nerdexam
Isaca

CRISC · Question #363

Which of the following process controls BEST mitigates the risk of an employee issuing fraudulent payments to a vendor?

The correct answer is D. Enforcing segregation of duties between the vendor master file and invoicing. The most effective process control to mitigate the risk of an employee issuing fraudulent payments to a vendor is enforcing segregation of duties between managing the vendor master file and processing invoices.

Submitted by kev92· Apr 18, 2026Risk Response and Reporting

Question

Which of the following process controls BEST mitigates the risk of an employee issuing fraudulent payments to a vendor?

Options

  • APerforming credit verification of third-party vendors prior to payment
  • BConducting system access reviews to ensure least privilege and appropriate access
  • CPerforming regular reconciliation of payments to the check registers
  • DEnforcing segregation of duties between the vendor master file and invoicing

How the community answered

(18 responses)
  • A
    33% (6)
  • B
    11% (2)
  • C
    6% (1)
  • D
    50% (9)

Why each option

The most effective process control to mitigate the risk of an employee issuing fraudulent payments to a vendor is enforcing segregation of duties between managing the vendor master file and processing invoices.

APerforming credit verification of third-party vendors prior to payment

Performing credit verification helps assess a vendor's financial stability, but it does not prevent an employee from creating a fraudulent vendor entry and issuing payments.

BConducting system access reviews to ensure least privilege and appropriate access

System access reviews are important for general security and least privilege, but they do not directly address the process risk of fraudulent payments where an employee might have legitimate access to parts of a process.

CPerforming regular reconciliation of payments to the check registers

Regular reconciliation of payments to check registers is a detective control that identifies fraudulent payments after they have occurred, rather than preventing them upfront.

DEnforcing segregation of duties between the vendor master file and invoicingCorrect

Segregation of duties (SoD) is a fundamental internal control designed to prevent fraud and errors by ensuring that no single individual has complete control over a critical transaction from beginning to end. By separating the ability to add or modify vendor details from the ability to approve and process payments, it becomes significantly harder for an employee to create a fictitious vendor and then make unauthorized payments.

Concept tested: Segregation of duties for financial fraud prevention

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-53r4.pdf

Topics

#Segregation of Duties#Fraud Prevention#Payment Controls#Risk Mitigation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice