Title: Fighting Fraud With Software The WizSoft Approach for Auditors
1Fighting Fraud With SoftwareThe WizSoft
Approach for Auditors
IIA North Jersey Software Expo Presented May
17,2007 BOB DENKER, CIA,CISA,CFE Baruch College,
CUNY For WizSoft Inc.
2Problems with data analysis tools
- Becoming complacent
- Ignoring non-trivial fields in testing
3Fraud Testing Applications
- Insurance
- Due Diligence
- Money Laundering
- Human Resources
4What are the data mining applications that should
draw the attention of the auditor?
- Human resources
- employees earning salaries inconsistent with
their title - employees not availing themselves of benefit
programs (perhaps to maintain as much anonymity
as possible) - employees whose household address matches an
address from the vendor file - employees appearing more than once on umbrella
security file
5What are the data mining applications that should
draw the attention of the auditor?
- Financial applications
- (Money Laundering) - structured transactions
(clients who make cash/travelers checks/money
order contributions to annuities, single premium
life insurance, IRAs, mutual funds, etc.) in
aggregate amounts that exceed the US 10,000
reporting threshold
6What are the data mining applications that should
draw the attention of the auditor?
- Financial applications
- 2. clients making contributions to investment
vehicles that are disproportionate to their income
7What are the data mining applications that should
draw the attention of the auditor?
- Assistance in due diligence testing
- by revealing the business rules, data mining
tools can be used to train new auditors for new
areas or new systems that are being audited for
the first time - identical applications can be used for due
diligence testing
8What are the data mining applications that should
draw the attention of the auditor?
- Construction and purchasing
- invoice for large purchases made at the end of
the fiscal accounting period - price of goods inconsistent with industry costs
9What are the data mining applications that should
draw the attention of the auditor?
- Medical/ dental applications
- patient substitutions
- over-utilization of specific diagnoses
inconsistent with the patient population
10Dental Fraud?
- What is a Sunday Dentist?
- Where is your dentist?
11What are the data mining applications that should
draw the attention of the auditor?
- Provider open seven days a week for
disproportionate number of non-emergency
procedures (could indicate provider is filing
false claims and is spreading out the submissions
to divert suspicion)
12What are the data mining applications that should
draw the attention of the auditor?
- Excessive number of patients traveling great
distances to a provider (could indicate provider
utilizing a postal drop site)
13UNCONDITIONAL RULES1) STATE is CA Rule's
probability 1.000 The rule exists in 1015
records.2) PATIENT_ZIP is 92108 Rule's
probability 0.993 The rule exists in 1008
records.3) PROVIDER_ZIP is 90210 Rule's
probability 1.000 The rule exists in 1015
records.
14Data Auditing Tools
WizRule? - business rules detector for data
auditing, exposes suspected errors in the
data. WizWhy? - analyzer and predictor for
databases, reveals main patterns, interesting
phenomena, unexpected cases, and predicts for new
cases. WizSame? - reveals identical and similar
records suspected as duplicates, in one or two
data sets. WizCount? - performs account/bank
reconciliations and finds all the one-to-many and
many-to-many relevant combinations of matching
transactions.
15WizRule
- WizRule reveals the rules governing the data and
points out cases deviating from the discovered
rules. The deviating cases having the highest
degree of unlikelihood are listed as suspected
errors.
16WizRule?
- WizRule analyzes the data by revealing three
types of rules - Formula rules
- If-then rules
- Spelling rules
17WizRule?
- WizRule issues three reports
- Rule Report - lists the discovered rules
- Spelling Report - lists cases that are likely to
be spelling errors of names or other values
(cases to be audited) - Deviation Report - lists the cases that deviate
from the set of the discovered rules (cases to be
audited)
18Deviation Report
19WizRule
- Corporate users
- Audit Directors
- Internal Auditors
- Risk Managers
- Security Officers
- Financial Analysts
- Consultants
20WizRule
- Business Applications
- Fraud detection
- Internal audit
- IS/IT/EDP audit
- Risk assessment
- Special investigation
- Data quality improvement
- Reverse engineering for business rules
21WizSame
- WizSame reveals similar and identical records
suspected as being duplicate, based on the user's
criteria. - WizSame analyzes one data set or compares two
data sets.
22WizSame
- Reveals cases where records contain synonymous
value (e.g. NY and New-York) - The matching criteria may be defined by several
conditions, connected by AND or OR operators - Reveals matching records in a new table set that
is to be merged in an existing table
23Matching Set Report
24 WizSame
- Revealing duplicate records is mandatory to the
auditing process - compare the Vendor List with the Employee List
- reveal duplicate invoices, payments
- reveal duplicate inventory entries
25In conclusion
- Auditors need to approach each audit with an
open mind and expect the unexpected. - Having additional software tools to augment your
traditional data analysis tools is not a luxury
but a necessity in todays complex audit world! - Thank you for your attention.
-
26Who Are They?
- Fully owned subsidiary of WizSoft Ltd. (1983)
- Headquarters in Tel-Aviv, Israel
- US office in Syosset, NY
- 35,000 customers world wide
- 200 employees
- 18 sales and services offices
- 516-393-5841
- www.wizsoft.com
27- Contacts
- Irina Sered Scott Safara
- Executive V.P. Technical Sales/Support
- 6800 Jericho Tpke., Suite 120W 6800 Jericho
Tpke., Ste 120W - Syosset, New York 11791 Syosset, New York 11791
- Tel (516) 393-5841 Tel (516) 393-5841
- Fax(516) 393-5842 Fax (516) 393-5842
- isered_at_wizsoft.com ssafara_at_wizsoft.com
- www.wizsoft.com