members of an organisation will take when suspicions of fraud have arisen. Because every fraud is different, the fraud prevention strategy should not outline how a fraud examination should be conducted. Instead, fraud prevention strategy should help organisations manage their responses and create environments to minimise risk and maximise the potential for success.
Additionally, a fraud prevention strategy will allow management to respond to suspected and detected incidents of fraud in a consistent and comprehensive manner. By having a fraud prevention strategy in place, management will send a message that it takes fraud seriously.
More specifically, the fraud prevention strategy should guide the necessary action when potential fraud is reported or identified.
Also, a fraud prevention strategy should not be unduly complicated; for a response plan to work in high-pressure and time-sensitive situations, it must be simple to understand and administer.
While the appropriate response will vary based on the event, management should include a range of scenarios in the fraud prevention strategy.
Organisations without a fraud prevention strategy might not be able to respond to issues properly, and will likely expend more resources and suffer greater harm than those that have such a plan in place. Conversely, having a fraud prevention strategy puts an organisation in the best position to respond promptly and effectively.
The elements of a fraud prevention strategy include:
  • Reporting protocols
  • A response team responsible for conducting an initial assessment
  • Factors used to decide on the course of action
  • Litigation hold procedures
  • Principles for documenting the response plan
  • A template or form to report fraud incidents

Reporting Protocols :

One of the first steps when developing a fraud prevention strategy is to establish reporting protocols for tips, matters, allegations, and other indicators of improper activity. Reporting protocols are necessary to ensure that designated individuals are notified immediately to enable a prompt response.
 
Reporting protocols should outline notification principles and escalation triggers that vary depending on the nature and severity of the allegations. That is, they should indicate how to communicate the incidents to the appropriate level of management. For example, a fraud prevention strategy might instruct employees to report suspicions of fraud to their manager (if possible), a designated human resources (HR) or compliance officer, or the head of audit and enforcement.
Next, the issue should be reported to the party or parties responsible for conducting an initial assessment to determine how to respond and whether a full investigation is necessary.
Additionally, organisations should provide multiple channels for reporting concerns about fraud.
 

A Response Team :

 No single person can effectively address every fraud-related issue. Therefore, the fraud prevention strategy must identify key individuals who might be required to respond to a particular fraud. The response team members will vary depending on the facts and the potential severity of the suspected fraud, but the team might include:
  • Legal counsel
  • A representative of management
  • A Fraud Examiner
  • The finance director
  • General counsel
  • A representative of internal audit
  • Audit committee members
  • A C-level executive
  • Information technology (IT) personnel
  • A representative of human resources (HR)

Factors Used to Decide on the Course of Action :

Again, the response team should determine the appropriate course of action when fraud is suspected. In general, if an allegation of fraud-related misconduct arises, management should conduct an investigation, but there are other courses of action it might decide to take. To help decide the best course of action, management should identify a list of factors it will use to make this decision. Identifying such factors will help the response team determine whether to escalate an incident into an investigation.
Each organisation will have different criteria for deciding whether allegations/suspicions qualify for a formal investigation, but common ones include:
  • Credibility of the allegation
  • Type of incident
  • The subject of the allegation
  • The business purpose of the activity at issue
  • Seriousness or severity of the allegation
  • Potential negative impact
  • Likelihood that the incident will end up in court
  • The ways in which prior, similar incidents were handled

Litigation Hold Procedures :

If an organisation does not already have litigation hold procedures in place, management should institute them immediately. A litigation hold refers to the steps an organisation takes to notify employees to suspend the destruction of potentially relevant records when the duty to preserve information arises.
Litigation hold procedures are necessary to ensure that potentially responsive documents are not destroyed once evidence of misconduct arises. The failure to preserve relevant evidence could have several adverse consequences, including, but not limited to, the government’s questioning of the integrity of any fraud investigation, monetary fines and sanctions, adverse inference jury instruction sanctions, or dismissal of claims or defences.
To establish litigation hold procedures, management should:
  • Identify the scope of litigation hold procedures (i.e., the locations that the litigation hold procedures will cover).
  • Examine how information moves through the organisation.
  • Determine how to identify relevant documents.
  • Develop a process to ensure such information is preserved.
Litigation hold procedures should apply to individual communications (e.g., email, chat messages, voice recordings), data on shared devices (e.g., network folders), system backup files, and archived data.
In general, litigation hold policies should be developed so the organisation can:
  • Promptly notify employees who might possess relevant documents.
  • Issue a preliminary hold order to all individuals and employees who might possess relevant information.
  • Promptly notify information technology (IT) personnel and get their involvement if electronic data is at issue.
  • Notify employees and IT personnel of their duty to preserve.
  • Suspend any deletion protocols.
  • Prohibit the destruction, loss, or alteration of any potentially relevant documents.
  • Prohibit employees from destroying, hiding, or manipulating documents.
  • Alert employees as to the risk to the company and the employees if they fail to heed the litigation hold request.
Moreover, establishing litigation hold procedures will help those involved in an investigation identify the relevant sources of information quickly, and it will help them understand the technology options available for searching, analysing, and reviewing data.
Even though litigation holds should apply to both electronic data and physical documents, electronic data contains certain attributes that make executing a timely litigation hold more difficult. Specifically, electronic data might only be available for a temporary period, business practices are often designed to free up storage space by deleting this type of information, electronic data can reside in numerous locations, and identifying relevant electronic data within today’s large and complex data systems can be challenging and costly.
 
Moreover, if an organisation operates internationally, it is more difficult to execute a timely hold. In such cases, management should consider retaining an outside expert to help with the data search and preservation.
A key objective of a litigation hold is to stop any automatic document deletion programmes or rules that might be in place.
Read More

Thursday, August 4, 2016

What is the the real forgery definition to detect fraud

Forgery definition 

forgery meaning
 

A forgery definition is any writing prepared with the intent to deceive or defraud. Thus, forgery meaning occurs when an individual, with intent to defraud, makes or alters a document apparently capable of defrauding another.

A document is not a forgery crime just because it contains a false representation. To constitute a  forgery definition, the writing as a whole must have apparent legal significance. In addition, forgery crime occurs not only when an entire writing or instrument is created, but also when there is any material alteration that affects the legal significance of the document or whenever a signature on a writing is fraudulently procured from a person who does not know what he is signing. Furthermore, the forgery definition is committed even if no one is actually defrauded.

Forged Maker Schemes in forgery definition

Forgery definition can include not only the signing of another person’s name to a document such as a cheque (check forgery) with a fraudulent intent, but the forgery crime is also the fraudulent alteration of a genuine instrument.

This forgery definition is so broad that it would encompass all cheque tampering schemes. For the purposes of this post, the forgery definition has been narrowed to fit the fraud examiner’s needs. To properly distinguish the various methods used by individuals to tamper with cheques, the concept of “forgery crime” will be limited to those cases in which an individual signs another person’s name on a cheque.

The person who signs a cheque in forgery definition is known as the “maker” of the cheque. A forged maker scheme can thus be defined as a cheque tampering scheme in which an employee misappropriates a cheque and fraudulently affixes the signature of an authorised maker thereon. Frauds that involve other types of cheque tampering, such as the alteration of the payee or the changing of the dollar amount, are classified separately.

To forge a cheque, an employee must have access to a blank cheque, be able to produce a convincing forgery meaning of an authorised signature, and be able to conceal his crime.

Concealment is a universal problem in cheque tampering schemes; the methods used are basically the same whether one is dealing with a forged maker scheme, an intercepted cheque scheme, or an authorised maker scheme. 


Obtaining the Cheque for the forgery definition

EMPLOYEES WITH ACCESS TO COMPANY CHEQUES

One cannot forge a company cheque unless one first possesses a company cheque. Most schemes of forgery meaning are committed by accounts payable clerks, office managers, bookkeepers, or other employees whose duties typically include the preparation of company cheques. These are people who have access to the company chequebook on a regular basis and are therefore in the best position to steal blank cheques.


EMPLOYEES LACKING ACCESS TO COMPANY CHEQUES

If perpetrators do not have access to the company chequebook through their work duties, they will have to find other means of forgery definition and misappropriating a cheque. The method by which a person steals a cheque depends largely on how the chequebook is handled within a particular company. In some circumstances, the chequebook is poorly guarded and left in unattended areas where anyone can get to it. In other companies, the cheque stock might be kept in a restricted area, but the perpetrator might have obtained a key or combination to this area, or might know where an employee with access to the cheques keeps his own copy of the key or combination. An accomplice might provide blank cheques for the fraudster in return for a portion of the stolen funds. Perhaps a secretary sees a blank cheque left on a manager’s desk or a custodian comes across the cheque stock in an unlocked desk drawer.

In some companies, cheques are computer-generated. When this is the case, an employee who knows the password for preparing and issuing cheques can usually obtain as many unsigned cheques as he desires and commit a forgery definition. There are an unlimited number of ways to steal a cheque, each dependent on the way in which a particular company guards its blank cheques. In some instances, employees go as far as to produce counterfeit cheques.
 
forgery crime
 


To Whom Is the Cheque Made Payable in forgery definition?

TO THE PERPETRATOR

Once a blank cheque has been obtained, the perpetrator must decide to whom it should be made payable. In most instances forged cheques are made payable to the perpetrator himself so that they can be easily converted to the forgery definition. Cancelled cheques that are payable to an employee should be closely scrutinised for the possibility of fraud and forgery meaning.

If the perpetrator owns his own business or has established a shell company, he will usually write fraudulent cheques to these entities rather than himself. These cheques are not as obviously fraudulent on their faces as cheques made payable to an employee. At the same time, these cheques are easy to convert because the perpetrator owns the entity to which the cheques are payable.
 

TO AN ACCOMPLICE

If a fraudster is working with an accomplice, he can make the forged cheque payable to that person. The accomplice then cashes the cheque and splits the money with the employee fraudster. Because the cheque is payable to the accomplice in his true identity, it is easily Converted and the forgery definition is done. An additional benefit to using an accomplice is that a cancelled cheque payable to a third-party accomplice is not as likely to raise suspicion as a cancelled cheque to an employee. The obvious drawback to using an accomplice in a scheme is that the employee fraudster usually has to share the proceeds.


TO “CASH”

The perpetrator might also write cheques payable to “cash” to avoid listing himself as the payee. Cheques made payable to cash, however, must still be endorsed. The perpetrator will have to sign his own name or forge the name of another to convert the cheque. Cheques payable to “cash” are usually viewed more sceptically than cheques payable to persons or businesses. Some institutions might refuse to cash cheques made payable to “cash” to avoid forgery definition.

TO VENDORS

Not all fraudsters forge company cheques to obtain cash. Some employees use forged maker schemes to purchase goods or services for their own benefit. These fraudulent cheques are made payable to third-party vendors who are uninvolved in the fraud. For instance, the forgery definition is done if an employee might forge a company cheque to buy a computer for his home. The computer vendor is not involved in the fraud at all. Furthermore, if the victim organisation regularly does business with this vendor, the person who reconciles the company’s accounts might assume that the cheque was used for a legitimate business expense.
 
forgery meaning
 
 

Forgery definition by Forging the Signature

After the employee has obtained and prepared a blank cheque, he must forge an authorised signature to convert the cheque. The most obvious method, and the one that comes to mind when one thinks of the word forgery definition, is to simply take pen in hand and sign the name of an authorised maker.

 

FREE-HAND forgery definition

The difficulty a fraudster encounters when physically signing the authorised maker’s name is in creating a reasonable approximation of the true signature. If the forgery definition appears authentic, the perpetrator will probably have no problem cashing the cheque. In truth, the forged signature might not have to be particularly accurate. Many fraudsters cash forged cheques at liquor stores, grocery stores, or other institutions that are known to be less than diligent in verifying signatures and identification. Nevertheless, a poorly forgery definition by forged signature is a clear red flag of fraud. The maker’s signature on cancelled cheques should be reviewed for forgery meaning during the reconciliation process.


PHOTOCOPIED forgery definition

To guarantee an accurate forgery definition, some employees make photocopies of legitimate signatures. The signature of an authorised signer is copied from some document (such as a business letter) onto a transparency and then the transparency is laid over a blank cheque so that the signature copies onto the maker line of the cheque. The result is a cheque with a perfect signature of an authorised maker.
 
forgery
 

Forgery definition by AUTOMATIC CHEQUE and SIGNING MECHANISMS

Companies that issue a large number of cheques sometimes use automatic cheque-signing mechanisms in lieu of signing each cheque by hand. Automated signatures are produced with manual instruments, such as signature stamps, or they are printed by computer. Obviously, a fraudster who gains access to an automatic cheque-signing mechanism will have no trouble forging the signatures of authorised makers. Even the most rudimentary control procedures should severely limit access to these mechanisms.

The same principle applies to computerised signatures. Access to the password or programme that prints signed cheques should be restricted, specifically excluding those who prepare cheques and those who reconcile the bank statement.


Converting the Cheque in forgery definition

To convert the forged cheque, the perpetrator must endorse it. The endorsement is typically made in the name of the payee on the cheque. Since identification is typically required when one seeks to convert a cheque, the perpetrator usually needs fake identification if he forges cheques to real or fictitious third persons. As discussed earlier, cheques payable to “cash” require the endorsement of the person converting them. Without a fake ID the perpetrator will likely have to endorse these cheques in his own name. An employee’s endorsement on a cancelled cheque is obviously a red flag.


