COSO Fraud Risk Management Guide
Definition
A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding to fraud risks. Aligned with the COSO Internal Control Integrated Framework. The current edition is 2023.
- Publisher
- Committee of Sponsoring Organizations (COSO)
- Purpose
- Methodology for identifying, assessing, and responding to fraud risk
- Aligned with
- COSO Internal Control Integrated Framework
- Current edition
- 2023
Common questions
How does the Fraud Risk Management Guide relate to the broader COSO Internal Control Framework?+
It applies the same five-component internal control structure specifically to fraud risk, translating general control-environment and risk-assessment principles into fraud-specific practices like anti-fraud policy, reporting mechanisms, and investigation protocols.
Why would an auditor reference the current edition specifically rather than an older version?+
Citing the current edition signals that the fraud risk assessment was benchmarked against COSO's latest methodology rather than a superseded version, which matters if the assessment's currency is later challenged in litigation or by a regulator.
Related terms
- Control Gap
- A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
- Inherent Fraud Risk
- The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
- Residual Fraud Risk
- The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Scheme Mapping
- The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment...