University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

9
University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007

Transcript of University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

Page 1: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

University of Waterloo - 5th Symposium on Information Systems AssuranceOct 11 - 13, 2007

Page 2: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

2

Agenda

·Introduction

·What’s not covered / What is covered

·Approach and Findings

·Conclusion

Page 3: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

3

What’s not Covered·A discussion of the mathematical underpinnings

What is Covered·An evaluation of the paper from a practitioner’s point of view

·Using 3 datasets with known fraudulent entries

·A practical application from South Africa with demonstrated success

·Comments on the paper

Page 4: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

4

Approach and Findings

·Applied the concepts of second order tests to 3 datasets:– Extended Warranty Insurance company– Wake County Public School System procurement fraud– Journal entry training data

·Results and conclusions of each

Page 5: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

5

Extended Warranty Insurance Co. Fraud

E

Fictitious Repair Shops

R T N V I V

E R A O O A E N N T

P A M N C M S C N N V D T O

F N T E R T P E A O D D S O T

A S G _ E G O Q R N I E C T C

C G T A D T B I E R N L O A L

I T 3 D I 5 O N O E I A R M M

L 3 K J T 0 X V F G T Y E T S

AUTOTECH REPAIR 1 1 1 1 1 0 1 0 1 0 1 8 $14,921.04 13

CIVIC TIRE AND BATTERY 1 1 1 1 1 1 0 0 1 0 1 8 $7,412.16 8

DOUG'S METRO 1 0 1 1 1 1 1 0 1 0 1 8 $1,449.31 4

DOUGS HEAVY DUTY REPAIRS 1 0 1 1 1 1 1 0 1 0 1 8 $1,870.64 4

EARL BLOIF REPAIR 1 0 1 1 1 1 1 0 1 0 1 8 $701.94 5

G.C.T. AUTO TECH 1 1 1 1 1 0 0 0 1 1 1 8 $4,333.05 4

GUS REVENBURG 1 1 0 1 1 0 1 0 1 1 1 8 $3,818.72 8

K&M TUNE-UP CENTRE 1 1 1 1 1 0 0 0 1 1 1 8 $26,651.06 17

MINDEN AUTO CARE 1 1 0 1 1 1 1 0 1 0 1 8 $3,058.64 6

S T S MOTORS 1 0 1 1 1 0 1 0 1 1 1 8 $2,219.55 4

== = = == == = = = == = == == =============== ==

10 6 8 10 10 5 7 0 10 4 10 80 $66,436.11 73

E

Summary by Claims Approver

Page 6: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

6

Wake County Public School System - N Carolina- Procurement Fraud

Page 7: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

7

Journal Entry Training Data

Page 8: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

8

South African Example

· “Using Benford’s Law To Predict Data Error and Fraud” – Dr, Adrian Saville, Chief Investment Officer, Cannon Asset Managers [www.cannonassets.co.za]

·Used Benford’s Law to predict the failure of several listed companies in SA based upon publicly available data

· “First, the tool has been used in a dumb and live environment with great success.  By way of example, the tool identified Nedbank’s financials as failing a first order test of Benford’s law.  Nedbank went on to report a series of investments that needed to restated and also had to go to shareholders for recapitalization.  The implication for investors was costly.  Further, the tool we employ identified two of South Africa’s large gold miners – JCI and Randgold – as producing questionable results and so steered us away from these companies as investment candidates.”

Page 9: University of Waterloo - 5 th Symposium on Information Systems Assurance Oct 11 - 13, 2007.

9

Conclusion

·When looking at the second order test results alone it is not immediately evident that fraud exists in the first two datasets

·More research and guidance is needed to aid the practitioner

·There is no doubt that Benford Analysis is useful and is providing competitive advantage to many organizations