
Fraud Talk · 2026-06-05 · 52 min
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
This episode combines a brief Q&A with Andy McNeil, the ACFE's chief training officer, followed by an interview with Dr. Ursula Schmidt, founder of Schmidt Advisory and former executive vice president of Audit and Compliance at RTL Group. McNeil addresses the human dimension of fraud risk management, explaining how intentional concealment makes fraud unique among organizational risks and why trust must be balanced carefully - too little inhibits reporting, too much creates opportunity. He advocates for skip-level meetings, proactive use of the word "fraud" by leadership, and reframing fraud risk assessment questions to be conversational rather than checklist-based. Schmidt then shares her 20-year journey from accidental entry into internal audit to leading both audit and compliance functions simultaneously. She critiques the widespread perception that internal auditors are merely "policing" the organization (cited by 51% in IIA's Vision 25 research) and identifies a critical gap: lack of visibility into what auditors actually do. Schmidt emphasizes that fraud ownership without clear accountability creates unmanaged risk, and that organizations are most unprepared when communication and escalation protocols around fraud response are unclear or absent.
Fraud is unique because the perpetrator intentionally conceals the risk and attempts to hide its existence, unlike other risks that are typically visible or have observable hallmarks. This intentional deception makes fraud harder to detect and manage through standard risk frameworks.
Organizations should recognize that resistance to reporting is biologically hardwired and reframe reporting as something that's rewarded and valued rather than feared. Skip-level meetings, visible leadership engagement, and framing fraud protection as part of the in-group rather than tattling can reduce the courage required to come forward.
Instead of directly asking 'Do you know of any fraud?' teams should use softer, conversational approaches like 'Have you had concerns about someone not following processes?' or 'How do you think someone could commit fraud here?' to allow employees to share concerns without committing to calling something fraud.
The most damaging misconception is that internal auditors are organizational police or spies; 51% of respondents in IIA's Vision 25 survey hold this view. This perception undermines auditor credibility and prevents them from being seen as value-adding partners in the organization.
The clearest sign is when multiple departments have unclear or overlapping responsibility for fraud ('passing the buck'), when fraud is treated as a metric to report rather than an active risk to manage, and when employees give conflicting answers about which department owns fraud risk.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of genuinely interesting framings - trust as a dual-sided fraud risk, the evolutionary biology of reporting resistance, the bronze/silver/gold communication culture taxonomy - but these are surrounded by extended throat-clearing, repeated platitudes ('tone at the top,' 'walking the talk,' 'zero tolerance'), and meandering conversational bridges that dilute the non-obvious-ideas-per-minute ratio considerably.
resistance to report is kind of a feature, not a bug in how we're wired
we know and we've actually heard quoted from convicted fraudsters, too much trust leads to them feeling more of the pressure under the fraud triangle. That's where the opportunity comes from
The reframing of whistleblowing as joining the in-group (rather than mustering courage to leave it) is a genuinely counterintuitive inversion, and the bronze/silver/gold communication standard is a usable original taxonomy; however, the majority of the episode retreads familiar ACFE territory - fraud triangle, tone at the top, tips as the leading detection method - and the guest herself repeatedly acknowledges she is 'boring to repeat' obvious points.
pragmatism eats dogmatism for lunch
If your culture totally empowers you, then you are entirely lost
Dr. Schmidt is a genuine senior practitioner who held EVP-level responsibility for both internal audit and compliance simultaneously at RTL Group (a large European media conglomerate) for seven years - a real dual-hat operational role at scale - and now advises and sits on boards; she is not a career podcast guest, though her experience is regional and sector-specific rather than cross-industry at the very largest scale.
I did both together. It's not a walk in the park to do it together, and it wasn't a walk in the park to get accepted in those two roles together
in the group I was working for over 20 years, it's a large group and then has very small subsidiaries and very large subsidiaries across, I mean, all over the world
The episode produces exactly one hard data point (IIA Vision 25 survey with thousands of respondents, 51% viewing internal audit as 'policing') and one dollar-figure behavioral anecdote ('$2,000 shoes'); the lone case study is fully anonymized, stripped of dollar amounts, company name, industry, and timeline, rendering it illustrative but not verifiable or actionable.
if you look at what IIA Global published like the Vision 25 that was published in 2024, there were thousands of respondents. 51% said like more than half said internal auditors are kind of seen as policing
bad accounting clerk, junior guy, no way he didn't inherit from his grandma. He was still always wearing those $2,000 shoes
The host makes some effort to connect themes across the conversation and uses the guest's own metaphors as springboards, but questions are frequently long, meandering, and self-answering, and there is no meaningful pushback or challenge to any claim made; the Andy McNeil segment in particular feels like a soft warm-up with leading questions rather than genuine inquiry.
Yeah. Also having the. The culture in place to, you know, that the channels are there and there's a system in place is do the employees, do the staff have the comfortability to actually escalate them into your point, Put it through the right channels and do it with the, um, the right intention and the right information
So let's go one level deeper. Let's go into that box a little bit
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Fraud Talk , Ursula Schmidt, Ph.D., CCEP-I, founder of Schmidt Advisory and a former executive vice president of audit and compliance, joins the show to explore how culture, communication and human behavior shape effective fraud risk management. Drawing on her global experience in internal audit and compliance, Dr. Schmidt explains why fraud is fundamentally a human problem, the importance of clear ownership of fraud risk, and why organizations must move beyond checklists and controls to address trust, transparency and accountability through honest communication and expectations. Also in this episode, ACFE Chief Training Officer Andi McNeal, CFE, CPA, answers questions about the human element of fraud risk management and the value that tone-at-the-top culture brings to ensure all layers of an organization work together to improve prevention and detection. Do you have questions about fraud? Reach out to us at Communications@ACFE.com.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hello and welcome to Fraud Talk, the ACFE's monthly podcast. I'm John Duffley and I'm joined by a special guest. I'm Andy McNeil, ACFE's chief training officer. Andy, thank you so much for taking some time today.
Speaker B: Glad to be here.
Speaker A: We are uh, doing a little bit different episode today. So we are actually going to be talking about audit compliance, ethics and transparency. We have a great interview this episode with Dr. Ursula Schmidt, who uh, is the founder of Schmidt Advisory. Ursula is also a former executive Vice president of Audit compliance at RTL Group. We had a great discussion about her experiences kind of in that first, first hand look at how culture and character are vital pieces of maintaining effective fraud risk management programs. Uh, today Ursula advises organizations through her own practice. She serves on various boards. She's also a speaker at international and national conferences. And she, she really is terrific at sharing, you know, her experiences in a really relatable manner. So stay tuned for that interview. It's really terrific. Uh, but to start, Andy, thank you for joining me. For uh, something we're trying a little bit different. We've kicked around a couple of names, Ask the acfe, Ask Andy has come up a few times. Uh, but really what we wanted to do is kind of take a couple of minutes and talk about some questions that we've been fielding a lot. So these are things that we've been hearing related to report to the nations which recently released different, uh, things we've heard from practitioners. Uh, if you have any questions about fraud risk management. You know, we want to be able to use experts here at the ACFE to talk about some of these things. So you can reach out to us@communicationscfe.com via email. We're happy to take some questions and actually answer some of these on the episode. Uh, so Andy, I want to start first with this broad brushstroke view of fraud as a human problem. And you know, we hear a lot about, um, you know, organizational risk and how that kind of manifests itself in internal control and fraud risk management frameworks. Um, but how can organizations kind of change the way that they think about prevention from a human perspective and the various ways that people within an organization can share in the responsibility of preventing and detecting fraud.
Speaker B: Yeah, I think it's really important for organizations to understand sort of the uniqueness of fraud when it comes to risk management. We talk about enterprise risk management, all the different types of risks that organizations can experience. Fraud is unique in that it's the only one or uh, at least one of the very, very few. That involves an element of intentional concealment. Right. Like we talk about all the risks an organization might face. Hurricane's not trying to lie to you and pretend it's not coming your way. Right. Economic downturns tend to be visible. Supply chain risks tend to have hallmarks of m. The issue cropping up fraud. The perpetrator is intentionally trying to make you think the risk doesn't exist. And so that in and of itself makes risk management even more challenging for a lot of organizations because if you don't know what's happening, you, you're going to downplay that risk automatically. So that element of concealment really comes from that human component. Um, I think the other big piece that is really important to understand when we're thinking about fraud risk management and fraud prevention specifically is as humans, the, uh, concept of trust is enormous when it comes to fraud risk management because it's kind of a dual sided challenge for us. We want people to trust that they can come forward with concerns. We want people to trust the environment that they're working in is ethical and uh, leadership has their best interest in mind and that helps foster like that ethical culture and anti fraud culture. But at the same time we know and we've actually heard quoted from convicted fraudsters, too much trust leads to them feeling more of the pressure under the fraud triangle. That's where the opportunity comes from. So organizations really have to figure out how do we build trust in the positive way where without overstepping and creating so much trust that people are able to take advantage of that trust and turn it around and defraud us.
Speaker A: Yeah. On, on the flip side of that, you know, you and I, in last year, in November, we went to the Whispers of America conference. Dr. Jackie Garrick, who was on the podcast about a year ago. Exactly. Now, um, you know, we heard stories about this of people who speaking up in an organization sometimes falls on deaf ear, sometimes falls on retaliation. And so there is a stigma unfortunately about speak up culture and being able to make it a vital component. Again. We see this with board to the nations tips far and away the way that frauds are reported. Um, but you know, I'm wondering if you have kind of a perspective on this of, you know, what, what are some of the ways that an organization can actually make people feel comfortable coming forward? Especially when they maybe have a behavioral red flag that they happen to see or maybe they see something in the numbers or something in the work that they do so that they don't feel, I guess the phrase that comes to mind is like a tattletale. They don't feel ostracized. They're just trying to benefit the organization. But again, at times you hear these horror stories of it not always working out in the way that they hope. So I'm wondering if you have a perspective on that.
Speaker B: Absolutely. And those stories are heartbreaking. Right. When you actually sit down and talk to whistleblowers who have been through huge amounts of personal loss because they came forward with their story, it's. It becomes a lot easier to understand why people may not want to stick their necks out. Right. And, uh, the Whistleblowers of America, they give out awards called the Giraffe Awards for sticking their neck out. I think it's a really lovely mascot for what they do. Um, really important for us to remember as we're designing whistleblower programs and fraud risk management programs, the resistance that humans feel to reporting, to not wanting to stick their neck out, is kind of biologically hardwired in us. If you look back at how we've come to be staying part of the in group was vital to survival for millennia. And going against that, being ostracized actually could be a risk to your own life. We still have that wiring in our brains. We're just in a very different environment right now. So I think it's really important for organizations to remember that resistance to report is kind of a feature, not a bug in how we're wired. And then setting up systems around that to almost flip how reporting is viewed where you don't want people to have to muster up courage to report because they are concerned that they will be ostracized or put in the out group. You actually want them to feel like they're going to be recognized, rewarded, lauded for reporting. Then they are part of the in group. Right. So if we can turn it around and say helping to protect the company is what gets a, uh, beacon shown on it, it's what's rewarded. It's what we value here. That's going to reduce the amount of courage it takes for people to come forward. It's going to reduce that internal resistance of what if I stick my neck out and I'm wrong or this is no big deal, and then I get in trouble and I'm pushed to the side.
Speaker A: Yeah. It's one of the things in my interview with Ursula that she actually talked about a bit. Uh, when it comes to tone of the top. Right. And you have the executive level, you know, she, she made the great point that I really resonated with was, you know, you have directors who are sharing information upward, but at times the executives are only getting a, uh, small piece of that. And so everybody else at the management and the employee level, they, the executive level might not understand where, what they're going through. And so that notion of skip level meetings and really making sure that people not only know that their leadership is aware of what's happening, but they're actively involved. And uh, you have this collaborative nature of what's happening and that's like a great way to build that trust and make sure that everybody really is pulling the rope in the same direction so that you don't have these, these instances where somebody feels like they have the support and to come forward to say something and maybe it's met with resistance. And so anything to do to build that trust. And so Andy, I wanted to ask you what are maybe, let's say, two things that an organization can do to build a healthy culture to make sure that trust and transparency and communication are there and available to employees?
Speaker B: Um, I think I could definitely come up with two. And I think you just really hinted at one, which is, first of all, the people at the top need to be proactively using the word fraud. And in a way that sounds like they are inviting open conversations around, it sounds like they don't tolerate it and they really want the help and support of people at all levels in the organization to protect the company from fraud. Right. So I think those skip level meetings, making sure that it's not getting lost in translation, but that really comes from those at the top being that voice, being that visible, um, beacon again of this is what we are prioritizing here. And anybody at any level, if you have concerns, go to our hotline, go to your manager. But also feel free to come right to me as a leader in the organization because I care. I'm busy, but I care. Um, the second thing I think is really important is a lot of organizations will do culture surveys and fraud risk assessments. And those things are vital parts of our holistic programs. But sometimes the questions that get asked are framed in a way that get answers that don't actually illuminate the true risk of fraud. And so, um, I think that's things like not directly asking, hey, do you know of anything that makes you think that fraud could happen here? Right. Having that level of true, like candor and insight from individual employees is probably going to help identify things a lot quicker than just a checklist of things or uh, all these controls being followed or have you seen even. Have you seen any fraud? Have you seen any fraud? People are going to be like, that's. I don't think, I don't know if I have. But if it's more. Have you ever had any concerns that somebody might not be following processes or if you, if you had to brainstorm how someone could commit fraud here, what would you make think that that might look like? Right? So that gives people a softer way to share some of their concerns, to say something that maybe they've seen but they don't feel comfortable making the call that it actually is fraud. So baking in some of those more um, user friendly versions of fraud risk, questioning into the conversations that your audit teams, compliance teams, risk teams are having with employees across the organization.
Speaker A: I love that. And that's actually a, a theme that, you know, you'll hear in a second when we take the interview with Ursula. Talks a lot about communication and how valuable that is. And I uh, like how you mentioned they're making it relatable and not necessarily putting it in a way of, you know, everybody has to be on the same playing field of making sure everybody's involved in different capacities. But how someone sees over here is not how someone's going to recognize it over here.
Speaker C: Absolutely.
Speaker A: So Andy, thank you so much. Like I said, I wanted to make sure we at least have a little bit of a table setter for the conversation with Ursa. So thank you for your time. Um, and for everybody else, we're going to kick it to my interview with Dr. Ursula Schmidt. Ursula, thank you so much for taking some time. Again, we're here in Austin, Texas. You're in Luxembourg, so we have a bit of a time difference. So I know you have dinner coming up pretty soon, so we won't keep you super long today. But really appreciate you joining us and talking a little bit more about audit compliance and you know, everything that has kind of brought you into this world. So my first question, we could start right there. Um, you know I saw, I was introduced to you for the ACFE Fraud Conference Europe. I know you've done the pre conference there. You'll be speaking at the 37th Annual ACFE Global Conference in July this year. Um, but you have a certain energy about you. Want to bring you on and talk a bit about it. Curious. What, what was your path into internal audit and compliance and um, you know, what kind of pulled you towards this realm of fraud and misconduct and setting organizations up for success?
Speaker C: Well, um, number one, thank you for having me. M really, really happy to have the opportunity to share whatever I have to share about all the things we're going to discuss in this setup. Well, yes, thank you for saying that. I have a decent energy to put on the screen, but I think I can't do much differently. So what brought me in? I mean, what brought me in? I think. Well, it's two different streams and then there's some. So number one, in internal audit, what brought me an audit was pure coincidence because I wasn't working in audit. I didn't have. I knew how to write internal audit, but that's one bit. But there was a wakened role. And then our then CFO of my former employer because the, like, external recruitment didn't really bring the result that they were looking for, which has probably something to do with energy as well. So, um, they basically, Basically my CFO then said, okay, why should we not try that resource filler? So, um, as I said, without any, uh, m. Internal audit experience whatsoever, I like a good challenge usually. Right. So told myself, okay, I mean, let's give it a start. And then I started this super long, super steep learning path. But then, um, number one, I found out that it suited me. I mean, it suited my attitude to. I think it. I prefer to get things done as they should. Right. So in principle, I think that's a good mindset for that role. So, uh, that's one thing. And then I think the way I approached it, by being, uh, pragmatic and simple and down to earth, that suited the organization as well because both sides have to. Well, it has to suit. But then on the compliance side, there was a totally different animal because there was a sort of governance trigger, which often I think is the case if something changes in compliance because the company got IPO'd. And, uh, in the context of all the changing regulatory expectations, it was clear that compliance had to be brought on another level, so to say. Now in my internal role, a lot of things that compliance does, they landed on my desk. So if there was a case, it was very quickly like, ursula, can you have a look? And I was involved in code of conduct drafting and policies and rollout and all these kind of things. So, um, at that point I told myself, okay, let's do that properly. So I really proposed to the board and to my management. Let me pick that up on top of what I do already in internal audit. And from a regulatory perspective, it was entirely possible and it required a little bit of convincing because boards who are not. Or board members who are not used to this kind of setup, they Might typically say, well, you can't, but, well, I could. And so, uh, it worked out. And so I did for the last, whatever, seven years in my role there. I did both together. It's not a walk in the park to do it together, and it wasn't a walk in the park to get accepted in those two roles together. But in the end, um, it worked out.
Speaker A: Well, you, you mentioned it, Ursula there, and I've seen you bring this theme of pragmatism a lot in the work, and I'm curious if that's something that is kind of inherent within you or if that is almost something that, when you started in the world of audit and compliance, if pragmatism maybe wasn't something that you'd seen, that you felt was, uh, a different way to reframe it. Because it, it does, to me, I think, strike a chord of, you know, there's this practicality to it in making it. Making it make sense in the real world and in context, as opposed to just the theory of audit and how you can go into it. So I was wondering if you could talk a little bit about that.
Speaker C: I think it's pretty much within me. So I'm, I'm. I. Well, my, my mantra is always pragmatism eats dogmatism for lunch. You look at my LinkedIn profile, you just see that, and I think that's pretty much me. So I, I'm. I, I mean, as I said, I think from, from my mindset, I think if there are certain good reasons to do things in a certain way, then that, well, can we just follow those rules? Otherwise we are in a mess. But those rules have to make sense and they have to be suitable to the organization. And, um, in the group I was working for over 20 years, it's a large group and then has very small subsidiaries and very large subsidiaries across, I mean, all over the world. And so very obviously there's no point in saying, okay, here's the rule. Just apply it and get lost. It does not work. So you have to figure out what works in which context and, uh, with which culture and, uh, how the people tick, et cetera. And that was, I mean, it suited, I would say, my character, which is obviously useful, and in the end it suited the organization as well.
Speaker A: Yeah. Uh, so one of the things too, that I'd seen that you spoke with IA Slovenia recently and you had. I'd seen in kind of one of your recaps of your sessions is really focused around this idea of pain points in the profession, um, and Then I saw you use this great metaphor of, of cleaning up the attic, if you will. So I'm curious, kind of going back into that, you know, kind of looking at things pragmatically. You know, what is one misconception, um, that maybe people outside the profession of internal audit have about the inner workings of it and kind of what the expectation of the auditor is.
Speaker C: I would say there's probably not one misperception of the role of internal, but there's about 1,000 of probably as many people as you ask. I would say the biggest one, and that's the nastiest one as well is very certainly they are just policing the organization. They are a spy of the organization. And if you go Back to what IIA Global published like the Vision 25 that was published in 2024, there were thousands of respondents. 51% said like more than half said internal auditors are kind of seen as policing. I mean how bad is this? So against that if you then hear yeah, so uh, uh, they're a little boring. I think that was 20 something percent. It's almost funny. So for me this is the worst of the misconceptions. On the other hand, I think there's one thing in internal audit which is, I mean it's not helping the profession and that's pretty much a lot of people just have no clue of what attributed auditors are doing. And that's even worse because it means we don't do a good job in, in, in, in being visible as a role. And so that's very certainly something I think where each internal auditor, but certainly the profession as such they have to do something about because otherwise how can you, how can you create impact if people have no idea how you're spending your time and why. Why.
Speaker A: Sure. It also goes into um, kind of my next question. There's um, this kind of I guess unclear sense uh, of ownership a lot of times especially specifically with just larger anti fraud initiatives. Um, sometimes that falls with internal audit, sometimes that falls with legal. Sometimes organizations are fortunate enough to have anti fraud teams. So um, in your work when you actually are consulting with a group or working with ah, uh, whether smaller team, larger team, you know, what is the clearest sign to you that ownership is in the wrong place when it comes to kind of risk management, um, internal control. So what, what is kind of some of those signs that maybe it's, it's maybe the people are well intended but maybe the work is in the wrong place or responsibilities or maybe are shared in the wrong way?
Speaker C: Yeah, I think it's exactly what, when you say it's shared in the wrong way, I would say when you see something like passing the buck, right, passing the bug about the topic, fraud, anti fraud, however you call it. And if an organization doesn't learn from mistakes, then it's not well placed because then you have a risk without an owner. And what's the risk without an owner? It's just not addressed. And so if it's really not clear who is really looking into what, if everyone scratches a little bit about at the surface, if at all, obviously. Uh, and also if you ask people, okay, who's looking after fraud here? And then you get very vague messages as to number one, why do we do it in the first place? For me, I'm always getting very allergic to when people are going to say yeah, you know about fraud, this is something that we report every six months to our shareholder or to the regulator. If it's considered a metrics, if it's considered, that's where we put an Excel. If you say okay, here's our dashboard, then I'm going to say it's not in the right place because then it's perceived as something which we have to measure to report it. And that's not the point. And in uh, the same way, if there's a risk without an error, pretty much often then you're going to see that people are very unclear about what actually are we talking about when we talk fraud. And then you might have people who are going to say yeah, it's what the lawyers look after. And then someone says oh no, that's compliance. And someone says well anyway, it's just finance fraud. And then people are going to tell you, you m know, but cyber is something else. Right? And so if you hear all these kind of weighing this, then you have this risk without an owner and then obviously you have a problem because then I mean that's the worst setup that you can have. It's really, it's really that one, that one um, say ah, organization or that one department, uh, where it's placed. It's rather how the general perception of the risk is perceived. And uh, again risk without an owner is how worse can it get in an organization?
Speaker A: Yeah, that perception of the risk I think is um, kind of, it takes me to kind of this other thought of preparedness. And so when you're not sure what the risks are and you're unsure what systems we have, why we do what we do, um, it just, you know, the preparation is really, really critical to Again, lowering losses. We see this research all the time. You know, what do you see with organizations, um, you know, outside of what we've talked about, when it. When it comes to ownership and understanding of responsibility, you know, how are organizations that you've seen, like, how are they most unprepared to. Again, combating risk, I would say in
Speaker C: regard to the risk of fraud, it's everything in regard to unpreparedness for the right communication, um, in the sense that if we are not clear who should know what and when and why and from whom, then obviously you don't have a real protocol behind. And if fraud happens, whatever kind of fraud might be, small, uh, big, wherever, whatever, the only thing you can't have is that people are like, head is chicken. And I mean, who's doing what? You can't have that because at worst you waste the case. And that is really, really bad. So for me, this is really the lack of clarity about the relevant communication, escalation protocols, etc. This is what makes everything very, very messy. And that's also where really mistakes obviously can be made. But, um. Yeah, yeah, you know, I think generally it's. It's really bad. It's really about how do we talk about it.
Speaker A: Yeah. Also having the. The culture in place to, you know, that the channels are there and there's a system in place is do the employees, do the staff have the comfortability to actually escalate them into your point, Put it through the right channels and do it with the, um, the right intention and the right information to actually take that from a complaint or an observation into something that's potentially actionable.
Speaker C: Of course, if people don't trust this, whatever is behind, if they don't trust the system behind the people behind, if the criteria doesn't allow it, then, uh, well, um, uh, you're a little bit lost. Then you don't even have to start thinking about communication because it's somehow broken, uh, from the onset.
Speaker B: Yeah.
Speaker A: And so taking I think a page from your book, Ursula, into the positivity of all this, you know, what makes a successful culture. And, you know, there's. I think the natural one is tone at the top, you know, a phrase I think everybody in this profession understands. But what are some other traits that you've seen that takes this from. Again, practical. We have all this to these systems actually working for the people who are responsible for fraud and internal audit.
Speaker C: So you said, well, yeah, turn at the top. But I think it's. I mean, it sounds trivia, but I Think it's still the essence of things because in the end it's nothing else but walking the talk. I mean, again, it's trivia. I hate trivia. But it's exactly that, right? If the culture is not founded on doing what we preach, well, you just forget it. So, um, it's all about, it's very much about consistency. So if you ask yourself, what can't we allow ourselves to have in our culture, then for me, that's very evident. We can't have an illusion of perfection. We can't have an illusion that everything goes right. Number one, we can't have tolerance for fraud. And it's easy to be misunderstood because I don't mean by that the CEO is going to say, well, there's zero tolerance against fraud. Well, that's easy. I mean, anyone can write that or say that. But the point is to have a, um, baseline as to what do we tolerate. Do we tolerate, do we tolerate that someone is cheating on us? And then the consequences will be different. You have that whatever the hundred dollar fraud and the 100 million fraud and the consequences will be different. But whatever you do and you have to do is different. But there must be a general baseline as to what don't we tolerate. And you may totally have an organization, depending on the sector where you're going to say, we know people will steal from whatever from, because it's shops, it's retail, whatever. We know people will steal because it's unfortunately in the human nature. But we also know we can't efficiently and effectively run after every dollar. It does not work. But then let's be clear about what we tolerate and what we don't tolerate. So we can't have the fact that we don't know what we are tolerating. We can't have selective protection, the kind of immunity, because those are, uh, things that are known and that's the worst. And people will know that person X gets away with something and person Y does not. And you don't understand why. And that's not considered fair. And it's not considered consistent as well. You can't have this biased response. It's things that an organization will just not find. You can't have that strategy of, okay, where's the rug below which we can swipe everything? And you can't have, and that's, I think, most important, you can't have a, uh, tolerance for silos. You kind of, you can't tolerate that everyone just does his or her thing, right? I mean, kind of that Frank Sinatra Approach. Just, just do it my way. No, you can't, because you have an, you have to have an organizational, uh, approach as to how do we handle that risk. If you have those things, then I think you are well prepared. Having them all together is like gold standards. Is it easy? No. But, uh, I think it's a general mindset that should be based on those principles.
Speaker A: I love that phrase you use the kind of the, um, having the tolerance to avoid silos and make sure we're not having all these conversations in isolation. And then when something does happen all of a sudden, like you said, we thought we had the system in place. We thought it was perfect, but it wasn't really working for anybody at the board and the executive level. I'm curious, um, kind of what you hear about these conversations of oversight, of culture, of making sure that there is clarity and communication between everybody working underneath. Because I think everyone has experienced this where when you're communicating up to the board level, they only have so much time and they need the key details to make sure things are running, operations are working, systems are in place. But I'm wondering, you know, kind of in your experience, when we kind of take it up to the board level, you know, how are those conversations about oversight and to your point, like ensuring that the little minutiae that make the program successful are being understood and kind of what it takes to make sure that there is clarity from the top down about what the challenges are and what's happening when with. At the staff and the employee level to, to ensure that the systems work when they're needed.
Speaker C: I, I think, I mean, everything starts and ends in the end with oversight culture. Of, of course, I mean that's, it's. Without that, you will. You're going to have an organization that just does it their way and um, uh, and oversight couldn't care. That's a super high risk. So, um, I think again, and I, I, on the risk of repeating myself, I think the question what's, uh, our tolerance? What do we tolerate and do we know and do we agree on what we tolerate? Do we as an organization have a kind of governance baseline as to, here's our limit and anything beyond that we don't tolerate, we have. Boards need to have a discussion about that and they have to have that discussion potentially without management at some point. And boards need to be super aware about their own red flags. And I am not sure to what extent board necessarily, necessarily discuss their own red flags. Uh, and I think that that's, again, it's something which they, which board members, audit committees. They really have to ask themselves what are we tolerating also in regards to for example management behavioral issues? I mean do we tolerate, are we aware and do we really see that, for example we might have a CEO who is um, always super easily getting aggressive or super defensive on whatever. Um, how do we, who controls our agenda? If we, what can, how far can you delegate as a board? If I, if I over delegate, if I delegate my agenda, if I delegate, who attends my meetings to well, the cfo, the CEO, whoever is going to tell me and um, I'm never going to have those uh, one to ones with, with audit, with compliance, maybe with the cfo. That's a big fat red flag and I need to ask myself those questions and that's not fun. I need to ask myself what I am um, incentivizing and does that make sense and do I incentivize collaboration, Do I incentivize short term motives? All these kind of things. I need to ask myself what's the attitude of management towards really sensitive topics? How do people react when we discuss a matter of conflict of interest or um, related parties trend Beautiful related parties transactions. How happy is a board of senior um, management group to be totally open about related parties transactions? If you see reluctance there, I think you have a big fed red flag again. How is our conversation with the external auditors go? If we, again, I think I repeat the word tolerance, I don't think it makes sense because here again, if you are an audit committee and you tolerate that, you have, let's say you have 20 subsidiaries and you get 15 management letters with the external audit every year and for five you don't. And then the answer is, uh, well, what is nothing? And then if you dig deeper and you hear, well, um, that local CFO doesn't tolerate management, I guess, well, you have a problem. And if you let that slip, I think you are not worth the salt of an oversight body. How you perceive compliance issues, how you react on internal audit findings that remain unsolved for whatever 18 months. What's your reaction to that? I mean it's not nice questions for a board to ask themselves. But I think, and being fair, I have to do that.
Speaker A: Yeah, those challenges aren't going to go away. To your point that um, at the, at the executive level, taking it out of your hands to somebody else is I think is something that you know, a lot of people recognize because it's, you know, the information you hear is the information that someone else is putting together. For you. But if you don't have a real hands on interest in what's happening, you know, uh, I, I think a pretty common thing that I'm sure a lot of people can recognize is, you know, this idea of, of skip level meetings, right, is the people directly below you who are presenting you the information. To your point, Ursula, is, is, is valuable and important and they help to share the most, the most pressing findings. But not having that direct visibility is where, you know, I think you, you said it again, which I really like. The, the CEO, for example, needs to do their own audit. It needs to understand, you know, what are the red flags that I'm missing. What have I actually not had eyes on. And I love that as a kind uh, of a, you know, as a leadership example of you really have to get your hands dirty and you really have to understand, you know, going back to your, you know, your, your adage we mentioned earlier is kind of cleaning out the attic. You need to go up there and you need to figure out what are the issues, the underlying issue that we've let sit dormant and collect dust that are now potentially raising themselves. And you know, unfortunately there are circumstances, and I'm sure you've come across it, where some of these things have sat around and they festered for a long time, taking you know, some time every six months or so just to check in and make sure that processes are working and you understand maybe what the issues are. Having that hands on approach saves you so much headache down the line.
Speaker C: It's totally true. And that's also one, I think, I think the main, many of the many main, um, um, attitudes of fraud resilience organizations is that they accept that we have to be adaptable. And again that goes. It's all the opposite of perfection, of illusion. Just because you have written once this is how the process should work and that's how our controls work, doesn't mean that it's. Well in six months that still makes sense. And um, uh, especially after something bad has happened, well, somewhere someone found an open door and uh, then it's maybe worthwhile as you say. I mean you open that box, you undust it and you say, okay, what's inside? Does it still make any sense? Shouldn't we throw it out? Shouldn't we change it? On the other hand, there could be good stuff inside and then your entirely family loves it. Please keep it and protect it. But that's exactly, um, I mean the purpose of cleaning your attic. I like it that you quote my cleaning the attic metaphor.
Speaker A: I'm a very visual person. It helps me to see it that way. Yeah, so let's go one level deeper. Let's go into that box a little bit. Um, so where in the fraud life cycle and again, in all the work that you've done in your career and obviously doing advising and client work. Now, where do organizations most often miss red flags? Is there a certain. And, uh, again, I'm sure this varies organization to organization, but have you noticed maybe a top two or top three things that organizations maybe again to your point, they thought they had controls for, but then they just missed because maybe they weren't paying attention to it or what have you. So are there any red flags that come to mind?
Speaker C: I would say there's one big box of red flags and that kind of outperforms any other red flags and that's any sort of people behavioral red flags. Because that's the, the thing nobody likes to see. And I include internal auditors there. Nobody likes to see that. And um, the problem is also that, I mean, you and I as fraud fighters and everyone else as fraud fighters in the world, we know all those red flags. And still, even for us, it is not super comfortable to accept that those super nice people we are discussing with our audit findings, but something is still looking like, off. We don't like it. But how do you. If even we are not, uh, like the most comfortable people in the world when we see and sense and escalate these kind of things, how do we want anyone else doing that? Plus the fact that very often this is the expert talk to expert talk. Right. So, uh, how do you want people in operations being super aware about these kind of things, let alone, how do you want people in operations, um, wanting to look suspicious? Nobody likes that. People hate other people looking suspicious. And it's super. I mean, it's a super fine line between professional skepticism on the one hand and just being suspicious on the other hand. But I'm totally sure I've not seen one simple single fraud case, big or small, where in hindsight everyone knows you're going to be told like, yeah, but, you know, I sensed something, whatever that was, something too good to be true. Something, whatever the m. At all levels, you might have a fraud where someone. And we, well, we all know that that happens all the time. You have someone very senior, um, involved. Why? Because those people have all the knowledge and they have, or maybe the relevant accesses and then the experiences and then all the loopholes. Those are very smart people and very often they are very social Socially, um, how do you say? Adequate people, very nice people very often. Right. How can that great guy or lady be that one person who cheats on us? You don't like to believe that. And so we tend to close our eyes and exactly the same happens at operational level where in hindsight everyone is going to tell you listen, bad accounting clerk, junior guy, no way he didn't inherit from his grandma. He was still always wearing those $2,000 shoes. And I was always wondering how that was possible. And then you and people know it. If people have addictions, normally they know it. If people go gambling all the time, they know it. If there's a drug problem, very often people know it and know it. If people have financial difficulties of um, family issues, etc. And still you don't like making the link between what you know and what that person does in the job and could that be at risk? People just don't like to see that. For me, people, Red Flag is the biggest box, so to say. And we're never ever going to totally empty that.
Speaker A: I don't know that I've had a conversation about, I would say fraud generally in the last few weeks that hasn't involved this element of the human eye. We have technology that has made efficiency increase. We have hybrid cross border international organizations where maybe you don't get a chance to see those $2,000 shoes. And curious like okay, well I know that he didn't inherit those to, to use your example, um, but it really is so critical that you know those behavioral elements are seen and understood because again there's only so much that a system is able to detect. To your point, in human intuition, human observation, there's not, there's not a replacement for it. It is so, it's so critical to actually making sure that employees feeling like they have an involvement in what's happening and then also to your point, not necessarily backing down from those um, professional skepticism suspicion and knowing that there is something else here that maybe it doesn't escalate itself to. There's potentially fraud happening here. But the, the um, the I'm losing, losing my train of thought. The uh, the indicators go up. There's something here that we need to make sure we are keeping an eye on.
Speaker C: Mhm. No, I completely agree and it's, it's very hard to in, in, in it's ingrained that in an organization that professional skepticism is something very healthy. Yeah, but it has to be explained over and over again. And, and, and still, I mean it will always happen that people don't like to. Don't see. Well, they might see things, but they might not kind of actively sees things, and they might not make something out of that because it just feels so uncomfortable.
Speaker A: So, Ursula, you've done a lot of work in a lot of different countries and going back to your experience of going around consulting and working with different, um, groups in the company that you were with. So I know we talked about this a lot, and it's pretty commonly held as organization to organization. Fraud risk looks different. Um, but I'm curious what you found kind of varies the most in your experience of working in different countries, working with different teams, in different structures, different personalities. You know, I'm wondering, you know, when it comes to, uh, you know, fraud risk management and actually having an effective culture, you know, what really varies the most and what has been something that you've been able to help people see, like having maybe this basic element here really can take things up a level.
Speaker C: M. Well, you put the word right into my mouth because you mentioned culture. And I mean, I think we all know that nations are different, countries are different, the different regional aspects of how we communicate. I mean, we all know that. And there's a more indirect or more hierarchical or less hierarchical, et cetera, way of how someone, maybe in Asia might communicate, whereas someone in the Netherlands or in the United States, et cetera. We all know that. But still, I still believe the most important differentiation that. That. Well, what differentiates. Is that the right word? Yes. What differentiates, um, organizations is. Again, I'm boring to repeat myself, but it's culture. It is um, really, um, a culture that makes people believe that something relevant will happen if things are being flagged and if people feel safe to open their mouth. And that's pretty much it. It drives everything else. It drives everything else. You may, uh, in the most, uh, let's say hierarchical, uh, indirect, uh, let's say surrounding culture, so to say, of communication. You still may have a leader who says, I want to know what's going on. And, uh, lives through that. And then if you empower people to do that. And I thought about this this morning. It's this difference between you empower someone or you empower someone. If your culture totally empowers you, then you are entirely lost. And so if you consider you might have already a rather decent way of handling those risks, and people are more or less open. I mean, if. If someone is. If. If an organization has a communication of tell us if something is going wrong, if something looks like off. I think that here's my bronze medal for you because that's not bad. I mean it's. Then you're already better than many. If you have an organization that acknowledges, regardless of where that organization is in the world, that acknowledges that silence is a risk, this is a silver standard, right? It's really, really important. But if people in an organization are going to tell you, I can um, safely tell my boss that I disagree, then I'm going to say, uh, you get your lucky gold standard star. Because in such an organization, people will dare to open up and to speak. And that's all an organization needs. You can have the best, whatever kind of tech controls and God knows what and 25,000 policies. But if you have, if I were there to tell my boss, whichever position that might be in the hierarchy, listen, I don't agree. I think that's a mistake. I think that's a risk. And I know my head won't be cucked, but I will be listened to and it won't be, uh, at my, ah, let's say at my damage, I think then we are good. And this depends on the people on the top
Speaker A: with regard to that. Ursula, I'm curious and people are motivated in different ways, but I'm curious what you feel is really the most effective response from an organization. And again, the guardrails of comfortability of maybe privacy of different things for someone to come forward in and actually, you know, share that something's happening and you know, potentially blow the whistle on something larger. But I'm curious what you feel and what you've seen an effective, successful organization does in response to, to fraud or for somebody actually coming forward to express concern about something.
Speaker C: I would say I have one fraud case that always springs to my mind when you're asking me, uh, what could resilience look like in practice? And this is, I mean, it's many, many, many years ago, a totally small company, really small company, like 15 employees and fraud, uh, was discovered. And it was very classical fraud. Someone had to be let go for good reasons. But, and I, I remember it like yesterday as well, because even I, I'm still in contact with that, with that CEO still there. And um, he's going to tell me, listen, people still talk about that, and I want them to still talk about it because I want them to remember that we were all paralyzed and we can't have that seeing again. And I completely, I, I totally remember as well the, all the actions that that person took, like hiring someone, um, as a new CFO at that time who was Totally above the budget that he was normally allowed to pay because he said, I want that person, because that's a person whom I can trust to tell me the truth. It was, I mean, the entire setup afterwards and how it was communicated, what was how many, I don't know, I don't even remember how many times I came after to that company and I was asked, speak to my people and train them, talk to them about complaints, give them, uh, a, uh, training about whatever you want to talk about, code of conduct or knows what, just to be sure that they know that kind of pressure on the pump. People are interested in this, they like to talk about it. And, um, it felt like people were very much being told the truth in the sense that that manager clearly said, I made a casting error. I hired someone, um, who, um, in the end, well, we could, for all the reasons that everyone knew, in the end we could not keep that person. And that was a casting error. And I now need someone who's filling this role to help me doing all the things that I, in my role as MD can't, because that's not my competencies. So, so I need someone to trust to basically tell me if I'm taking the wrong decision and helping me monitor, support all those things that I can't. Because I am not the competent person here. For me, this is a very humble and truthful way of handling a case of fraud. And people will find that credible. And that's, for me, it's a case study, an example of where I would say this company came out of that way, way strong.
Speaker A: The simplicity of transparency. Just let people know what makes them comfortable, let them into the process, let them behind the curtain a little bit. Tell them the truth. Exactly. Um, Ursa, we could do this all day, but I do want to be mindful of your time. So I'd like to close with a couple lightning round, couple quick questions for you if that's okay. Um, so first, one, uh, one internal control within an organization that you, you would get rid of. And why you think it's. Maybe it needs refined or maybe it's unnecessary.
Speaker C: I think I would love to say any sort of control that cannot be checked for being bypassed, if you don't know if there's no way of checking that someone can work around that control, that control, throw it in the bin. I mean, then you took it from the attic, but then you find out that you have to throw it out of the box because it doesn't work. Now my problem is I can't tell you which control that's going to be because that will again depend on each and every setup. So I'm afraid I can't tell you that one single control I can very certainly I'm going to tell you what you always in mile you have to bin is any kind of control that gives you an illusion of control. So in organizations where there's still, and there's obviously it still exists, there are still analog controls, there are still people signing stuff. Each and every time I'm going to see um, contracts being signed, not before eight different people in an organization have to wet them for whatever kind of reasons. They mostly even don't know bin it immediately because that's totally unaffected. It's an illusion.
Speaker A: One behavior you'd invest in to strengthen fraud resilience within an organization.
Speaker C: I would always say collaboration.
Speaker A: Mhm.
Speaker C: Do your best to help people. Being intrinsically motivated to collaborate. Because only if I'm intrinsically motivated, I'm going to do that. Otherwise, I mean if I'm the only idiot who's going to play the game, what do you want? Why should I do that? So for me it's collaboration, involvement in the process.
Speaker A: Absolutely. Um, and then my last one, one question that every board or audit committee should be asking themselves about fraud risk. And let's take it through the lens of kind of in the near term, in the future here, uh, one question that they really need to, to your point, kind of have a firm dialogue not just with themselves, with the employees as we kind of look forward here.
Speaker C: Mhm. I have something on my mind. I'm not sure if it's something which is um, to have a discussion with the employees, but I think it's again, I repeat myself, apologies for that. I think like a board or management, they have to ask themselves number one, what's our tolerance again? Do we agree on what's our tolerance for miscon Conduct but also how did this tolerance display in the past? And that's a question we have to have an answer for. And if we don't have an answer for, or if the answer is unsatisfactory, then we know where we have a to do which is again, uh, everything about playing the game of consistency.
Speaker A: I love that the work truly never stops. It's constant communication, constant collaboration. All themes that I think everybody can take away. Ursula, I really appreciated your time today. Um, taking some time. I know it's getting a little bit late over there in Luxembourg.
Speaker C: So far I must be there.
Speaker A: Absolutely. Uh, well, I appreciate it again. Thank you so much. And um, I hope we get a chance to see each other very soon.
Speaker C: We totally will. I hope very much to see you in Boston in July.
Speaker A: Absolutely. Well, thanks, Ursula. Take care.
Speaker C: Thank you.
Speaker A: Thank you again, Ursula, for joining us today. Thank you for Andy for joining us today. Thank you all for listening. Uh, you can find every episode of Fraud Talk on Apple Podcasts, Spotify, YouTube, ACFE.com or wherever you listen. I'm John Duffley signing off.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.