Video summary

Fraude en las empresas por falta de controles internos

Main summary

Key takeaways

News and Commentary

Overview

This video is a panel discussion by the Mexican Institute of Public Accountants (“Accounting Comments”) focused on how fraud happens in organizations, particularly when there are weak or missing internal controls—and what companies should do to prevent, detect, and respond to it.


Main arguments and key points

Fraud is universal (not determined by company size)

Panelists emphasize that fraud can occur in both small and large companies and in any region. Some studies suggest smaller firms may feel fraud’s impact more strongly—often due to simpler structures and less complex control environments—but the risk of fraud itself is not exclusive to any size or geography.

Weak internal controls enable multiple forms of fraud

The panel highlights that when controls are absent or weak, organizations become vulnerable to:

  • Misappropriation of assets and funds
  • Ethical and moral deterioration within the organization

Controls are framed as preventive and structural tools, not merely compliance checklists.

Fraud has financial and reputational consequences

The panel describes fraud’s impact in three dimensions:

  1. Amount of fraud (direct economic harm)
  2. Costs of investigating (forensic work, lawyers, evidence gathering, legal action)
  3. Reputational damage (loss of clients, employee departures, and potential effects on stock performance)

Reputational harm is often described as harder to quantify, yet highly damaging—potentially triggering a “downward spiral,” such as:

  • Clients reducing business
  • Suppliers refusing favorable terms
  • Investors losing confidence

“Tone at the top” and culture drive fraud risk

Fraud risk is linked to organizational behavior and leadership example, often called management tone.

  • If authorities observe owners/employers engaging in bribery during inspections, it may normalize wrongdoing and encourage similar behavior internally.
  • Codes of ethics are necessary, but must be actively disseminated and verified (e.g., acknowledgment/certification and corporate governance mechanisms).

Fraudsters can be internal and external

The panel notes fraud is committed by:

  • Employees/internal parties
  • External actors

Example: a fake customer scenario where a salesperson ships products based on a large order, only for the customer verification/check to be fraudulent (“plastic”/not real).

Companies are vulnerable primarily due to control weaknesses and lack of monitoring

Vulnerability is attributed largely to:

  • Missing internal control systems

Preventive mechanisms include:

  • Systems, policies, procedures
  • Indicators
  • Monitoring of sensitive areas of the business

Internal controls should be treated as an investment (measurable ROI)

Internal controls are positioned as an investment, not an “expense.”

  • Cited statistic: organizations investing in anti-fraud mechanisms (e.g., internal audit functions, external audits, ethics codes, reporting channels) can reduce fraud detection time by about 50%.
  • The discussion also warns that without these mechanisms, fraud may continue and grow.

Detection timing depends on control maturity

Fraud detection depends on how mature and effective the controls are:

  • With strong controls: detection may happen in less than a year (sometimes faster)
  • Without strong controls: detection may take around 18 months to two years or more

Fraud is also described as ongoing if not stopped—“finding one opportunity can lead to larger repeated behavior.”

Cyber fraud is increasingly relevant

The panel includes digital and identity/data theft fraud, such as:

  • Phishing via websites/emails
  • Unauthorized use of bank details
  • Identity impersonation

Recommendations include investment in:

  • Cybersecurity (firewalls, penetration/hacking tests)

It also highlights insider-related IT fraud risks, such as:

  • Tokens/keys
  • Password changes
  • Payroll/accounting authorization misuse

A further audit concern: auditors may face greater distrust in automatically generated statements/records, and tools like spreadsheets (e.g., Excel) are mentioned as inadequate without proper security controls.

The “fraud triangle/diamond” explains behavior

The panel uses the fraud framework to explain why fraud occurs:

  • Opportunity: created by missing controls
  • Pressure: personal needs (e.g., financial stress) and business pressure (targets and management demands)
  • Rationalization: common justifications (e.g., “I deserve it,” resentment over lack of promotion/raises)

The cycle must include prevention, detection, and response (sanctions)

The panel warns that prevention and detection alone are insufficient if organizations do not sanction and close the cycle.

If fraud is detected but no consequences follow, it signals permissiveness and discourages reporting.

Governance and audit committees play a critical role

Corporate governance is described as crucial—especially through audit committees. Committees should:

  • Be properly informed
  • Act decisively
  • Be supported by people with relevant skills (not just “in presence,” but effective functioning)

Shareholders may withdraw funding if fraud or reputational risk becomes evident, so governance must be strict.

Practical suggestions for public accountants

Public accountants are urged to:

  • Act ethically and receive specialized training in controls and fraud prevention/detection
  • Help establish or recommend monitoring of sensitive activities, risk matrices, and accessible control frameworks such as COSO and Kobe (as referenced in the subtitles)
  • Use simple risk tools (e.g., prioritizing and scoring risks as low/medium/high) based on the company’s core processes

Final takeaway

The panel concludes that internal controls are central to reducing fraud, but the true strategy is a complete cycle:

prevent, detect, and respond (sanction)

This cycle should be supported by:

  • Ethics and leadership tone
  • Strong governance (including audit committees)
  • Cybersecurity
  • Continuous updating of control procedures

Presenters / Contributors

  • José de la Fuente Molina (advisor to the Vice Presidency of Communication, Mexican Institute of Public Accountants)
  • Alfonso Crespo Molina
  • Roberto Ramón Marí
  • Ángel Bravo Trujillo

Original video