Skip to main content
The state of ai impact assessment
Fraud Controls in Telecoms: Five Myths Auditors BelieveRegulatory Bodies
5 min readFor Internal Auditors

Fraud Controls in Telecoms: Five Myths Auditors Believe

When the U.K.'s Serious Fraud Office announces an investigation into suspected fraud, false accounting, and money laundering at a telecom firm like Internet Mobile Communications Limited, internal auditors should take notice. These investigations don't happen overnight. They're the result of control failures that were likely visible months or years earlier.

Yet many internal audit teams in telecoms still operate under dangerous misconceptions about fraud detection, regulatory risk, and their role in prevention. These myths don't just create blind spots; they create conditions where financial misconduct flourishes undetected until external investigators arrive.

Myth 1: Fraud Detection Is the Fraud Examiner's Job

Reality: Your periodic financial audits are the first line of defense, and you're uniquely positioned to spot patterns that specialized fraud teams might miss.

Fraud examiners investigate after suspicion arises. You review controls, transactions, and reconciliations as part of routine operations. That regular access gives you the earliest warning signals: unusual journal entries, revenue recognition anomalies, or accounts payable patterns that don't match operational reality.

Under ISO/IEC 27001 Annex A.5.1, you're expected to establish policies for information security that include fraud risk. The COSO Framework positions internal audit as a monitoring function that evaluates fraud risk management. When you defer fraud detection entirely to specialists, you're abdicating a core responsibility.

The practical step: Build fraud indicators into every financial audit workpaper. Flag transactions above materiality thresholds that lack proper authorization trails. Review segregation of duties matrices quarterly. When you spot a revenue booking that doesn't align with contract terms, escalate it.

Myth 2: Strong Preventive Controls Mean You Can Reduce Detective Controls

Reality: Preventive controls fail. Detective controls catch the failure before it becomes an SFO investigation.

Many audit committees push back on detective control costs, arguing that if you've implemented proper authorization workflows and segregation of duties, continuous monitoring is redundant. This logic collapses the moment someone with proper authorization decides to commit fraud.

Consider your three-way match process for accounts payable. It's a preventive control. But without detective analytics that flag duplicate invoices, sequential invoice numbering gaps, or vendor addresses matching employee addresses, you won't catch the authorized user creating fictitious vendors.

The NIST Cybersecurity Framework 2.0 emphasizes continuous monitoring under its Detect function because prevention alone is insufficient. Your detective controls, reconciliation reviews, exception reports, data analytics on transaction populations, provide the audit trail that demonstrates you identified issues before external parties did.

The practical step: For every preventive control you test, identify the corresponding detective control. If you're testing purchase order approval limits, also test exception reports that flag split purchases just below those limits. Budget for both.

Myth 3: If Financial Statements Are Clean, Controls Are Working

Reality: Financial statement accuracy is an outcome measure, not a control effectiveness measure. Material misstatements can hide in immaterial accounts for years.

Your external auditors test controls over financial reporting under SOC 1 principles or Sarbanes-Oxley Act Section 404 requirements. They're sampling for material misstatement risk at the consolidated level. They're not designed to catch fraud schemes that manipulate immaterial accounts, defer small expenses across periods, or create fictitious assets below materiality thresholds.

False accounting often starts small. An employee defers £50,000 in expenses to meet quarterly targets. Next quarter it's £100,000. Within two years, you have a pattern of material misstatement that no single-period audit would flag because each individual manipulation stayed below detection thresholds.

The practical step: Test high-risk processes regardless of financial statement materiality. Review all manual journal entries to revenue and deferred revenue accounts, even if the amounts are immaterial. Analyze expense accruals for patterns: Are the same accounts consistently adjusted in the final week of each quarter? That's a red flag, even if amounts are small.

Myth 4: You Can't Afford Continuous Monitoring Tools, So Annual Testing Is Sufficient

Reality: You can't afford not to have continuous monitoring, and you're probably already paying for capabilities you're not using.

The cost-benefit argument against fraud analytics tools assumes that annual control testing provides sufficient assurance. But when fraud occurs, the cost isn't the tool you didn't buy, it's the regulatory investigation, the reputational damage, and the executive terminations that follow.

You likely already have data analytics capabilities in your ERP system, your audit management platform, or your business intelligence tools. The gap isn't technology; it's the audit program design that still treats testing as an annual event rather than a continuous process.

Under the COSO Framework, monitoring activities should be ongoing or periodic depending on risk. For high-risk processes like revenue recognition, cash disbursements, and payroll in telecom operations, ongoing monitoring is the appropriate response.

The practical step: Start with one high-risk process. Build a monthly analytics routine that flags anomalies: payments to new vendors above £10,000, revenue bookings without corresponding service activation records, or payroll changes for terminated employees. Use your existing tools. Refine the queries as you learn what normal variation looks like.

Myth 5: Regulatory Investigations Only Happen to Companies With Weak Governance

Reality: Investigations happen to companies where fraud occurred and wasn't caught early enough. Governance quality determines how quickly you detect and report, not whether fraud attempts occur.

The presence of an audit committee, a whistleblower hotline, and an internal audit function doesn't prevent fraud. It creates the environment where fraud is more likely to be detected and reported before it reaches investigation-worthy scale.

The SFO doesn't investigate control weaknesses. It investigates suspected criminal conduct. The question isn't whether your governance framework is strong on paper, it's whether your controls actually detected the issue and whether you self-reported before external parties discovered it.

Under the General Data Protection Regulation accountability principle and ISO/IEC 27001's continual improvement requirement, you're expected to demonstrate that your controls are operating effectively, not just that they exist. Documentation of control design is table stakes. Evidence of control operation and issue detection is what matters.

The practical step: Track your issue detection source for every significant finding. Was it identified by a control (automated reconciliation, manager review), by internal audit, by external audit, or by a third party? If most issues are found by external parties, your detective controls aren't working regardless of how good your governance documentation looks.

What to Do Instead

Stop treating fraud risk as someone else's problem. Your audit plan should include specific fraud detection procedures for every high-risk process, not just control effectiveness testing.

Build detective controls into your monitoring routine. Test them as rigorously as you test preventive controls. When you find control failures, trace them back: How long did the issue exist? Why didn't existing detective controls flag it?

Quantify your detective control coverage. What percentage of your high-risk transactions are subject to ongoing monitoring versus periodic sampling? If the answer is below 50%, you have a gap that annual testing won't close.

And when you brief your audit committee on control effectiveness, include metrics on detection speed: How long does it take to identify a control failure? That metric matters more than control design ratings when regulators start asking questions.

The IMC investigation is a reminder that fraud detection isn't about having the right policies. It's about having controls that actually catch problems before external investigators do.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like