Investigation and prevention are different engagements
An investigation answers what happened in a specific case. A fraud risk assessment answers where it could happen next. Both matter, and organisations usually arrive needing the first while discovering they never did the second. COSO Principle 8 requires fraud risk to be considered as part of internal control, and in a financial reporting context that means revenue recognition, management override and estimates before it means expenses.
How an investigation actually runs
Scope and terms of reference agreed in writing before anything begins. Evidence preserved before anyone is interviewed. Data analysed for the pattern rather than the anecdote. Interviews conducted in an order that does not tip off the subject. Findings reported to whoever commissioned the work, usually the audit committee or counsel, with a clear line between what the evidence supports and what it merely suggests.
Assessing fraud risk before it happens
We map where fraud could occur across the financial reporting cycle and the operational processes that feed it, then test whether the controls that should prevent or detect it actually operate. The output names the schemes that are plausible in your specific business, not a generic taxonomy, and identifies who would need to be involved for each to succeed.
