COSO Framework
COSO Fraud Deterrence Mapping
Mapping COSO Principle 8 fraud coverage across likely schemes.
Mapping fraud-risk coverage to the schemes most likely to occur
Fraud risk is not a generic category to be ticked; it has to be considered scheme by scheme against the specific ways an entity could be defrauded. COSO Principle 8 explicitly requires the consideration of fraud potential in assessing risks, and in the SA public sector PRECCA and the fraud-risk expectations of AGSA give this real teeth. AuditPro Core maps fraud-deterrence coverage across the schemes most likely to occur, exposing where deterrent and detective controls are thin.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Fraud schemes mapped
14
Well-deterred schemes
8
Weakly deterred
4
controls thin
Avg deterrence score
67%
Deterrence score by scheme (%)
Scheme deterrence detail
| Fraud scheme | Controls | Deterrence % | Verdict |
|---|---|---|---|
| Tender splitting | 4 | 58 | Strengthen |
| Ghost employees | 6 | 71 | Adequate |
| Duplicate payments | 7 | 79 | Adequate |
| Asset theft | 3 | 54 | Strengthen |
| Bribery / kickbacks | 3 | 49 | Strengthen |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Scheme-level thinking
Effective fraud assessment names concrete schemes such as ghost employees, bid rigging or split purchases. Naming the scheme is what lets you ask whether a specific control would actually deter or detect it.
The fraud triangle
Schemes become likely where pressure, opportunity and rationalisation coincide. Mapping coverage against opportunity in particular shows where weak controls create the easiest path.
Deterrence versus detection
Deterrent controls reduce the temptation to attempt fraud, while detective controls find it after the fact. A mature map shows both, because detection alone accepts that the fraud will occur first.
Coverage gaps
The most useful output is the list of high-likelihood schemes with weak or absent coverage. These gaps are exactly what an investigator or the AGSA would probe.
How AuditPro Core Bridges the Gap
- Scheme register: fraud risks are recorded as named schemes, not a single line item, so coverage can be assessed precisely.
- Coverage scoring: each scheme is mapped to its deterrent and detective controls, exposing thin areas.
- Exception workflow: high-likelihood schemes with weak coverage raise an action for the fraud-risk owner.
- Audit-ready export: the mapping supports the fraud-risk assessment expected under COSO Principle 8 and AGSA review.
Key Takeaways
- Assess fraud at the level of named schemes, not a generic category.
- Map coverage against opportunity, the lever controls can move.
- Show both deterrent and detective controls, not detection alone.
- The gap list of uncovered high-likelihood schemes is the real deliverable.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
