Business and Technology · Internal controls
Fraud, Fraud Prevention and Detection for ACCA BT
Updated 11 October 2026 · Fact-checked
Fraud is an intentional act of deception to gain an unjust or illegal advantage. Error is unintentional. The fraud triangle says fraud needs pressure, opportunity and rationalisation. To answer questions, identify the fraud type, link it to the triangle element, then name preventive and detective controls and who is responsible.
Understand Fraud, Fraud Prevention and Detection
Fraud is an intentional act by one or more people, using deception, to gain an unjust or illegal advantage. Error is an unintentional mistake, such as a wrong entry, a misread figure or a misapplied rule. The key difference is intent. The effect on the accounts may look the same, but the cause is not.
Two broad types of fraud come up often. Misappropriation of assets (theft) means someone takes cash, inventory or other assets, for example by creating a fake supplier or stealing receipts. Fraudulent financial reporting means misstating the accounts on purpose, for example by overstating revenue or hiding liabilities to hit targets or flatter results. Fraud by employees is common, but managers can also commit it, and management fraud can be harder to detect because managers can override controls.
The fraud triangle explains why people commit fraud. It has three elements. Pressure (or incentive) is the motive, such as personal debts or tough targets. Opportunity is the chance, created by weak controls or poor supervision. Rationalisation is the person's justification, such as 'I am underpaid' or 'I will pay it back'. Remove or reduce any one element and fraud becomes less likely. Organisations can control opportunity most easily.
Controls work in two ways. Prevention stops fraud happening: segregation of duties, authorisation limits, physical security, background checks before hiring, a clear code of ethics and a strong culture from the top. Detection finds fraud that has happened: reconciliations, exception reports, surprise inventory counts, internal audit, analytical review and a whistleblowing channel. No control is perfect, so you need both.
Responsibility sits mainly with management and those charged with governance (the board and audit committee). They design, operate and monitor controls. Internal audit reviews controls and may investigate. External auditors are not responsible for preventing fraud. They must plan the audit to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error, and must use professional scepticism.
Key formulas to remember
- Fraud versus error
- Fraud = intentional deception; Error = unintentional mistake
- Intent is the deciding test. Always state it when asked for the difference.
- Fraud triangle
- Fraud risk = Pressure + Opportunity + Rationalisation
- All three are normally present. This is a model, not a calculation. Removing one element reduces risk.
- Two main types of fraud
- Misappropriation of assets; Fraudulent financial reporting
- Theft of assets versus deliberate misstatement of the accounts.
- Control approach
- Prevent first, then detect
- Preventive controls stop fraud; detective controls find it after it occurs.
- Responsibility
- Management and governance prevent and detect; auditors assess risk of material misstatement
- Auditors do not guarantee that fraud will be found.
How to solve Fraud, Fraud Prevention and Detection questions
Use this method for any BT question on fraud, whether it is a multiple choice item or a scenario in Section B.
- 1Read the scenario and ask: was the act intentional? If yes, it is fraud. If not, it is error.
- 2Classify the fraud: misappropriation of assets or fraudulent financial reporting.
- 3Match the facts to the fraud triangle: find the pressure, the opportunity and the rationalisation. Opportunity is usually a control weakness.
- 4Identify the control weakness, such as one person handling both custody and recording of cash.
- 5Pick the control that fixes it, and say whether it is preventive or detective.
- 6If asked about responsibility, name management and those charged with governance first, then internal audit and external audit roles.
- 7Check your answer fits the number of marks or options the question asks for.
Quickest way: Intent, element, control
When to use it: Use this for objective test questions where you have about a minute per mark.
- Look for the word that signals intent (deliberately, falsified, concealed) or the lack of it (mistakenly, misread).
- Decide which triangle element the question tests: motive means pressure, weak control means opportunity, excuse means rationalisation.
- For control questions, ask: does it stop the act (preventive) or find it later (detective)?
- Eliminate options that say auditors are mainly responsible for preventing fraud.
- In multiple response questions, select exactly the stated number of options.
Common mistakes in Fraud, Fraud Prevention and Detection
Calling an unintentional mistake fraud, or the reverse.
Students focus on the financial effect, which can look the same.
Fix: Always test for intent. No intent means error, even if the loss is large.
Confusing the three elements of the fraud triangle, especially pressure and rationalisation.
Both relate to the person's state of mind.
Fix: Pressure is the reason for needing gain. Rationalisation is the excuse that makes the act feel acceptable.
Saying external auditors are responsible for preventing and detecting fraud.
Students assume an audit exists to catch fraud.
Fix: Management and those charged with governance are responsible. Auditors assess risk and obtain reasonable assurance.
Mixing up preventive and detective controls.
Some controls, such as reconciliations, feel like they stop problems.
Fix: If it acts after the event to find a problem, it is detective. Authorisation and segregation of duties are preventive.
Listing controls without linking them to the scenario weakness.
Students recall a generic list instead of reading the facts.
Fix: Name the specific weakness in the scenario first, then give the control that addresses it.
Claiming controls can eliminate fraud entirely.
Overconfidence in systems.
Fix: State that controls reduce risk. Collusion and management override can defeat them.
Worked examples
Example 1
A cashier at a retail company also keeps the cash book and prepares the bank reconciliation. Over a year, the cashier removes cash and hides the shortfall by altering entries. The cashier says the company underpays staff. Identify the type of fraud and the three fraud triangle elements, and suggest one preventive control.
Show the solution
- The act is intentional, so it is fraud, not error.
- Cash is stolen, so it is misappropriation of assets.
- Opportunity: one person has custody of cash and records it, with no independent check.
- Rationalisation: the belief that the company underpays staff, so the theft is deserved.
- Pressure: not stated in the scenario. You should say it is not given, though personal financial need is a possible motive.
- Preventive control: segregation of duties, so one person handles cash and a different person keeps records and prepares the bank reconciliation.
Answer: Misappropriation of assets. Opportunity is the lack of segregation of duties, rationalisation is the underpay belief, pressure is not stated. Preventive control: segregate custody of cash from recording and reconciliation.
Example 2
Which ONE of the following is the best description of the responsibility for preventing and detecting fraud in a company? A) External auditors; B) Management and those charged with governance; C) Internal auditors only; D) Shareholders.
Show the solution
- Responsibility for designing and operating controls lies with those who run the company.
- External auditors give an opinion on the financial statements and obtain reasonable assurance. They do not guarantee fraud will be found, so A is wrong.
- Internal audit reviews and tests controls but does not own them, so C is wrong.
- Shareholders own the company but do not run its controls, so D is wrong.
- B matches the principle.
Answer: B) Management and those charged with governance.
Exam tips
- Test intent first. Many objective questions hinge on whether an act is fraud or error.
- Learn the three triangle elements with one example each, so you can match a scenario in seconds.
- In scenario questions, tie every control to a named weakness. Generic lists earn fewer marks.
- Know which controls are preventive and which are detective, and remember that auditors do not carry primary responsibility.
- In multiple response questions, select exactly the number stated. Selecting too many or too few usually scores nothing.
Practice questions from Internal controls
- An internal auditor at Brandt Co finds that purchase orders above the approval limit were repeatedly authorised by one manager alone. Which …
- The internal audit department of Kestrel Co reports directly to the finance director, who also decides its budget and promotion of its staff…
- Brindle Co's internal auditor reports directly to the finance director, who also approves the internal audit work plan. The audit committee …
- Which of the following is an example of a corrective control?
- An internal auditor at Marlow Co is reviewing the purchasing cycle. She finds that purchase orders over a set value are authorised by one ma…
Fraud, Fraud Prevention and Detection in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Fraud, Fraud Prevention and Detection: frequently asked questions
What is the difference between fraud and error?
Fraud is intentional deception to gain an unjust or illegal advantage. Error is an unintentional mistake. The financial effect can be the same, so intent is the key test.
What are the three parts of the fraud triangle?
Pressure, opportunity and rationalisation. Pressure is the motive, opportunity is the weak control that allows the act, and rationalisation is the person's justification. Reducing any one lowers the risk of fraud.
How can organisations prevent fraud?
They use preventive controls such as segregation of duties, authorisation limits, physical security and careful recruitment. A strong ethical culture set by senior management also helps. Detective controls such as reconciliations and internal audit then catch what is missed.
Are auditors responsible for detecting fraud?
Not primarily. Management and those charged with governance are responsible for preventing and detecting it. Auditors plan the audit to obtain reasonable assurance that the financial statements are free from material misstatement, using professional scepticism.