• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

fraud

Article 12.8.2020 Dean Dorton

Over the course of the past nine months, many of our clients’ business processes were shaken up, employees shifted to working in isolation, and internal controls became dismembered.

Monitoring an organization’s pulse can be a challenge, but during these unprecedented times it can feel almost impossible. Unfortunately, sitting back and just hoping for the best is not the right response; there are serious money and reputational issues at play, no matter the size of your organization.

Although we live in an ever-changing world, there are three concrete things you can do to protect your organization from potential fraud:

1. Internally communicate

Remote work has the potential to make our teams feel disconnected and isolated. This can lead to various motivations and opportunities for fraud, especially if conditions persist for an extended period of time.

Now is the right time to establish an ongoing culture of communication within your organization. Start with planning out weekly team meetings with time for open conversations about what is and isn’t working well. The more receptive you can be to honest responses, the more trust you will build inside your company.

2. Re-establish internal control processes

Many of our business functions have permanently changed and responsibilities have shifted around. Now is the perfect time to map out your current control processes in writing (this exercise is sometimes easier said than done). Then, assess each process to see if proper segregation of duties, approvals, and information access are in place for each function.

3. Launch a whistleblower hotline

No matter the size or structure of your organization, implementing an ethics or whistleblower hotline can be one of the best investments you can make to protect your organization against fraud.

The Association of Certified Fraud Examiners found that 43% of detected fraud was uncovered due to a tip. Additionally, fraud losses at companies with a hotline were nearly half the amount of losses experienced by companies without a hotline; a $100,000 median loss compared to $198,000.

Tip hotlines have also had a positive impact on reducing the length of frauds, helping organizations detect fraud an average of six months faster.

In this unpredictable landscape, organizations should make it easy for their employees to report suspected fraudulent activity/theft, misconduct, or unethical behavior, and to remain completely anonymous throughout the entire reporting process. This is one of the most effective and inexpensive improvements you can make to your company.

The Dean Dorton team has streamlined our Whistleblower Hotline service to be an affordable plug and play option for a wide range of organizations. If you haven’t implemented a hotline yet, we would love to talk with you about your options.

Learn More about Dean Dorton’s Whistle Blower Hotline

Dean Dorton is here for you as your organization navigates through these unprecedented times. Contact us if you have questions about adapting and changing to this new landscape.

Nick Lynch, CPA/CFF, CFE
Consulting Associate Director
nlynch@deandorton.com • 859.425.7635

Filed Under: Forensic Accounting, Risk Management, Services Tagged With: communication, Controls, fraud, hotline, prevention, whistle blower

Article 06.24.2020 Dean Dorton

I never cease to be amazed at the creativity and effort of cyber criminals. Any time I think I’ve seen it all, our team runs across a new tactic that has caused significant harm to a business. This week we assisted a client that fell victim to a complex, yet simple cyber-scheme, leading to the compromise of bank accounts and the possible loss of millions of dollars. Please share this article with anyone in your organization who is involved in the banking and finance area. You do not want this happening to your organization.

Just when we get comfortable with the assumption that our controls are protecting us, cyber criminals find a new way to bypass security measures. This industry is ever-changing. We spend a lot of time preaching about multi-factor authentication (MFA) and for years banks have provided customers with comfort in this control. This week we saw that control fail, further enforcing the importance of layered security measures and continual risk assessment and control improvement.

It all started with a user in our client’s accounting department who had elevated administrative access to the corporate online banking platform. This user searched for their banking login page through a normal Google search. She clicked the search result and navigated to the bank login website (or so she thought). She entered her user ID, her password, and her rotating MFA token code to login as normal. Little did she know, the top result was not the site that she expected. The website in which she entered her sensitive information, including MFA token, was a fake site, mocked up to look identical to her real banking login site. The cyber criminals instantaneously initiated a login to the real banking site using her credentials and MFA token to gain access to the bank account. Think about the sophistication here—on average, MFA codes change about every 30 seconds.

Upon gaining access to the real account, the cyber criminals quickly moved to create additional user accounts. These accounts were used to initiate multiple wire requests for hundreds of thousands of dollars each (totaling close to $2 million in total). They then used the compromised account to approve the wires they had initiated with the fake user accounts. During this same time, they initiated attacks on the compromised user’s email to flood the inbox and distract the user from seeing any banking communication. Later they initiated a distributed denial of service (DDoS) on the user’s internal internet connection. This rendered the user’s internet connection basically useless. The cyber criminals attempted to limit the user’s ability to access the real bank account or any other online resources, thus helping to cover their tracks.

At the time of this article, the user is still working with the bank to recover a large portion of the funds that were not stopped before they were fully processed.

What are the critical lessons learned and how do we improve our controls to protect your organization?

  • Be sure you have a robust and continual user awareness training program.
    • Users should be cautious of search results
    • Users should be cautious about clicking links in emails and never click on links regarding banking
  • Review your online banking platform security and controls.
    • Be sure all users’ logins have multi-factor authentication
    • Be sure you are using all of the latest security controls offered by your bank
    • Think through segregation of duties. First, an approver should not be able to create/initiate transactions. Second, a user who can approve/release funds should not have the ability to create users and manage user security.
    • Your bank should provide controls that prevent any one single person from making changes to user security. Any security changes should require secondary approval and the secondary approver should not have any transaction approval authority.
    • Many people ignore segregation of duties in smaller organizations, likely due to physical personnel limitations. This should not be an excuse. Leverage trusted advisors like your CPA or attorney to give you the secondary approval, if needed.
  • Continually evaluate your cyber risks and improve your controls. As we have seen here, very reliable controls like MFA can potentially now have vulnerabilities under certain targeted campaigns. Layer controls whenever possible.

Contact us to evaluate your cyber risks and improve controls before your organization becomes the next victim.

Cybersecurity Assessment Information

Filed Under: Cybersecurity, Services, Technology Tagged With: Banking fraud, case study, Controls, cyber criminals, Cybersecurity, fraud, protections

Article 06.29.2018 Dean Dorton

The OIG recently announced that the 2018 National Health Care Fraud Takedown was the largest in history, focused on opioid diversion and abuse. Organizations which prescribe, dispense, or otherwise maintain investments in opioid or opioid containing products should maintain a strong internal control and monitoring strategy to mitigate risk. A well-designed monitoring program should include review of prescribing patterns, refill request patterns, inventory controls, and segregation of duties.

Read More

For more information on risk mitigation strategies and compliance monitoring, contact Shawn Stevison at sstevison@ddafhealthcare.com or 502-566-1066.

Filed Under: Healthcare, Industries Tagged With: fraud, opioid

Article 02.18.2018 Dean Dorton

As the population of elderly Americans with retirement savings grows, so does the opportunity for financial fraud against this often vulnerable group. To compound the problem, technology allows fraudsters to share lists of seniors who have succumbed to fraud, so the same person can be scammed repeatedly.

Kentucky statutes require all citizens to report reasonable suspicion of financial exploitation against adults. Such exploitation can be difficult to detect; it sometimes is perpetrated by family members or close advisors against victims who may be unaware of the exploitation or embarrassed to report it.

Relatives and caregivers can take advantage of the elderly in multiple ways. For example, they may take money or other valuables, without permission, for themselves or to give away to others. They may “borrow” money without repaying it, misuse debit or credit cards, or cash pension or social security checks.

Signs of financial exploitation against the elderly include:

  • Unpaid bills
  • Lack of essential items like food and medicine
  • Unusual bank account activity, including expenditures inconsistent with history, and large unexplained withdrawals
  • Use of ATM withdrawals, if inconsistent with typical transaction activity
  • Changes to wills or other legal documents, especially if they change fiduciaries or beneficiaries
  • Missing valuable items (silver, electronics, art)

Current scams against the elderly, typically perpetrated by strangers, include:

  • Prizes or sweepstakes – A victim is required to send money to cover taxes, shipping, or processing.
  • Investments – Pressure to maximize returns makes seniors vulnerable to persuasion to invest in assets which promise unrealistically high rates of return.
  • Charitable contributions – Fraudsters solicit donations to nonexistent charities or religious organizations.
  • Repairs to home or automobile – Advance deposits may be required, but repairs may not be completed or may be performed at a substandard level.
  • Health, funeral, life insurance – Fraudsters sell policies that duplicate current coverage, or are bogus.
  • Loans and mortgages – Unscrupulous lenders give loans with very high interest rates and hidden fees.

Many agencies are charged with protecting seniors. Federal agencies include the FBI, Postal Service, and Secret Service. State and local police may be involved in investigating consumer fraud. State social service agencies are charged with protecting seniors. In Kentucky, this includes these agencies, among others: Cabinet for Health and Family Services, various Ombudsman programs, Kentucky State Police, Area Agencies on Aging, Office of the Inspector General, and Office of the Attorney General.

Block Insets

Tips to avoid becoming a victim of elder financial abuse:

  • Do not provide your SSN over the phone, unless you initiated the call and know the party you call can be trusted.
  • Do not click on any links in an email from an unknown sender.
  • Do not give others access to your computer or provide security information. If someone contacts you requesting such information and claims to be from your bank or credit card company, for example, hang up and call a verified number for the organization.
  • Check your credit report regularly to ensure that fraudulent new accounts have not been set up in your name.
  • Secure your smartphone and your computer with strong passwords.
  • Shred documents showing your personal information and lock your mailbox; do not leave your wallet in your car.

For more information on how Dean Dorton can help you identify fraud, follow the link below:

Learn more

Filed Under: Forensic Accounting, Litigation Support, Services Tagged With: elder abuse, financial fraud, fraud, retirement

Article 11.9.2017 Dean Dorton

…What’s the big deal?

Issued by AICPA FLS Fraud Task Force
Lead Author: Elizabeth Woodward, CPA/CFF

Corruption is defined as “dishonest or illegal behavior, especially by powerful people such as government officials or police officers).”¹ This publication is not intended to address political or international corruption; rather, we intend to address the insidious nature of employee corruption that keeps forensic accountants up at night — that is, our experience, education and training combine to absolutely convince us that the “depravity, decay and decomposition” (also part of Merriam-Webster’s definition stated previously) embodied by corrupt individuals will likely always be the strongest opponent we face in our fight to prevent fraud. Forensic accountants believe that for fraud to occur, three factors generally need to be present:

  1. Opportunity (under control of company)
  2. Rationalization (internal to individual)
  3. Pressure (possibly more internal to individual)

Corporate fraud is apparent at all levels, including supervisors, management and even executives. The problem for forensic accountants is that if a person is “corrupt,” they will always have the ability to rationalize theft. Some of the most troubling projects that an investigator pursues can involve employee theft via violations like expense report abuse, improper vendor relationships and low-dollar bribes. Perhaps what makes these offenses so unpleasant is that they show a diseased corporate culture where employees feel entitled to “extra” benefits. Imagine the manufacturing engineer who awards million-dollar contracts for factory maintenance, and that same engineer has a barn built at his personal residence for free, or at a very low cost using his employer’s resources or discounts from vendors (which, his employer would pay for indirectly via higher prices). “It doesn’t hurt anybody” is never a true defense. When personal gain is factored in to business decisions, the employee is not acting in the best interest of his or her employer and the business is harmed.

It should be noted that corrupt activities may be either committed acts such as defalcation of records or misrepresentation of work performed, or omitted acts such as “looking the other way” or failing to enforce policies or regulations in exchange for something of value.

Examples of Employee Corruption

Payroll and ghost employees

“Ghost” employees are individuals who receive paychecks but do not exist, or exist but are not legitimate employees. In the first instance, they are fictitious employees who are entered into the payroll file. In the latter, they may be associates of an existing employee or former employees who continue to receive checks after their employment is terminated. For this fraud to occur, employment files are created or altered. Work activity records (like time cards) are maintained. Payroll checks, or more conveniently, direct deposits, are diverted to an account controlled by the perpetrator.

Billing and fictitious vendors

This fraud scheme is perpetrated by issuing disbursements to either a fictitious vendor or to a legitimate vendor for fictitious goods/services. The fictitious vendor is entered into the vendor master file and receives payment for goods and services not actually provided. Legitimate vendor accounts may also be used to commit fraud. Payments to legitimate vendors for fictitious goods/services may be intercepted and converted, or employees can collude with existing vendors to create inflated invoices or false invoices and provide kick-backs or bribes to the employee. Please see “Vendor Fraud” in the Spring 2017, Issue 3, edition of FVS Eye on Fraud for more information.

Expense reimbursement

As mentioned previously, expense reimbursement is one of the most prevalent forms of corruption because it is so easy to commit compared to other frauds. Some common examples include:

  • Submitting personal expenses as business expenses (for example, dinner with a spouse is submitted as dinner with a client)
  • Writing in overstated amounts for blanks on a receipt (for example, a $20 taxi ride from the airport is submitted as a $40 ride)
  • Duplicating reimbursement (for example, a board member is reimbursed mileage from the organization and from their employer)
  • Masking true nature of expense to one that is allowed by company policy (for example, submitting “discrete receipt” from a “gentlemen’s club,” to make an outing appear to be dining, rather than non-allowed adult entertainment)

Some Slightly More Sophisticated Examples of Employee Corruption

Bid rigging

Bid rigging occurs when participants work together, also referred to as colluding, to make it appear as though several competitive bids have been received, when in fact the process is “rigged” to favor a higher-than-necessary price. This is often accomplished through employees inside an organization’s procurement department working with accomplices to set up sham “business” entities. These employee-controlled “businesses” work in coordination to fabricate the bids. Of course, an enterprising procurement employee may work with individuals outside the company as well.

The element of collusion can make fraud much more difficult for a forensic accountant to detect. However, the involvement of more than one participant can sometimes cause the scheme to unravel — when one participant feels shortchanged, they may turn on the others.

Kickback

The barn built for the manufacturing engineer mentioned previously is an example of a nonmonetary kickback. Although the engineer’s employer does not directly lose cash, the company is likely paying more than they need to for the maintenance service in this case. In other cases, the cost of whatever good or service the vendor is providing may be inflated due to the “extras” that have been provided to the employee awarding the contract(s).

