-
Coordinate with other units.
-
Involve legal counsel and law enforcement personnel in the investigation. Seek advice about strategy, possible recovery, and the development of evidence.
-
Develop a "profile" of the agency, its personnel. and program beneficiaries, using information available in public and agency on-line databases.
-
Debrief all persons with previous knowledge of the agency 'Or incident. Further. reevaluate all written reports submitted by auditors or regulators. Consider reviewing previous audit work-papers.
-
Evaluate the effectiveness of auditee hiring practices. Particular consideration should be given to the results of reference checks. polygraph tests, and bonding company investigations.
-
Assess the agency's control environment and. particularly. its moral climate.
-
Assess separation of duties in light of management's awareness of deficiencies, Decision support software may prove useful in this task.
-
Use EDP security software; have people with appropriate qualifications interpret the results.
-
Use analytical review procedures leavened by operational knowledge. The auditor must have informed expectations about anticipated results. Moreover. all information used in the analytical reviews should be subject to completeness and accuracy controls and should be protected from management overrides; an especially created database of financial and operational ratios may be helpful.
-
Use automated flowcharts to identify inexplicable document routings. transportations, and delays. Special attention should be paid to transaction types that do not appear necessary.
-
Conduct behavioral interviews with extreme care; seek guidance of psychologists and law enforcement officers.
-
Make compliance tests meaningful by relentless pursuit of exceptions. Consider expansion of compliance tests to operational controls to enhance the likelihood of detecting improprieties.
-
Reevaluate the nature, timing. and extent of substantive testing in the light of circumstances. Consider the degree of uncontrolled inherent risk for the financial statements as a whole. for individual accounts. and for areas of particular exposure. Assemble a program for substantive audit tests by custom-assembling program modules, such as those incorporated in the AICPA's APG program; add customized program steps to take advantage of operational information for financial audit purposes; identify steps to be performed by use of a general purpose computer audit program.
-
Establish high standards for documentation, guided by counsel.
-
Consider discovery sampling in a relentless search for breakdowns.
-
Provide information to those with a need to know. Based on advice from counsel, feed back information to law enforcement agencies and set the stage for prosecution.