View Full ACFE CFE – Fraud Prevention Exam Dumps and Practice Test Dumps.
Question 381. What should a fraud governance policy define first
- Employee vacation schedules
- Customer payment terms
- Roles and accountability for fraud risk
- Product marketing targets
Correct Answer: 3. Roles and accountability for fraud risk
Explanation:
A fraud governance policy should clearly establish who is responsible for overseeing fraud risk, who manages specific risks, and how significant concerns are escalated. Clear accountability prevents fraud risk management from becoming an activity that everyone supports but nobody owns. Governance normally involves the board or an appropriate committee, senior management, process owners, compliance functions, and other relevant personnel. The COSO and ACFE Fraud Risk Management Guide identifies visible and rigorous fraud governance as a foundational element of a comprehensive fraud risk management program.
Question 382. What is the best reason to reassess fraud risk after an acquisition
- New systems people and processes can create new risks
- Acquisitions eliminate internal controls
- External auditors become management
- Existing controls always remain sufficient
Correct Answer: 1. New systems people and processes can create new risks
Explanation:
An acquisition can change systems, reporting lines, vendors, locations, access privileges, management structures, and business processes. These changes can introduce fraud risks that were not included in the previous assessment. Management should therefore reconsider fraud scenarios, control ownership, segregation of duties, third party relationships, and monitoring activities after major organizational change. The ACFE and COSO guidance emphasizes conducting fraud risk assessments periodically and adjusting fraud risk management practices as circumstances evolve.
Question 383. What should occur after a serious fraud allegation is substantiated
- Delete investigation records
- End all monitoring
- Ignore related controls
- Take corrective action and address control weaknesses
Correct Answer: 4. Take corrective action and address control weaknesses
Explanation:
A completed fraud investigation should lead to more than a decision about the individual involved. Management should evaluate how the misconduct occurred, whether controls failed, and what corrective measures can reduce recurrence. Responses can include discipline, recovery efforts, reporting, process changes, stronger controls, and additional monitoring. The Fraud Risk Management Guide specifically identifies investigation and corrective action as a major component of an effective fraud risk management program.
Question 384. What should management monitor after implementing a new fraud control
- Only employee opinions
- Whether the control works as intended
- Only external audit fees
- Product sales volume
Correct Answer: 2. Whether the control works as intended
Explanation:
Implementing a control does not guarantee that fraud risk has been reduced. Management should determine whether the control operates consistently, addresses the intended fraud scenario, and produces useful results. Monitoring can reveal whether employees bypass the procedure, whether alert thresholds are poorly designed, or whether business changes have reduced the control’s relevance. Fraud risk management guidance identifies monitoring and evaluation as essential parts of maintaining an effective program over time.
Question 385. What should a smaller organization do when full segregation of duties is impossible
- Use compensating independent reviews
- Ignore the risk
- Give one employee unlimited authority
- Stop reconciling accounts
Correct Answer: 1. Use compensating independent reviews
Explanation:
Smaller organizations may not have enough employees to separate every incompatible responsibility. In that situation, management should consider compensating controls such as owner review, independent reconciliation, transaction reports, approval limits, or periodic surprise reviews. The goal is to reduce the same underlying fraud opportunity through another practical method. The COSO and ACFE Fraud Risk Management Guide specifically includes considerations for smaller entities, recognizing that control design should reflect organizational size and circumstances.
Question 386. What is the main purpose of preventive fraud controls
- Investigate fraud after conviction
- Calculate fraud losses
- Reduce the chance that fraud can occur
- Replace governance oversight
Correct Answer: 3. Reduce the chance that fraud can occur
Explanation:
Preventive controls are designed to stop or discourage improper activity before it is completed. Examples can include authorization requirements, segregation of duties, access restrictions, vendor approval procedures, and system validations. Preventive controls are most effective when they address specific fraud risks identified during assessment. The Fraud Risk Management Guide identifies designing, implementing, and maintaining preventive and detective fraud control activities as a core component of comprehensive fraud risk management.
Question 387. What is the main purpose of detective fraud controls
- Remove all opportunity
- Identify suspicious activity that has occurred or is occurring
- Replace investigations
- Guarantee recovery of losses
Correct Answer: 2. Identify suspicious activity that has occurred or is occurring
Explanation:
Detective controls are intended to identify unusual or improper activity so the organization can respond. Examples include reconciliations, exception reports, transaction monitoring, data analytics, management review, and audit procedures. Detective controls do not necessarily prevent the initial act, but they can reduce the length and impact of a scheme by increasing the likelihood of discovery. A balanced fraud control framework normally combines preventive and detective measures according to the organization’s assessed risks.
