Journal of Accountancy Podcast · 2026-09-10 · 20 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Jonathan Marks argues that fraud oversight is fundamentally a structural discipline, not a reporting ritual, and boards must adopt an "eyes in, fingers out" approach - ensuring fraud risk management programs exist and work without micromanaging operations. The widening gap between boards' knowledge of mitigation plans and their knowledge of actual effectiveness stems from rapidly changing regulations, high-profile cases like Boeing and FTX, and communication breakdowns. Marks introduces the Candor Chain, a framework showing how honest people under pressure systematically strip factual information from reports as messages travel upward, leaving boards with sanitized versions. Small and midsize organizations face greater risk not from resource constraints but from prioritization failures and lack of structural discipline. Boards don't need to understand every control but must grasp the architecture, ask tough questions, and ensure they receive unscrubbed debriefs with two-way feedback loops. Marks also contributed to the 2023 COSO Fraud Risk Management Guide, which modernizes Cressey's fraud triangle into a fraud pentagon by adding competence and arrogance as perpetrator risk factors, providing updated frameworks for governance and risk assessment.
Ownership means boards ensure fraud risk management programs exist, are properly resourced, and actually work in practice through active oversight and structural discipline, rather than passively receiving reports. It requires understanding the architecture of controls and regularly asking tough questions with two-way feedback loops.
The Candor Chain is a framework showing how honest people under real pressure systematically strip factual information from reports as messages travel upward through organizational layers, resulting in sanitized versions reaching the board. This causes boards to be the last to know and first to be blamed when issues emerge.
Smaller organizations struggle not due to resources but because of lower prioritization of fraud risk structures and discipline; they often lack the governance architecture that larger organizations have built, though Marks argues this is often an excuse rather than a true constraint.
The fraud pentagon, introduced in the 2023 COSO Fraud Risk Management Guide, adds competence and arrogance to Cressey's original three fraud factors (pressure, opportunity, rationalization), better reflecting how modern fraudsters actually operate.
Boards must understand the control architecture in broad terms and ask tough questions while resisting the urge to step into management's operational shoes, ensuring they have unscrubbed information and two-way communication without drifting into day-to-day management decisions.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains moderate substance with recurring ideas like 'eyes in, fingers out,' the Candor Chain, and the Fraud Pentagon. However, much of the discussion reiterates known principles (communication breakdowns, tone from the top) and relies heavily on general concepts rather than granular, novel insights. The repetition of frameworks and gentle restatement of oversight best practices limits novelty per minute.
Fraud risk oversight is a structural discipline, not a reporting ritual
The Candor Chain. A framework for showing how critical information loses urgency at each handoff
While the Candor Chain concept and Fraud Pentagon are positioned as original contributions, they are largely repackagings of established frameworks (Cressy's fraud triangle from the 1950s, COSO guidance). The guest references famous fraud cases (Enron, Madoff, Theranos) without deriving fresh, counterintuitive insights from them. The core thesis - boards need better communication and oversight - is orthodox board governance advice.
The Fraud Pentagon, which is something that I helped create, that adds two additional components to what I call the perpetrator side, which is competence and arrogance
Fraud risk oversight is a structural discipline, not a reporting ritual
Jonathan Marks holds relevant credentials (CPA, governance and fraud risk strategist at BDO) and has hands-on investigative and board experience. He contributed to the COSO 2023 guide and runs fraud investigations. However, he is primarily a consultant and guide contributor rather than an operator who built and scaled business functions or faced board scrutiny as a CFO or CEO, limiting the practitioner authenticity for B2B operators.
BDO Senior Principal Jonathan Marks, a governance and fraud risk strategist. He's a CPA who holds a host of other designations and credentials
serving on a board myself
The episode lacks concrete metrics, timelines, and dollar figures. While Marks mentions famous fraud cases (Boeing, McDonald's, FTX, Theranos, Enron), he does not provide specific details - no numbers, no board meeting examples, no quantified impact of communication breakdowns. The discussion remains largely abstract ('50 internal audits came out okay') without drilling into actual audit findings or measurable outcomes.
You look at the cases that we keep seeing, like Marshand, Boeing, McDonald's and FTX
We've conducted, let's say, you know, 50 internal audits, and all of them came out okay
Neil Amato asks competent opening questions but rarely challenges or probes deeper into claims. When Marks offers frameworks, Amato accepts them at face value without pushing for specifics or examples. There are few follow-ups that press on contradictions or demand evidence. The conversation reads as a structured promotional format for Marks' report rather than a critical dialogue.
To me and I am just the question asker here
We will link to the Eye on Fraud report in the show notes, uh, for this episode
Computed from the transcript - who did the talking, and the words that came up most.
Boards need more than reports to provide effective fraud risk oversight; they need structures that help them determine whether risk management programs work. Jonathan Marks, CPA/CFF/CITP, CGMA, CFE, the author of the most recent FVS Eye on Fraud report , explains more about how boards should be involved - and how they shouldn't - when it comes to oversight of fraud risk. Key points of the discussion include how information that reaches the board is often "scrubbed" and why the right questions can help directors stay in the loop on fraud risk. Editor's note: The summer FVS Eye on Fraud report is available for download at the link above. It becomes exclusive to FVS Section members after Oct. 9. What you'll learn from this episode: Why effective fraud risk oversight is a structural discipline rather than a reporting exercise. How boards can determine whether a fraud risk management program works in practice without stepping into management's role. Why feedback loops are essential to ensuring that directors receive and understand the right information. An explanation of the Candor Chain and the ways critical information can be softened, altered, or lost before reaching the board.
Transcribed and scored by The B2B Podcast Index.
Speaker A: How can a company's board go from hearing about risk to owning risk management? This quarter's FVS Ion Fraud report focuses on a board's roles and responsibilities in fraud risk management. And the author of that report is our guest on the Journal of Accountancy podcast. You'll hear the conversation after this brief sponsor message. You help clients plan for their futures,
Speaker B: but have you planned for yours? With instant approval opportunities for some members, applying for AICPA endorsed life and spouse insurance could be even easier than tracking
Speaker A: down all those missing client receipts. Get started@cpai.com Lifeplan welcome back. I'm Neil Amato with the Journal of Accountancy, and I'm joined by BDO Senior Principal Jonathan Marks, a governance and fraud risk strategist. He's a CPA who holds a host of other designations and credentials, and we're glad to have him on the podcast. Jonathan, as I said in the intro, you are the author of this quarter's ion fraud report. We look forward to talking about it. Thanks for being on the podcast.
Speaker B: Thanks, Neil. Thanks for having me.
Speaker A: To me and I am just the question asker here. The key message of this quarter's FVS ion fraud report, I think is in the subhead, why boards must own the risk, not just hear about it. That's an easy concept for us to talk about right now, but it's not as easy to do. So how do boards make sure they're taking ownership and not just listening?
Speaker B: Boards don't fail at, uh, fraud oversight because they lack reports. You know, the article itself argues that fraud risk oversight is a structural discipline, not a reporting ritual. So the board's job is captured in one phrase, eyes in, fingers out. You know, directors must ensure that fraud risk management program exists. It's resourced and actually works in practice without drifting into management's lane. So when I get into the article, I talk about oversight and some managing principles, so viewed from the board's chair rather than a practitioner's. And it introduces a concept that I call the Candor chain. A, uh, framework for showing how critical information loses urgency at each handoff. And that's a real serious issue. But getting back to how the board really comes into play here, you know, it's really framed by a lot of the things that are going on today, including some of the cases that we keep seeing, like Marshand, Boeing, McDonald's and FTX.
Speaker A: You wrote in the early parts of this report that the gap between what a board knows about a plan to mitigate fraud and what it knows about the Effectiveness of that plan is now a widening gap. What are some of the reasons for that widening gap?
Speaker B: Yeah, regulations, obviously, keeping up with the regulators is certainly an issue. And obviously those things are changing minute by minute, day by day. And their interpretations are as well. The courts I had mentioned in my opening question, you know, these cases that are coming through, Marchand, Boeing, McDonald's, FTX, Theranos, I mean, certainly have lessons learned in there. If you really go back and you look at those specific things, they really do shape everything that we're doing. And the reason that the gaps keep widening is because it's very difficult to keep up with all this. If you remember, a board's role is oversight, right. And making sure that information is being communicated to them and the right information is being communicated to them. And so senior leadership is also in a position where they have to keep up with what's going on as well. And that communication needs to be effective. And we all know that communication has a bunch of different parts. There's a sender, there's a medium, and there's a receiver. But the big thing that everybody fails to really understand, and I trick people with this all the time, is that there has to be a feedback loop. And if there's not a feedback loop, then we really don't understand what's going on. And so since everything is moving at the speed of light and technology is changing so quickly and the world environment is changing so quickly these days, those gaps are really widening. Because, uh, again, if you look at the regulatory environment three or four years ago, completely different the way it sits today, we look at enforcement actions, a lot of those are down. When those go down, a lot of people think they could take their foot off the gas. It's never a set it and forget it type of exercise. And so those perceptions, whether real or not, whether the regulators are playing a more strict role within what's going on, when people look at those numbers, they tend to act or react, and sometimes they don't realize that in order to maintain their control environment, in order to maintain the proper risk posture, you can't forget about this stuff. And you have to constantly be learning about what's going on, not only from, um, an external and an internal perspective, but, you know, all those things that, that come into play from a business perspective. And that's why I believe those gaps are widening, and they're widening every day. And, and we see them when we do investigative work all the time. Because one of the things that is really required now is to do root Cause analysis. And we go back and we look at root cause. The boards that get blindsided and the boards that catch fraud early aren't separated by intelligence or good intentions. The difference is really structural. Like I said in the very beginning, it's whether the board itself is built to see those things. And some of them are not. And a lot of that's related to skill and experience and things like that. But there's a world of, uh, difference between being told something exists and knowing that a program actually works as well. And that's the other thing from an oversight perspective that we see from a board level, that really could be the difference between a gap being not there and a gap actually appearing.
Speaker A: We will link to the Eye on Fraud report in the show notes, uh, for this episode. Clearly there's more to say about the reasons behind the gap widening. Can you explain why is greater oversight needed in small and midsize organizations compared with large organizations?
Speaker B: A lot of people revert to resources. I really go back to what's really important. If you look at smaller organizations as compared to larger organizations, smaller growing companies obviously have different focus and different priorities. And a lot of times it's not a resource thing at all, Neil. It's more of a priority thing. And I have this saying that I use sometimes it's called perfect place syndrome. And a lot of times, you know, when you're dealing with smaller organizations, they have Fussle. It's not really muscle, it's fat and muscle. And the reason for that is because they're doing other things and they don't have the structure in place yet. And they're building structure on a continuum, you know, as they move through their life cycle or their growth. But smaller organizations don't necessarily have their priorities set up in the right way. And I don't really see a, uh, difference sometimes between small organizations and large organizations. And why small organizations struggle sometimes, again, is because they're not focused on these particular things. I think it comes down to discipline, it comes down to structure. And a lot of times they're getting there and they're moving in the right direction, but it becomes a focus thing for me. And I think that's one of the things that we can all do. It's like professional skepticism. We talk about that all the time ad nauseam. Professional skepticism is not a set it and forget it activity. It's one of those things that has to be recalibrated all the time. And every single thing that we do, no different from a risk perspective. If I'm Sitting on a board. Boards have to recalibrate their oversight. What they're looking at, um, what they're doing, what's senior leadership doing, what are they focused on? And if you don't have that built in, you don't have that structure built in. A lot of times it just gets missed or gets pushed to the side. So when I hear that we're resource constrained or whatever, or, you know, we don't have budget for something, there are so many different things that we could do today that really didn't exist before that I find that more of as an excuse because we're focused on other things, or that these organizations just think that they're immune to some of the things that larger organizations generally have issue with.
Speaker A: That's a good point all the way around. It can be an excuse, especially in the age of AI, when you can put some tools to use for some quick answers on a lot of things. Getting back to your phrase, eyes in, fingers out. A board can't totally be in the weeds on all of a company's processes. I think what you wrote is a board does not need to know every control, but it should understand the architecture in broad terms.
Speaker B: Again, I think that goes back to the structure. How are things being set up? Who's looking at them? What is the process for that? When it comes to communication, what's being communicated to them? Are they seeing the right information, getting the right feedback? Do they get a debrief that is not scrubbed? Do they get a debrief that has that information in them? Providing oversight and being independent is not a luxury for a board. That's their job, right? And so they need to ask those tough questions. They need to get that information, they need to ensure that things are being done proper. An organizational perspective. And we've seen that in some of these cases where they've tried to go back to the board and said, hey, you were remiss in your oversight. You did not focus on these particular things. And again, you can't catch everything. And like I said, you can't understand every single control, everything that's going on. But if you understand that there's good structure and there's good process and there's good communication, and again, communication is one of those things. Sender, medium, receiver, feedback. You, you're getting the right feedback, you feel comfortable that you're getting the right information in your pocket so that you can review that and act on it accordingly, I think that's where we need to land. It's a balancing act to some degree. But serving on a board myself, I have to be careful. Am I providing oversight, or am I stepping in the shoes of management? And that's the struggle today, especially with the fact that these cases are kind of forcing a lot of these boards to tip over and look over that line. You have to kind of reel yourself back and say, hey, what's the structure here? What are we doing? Who are the individuals that are involved? What is our communication look like? What is our overall risk program look like? You know, what kind of feedback am I getting from them? Do I have to go get it? Are they providing it to me? Do we have good collegial conversations about risk and. And things that are going on? And do I feel comfortable that those things make sense based on what I know? And again, I think that's kind of where we need to land. There has to be a balance.
Speaker A: You said early in that answer, you mentioned getting a debrief that is not scrubbed. I, uh, think that relates to a term you trademarked, the candor chain. Why do you think company cultures tend to sanitize a message that gets to the board instead of flatly stating the problem as it was identified at initial detection?
Speaker B: Everybody likes to get great news, right? It's good this happened, and we met our budget, you know, we met our revenue target. But let's go back to the candle chain. This theory that I came up with was really based on the fact that a long time ago, when the term tone from the top came out, it was actually tone at the top. And I said that that can't be. It has to be tone from the top. And the reason for that is tone from the top, to me, is probably a subtle change. But it. What it means to me is that that tone that's set by senior leadership of the organization resonates down and through the organization. I've been saying this for 25 years. People talk about mood at the middle and buzz at the bottom and all that. That. That's wonderful. But seeing something and doing something are completely different. And so when I kept thinking about this and thinking about what's going on today, I said, well, it's not only the tone from the top, but it's also the actions that people take along the way, either intentional or unintentional. So if you think about the candor chain, it's really not a theory about liars. It's a theory about how honest people, under real pressure, can systematically produce boards that are not the last to know and the first to be blamed. The question is, are Employees safe about speaking up. And when that information gets generated to folks along the way, what do they do with that information? How is it synthesized? Does it get looked at in its raw form? One of the things that we started to do a long time ago is when whistleblowers and hotlines came into play. We said, well, let me see the original complaint. And the reason for that is exactly what we talked about, is this information gets scrubbed along the way. Because a lot of times people are trying to protect themselves, either consciously or unconsciously. Sometimes. Sometimes people have different views of things. We don't have the same core values. Every individual doesn't have the same core values. We like to think that, but that's really not the case. And so as you look at information and when you were a kid, you played whisper down the lane, right? You know, you'd say something to someone, and by the time it got to somebody else, you know, all the way down the lane, the message could be completely and totally different. You were lucky if the message was somewhat the same, right? Well, it's no different. In an organization, however, there are jobs at stake. There is potentially accounting disclosures that are at stake. There's potential regulatory issues that are at stake, depending on what those matters are. And not everything rises to this grandiose level. But when you start to do this and you start to strip out factual information along the way, the messaging starts to change. And when that messaging starts to change, you may hear from senior leadership, hey, we've conducted, let's say, you know, 50 internal audits, and all of them came out okay. What does okay meet? And if you don't ask that next obvious question, were there any issues? Were there any overrides of controls? Was there any process breakdowns? Was there any change in key positions? If you're not smart enough to understand that, then what happens is, along the way, along the chain, you know, that information starts to break. And I've actually seen this, uh, in investigations where you have somebody who comes forward and says, hey, I don't think this is right. And then it goes to a manager. And if that manager doesn't know what to do with that information, they either report it or they don't pour it. So sometimes it goes out the chain. But if it does get reported, a lot of times it's their version of what was said to them. And then if it goes up, then it becomes somebody else's version of what was said before it even gets to the board. If it gets to the board. And when it gets to the board, it can look completely different than the original message. So, you know, one of the things that we encourage folks to do when doing an investigation, um, you know, I know this is really outside the purview of this particular article, but is really, like I said before, look at the original complaint. What did somebody say? You know, what did they write down? What did they articulate? And that's really what I mean about this whole concept of the Kanjo chain. And you could read all about it, but we, you know, we have really expanded on that because I do think it's not only the tone, but it's the actions that people take along the way when they do get that information.
Speaker A: Yeah, you've given us a lot to think about. You were a contributing writer to the Koso Fraud Risk Management Guide, second edition published in 2023. Why is that framework valuable for boards and risk?
Speaker B: There's a couple of things. One coso and all the people and all the contributors to that piece. I think what we try to do is we try to bring things into the current state. And so there, there are concepts in there that allow people to think differently. But I think there's better structure, better awareness. You know, we talk about different concepts. I'll give you a great example. You look at what I call the fraud triangle. No, I don't call it that, but you know, it was named that eventually. But you look at the three concepts that Pressy came up with back in the 1950s when it comes to fraud. Pressure, opportunity, rationalization, it all made sense back then, but companies were way different than they were in the 50s than they are in 2026. Single line reporting authority. I mean, I can go on and on and on. You look at what's going on today and you look at the frauds that have happened, you know, Madoff, Milken, Kozlowski, you know, Enron, Rollcom, Adelphia, uh, keep going on and on. Some of the things that we talked about today. If you look at the Fraud Risk Management Guide, we kind of bring in that human element to a lot of this. We actually introduce a new concept called the Fraud Pentagon, which is something that I helped create, that adds two additional components to what I call, uh, the perpetrator side, which is competence and arrogance. So if you look at Cressy's original concept of pressure, opportunity and rationalization, all still hold, all still great things that we should be considering. But uh, competence and arrogance certainly play a role too. And so that's one dimensional, right? So we look at these things and then we bring in other concepts along the way as well. We talk about, I think there's a, uh, definition of control in there, which I always say this to people. I go like, well, we're in the control world. What does a control mean? You know, if I say internal control, what does that mean? What's the definition of an internal control? A lot of times people just sit there and they don't know what the definition is. Um, and they can't just, they can't even describe it. Well, control does something. It has a certain objective to it. Right. Um, and if you don't understand that, how can, how can you be in the. How can you be in the game here? How can you be helping companies analyze gaps or weaknesses or controls if you don't understand what a control should be doing? And so I think if you look at the Fraud Risk Management Guide, it does a really good job of not only laying out these principles and the concepts, but it also some of the definitions in there and some of the things like bringing the human in a loop with was something that I think we were all pretty passionate about when we sat down and wanted to make this better. And I give Koso and the ACFE a great deal of credit for this because they said, hey, you know what? We've got this guidance, we really need to update this. And that continues to go forward. But having that structure, having that framework in place and having some uniformity with regards to all of this really does help. And again, it's not perfect and it's not meant to be, but if you can go through and look at the structure and the framework and get a good idea, hey, where do we stand against this? Do we have these things? Are we considering these things? You know, is this our process? Those are all fair game questions. And I think that document actually helps bring all that out.
Speaker A: That's great. Jonathan Marks, anything you'd like to add as a closing thought to what's been a great conversation?
Speaker B: The most important question a director can ask is this. What information was identified but never reached me? It's not what we know, it's what we don't know. Neil and I think kind of ending on that, what's required is not new power. It really isn't. It's the will to use that power the board already holds deliberately and on schedule. That's really what this is all about. It's really being better informed and making good decisions. And I think some of these cases articulate that, that the boards were really weren't focusing on asking those particular questions to senior leadership. They were just comfortable and what was provided to them. And I think that's really where we need to be going. We need to make sure that everyone's got an oar in the water and they're all rowing in the right direction. But more importantly is everybody's functioning, um, in a way where it's not just one way information, it's two way information.
Speaker A: That's Jonathan Marks on the Journal of Accountancy podcast. Jonathan, thanks very much.
Speaker B: Thanks Neil. Thanks for having me.
Speaker C: This content is designed to provide illustrative information with respect to the subject matter covered and does not represent an official opinion or position of the aicpa, the association, or cima. It is provided with the understanding that they are not engaged in offering legal, accounting or other professional services. If such advice or expert assistance is required, the services of a competent professional person should be sought. The aicpa, the association and CIMA make no representations, warranties or guarantees as to, and assume no responsibility for the content or application of the material contained herein and especially disclaim all liability for any damages arising out of the use of, reference to, or reliance on such material.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.