Scheme Mapping
Definition
The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment where it could occur. Scheme mapping converts a general list of fraud possibilities into actionable targets for control evaluation.
- Step in
- Fraud risk assessment process
- Links
- Fraud scheme to business process and control environment
- Converts
- General scheme list into actionable targets
- Field
- Forensic accounting
Common questions
Why isn't a generic list of fraud schemes enough on its own?+
A generic list, such as billing fraud or payroll fraud, does not say where in a specific organisation the exposure sits, so without mapping it to the actual process and control point, the risk assessment cannot direct testing or remediation efforts.
Who typically performs scheme mapping in an organisation?+
It is usually done jointly by internal audit or a forensic accountant and the process owners who understand day-to-day operations, since the mapping needs both fraud expertise and detailed knowledge of how the specific process actually runs.
Related terms
- Control Gap
- A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
- COSO Fraud Risk Management Guide
- A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
- Inherent Fraud Risk
- The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
- Residual Fraud Risk
- The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...