Question 388. What should management do if a fraud alert produces many false positives
- Treat every alert as confirmed fraud
- Eliminate all monitoring
- Ignore every future alert
- Reassess and refine the monitoring logic
Correct Answer: 4. Reassess and refine the monitoring logic
Explanation:
Excessive false positives can consume investigative resources and cause reviewers to become less attentive to alerts. Management should evaluate whether thresholds, data inputs, scenarios, or rules can be improved while preserving useful coverage of the underlying fraud risk. Data analytics is valuable when it produces meaningful information that can be reviewed and acted upon. The Fraud Risk Management Guide includes data analytics as a tool supporting fraud risk management and monitoring activities.
Question 389. What should a fraud control owner understand
- Only the control name
- Only the audit schedule
- The risk the control is intended to address
- Only the policy publication date
Correct Answer: 3. The risk the control is intended to address
Explanation:
A control owner should understand why the control exists, which fraud scenario it addresses, how it should operate, and what evidence demonstrates performance. Without this understanding, controls can become routine tasks that employees perform mechanically without recognizing important exceptions. Linking each control to a specific risk also makes testing and remediation more meaningful. Fraud risk management programs depend on clear roles and responsibilities together with appropriately designed control activities.
Question 390. What is the best response to a major unexplained increase in control overrides
- Investigate the reason for the overrides
- Assume they are all valid
- Stop recording overrides
- Expand override authority
Correct Answer: 1. Investigate the reason for the overrides
Explanation:
A sudden increase in control overrides can indicate operational problems, weak control design, management pressure, or deliberate circumvention. The pattern does not automatically prove fraud, but it should be evaluated. Reviewers should determine who authorized the overrides, whether supporting reasons were appropriate, and whether certain individuals or transactions appear repeatedly. Monitoring override activity is especially important because management or privileged personnel can sometimes bypass controls that protect against ordinary employee fraud.
Question 391. What should happen when an employee reports suspected fraud anonymously
- Discard the report
- Publish the reporter’s identity
- Wait for a signed complaint
- Assess the allegation based on its substance
Correct Answer: 4. Assess the allegation based on its substance
Explanation:
An anonymous allegation should be evaluated according to the information provided rather than rejected merely because the reporter did not identify themselves. The organization can consider the specificity, credibility, supporting details, and seriousness of the allegation when deciding what follow up is appropriate. Reporting programs are more effective when employees have trustworthy channels for raising concerns. Anonymity can be particularly important when employees fear retaliation or believe management may be involved.
Question 392. What is the best purpose of annual conflict disclosures
- Identify relationships that could impair objective decisions
- Replace vendor due diligence
- Eliminate all conflicts automatically
- Set employee compensation
Correct Answer: 2. Identify relationships that could impair objective decisions
Explanation:
Conflict disclosures help organizations identify personal, financial, or family relationships that could influence business decisions. Disclosure does not necessarily mean the relationship is improper, but it allows management to evaluate whether recusal, independent approval, monitoring, or another response is appropriate. Conflicts can create fraud risk in procurement, hiring, contracting, and other areas when undisclosed interests influence decisions. Ethics programs and fraud risk management should provide clear processes for reporting and addressing these situations.
Question 393. What is the best reason to rotate responsibility for certain sensitive duties
- Increase employee access
- Reduce documentation
- Make continuous concealment more difficult
- Eliminate supervision
Correct Answer: 3. Make continuous concealment more difficult
Explanation:
Some fraud schemes depend on one person continuously controlling a process and concealing irregularities. Rotating responsibility can expose unusual transactions or practices when another employee performs the work. Rotation is not appropriate for every role and does not replace segregation of duties, reconciliations, or monitoring. It is one possible preventive and detective technique that can reduce dependence on a single individual and increase the perceived likelihood that concealed misconduct will eventually be discovered.
Question 394. What should a company do when a vendor requests payments to an unrelated account
- Pay immediately
- Verify the change independently
- Remove approval controls
- Accept email instructions alone
Correct Answer: 2. Verify the change independently
Explanation:
An unexpected request to change vendor banking information can create fraud risk, particularly when instructions arrive through email or another channel vulnerable to impersonation. An independent verification procedure can help determine whether the request is legitimate before payment information is changed. The organization should use trusted contact information rather than relying solely on details contained in the change request itself. Third party fraud risk management and preventive control design are important elements of an effective fraud prevention program.
Question 395. What should management do when a fraud control fails repeatedly
- Analyze the root cause and redesign it
- Stop documenting failures
- Assume employees are always responsible
- Keep the control unchanged
Correct Answer: 1. Analyze the root cause and redesign it
Explanation:
Repeated control failure can result from poor design, unclear responsibilities, inadequate training, system limitations, excessive workload, or intentional circumvention. Management should determine why the control fails rather than repeatedly correcting isolated exceptions. Root cause analysis can reveal whether the procedure should be redesigned, automated, strengthened, or replaced. Fraud risk management monitoring is intended to identify weaknesses and support corrective action so the program becomes more effective over time.
Question 396. What should a CFE do when receiving pressure to omit a material fact
- Follow management instructions automatically
- Remove the fact if inconvenient
- Delay the report indefinitely
- Maintain complete and objective reporting
Correct Answer: 4. Maintain complete and objective reporting
Explanation:
A fraud examiner should not omit a material fact simply because a client, manager, or other party finds it unfavorable. Professional reporting should be based on evidence and should include information necessary for a fair understanding of the findings. Ethical obligations require integrity, diligence, objectivity, and an appropriate evidential basis. Pressure from interested parties does not justify producing a misleading report. The Fraud Prevention and Deterrence section of the CFE body of knowledge includes ethical considerations for fraud examiners.
Question 397. What should an organization do when fraud training completion is high but misconduct continues
- Assume the program is effective
- Evaluate culture controls and training quality
- Stop investigating incidents
- Eliminate reporting channels
Correct Answer: 2. Evaluate culture controls and training quality
Explanation:
Training completion measures participation but does not prove that employees understand or follow ethical expectations. Continuing misconduct can indicate weak leadership, ineffective controls, poor enforcement, unrealistic incentives, or training that is not relevant to actual risks. Management should therefore evaluate the broader anti fraud environment rather than relying on completion statistics alone. Effective fraud prevention requires governance, culture, control activities, reporting mechanisms, risk assessment, and monitoring to work together.
Question 398. What should a company do when fraud risk increases because of rapid growth
- Reassess controls and resource needs
- Stop risk assessments
- Reduce governance reporting
- Assume existing processes will scale automatically
Correct Answer: 1. Reassess controls and resource needs
Explanation:
Rapid growth can strain controls that worked effectively when an organization was smaller. Transaction volume can increase, new employees may receive broad access, responsibilities can become unclear, and management review may become less detailed. Fraud risks should therefore be reassessed as the organization changes. Management can then determine whether additional segregation, automation, supervision, monitoring, or staffing is necessary. The Fraud Risk Management Guide emphasizes periodic assessment and tailoring the program to the organization’s size and circumstances.
Question 399. What should senior leadership demonstrate to strengthen fraud deterrence
- Tolerance for high performers who violate rules
- Consistent commitment to ethical conduct
- Resistance to reporting concerns
- Frequent control overrides
Correct Answer: 2. Consistent commitment to ethical conduct
Explanation:
Employees judge organizational values partly by observing what leaders actually do. Senior management strengthens fraud deterrence when it follows policies, responds consistently to misconduct, supports reporting channels, and demonstrates that results do not justify unethical behavior. A strong anti fraud culture becomes difficult to sustain when executives receive exceptions from standards applied to everyone else. The ACFE and COSO guidance identifies a transparent and sound anti fraud culture as a key part of comprehensive fraud risk management.
Question 400. What best describes a mature fraud risk management program
- A hotline used only after losses occur
- A single annual fraud audit
- An integrated process of governance assessment controls response and monitoring
- A program managed only by external auditors
Correct Answer: 3. An integrated process of governance assessment controls response and monitoring
Explanation:
A mature fraud risk management program combines several coordinated elements. Governance establishes accountability, fraud risk assessment identifies exposure, preventive and detective controls reduce risk, investigations and corrective actions address allegations, and monitoring evaluates whether the program remains effective. The COSO and ACFE Fraud Risk Management Guide organizes its guidance around these interconnected areas. The current CFE Fraud Prevention and Deterrence section likewise examines governance, management and auditor responsibilities, fraud prevention programs, fraud risk assessment, fraud risk management, and ethics.