- 15 Marks
Question
At the annual general meeting of Aggressive Bank Limited for the year 2020, shareholders raised concerns over increasing cases of customer complaints about fraud. Shareholders emphasized that drastic actions were required to avoid brand damage and reputational issues.
In performing their oversight functions, the audit committee commissioned the internal audit unit to investigate fraud issues and likely causes. The internal audit report highlighted the following issues:
- Hacking of Accounts: Unauthorized transfers due to poor information security systems.
- Forgery: Forged cheques, signatures, and withdrawal slips used in collusion with bank staff.
- Fictitious Accounts: Opening and operating fake accounts to facilitate illegal transfers due to incomplete KYC.
- Loans to Fictitious Borrowers: Fictitious loans issued via fake accounts.
- False Overtime Claims: Junior staff claiming overtime for hours not worked.
- Suppression of Cash/Cheques: Diversion of customer deposits and loan repayments into fictitious accounts.
- Alteration of Programs: Unauthorized access to systems to manipulate account balances.
Likely Causes:
- Weak internal controls and supervision.
- Non-compliance with KYC rules.
- Poor IT and database management.
- Negligence, inadequate training, and poor working conditions.
- Fear of reporting fraud to regulators due to reputational concerns.
The audit committee mandated management to engage a forensic expert to investigate and report on the matter within four weeks. Your firm has been appointed for this engagement.
Required:
(a) Discuss the ethical principles applicable to this situation. (5 Marks)
(b) Advise on the procedures to gather evidence for an acceptable report to management. (5 Marks)
(c) Recommend the agencies and relevant laws management should use to tackle these problems, where legal actions might be required. (5 Marks)
Answer
(a) Ethical Principles Applicable to the Situation (5 Marks)
- Integrity: Ensure honesty and objectivity in investigating the fraud and presenting findings without bias.
- Confidentiality: Safeguard sensitive client information and avoid unauthorized disclosures.
- Objectivity: Maintain independence from management and other stakeholders to ensure unbiased conclusions.
- Professional Competence and Due Care: Use specialized skills, tools, and techniques to conduct a thorough and accurate investigation.
- Professional Behavior: Comply with relevant laws, standards, and regulations, ensuring that the investigation adheres to ethical and professional guidelines.
(b) Procedures for Gathering Evidence (5 Marks)
- Document Review: Collect and analyze financial statements, internal controls documentation, and relevant policies.
- Interview Key Personnel: Conduct interviews with staff, management, and other stakeholders involved in the processes.
- Data Analysis: Use forensic data analytics to identify unusual patterns, transactions, or discrepancies.
- System Audit: Examine IT systems for vulnerabilities, unauthorized access, and manipulation.
- Tracing Transactions: Track the flow of funds, particularly those linked to fictitious accounts or unauthorized transfers.
- Physical Inspection: Inspect physical records, such as cheques and withdrawal slips, to identify signs of forgery.
- Collaboration with Internal Audit: Leverage findings from the internal audit report to narrow down investigation areas.
- Evidence Preservation: Secure and document all evidence to ensure it is admissible in legal or regulatory proceedings.
(c) Agencies and Relevant Laws for Legal Action (5 Marks)
Recommended Agencies:
- Central Bank of Nigeria (CBN): Notify the regulator of compliance failures and seek regulatory guidance.
- Economic and Financial Crimes Commission (EFCC): Report cases of fraud involving financial crimes.
- Independent Corrupt Practices and Other Related Offences Commission (ICPC): Address corruption and abuse of office linked to internal fraud.
- Nigerian Financial Intelligence Unit (NFIU): Report suspicious transactions under anti-money laundering regulations.
- Police (Criminal Investigation Department): Pursue criminal charges against perpetrators.
Relevant Laws:
- Cybercrimes (Prohibition, Prevention, etc.) Act, 2015: Addresses unauthorized access and hacking of systems.
- Money Laundering (Prohibition) Act, 2011: Regulates suspicious financial transactions, particularly for fictitious accounts.
- Banks and Other Financial Institutions Act (BOFIA), 2020: Enforces operational compliance within the banking sector.
- Penal Code/Criminal Code: Governs prosecution for forgery and theft.
- Nigerian Data Protection Regulation (NDPR), 2019: Ensures accountability for data breaches linked to customer accounts.
- Topic: Forensic Auditing
- Uploader: Kofi