Inherent Fraud Risk
Definition
The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and significance. Separating inherent risk from residual risk prevents teams from assuming that a control exists and therefore rating the scheme as low risk without testing whether the control actually works.
- Field
- Fraud risk assessment
- Measured before
- Any controls are applied
- Scored on
- Likelihood and significance
- Contrasted with
- Residual risk
Common questions
Why does an assessment score inherent risk separately from residual risk?+
Scoring only the post-control level lets a team assume a control works simply because it exists on paper. Rating inherent risk first forces the team to test whether the stated control actually reduces the risk before it is allowed to lower the score.
Who typically scores inherent fraud risk in an organisation?+
It is usually assigned during a structured fraud risk assessment workshop involving internal audit, compliance, and process owners, who rate each identified scheme against likelihood and impact scales before control effectiveness is factored in.
Related terms
- Control Gap
- A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
- COSO Fraud Risk Management Guide
- A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
- Residual Fraud Risk
- The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Scheme Mapping
- The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment...