CRISC · Question #372
Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?
The correct answer is A. Segregation of duties. Segregation of duties is the most effective control to prevent fraudulent transactions by ensuring no single individual has complete control over a process.
Question
Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?
Options
- ASegregation of duties
- BMonetary approval limits
- CClear roles and responsibilities
- DPassword policies
How the community answered
(37 responses)- A92% (34)
- C5% (2)
- D3% (1)
Why each option
Segregation of duties is the most effective control to prevent fraudulent transactions by ensuring no single individual has complete control over a process.
Segregation of duties prevents a single individual from being able to complete all critical steps in a transaction process, thereby significantly reducing the opportunity for a lone actor to perpetrate and conceal fraudulent activities. This control ensures that at least two individuals are required to authorize, record, and reconcile transactions, creating a system of checks and balances.
Monetary approval limits can mitigate the *size* of individual fraudulent transactions but do not prevent fraudulent transactions from occurring if an individual can still bypass other controls for smaller amounts.
Clear roles and responsibilities define who does what, but without segregation of duties, one person could still perform conflicting tasks that enable fraud.
Password policies enhance system security against unauthorized access but do not directly mitigate internal fraud perpetuated by authorized users who exploit process weaknesses.
Concept tested: Fraud risk mitigation controls
Source: https://www.isaca.org/resources/isaca-journal/2014-volume-2/how-to-implement-segregation-of-duties-in-a-sap-environment
Topics
Community Discussion
No community discussion yet for this question.