 Endorsement Schemes in forgery definition


Forged endorsements are those cheque tampering schemes in which an employee intercepts a company cheque intended to pay a third party and converts the cheque by endorsing it in the third party’s name. In some cases the employee also signs his own name as a second endorser. 

A fraudster’s main dilemma in a forged endorsement scheme (and in all intercepted cheque schemes, for that matter) is gaining access to a cheque after it has been signed. The fraudster must either steal the cheque between the point where it is signed and the point where it is delivered, or he must re-route the cheque, causing it to be delivered to a location where he can retrieve it. The manner used to steal a cheque depends largely upon the way the company handles outgoing disbursements. Anyone who is allowed to handle signed cheques might be in a good position to intercept them.


Forgery definition by Intercepting Cheques Before Delivery


EMPLOYEES INVOLVED IN DELIVERY OF CHEQUES

Obviously, the employees in the best position to intercept signed cheques are those whose duties include the handling and delivery of signed cheques. The most obvious example is a mailroom employee who opens outgoing mail containing signed cheques and steals the cheques. Other personnel who have access to outgoing cheques might include accounts payable employees, payroll clerks, and secretaries.


POOR CONTROL OF SIGNED CHEQUES

Unfortunately, employees are often able to intercept signed cheques because of poor internal controls. For instance, many employees simply find signed cheques left unattended in the work areas of the individuals who signed them or the people charged with their delivery. In these cases it is easy for the perpetrator to steal the cheque. Another common breakdown occurs when the person who prepares a cheque is also involved in the delivery of that cheque once it has been signed.

 In addition to the preceding example, secretaries or clerks who prepare cheques for their bosses to sign are often responsible for mailing those cheques. It is very simple for those employees to make out a fraudulent cheque and obtain a signature, knowing that the boss will give the signed cheque right back to them. This scheme is indicative of the key problem with occupational fraud: trust. For an office to run efficiently, high-level employees must be able to rely on their subordinates. Yet this reliance is precisely what puts subordinates in a position to defraud their employer.


forgery definition by Theft of Returned Cheques

Cheques that have been mailed and are later returned to the victim for some reason, such as an incorrect address, are often targeted for theft by fraudsters. Employees with access to incoming mail are able to intercept these returned cheques and convert them by forging the intended payee’s endorsement.


Forgery definition by Re-Routing the Delivery of Cheques

Employees might also misappropriate signed cheques by altering the addresses to which those cheques are mailed. These perpetrators usually replace the payee’s legitimate address with an address where the employee can retrieve the cheque, such as the employee’s home or a PO Box the employee controls. In other instances, the perpetrator might purposely misaddress a cheque so that it will be returned as undeliverable. The employee steals the cheque after it is returned to the victim organisation.

 Obviously, proper separation of duties should preclude anyone who prepares disbursements from being involved in their delivery. Nevertheless, the person who prepares a cheque is often allowed to address and mail it as well. In some instances where proper controls are in place, employees are still able to cause the misdelivery of cheques.


Forgery definition by Converting the Stolen Cheque

Once a cheque has been intercepted, the perpetrator can cash it by forging the payee's signature, hence the term forged endorsement scheme. Depending on where he tries to cash the cheque, the perpetrator may or may not need fake identification at this stage. If a perpetrator is required to produce identification to cash his stolen cheque, and if he does not have a fake ID in the payee’s name, he might use a dual endorsement to cash or deposit the cheque. In other words, the perpetrator forges the payee’s signature as though the payee had transferred the cheque to him, and then the perpetrator endorses the cheque in his own name and converts it. When the bank statement is reconciled, dual endorsements on cheques should always raise suspicions, particularly when the second signer is a company employee. 
Read More

Saturday, July 2, 2016

Use of Digital forensics jobs in fraudd cases

Conducting an Investigation Involving digital forensics jobs:


 computer forensics jobs

Fraud examiners must be prepared to address the myriad issues related to examinations involving digital forensics jobs and computer forensics jobs.

The increasing usage of the Internet and other technology in all aspects of life has created new opportunities for technology to be used in perpetrating almost every type of fraud, and in most fraud cases, investigators gather some type of digital evidence by digital forensics jobs.

Digital forensics jobs are investigations that involve relevant digital data processed or stored by digital devices, devices that process data in the form of numbers (digits). Digital devices can be used to communicate with others, create documents, access data online, enter data online, store information, and so on. An investigator leading a digital forensics jobs into a crime that involves a digital device is not necessarily, and in most cases, should not be, the forensic examiner.

Conversely, digital forensics jobs encompasses the recovery and investigation of material found in digital devices.

 Hiring experts of computer forensics jobs :

When conducting an examination involving computer forensics jobs, fraud examiners should determine whether a digital forensics jobs expert is needed. digital forensics jobs experts are individuals who specialize in identifying, recovering, collecting, preserving, processing, and producing digital data for use in investigations and litigation. Some organisations have their own in-house personnel whom they have trained and outfitted with the proper equipment and software tools to conduct the examination and analyse digital evidence, while others might prefer the use of an outside examiner who will be able to conduct a digital forensics jobs, prepare a proper report, and deliver expert testimony if needed in legal proceedings.
Sometimes retrieving digital data in digital forensics jobs is as easy as searching the target computer’s hard drive, but other times retrieval requires a thorough knowledge of computers to conduct a computer forensics jobs. For example, many fraudsters delete or hide incriminating files, and in these instances, efforts must be made to recover or find such data. There are, in fact, a variety of ways in digital forensics jobs of recovering deleted or hidden data from a target computer, and digital forensics jobs experts are specially trained for such tasks.
Specifically, digital forensics jobs experts are capable of analysing digital media at the hexadecimal level, which means that such experts can view every sector, and all the bytes in those sectors, on a system. Thus, digital forensics jobs experts can recover data from deleted files, both those that have been purposefully deleted and those that were accidentally deleted.
Deleted files are recoverable in digital forensics jobs until they are overwritten because data is not erased from a computer’s hard drive until it is overwritten. A deleted file will remain present on a hard drive until the operating system overwrites all or some of the file. So, deleted files that have been overwritten generally are not recoverable by digital forensics jobs.
digital forensics jobs experts can also recover temporary auto-save files, print-spool files, deleted emails, and deleted link (shortcut) files, and they can work with data at the hexadecimal level.
The hexadecimal level contains various items found in restore points and registry files that define hardware, such as external drives and websites visited, in addition to the document revisions and files created and maintained by the user.
Computer forensics jobs and specialists can recover, among other things, the following types of information from computer systems:
  • Deleted files and other data that has not been overwritten (e.g., deleted documents, images, link or shortcut files, and email messages);
  • Files deleted through computer-automated processes;
  • Temporary auto-save files;
  • Print-spool files;
  • Websites visited, even where the browser history and cache have been deleted;
  • Communications sent via chat or instant messenger;
  • Financial-based Internet transactions;
  • Documents, letters, and images created, modified, or accessed, even if the data was not saved on the computer in some situations;
  • Data that has been copied, corrupted, or moved;
  • The time and date information about files (e.g., when files were created, accessed, modified, installed, deleted, or downloaded);
  • Data from a drive that has been defragmented or reformatted.
The increased sophistication of hardware and operating systems allows computer systems to store more information about how people use their computers, and therefore, the digital forensics jobs are able to uncover a large amount of data that relates to the use of a computer, what is or has been stored on it, and the details about the computer’s user.

Moreover, digital forensics jobs have special tools and software designed to facilitate a thorough and legally sufficient analysis of items that contain digital evidence. It is important to allow a trained digital forensics jobs expert to conduct a proper seizure and examination on a piece of evidence so the investigator will have the best chance of using that evidence in a legal proceeding.
Read More

Wednesday, June 29, 2016

Using Certified check definition in fraud cases

What is Certified check definition ?

Certified check

Certified check definition is customer's cheques stamped with the paying bank's guarantee that the maker's signature is genuine and that there is enough money available in the older’s account to cover the amount to be paid. Certified check definition is liabilities of the bank and, when paid, are kept by the bank. These Certified cheques are immediately charged against the customer's account by debit memorandums. Some bank certified check permit customers to retrieve the original cheques by surrendering the debit memorandum.

Another certified check definition is also called cashier’s cheques. Certified check definition are cheques that have been issued and certified by a bank with itself as the drawer. These items are called treasurer’s cheques when issued by a trust company. Cashier's cheques are frequently an excellent lead to other bank accounts, stock, real property, and other assets. Because certified check definition can be held indefinitely, subjects sometimes purchase cashier's cheques instead of keeping large amounts of currency on hand.

To reconstruct a subject’s transactions with certified check definition, the fraud examiner must be sure that all Certified cheques are accounted for because subjects sometimes exchange previously purchased Certified cheques for new ones.

Bank cheques, such as cashier’s cheques, certified cheques, can be extremely time-consuming and expensive to locate unless the fraud examiner knows the date and number of the cheque. However, if the subject has deposited a bank certified cheques into his account or purchased a bank cheque using a certified check definition from his account, copies of bank certified cheques are much easier to obtain because the subject’s account records will reveal the date and number of the bank cheque.
Read More