- podcast
- NEWS
What boards don’t know can hurt them
Sponsored by AICPA Member Insurance Programs
Boards need more than reports to provide effective fraud risk oversight; they need structures that help them determine whether risk management programs work.
Jonathan Marks, CPA/CFF/CITP, CGMA, CFE, the author of the most recent FVS Eye on Fraud report, explains more about how boards should be involved — and how they shouldn’t — when it comes to oversight of fraud risk.
Key points of the discussion include how information that reaches the board is often “scrubbed” and why the right questions can help directors stay in the loop on fraud risk.
Editor’s note: The summer FVS Eye on Fraud report is available for download at the link above. It becomes exclusive to FVS Section members after Oct. 9.
What you’ll learn from this episode:
- Why effective fraud risk oversight is a structural discipline rather than a reporting exercise.
- How boards can determine whether a fraud risk management program works in practice without stepping into management’s role.
- Why feedback loops are essential to ensuring that directors receive and understand the right information.
- An explanation of the Candor Chain and the ways critical information can be softened, altered, or lost before reaching the board.
- How the COSO Fraud Risk Management Guide can help boards evaluate risks, controls, and the human factors behind fraud.
Play the episode below or read the edited transcript:
— To comment on this episode or to suggest an idea for another episode, contact Neil Amato at Neil.Amato@aicpa-cima.com.
Transcript
Neil Amato: How can a company’s board go from hearing about risk to owning risk management? This quarter’s FVS Eye on Fraud report focuses on a board’s roles and responsibilities in fraud risk management, and the author of that report is our guest on the Journal of Accountancy podcast. You’ll hear the conversation after this brief sponsor message.
[Sponsor message]
Amato: Welcome back. I’m Neil Amato with the Journal of Accountancy, and I’m joined by BDO senior principal Jonathan Marks, a governance and fraud risk strategist. He’s a CPA who holds a host of other designations and credentials, and we’re glad to have him on the podcast. Jonathan, as I said in the intro, you are the author of this quarter’s Eye on Fraud report. We look forward to talking about it. Thanks for being on the podcast.
Jonathan Marks: Thanks, Neil. Thanks for having me.
Amato: To me, and I am just the question asker here, the key message of this quarter’s FVS Eye on Fraud report, I think, is in the subhead: “Why boards must own the risk, not just hear about it.” That’s an easy concept for us to talk about right now, but it’s not as easy to do. So how do boards make sure they’re taking ownership and not just listening?
Marks: Boards don’t fail at fraud oversight because they lack reports. The article itself argues that fraud risk oversight is a structural discipline, not a reporting ritual. So the board’s job is captured in one phrase: eyes in, fingers out. You know, directors must ensure that fraud risk management program exists, it’s resourced, and actually works in practice without drifting into management’s lane.
So when I get into the article, I talk about oversight and some managing principles. So viewed from the board’s chair rather than a practitioner’s. And it introduces a concept that I call the Candor Chain, a framework for showing how critical information loses urgency at each handoff. And that’s a real serious issue. But getting back to how the board really comes into play here, you know, it’s really framed by a lot of the things that are going on today, including some of the cases that we keep seeing like Marchand, Boeing, McDonald’s, and FTX.
Amato: You wrote in the early parts of this report that the gap between what a board knows about a plan to mitigate fraud and what it knows about the effectiveness of that plan is now a widening gap. What are some of the reasons for that widening gap?
Marks: Yeah, regulations, obviously keeping up with the regulators is certainly an issue. And obviously those things are changing minute by minute, day by day, and their interpretations are as well. The courts — I had mentioned in my opening question these cases that are coming through: Marchand, Boeing, McDonald’s, FTX, Theranos, I mean, certainly have lessons learned in there. If you really go back and you look at those specific things, they really do shape everything that we’re doing.
And the reason that the gaps keep widening is because it’s very difficult to keep up with all this. If you remember, a board’s role is oversight, right? And making sure that information is being communicated to them and the right information is being communicated to them. And so senior leadership is also in a position where they have to keep up with what’s going on as well. And that communication needs to be effective. And we all know that communication has a bunch of different parts. There’s a sender, there’s a medium and there’s a receiver. But the big thing that everybody fails to really understand, and I trick people with this all the time, is that there has to be a feedback loop. And if there’s not a feedback loop, then we really don’t understand what’s going on.
And so since everything is moving at the speed of light and technology is changing so quickly and the world environment is changing so quickly these days, those gaps are really widening because again, if you look at the regulatory environment three or four years ago, completely different the way it sits today, we look at enforcement actions. A lot of those are down. When those go down. A lot of people think they could take their foot off the gas. It’s never a set it and forget it type of exercise.
And so those perceptions, whether real or not, whether the regulators are playing a more strict role within what’s going on, when people look at those numbers, they tend to act or react. And sometimes they don’t realize that in order to maintain their control environment, in order to maintain the proper risk posture, you can’t forget about this stuff. And you have to constantly be learning about what’s going on not only from an external and an internal perspective, but all those things that come into play from a business perspective. And that’s why I believe those gaps are widening and they’re widening every day.
And we see them when we do investigative work all the time, because one of the things that is really required now is to do root cause analysis. And we go back and we look at root cause. The boards that get blindsided and the boards that catch fraud early aren’t separated by intelligence or good intentions. The difference is really structural. Like I said in the very beginning, it’s whether the board itself is built to see those things and some of them are not. And a lot of that’s related to skill and experience and things like that. But there’s a world of difference between being told something exists and knowing that a program actually works as well. And that’s the other thing from an oversight perspective that we see from a board level that really could be the difference between a gap being not there and a gap actually appearing.
Amato: We will link to the Eye on Fraud report in the show notes for this episode. Clearly, there’s more to say about the reasons behind the gap widening. Can you explain why greater oversight is needed in small and mid-size organizations compared with large organizations?
Marks: A lot of people revert to resources. I go back to what’s really important. If you look at smaller organizations as compared to larger organizations, smaller growing companies obviously have different focus and different priorities. And a lot of times it’s not a resource thing at all, Neil. It’s more of a priority thing. And I have this saying that I use sometimes it’s called perfect place syndrome. And a lot of times, you know, when you’re dealing with smaller organizations, they have “fuscle.” It’s not really muscle. It’s fat and muscle. And the reason for that is because they’re doing other things and they don’t have the structure in place yet. And they’re building structure on a continuum, as they move through their life cycle or their growth.
But smaller organizations don’t necessarily have their priorities set up in the right way. And I don’t really see a difference sometimes between small organizations and large organizations. Why small organizations struggle sometimes, again, is because they’re not focused on these particular things. I think it comes down to discipline. It comes down to structure. And a lot of times they’re getting there and they’re moving in the right direction, but it becomes a focus thing for me.
And I think that’s one of the things that we can all do. It’s like professional skepticism. We talk about that all the time ad nauseam. Professional skepticism is not a set it and forget it activity. It’s one of those things that has to be recalibrated all the time in every single thing that we do. No different from a risk perspective if I’m sitting on a board. Boards have to recalibrate their oversight, what they’re looking at, what they’re doing, what’s senior leadership is doing, what are they focused on? And if you don’t have that built in, you don’t have that structure built in, a lot of times it just gets missed or gets pushed to the side.
So, when I hear that we’re resource constrained or whatever, or, you know, we don’t have budget for something, there are so many different things that we could do today that really didn’t exist before that I find that more of an excuse because we’re focused on other things or that these organizations just think that they’re immune to some of the things that larger organizations generally have issue with.
Amato: That’s a good point all the way around. It can be an excuse, especially in the age of AI, when you can put some tools to use for some quick answers on a lot of things. Getting back to your phrase, “eyes in, fingers out” — a board can’t totally be in the weeds on all of a company’s processes. I think what you wrote is “a board does not need to know every control, but it should understand the architecture” in broad terms.
Marks: Again, I think that goes back to the structure. How are things being set up? Who’s looking at them? What is the process for that? When it comes to communication, what’s being communicated to them? Are they seeing the right information, getting the right feedback? Do they get a debrief that is not scrubbed? Do they get a debrief that has that information in them? Providing oversight and being independent is not a luxury for a board. That’s their job, right? And so they need to ask those tough questions. They need to get that information. They need to ensure that things are being done properly from an organizational perspective.