Kickbacks can also be in the form of cash. For example, a hiring manager negotiates with a potential recruit and offers them a high-paying position, as long as 5% of the new salary is secretly given back to the hiring manager.

Bribery

This scheme involves the corrupt payment of money, gifts or other rewards to influence the action of another person. Generally, in order to investigate bribery, a forensic accountant must understand a company’s compliance program and the applicable laws and regulations.

The U.S. Foreign Corrupt Practices Act (FCPA) prohibits corrupt payments to foreign officials and requires that books and records be maintained in a manner to assure that such corrupt payments are not made. Companies with international agents or operations are subject to extensive controls and monitoring responsibilities. The provisions of FCPA are beyond the scope of this publication. For guidance, see sec.gov/spotlight/fcpa/.

How Does This Happen?

Hiring practices

All too often employers just do not do enough to properly vet new employees. See the “Practice Tips — Pre-Employment screening” insert for some suggestions.

Failure of fraud victims to report theft

As forensic accountants, we often hear after the fact that a fraudster had actually stolen before, but the theft had not been reported. Unfortunately, this hesitancy is widespread and occurs for different reasons. Some organizations do not want the reputational harm of being known as a victim. Some fear the reaction of investors, donors, employees, or the community at large.

Lack of training/corporate culture

There should be no question regarding what a company believes is the appropriate use of funds. Leaders establish the tone at the top by embodying the values of the entity. If a CEO buys expensive wine with employees present at the company’s expense, those employees will likely mimic the behavior if given the opportunity.

Lack of internal controls surrounding accounting and procurement processes

Internal controls around key accounting (cash disbursements and cash receipts) and procurement (purchase orders and receiving) processes help mitigate the risk of employee corruption. Segregation of duties and secondary reviews within these processes are examples of controls that will prevent and detect various fraud schemes.

FVS Eye on Fraud

Filed Under: Forensic Accounting, Services Tagged With: AICPA, corruption, Elizabeth, fraud, fvs, Valuation, Woodward

Article 02.21.2017 Dean Dorton

Fraud is estimated to be a $3.5 trillion annual business with the typical company losing 5% of its revenue each year. Managing the risk of fraud is challenging for any organization, but especially for a company in the manufacturing industry.

When ranking the number of frauds committed over the past 10 years, the manufacturing industry has been within the top five each year.

There are several reasons for this:

  • Decentralized operations make it difficult to ensure policies and procedures are being followed properly at all locations
  • Limited security and/or the size of certain products or supplies make it easy for employees or others to misappropriate assets
  • The use of low wage factory workers, especially in foreign locations, allows for employees to rationalize fraud
  • The increasing use of new technology allows hackers and outside fraudsters new opportunities to commit fraud
  • The complexity of accounting for inventory allows accounting personnel to cover up frauds
  • The tough economy continues to add pressure for management to meet or exceed budget

The continued increase in fraudulent activities is one of the reasons the Committee of Sponsoring Organizations of the Treadway Commission (COSO) has published a Fraud Risk Management Guide. Over the past 30 years, COSO has developed an internal control framework that is widely accepted and used and has provided thought leadership in the areas of enterprise risk management, internal control and fraud deterrence.

The Fraud Risk Management Guide’s executive summary emphasizes that deterring fraud is achieved when an organization has a strong fraud risk management program, which includes:

  • Establishing visible and rigorous fraud governance policies
  • Creating a transparent and sound anti-fraud culture
  • Performing a thorough fraud risk assessment periodically
  • Designing, implementing, and maintaining preventive and detective fraud control processes and procedures
  • Taking swift action in response to allegations of fraud, including, where appropriate, actions against those involved in wrongdoing

The guide includes examples of key program components and resources that organizations can use to effectively and efficiently develop a fraud risk management program. The guide also contains references to other sources of guidance for tailoring a fraud risk management program to a specific industry. It is designed for use by any organization, no matter the size or industry, and is highly recommended for companies in the manufacturing industry.

Our Recommendations
At Dean Dorton, we have assisted organizations in implementing various components of this fraud risk management program and have seen firsthand how it can reduce fraud. We recommend that your company starts by evaluating your existing business environment and gaining an understanding of the policies, controls, and processes you currently have in place. Secondly, you should gain an understanding of the objectives and mindset of your board of directors (or other governing body). This will give you a good idea of where you are today, what gaps you might have, and where you want to be. The COSO guide can then be leveraged to help you develop a strong fraud risk management program.

Questions?
Contact Jim Tencza at jtencza@deandorton.com.

Filed Under: Industries, Manufacturing & Distribution Tagged With: COSO, fraud, Jim, Manufacturing, Risk, Tencza

  • Page 1
  • Page 2
  • Page 3
  • Go to Next Page »
  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved