22108 Chap.4 Internal Controls, the Fraud Triangle and Control Design
Internal Controls, the Fraud Triangle and Control Design
Week 4 is the qualitative heart of the financial half of 22108, and it is the week with the most predictable answer shape in the subject. It covers the COSO origin of the internal-control framework and its five elements, the definition of fraud quoted from ASA 240.12(a), the fraud triangle's three legs, who is responsible under corporate governance (defined from Justice Owen in the HIH Royal Commission, 2003), the five common components of internal control, the two-step design method and the specific controls over cash. The in-tutorial problem this week asks you to identify the control activities present in a described business process, identify the weaknesses, and design a control for each - a three-part requirement that is worth learning as a repeatable sentence pattern, because it is also the natural shape of an exam question on this material. Week 4 is also when the Stage 1 written reflection falls due.
What this chapter covers
- 01COSO and the five elements: control environment, risk assessment, control of operational activities, information and communication, monitoring
- 02Fraud defined (ASA 240.12(a)): an intentional act involving the use of deception to obtain an unjust or illegal advantage - and the split between misappropriation of assets and fraudulent financial reporting
- 03The fraud triangle: incentives or pressures, perceived opportunity, attitudes and rationalisations - and why opportunity is the leg management can actually control
- 04Corporate governance (Justice Owen, HIH Royal Commission, 2003) and who is responsible: the board, management, and risk, compliance and internal audit functions
- 05Reporting on internal controls: no formal Australian requirement; listed firms' internal audit reports to the audit committee; Sarbanes-Oxley section 404 as the post-Enron US response
- 06The five common components: clear responsibilities, proper documentation, adequate insurance, separation of duties, use of technology
- 07Designing a control in two steps - identify the risk first, then design the control - then implement (systems, training, documentation) and monitor
- 08Internal controls over cash: registers, cameras, register reconciliations, electronic payments, petty cash, bank reconciliations, two-factor authentication on banking logins
The three-part control drill on a small equipment-hire business
- +1Credit the control that works. Entering every hire into the system and printing a pre-numbered contract is a genuine control activity - proper documentation - and it creates the record any later reconciliation depends on. The requirement asks for control activities as well as weaknesses, so answers that list only failures give away that mark.
- +1Weakness 1: one person takes the cash, records the hire and checks the item back in. Principle breached: separation of duties - custody, recording and authorisation sit in one pair of hands, so an unrecorded hire or a short-banked deposit leaves no trace. Control: the person who receives the deposit does not close out the hire record, and a second staff member confirms the item back in against the pre-numbered contract.
- +1Weakness 2: a shared login with an unchanged password and no limit on discounts. Principles breached: access control and authorisation limits - nothing is attributable to an individual and nothing caps the benefit. Control: individual credentials with role-based access and multi-factor authentication, a system-enforced discount cap per user, and any discount above the cap requiring a second, logged approval.
- +1Weakness 3: cash counted but never compared with recorded hires until the quarterly visit. Principle breached: independent verification and monitoring, and the frequency gap is the exposure - a whole quarter of transactions runs before anyone would notice. Control: a daily reconciliation of cash counted to the system's recorded hire receipts, performed by someone who did not handle the cash, with every difference investigated and initialled, not just the large ones. Detection layer: an exception report on discounts and on hires closed by the same user who opened them.
Key terms
- COSO framework
- The internal-control framework developed by the Committee of Sponsoring Organizations of the Treadway Commission. This subject teaches its five elements as control environment, risk assessment, control of operational activities, information and communication, and monitoring of control processes, with the control environment as the foundation.
- Fraud (ASA 240.12(a))
- An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage. Deception is the defining element - an honest error is not fraud.
- Misappropriation of assets vs fraudulent financial reporting
- Misappropriation is internal theft of assets such as cash or inventory, with an incidental effect on the financial statements. Fraudulent financial reporting is deliberate misrepresentation of reported balances - overstating revenue or assets, or understating liabilities.
- Separation of duties
- No single person should authorise, execute, record and hold custody of the same transaction. It is the single highest-yield concept in the topic: the recurring patterns are one person who both orders and receives inventory, and one person who both handles cash and records it.
- Corporate governance
- "The framework of rules, relationships, systems and processes within and by which authority is exercised and controlled within corporations", encompassing the mechanisms by which companies and those in control are held to account (Justice Owen, HIH Royal Commission, Vol. 1, April 2003).
- Sarbanes-Oxley section 404
- The US requirement, enacted in 2002 in response to Enron, for management to report on internal control over financial reporting (with auditor attestation for accelerated filers). Australia has no equivalent formal requirement to report on internal controls, though listed firms typically run internal audit reporting to the audit committee.
Internal Controls, the Fraud Triangle and Control Design FAQ
What exactly does an internal-controls question want from me?
A three-part answer, in this order. First, identify the control activities already present in the described process - there is always at least one working control planted, and listing only failures forfeits that mark. Second, identify the weaknesses. Third, design a control for each weakness. For each weakness, name the principle breached (separation of duties, authorisation limits, documentation, reconciliation frequency, access control, physical safeguarding, oversight) and then propose something specific and implementable: a threshold, a second approver, a system-enforced rule, a scheduled reconciliation, a log. Generic advice such as 'management should supervise more closely' is not a control and does not score.
Do all three legs of the fraud triangle have to be present?
Generally yes - the model's claim is that fraud typically requires an incentive or pressure the person cannot resolve legitimately, a perceived opportunity to act without being caught, and an attitude or rationalisation that makes the act acceptable to them. The examinable consequence is practical: an organisation cannot do much about an employee's personal financial pressure or their private rationalisations, but it can attack the opportunity leg directly. That is why the entire topic pivots from the triangle into internal-control design - controls are the organisation's lever on the one leg it controls.
Is 'no separation of duties' always the right answer?
It is the most common answer, but leaning on it alone will cap your mark. The archived pattern of this material rewards naming the specific principle each weakness breaches - and shared credentials are an access-control failure, an uncapped discount is an authorisation-limit failure, a quarterly reconciliation is a monitoring and independent-verification failure, and cash left on premises overnight is a physical-safeguarding failure. Diagnose each fact separately rather than reaching for the same label, and remember to say what the risk actually is if the weakness is left unaddressed.
Can AI help me practise control-weakness questions?
Yes, and this is one of the best uses for it in this subject. Sia is an AI tutor built to mirror how 22108 is taught and assessed at University of Technology Sydney: ask it to generate a fresh business-process narrative with weaknesses planted, then write your own three-part answer and have it check whether you credited a working control, named the right principle for each weakness, and proposed something concrete rather than a platitude. It explains step by step and does not do graded assessment for you - generative AI is not permitted in the in-tutorial problem or the final exam, and the UTS academic-integrity policy applies.
Exam move
Turn this topic into one table and one sentence pattern, then rehearse both. The table has five columns - process step, control present?, weakness, risk if unaddressed, control we would design - and it maps directly onto the three-part requirement you will be marked against. The sentence pattern is: 'Because [fact], [principle] is breached, exposing the business to [risk]; the control is [specific, implementable action], and the failure would be detected by [check].' Build a bank of weakness-to-control pairs so the second half of every sentence is instant recall: one person ordering and receiving inventory, shared or stale credentials, payments made without a three-way match, one person preparing and approving a payment, reconciliations performed rarely, cash counted but never compared to what it should be, cash held overnight, uncapped automatic discounts, undocumented manual system overrides. Memorise the COSO five and the fraud triangle three as named lists, because matching and fill-in-the-blank question types reward exact names. Week 4 is also Stage 1 reflection week - start that in the Week 2 careers workshop and the Week 3 reflective-writing workshop rather than the night before, since the two deadlines land in the same few days.
Working through Internal Controls, the Fraud Triangle and Control Design in 22108? Sia is AskSia’s AI Accounting tutor — ask any 22108 Internal Controls, the Fraud Triangle and Control Design question and get a clear, step-by-step explanation grounded in how 22108 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.