And we’ve seen that in some of these cases where they’ve tried to go back to the board and said, “Hey, you were remiss in your oversight. You did not focus on these particular things.” And again, you can’t catch everything. And like I said, you can’t understand every single control, everything that’s going on. But if you understand that there’s good structure and there’s good process and there’s good communication. Communication is one of those things, sender, medium, receiver, feedback, you’re getting the right feedback. You feel comfortable that you’re getting the right information in your pocket so that you can review that and act on it accordingly, I think that’s where we need to land.
It’s a balancing act to some degree, but serving on a board myself, I have to be careful. Am I providing oversight, or am I stepping in the shoes of management? And that’s the struggle today, especially with the fact that these cases are kind of forcing a lot of these boards to tip over and look over that line. You have to kind of reel yourself back and say, hey, what’s the structure here? What are we doing? Who are the individuals that are involved? What does our communication look like? What does our overall risk program look like? You know, what kind of feedback am I getting from them? Do I have to go get it? Are they providing it to me? Do we have good, collegial conversations about risk and things that are going on? And do I feel comfortable that those things make sense based on what I know? I think that’s kind of where we need to land. There has to be a balance.
Amato: You said early in that answer, you mentioned getting a debrief that is not scrubbed. I think that relates to a term you trademarked, the Candor Chain. Why do you think company cultures tend to sanitize a message that gets to the board instead of flatly stating the problem as it was identified at initial detection?
Marks: Everybody likes to get great news, right? “It’s good. This happened and we met our budget, we met our revenue target.” But let’s go back to the Candor Chain. This theory that I came up with was really based on the fact that a long time ago when the term tone from the top came out, it was actually tone at the top. And I said that can’t be, it has to be tone from the top. And the reason for that is tone from the top to me is probably a subtle change but what it means to me is that tone that’s set by senior leadership of the organization resonates down and through the organization. I’ve been saying this for 25 years. People talk about mood at the middle and buzz at the bottom and all that. That’s wonderful.
But seeing something and doing something are completely different. And so when I kept thinking about this and thinking about what’s going on today, I said, it’s not only the tone from the top, but it’s also the actions that people take along the way, either intentional or unintentional. So if you think about the Candor Chain, it’s really not a theory about liars. It’s a theory about how honest people under real pressure can systematically produce boards that are not the last to know and the first to be blamed. The question is, do employees feel safe about speaking up. And when that information gets generated to folks along the way, what do they do with that information? How is it synthesized? Does it get looked at in its raw form?
One of the things that we started to do a long time ago is when whistleblowers and hotlines came into play, we said, well, let me see the original complaint. And the reason for that is exactly what we talked about. This information gets scrubbed along the way. Because a lot of times people are trying to protect themselves either consciously or unconsciously, sometimes people have different views of things. We don’t have the same core values. Every individual doesn’t have the same core values. We’d like to think that, but that’s really not the case.
And so as you look at information and when you were a kid, you played whisper down the lane, right? You’d say something to someone and by the time it got to somebody else, all the way down the lane, the message could be completely and totally different. You were lucky if the message was somewhat the same, right? Well, it’s no different in an organization. However, there are jobs at stake. There are potentially accounting disclosures that are at stake. There are potential regulatory issues that are at stake, depending on what those matters are. And not everything rises to this grandiose level. But when you start to do this and you start to strip out factual information along the way, the messaging starts to change.
And when that messaging starts to change, you may hear from senior leadership, “Hey, we’ve conducted 50 internal audits, and all of them came out OK.” What does OK mean? And if you don’t ask that next obvious question: Were there any issues? Were there any overrides of controls? Was there any process breakdowns? Was there any change in key positions? If you’re not smart enough to understand that, then what happens is along the way, along the chain, you know, that information starts to break.
And I’ve actually seen this in investigations where you have somebody who comes forward and says, “Hey, I don’t think this is right,” and then it goes to a manager. And if that manager doesn’t know what to do with that information, they either report it or they don’t report it. So sometimes it goes out the chain. But if it does get reported, a lot of times it’s their version of what was said to them. And then if it goes up, then it becomes somebody else’s version of what was said before it even gets to the board, if it gets to the board. And when it gets to the board, it can look completely different than the original message.
So, one of the things that we encourage folks to do when doing an investigation, you know, I know this is really outside the purview of this particular article, but it’s really, like I said before, look at the original complaint. What did somebody say? You know, what did they write down? What did they articulate? And that’s really what I mean about this whole concept of the Candor Chain. And you can read all about it, but we have really expanded on that, because I do think it’s not only the tone, but it’s the actions that people take along the way when they do get that information.
Amato: Yeah, you’ve given us a lot to think about. You were a contributing writer to the COSO Fraud Risk Management Guide’s second edition, published in 2023. Why is that framework valuable for boards and risk?
Marks: There are a couple things. One, COSO and all the people and all the contributors to that piece, I think what we try to do is we try to bring things into the current state. And so there are concepts in there that allow people to think differently, but I think there’s better structure, better awareness. We talk about different concepts. I’ll give you a great example. You look at what I call the fraud triangle. I don’t call it that, but it was named that eventually. But you look at the three concepts that [Donald] Cressey came up with back in the 1950s when it comes to fraud: pressure, opportunity, rationalization. It all made sense back then, but companies were way different in the ’50s than they are in 2026. Single line reporting authority, I mean, that can go on and on and on.
You look at what’s going on today and you look at the frauds that have happened, Madoff, Milken, Kozlowski, you know, Enron, WorldCom, Adelphia, keep going on and on. Some of the things that we talked about today. If you look at the Fraud Risk Management guide, we kind of bring in that human element to a lot of this. We actually introduce a new concept called the Fraud Pentagon, which is something that I helped create. It adds two additional components to what I call the perpetrator side, which is competence and arrogance. So if you look at Cressey’s original concept of pressure, opportunity and rationalization, all still hold, all still great things that we should be considering, but competence and arrogance certainly play a role, too.
And so that’s one-dimensional, right? So we look at these things and then we bring in other concepts along the way as well. We talk about the definition of control in there, which I always say this to people. I go like, well, we’re in the control world. What does control mean? If I say internal control, what does that mean? What’s the definition of an internal control? A lot of times people just sit there and they don’t know what the definition is. And they can’t even describe it. Well, control does something. It has a certain objective to it, right? And if you don’t understand that, how can you be in the game here? How can you be helping companies analyze gaps or weaknesses or controls if you don’t understand what a control should be doing?
And so I think if you look at the Fraud Risk Management Guide, it does a really good job of not only laying out these principles and the concepts, but it also includes some of the definitions in there and some of the things like bringing the human in the loop was something that I think we were all pretty passionate about when we sat down and wanted to make this better.
And I give COSO and the ACFE a great deal of credit for this. Because they said, “Hey, you know what? We’ve got this guidance. We really need to update this.” And that continues to go forward. But having that structure, having that framework in place and having some uniformity with regards to all of this really does help. And again, it’s not perfect, and it’s not meant to be. But if you can go through and look at the structure and the framework and get a good idea. Where do we stand against this? Do we have these things? Are we considering these things? Is this our process? Those are all fair game questions, and I think that document actually helps bring all that out.
Amato: That’s great. Jonathan Marks, anything you’d like to add as a closing thought to what’s been a great conversation?
Marks: The most important question a director can ask is this: What information was identified but never reached me?
It’s not what we know, it’s what we don’t know, Neil. And I think kind of ending on that, what’s required is not new power. It really isn’t. It’s the will to use that power the board already holds deliberately and on schedule — that’s really what this is all about. It’s really being better informed and making good decisions. And I think some of these cases articulate that the boards really weren’t focusing on asking those particular questions to senior leadership. They were just comfortable in what was provided to them. And I think that’s really where we need to be going. We need to make sure that everyone’s got an oar in the water and they’re all rowing in the right direction. But more importantly having everybody functioning in a way where it’s not just one-way information, it’s two-way information.
Amato: That’s Jonathan Marks on the Journal of Accountancy podcast. Jonathan, thanks very much.
Marks: Thanks, Neil. Thanks for having me.
