IN BRIEF
Minimizing and mitigating fraud risks has evolved over the years, and this progress can be seen in the pages of The CPA Journal itself. The authors of the current article revisit a number of previous Journal articles exploring the history of fraud understanding, up to the current conceptualization of the “Fraud Prevention Pyramid.” This tool is intended to highlight the ways in which fraud can be detected, deterred, and hopefully prevented.
***
In their daily work routines, CPAs encounter a variety of professional challenges. Some of these challenges call upon their sense of ethical propriety. This article addresses one aspect of ethical challenges faced by CPAs—what to do about the red flags often associated with fraudulent behavior. Tax clients, for example, might apply pressure that the CPA recognizes as an effort at misrepresentation. Similarly, audit clients might attempt to make certain financial statement assertions which the CPA may doubt or outright object to. In every conceivable scenario, it is important that the CPA be grounded in an appropriate model of ethical guidance. Of course, the AICPA Code of Professional Conduct, with its detailed body of principles and rules of conduct, is an important component of every CPA’s toolkit. In recent decades federal and state governments have also taken legislative approaches to provide CPAs and others with legal guidance to ensure the proper presentation of financial statements and preparation of tax returns, for example. Still, there is the question of how to make oneself resilient to potential ethical challenges that could present themselves. Toward this end, one particular anti-fraud tool, the “Fraud Prevention Pyramid” (Exhibit 1), developed by Douglas M. Boyle and Dana R. Hermanson, provides a useful framework that CPAs can consider. Of course, there is no anti-fraud mechanism that can provide for complete fraud “prevention.” This article therefore focuses on the potentially greater levels of fraud deterrence and detection this pyramid model offers.
Before examining the Fraud Prevention Pyramid, its various elements, and the specific ways in which it can prove useful to CPAs responding to pressures, it seems worthwhile to first provide an over-view of the many possible forms of business fraud and their respective occurrence rates. After all, knowledge is power, and knowledge of the plethora of ethical issues that might present themselves indeed empowers CPAs to develop a keen sense of preparedness.
Reports from the Big Four reveal the ongoing incidence of fraud, key areas of concern, and recommended action items going forward. Recent fraud reports published by the Big Four and the Association of Certified Fraud Examiners (ACFE) indicate that global fraud losses have continued relatively unabated. Given this enormous scale and scope of fraud incidence globally, CPAs must continually seek more effective ways to deter fraud and deal with fraud-related challenges that may present themselves in their day-to-day work activities. An examination of related published articles offers CPAs a potentially useful foundation and serves as a segue to the discussion of the Fraud Prevention Pyramid.
The Fraud Triangle, Fraud Diamond, and Fraud Prevention Pyramid
An article in the March/April 2024 CPA Journal, “The Fraud Diamond: A 20-Year Retrospective,” by Dana R. Hermanson and David T. Wolfe, revisited the Fraud Diamond model (Exhibit 2). In the original article, the authors presented the “Fraud Diamond” as an enhancement to the traditional Fraud Triangle. The concept of a Fraud Triangle, developed by criminologist Donald R. Cressey starting in the 1950s, identified three elements as essential for committing fraud: pressure, opportunity, and rationalization. Pressure partially addresses the “why” of fraud, opportunity refers to the “how,” and rationalization addresses one’s “justification.”
The Hermanson and Wolfe article adds a fourth element: one’s capability to commit fraud. This addition highlights the importance of the fraud perpetrator’s personal traits and skills, such as “brains, position, ego, coercion skills, lying ability, and immunity to stress.” The Fraud Diamond thus underscores the fact that, even if someone has the requisite motivation, opportunity, and rationalization, fraud will not occur unless they also possess the capability to execute it successfully. Hermanson and Wolfe reflect on the model’s influence, its integration into professional and academic settings, and the ongoing need to address fraud as a major societal issue in today’s dynamic, uncertain world.
In the March 2024 Strategic Finance article, “The Fraud Prevention Pyramid,” Boyle and Hermanson present a comprehensive model aimed at helping accounting and finance professionals strengthen their ability to deter and mitigate fraud risk throughout their careers (Exhibit 1). This pyramid consists of five elements: (1) developing fraud awareness and acumen, (2) understanding fraud ingredients, (3) avoiding common fraud pitfalls, (4) mitigating dark triad traits and pressure, and (5) mastering emotional intelligence. This approach emphasizes the importance of professional ethics, including the recognition of unethical behavior and maintaining one’s own strong moral standards. Knowing and applying the five elements of the Pyramid throughout one’s career can immensely benefit anyone, especially CPAs, in their fraud deterrence and detection efforts.
Application of the Fraud Prevention Pyramid for CPAs
With fraud incidence increasing both nationally and globally, financial professionals unfortunately rank among the leading perpetrators of occupational fraud according to the recent ACFE Report to the Nations (ACFE 2024, p. 54-55, https://legacy.acfe.com/report-to-the-nations/2024). Boyle and Hermanson state, “It is especially important for financial professionals to be prepared to address inappropriate pressures and incentives, especially since occupational fraud perpetrators are often well-educated and first-time offenders” (Douglas Boyle and Dana Hermanson, “The Fraud Prevention Pyramid” Strategic Finance, Mar. 11, 2024). Fortunately, CPAs can look to the Fraud Prevention Pyramid to learn about ways to deter, detect, and prevent fraud based on its five elements.
Developing fraud awareness and acumen. Today’s CPAs should fully utilize fraud information resources like the ACFE report, the Big Four fraud-related reports, and others to stay informed about the perpetrators, victim organizations, fraud methods, and trends (summarized in Exhibit 3). For example, the ACFE 2024 report is based on data from 1,921 reported fraud cases that occurred between January 2022 and September 2023 across 138 countries. These occupational frauds resulted in total losses exceeding $3.1 billion. Asset misappropriation schemes, which account for 89% of all fraud cases, are the most common but least costly, with a median loss of $120,000. In addition, 48% of cases were shown to have involved corruption, defined by the ACFE as “when an individual misuses their position for personal gain” (Exhibit 3). Awareness of these facts and trends will help CPAs improve their fraud awareness and acumen and thus make it easier to recognize, in any given scenario, which potential asset misappropriation schemes pose the greatest risks in various entities and departments. Such awareness can help CPAs set appropriate risk levels, perform necessary analyses, determine appropriate sample sizes, develop auditing budgets, and respond more effectively to potential red flags.
Today’s CPAs must also go beyond recognizing fraud trends and statistics by deepening their understanding of behavioral cues often associated with fraudulent activities. Perpetrators of fraud frequently exhibit certain patterns such as sudden lifestyle changes, resistance to oversight, or anomalies in the financial decision-making processes. CPAs should be trained to identify these red flags not only in financial records, but also in interactions with clients. Behavioral red flags, such as defensiveness during routine inquiries or reluctance to provide supporting documentation, can often signal deeper issues. Awareness of these subtle indicators allows CPAs to anticipate fraud risks before they escalate, conduct more targeted investigations, and enhance their ability to connect discrepancies in behavior with irregularities in financial data. This heightened behavioral acumen is particularly important in on-site audits, where face-to-face interactions with personnel can reveal critical insights (S. Ramamoorti, D. E. Morrison, J. W. Koletar, and K. R. Pope, A.B.C.’s of Behavioral Forensics: Applying Psychology to Financial Fraud Prevention and Detection, 2013, Wiley; D. R. Hermanson, S.E. Justice, S. Ramamoorti, and R. A. Riley Jr., “Unique Characteristics of Predator Frauds,” Journal of Forensic Accounting Research, 2017, vol. 2, no. 1, pp. A31-A48).
Fraud awareness should not be treated as a one-time exercise, but as an integral part of ongoing risk assessments. CPAs must regularly evaluate how fraud risks evolve within organizations due to changes in the business environment, industry dynamics, or internal processes. For example, the rise of remote work environments has created new fraud risks such as reduced oversight over financial processes and increased vulnerabilities to cyber attacks (KPMG, “A Triple Threat Across the Americas: 2022 KPMG Fraud Outlook,” p.2). Economic pressures can also motivate employees to rationalize unethical behavior, like engaging in fraud, to meet targeted company goals. By incorporating fraud awareness into periodic risk assessments, CPAs can better align their fraud detection efforts with the changing landscape and allocate resources to areas of highest vulnerability.
Fraud elements. Understanding the four elements of the Fraud Diamond—motivation (the “why” of fraud), opportunity (the avenue of the “how” of fraud), rationalization (the “justification” of fraud), and capability (the “ability” to commit fraud)—provides CPAs with a comprehensive behavioral foundation for fraud detection and deterrence, and is thus essential to the CPA’s ability to assess fraud risk in an engagement. It is crucial to evaluate internal control weaknesses and consider clients’ personal traits, particularly those of executives and management, in order to mitigate fraud risk most effectively. Research has indicated that auditors using the fraud diamond model assess fraud risk more capably than auditors using the fraud triangle model (D. M. Boyle, T. DeZoort, and D. R. Hermanson, “The Effect of Alternative Fraud Model Use on Auditors’ Fraud Risk Judgments,” Journal of Accounting and Public Policy, vol. 34, no. 6, p. 578–596, 2015).
Avoiding common fraud pitfalls. A prior research article by one of the authors identified eight learning objectives that can help individuals avoid common pitfalls that might lead to fraud, including:
- Develop an ability to recognize one’s own human tendency toward rationalization.
- Understand that fraudsters typically are not black-cloaked villains, but real people.
- Recognize the psychological costs of “getting away with” fraud and the costs of getting caught.
- Define clearly the values most important in both one’s personal and professional lives.
- Understand the importance of living within one’s means.
- Build a trusted network as a means of mitigating non-sharable problems.
- Understand the importance of maintaining professional marketability, (e.g., one must recognize the importance of continuing education for possessing the skill sets that appeal to potential employers).
- Understand that individuals possess values that are reflected in their life choices. Avoid defining values based on one’s position or title (D. M. Boyle, J. F. Boyle, and D. P. Mahoney, “Avoiding the Fraud Mindset,” Strategic Finance, vol. 96, no. 8, 2015).
These learning objectives can be used by CPAs for ongoing self-reflection, serving as a means of assurance that they are avoiding any of the common pitfalls. For example, building a trusted network enables the CPA to reach out to colleagues and others on high-stress matters which might just result in much more acceptable behavior through meaningful discussion.
Strategies to Mitigate Dark Triad Traits and Pressure
CPAs should recognize that individuals with “Dark Triad” traits—narcissism (excessive ego), Machiavellianism (manipulativeness), and psychopathy (lack of remorse)—can exist within any organization. Research shows that these traits, particularly among members of the financial reporting supply chain, can increase the risk of fraud. During audits and other financial services, such individuals are more likely to challenge CPAs and apply pressure on matters such as the timing of work completion, audit fees, adjustments and reclassification entries, audit opinions, and more.
One piece of research on handling Dark Triad traits and pressures was offered by L. Haylon, C. Bishop, D. Boyle, and D. Hermanson in “How to Handle Pressure to Act Unethically” (Management Accounting Quarterly, vol. 23, no. 3, Summer 2022). The authors offered financial professionals a list of ten specific ways to mitigate pressures they may face during their careers, five of which address actions to be taken before they are pressured to behave unethically and five strategies once any such pressure has been applied.
The first group of five recommendations is as follows:
- Plan ahead. Pressure is very likely to be applied at some point. CPAs should thus plan ahead, decide how to reply, and be prepared to say “no.”
- Practice personal financial responsibility. Haylon et al. (2022) point out that one must be financially prepared to handle several months’ personal living expenses in the event of losing a job as a result of refusing to follow an order to behave unethically. Of course, such preparedness requires a sense of personal financial responsibility.
- Understand the pressure landscape and people’s landscape. The “pressure landscape” encompasses factors such as financial goals, credit stability, executive changes, and project priorities that may drive undue stress on employees. The “people’s landscape” identifies individuals’ strengths, motivations, and potential manipulative tendencies, such as those exhibiting “dark triad” traits. Awareness of both landscapes helps build resilience against manipulation and unethical pressure.
- Set the right tone. Setting the tone from the top is essential in any organization, as is setting the tone at the individual level by “making it clear that you do not entertain or tolerate inappropriate behavior, and it may help to shield you from ever being asked or told to do something inappropriate.”
- Have advisors. Build a small group of advisors or at least some rapport with the people you trust who will provide an objective view of emerging issues.
Emotional Intelligence allows CPAs to stay attuned to their emotional state and avoid reactions that could compromise their professional judgment.
Once pressure is applied, the authors suggested:
- Beware of “little asks.” If one agrees to or approves “small asks” of fraud behavior, even if the amounts involved are inconsequential, the basis to challenge larger items will be undermined.
- Watch the tendency to be a pleaser. It is necessary to remind oneself to consider the ethical standing and the consequences of the cost of pleasing someone. It may be necessary for financial professionals to take negotiation courses to bolster their skills in standing up to demanding executives.
- Guard against rationalization. CPAs should not use the excuse of “I was just following orders” or “My boss let me do so” to justify succumbing to pressure. Neither the SEC nor the AICPA’s Code of Professional Conduct sympathizes with CPAs who utilize this defense.
- Explain the role of a professional. Saying “no” to someone pressuring you can be difficult, but explaining why you are declining the request shows that you are simply conducting yourself professionally.
- Articulate the ask and the possible consequences. This strategy is to restate the request and provide the possible consequences to the requester. Laying it all out on the table may cause the other party to retreat or possibly explode in anger. Either outcome is preferable to simply succumbing to the pressure (Haylon et al. 2022).
Mastering Emotional Intelligence (EI)
Emotional intelligence (EI) has been described as “a multifaceted concept that breaks down how some-one recognizes or perceives emotions, manages them, and uses them to create knowledge or reach goals” (P. O’Brien and D. Boyle, “Do You Have Emotional Intelligence?” Strategic Finance, June 2019). EI includes self-awareness, emotional self-management, social awareness, and relationship management.
Self-awareness is the cornerstone of EI, emphasizing “the ability to recognize emotions as they occur” (P. O’Brien and D. Boyle 2019). For CPAs, this skill is essential when interpreting complex financial information, delivering difficult news, or engaging with various stakeholders, clients, auditors, and regulators. It allows CPAs to stay attuned to their emotional state and avoid reactions that could compromise their professional judgment. It also helps to identify ethical dilemmas by noticing internal discomfort or suspicion when irregularities arise. One needs to exhibit self-confidence, which is vital when addressing high-stakes conversations with managers, CFOs, or board members. A CPA with confidence can assertively raise concerns about fraud or other unethical behaviors, setting the tone for decisive and constructive discussions. Self-confidence helps empower CPAs to resist undue influence from powerful stakeholders, ensuring that objectivity and ethical standards guide their decisions.
Self-management builds on self-awareness by focusing on regulating emotions and actions to align with ethical and professional standards. CPAs who demonstrate strong self-management appear to maintain self-control under pressure, allowing them to address potential fraud without being influenced by fear or anxiety. They also adapt to dynamic situations by staying composed and flexible during audits, even when unexpected challenges arise. For example, when faced with a client attempting to justify financial misstatements, a CPA with strong self-management resists intimidation or persuasion, remaining steadfast in their commitment to accuracy and transparency.
Social awareness, encompassing empathy, and organizational awareness are critical for CPAs to navigate the relational aspects of fraud detection. Empathy allows CPAs to understand the motivations and pressures faced by individuals within an organization, while organizational awareness helps them identify systemic issues that may foster fraud. Through social awareness, CPAs can detect red flags such as an unhealthy culture of secrecy or excessive pressure on employees to meet financial targets. CPAs can also anticipate potential risks by understanding how power dynamics might influence financial reporting and decision-making.
Relationship management involves building trust, resolving conflicts, and fostering teamwork–essential skills for CPAs tasked with fraud prevention. Strong relationship management allows CPAs to influence ethical behavior by setting a positive example and advocating for integrity within their organization, which aligns with the AICPA’s Code of Professional Conduct. CPAs are also expected to constructively resolve conflicts to ensure that disputes over financial findings are addressed professionally and clearly.
While EI has not historically been associated with fraud prevention, recent research has found that EI contributes to fraud detection (X. Geng and A. S. Fleming, “Incorporating Emotional Intelligence as a Risk Factor for Auditors and Anti-Fraud Professionals,” Tennessee CPA Journal, vol. 18, no. 4, p. 20–23, 2019). CPAs who develop and apply EI skills can navigate the complex emotional and relational challenges inherent in fraud detection and prevention. In doing so, they not only safeguard organizational integrity, but also reinforce their role as trusted financial professionals.
Limitations of the Fraud Models and CPAs’ Fraud Assessment Skills
Pulling all five elements together was the focus of Boyle and Hermanson’s “Fraud Prevention Pyramid.” Their work cited prior research supporting much of the model’s conceptual foundation and those of similar frameworks. Still, further research is recommended in order to truly establish the veracity of these models and thus provide the accounting profession with a clearer understanding of their inherent limitations.
Aside from the limitations of the fraud models, there is a need to recognize the limitations of what CPAs themselves can do. With all of its useful applications for CPAs, the Fraud Pyramid (along with its predecessors, the Fraud Triangle and Fraud Diamond), is situated within a broad domain that is hardly “owned” by the accounting profession. Given the role of internal controls in mitigating the “opportunity” for fraud, CPAs are rightfully recognized as experts in addressing this component of the fraud triangle. As for “pressure” and “rationalization,” however, these are psychological/social issues that simply do not fall within the CPA’s bailiwick. Indeed, the Fraud Triangle has not been used in the courtroom. In “The Fraud Triangle on Trial,” John Gill, now ACFE President, points out that judges have disqualified the use of the Fraud Triangle, noting that CPAs, fraud examiners, and auditors lack expertise in the human behavior aspects of fraud (John Gill, “The Fraud Triangle on Trial,” Fraud Magazine, September 2017). Judges have also noted the fact that the attributes of the fraud triangle—and all behavioral models, including many attributes of the fraud pyramid—are not determinative. In other words, attributes such as pressure, opportunity, and rationalization are mere warning signs that hardly mean that an individual displaying such attributes will commit fraud. With proper training, however, CPAs can be equipped to recognize such warning signs and make use of their audit and fraud examination skills to conduct a proper examination of available evidence and thereby draw appropriate conclusions. This critical fact is recognized in a response to Gill’s article, “The Meta-Model of Fraud” (Fleming, Marks, and Riley, Fraud Magazine, July/August 2018). The authors combine the Fraud Triangle (i.e., the why-based) with the Triangle of Fraud Action (the what-based) to provide a better explanation of fraud cases, noting that red flags of fraud provide the basis for working towards “predication,” which, in turn, provides the basis for a fraud examination. In short, properly trained CPAs possess the requisite skills for recognizing the warning signs of fraud and, through careful examination of evidence, present their determination of fraud acts.
There is another limitation, which echoes the one noted in the opening paragraph of this article. Specifically, there is no model that can truly “prevent” the occurrence of fraud. Nevertheless, the “Fraud Prevention Pyramid,” as it is so labeled, offers much value. It is reminiscent of a statement offered in the AICPA Antifraud Programs and Controls Task Force’s 2005 publication “Management Override of Internal Controls: The Achilles’ Heel of Fraud Prevention,” which states “The risk of management override of internal controls is present in every entity. Although the guidance provided in this document cannot guarantee that the audit committee will prevent, deter, or detect [such overrides], the implementation of these suggestions should result in more effective audit committee oversight of management” (https://tinyurl.com/5fkm4ef3). In other words, while nothing offers complete assurance, the components of the “Fraud Prevention Pyramid” do indeed offer additional means of limiting the success of those who attempt to commit fraud, whether by control overrides or other means.
There is no model that can truly “prevent” the occurrence of fraud. Nevertheless, the “Fraud Prevention Pyramid,” as it is so labeled, offers much value.
Recognizing the Importance of Other Models/Guidance
The Fraud Prevention Pyramid that serves as the primary focus of this article can be useful to CPAs in guiding the performance of their day-to-day activities. Such discussion would be incomplete without mentioning the similar utility of the contributions made by Jonathan Marks’s Fraud Pentagon and Steve Albrecht’s Fraud Scale. It is also incumbent upon an article of this nature to mention the May 2, 2023 release of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and the ACFE’s Fraud Risk Assessment Guide, Second Edition, which provides organizations with guidance regarding fraud risk management. Collectively, all of these contributions provide useful components of an anti-fraud toolbox that can aid in the early detection of fraud and likewise help in the development of many fraud-deterrent mechanisms.
At one or more points in their careers, CPAs will likely be asked to act in ways that run counter to the soundly developed and clearly articulated AICPA Code of Professional Conduct. Possessing the ability to respond to such pressures is essential for every CPA. A keen understanding of fraud limitation models, including the so-titled Fraud Prevention Pyramid, can be very useful in this regard. The same is true, of course, of possessing an understanding of the Fraud Diamond, Fraud Pentagon, Fraud Scale, and other models. By mastering the steps outlined in the Fraud Pyramid and other models, CPAs can remain vigilant against fraud, safeguard their reputations, and meet the evolving challenges of the profession. In turn, CPAs help their clients with minimizing the incidence of fraud and, when fraud happens, detecting it earlier and thus minimizing its impact.
































