Your assignment
Role: Internal-audit manager redesigning journal-entry and fixed-asset controls after learning how threshold-aware entries can evade review
Deliverable: A control-redesign brief with an alleged-entry flow, aggregation analysis, management-override response, audit test plan, and governance escalation path.
Evidence basis: public records
Evaluation criteria
- alleged mechanism map (25%): Accurately maps how the complaint says entries were generated, split, classified, approved, and reflected in accounts.
- aggregation and analytics (25%): Explains why item-level thresholds are insufficient and specifies meaningful aggregation dimensions and anomaly tests.
- control and evidence design (30%): Links each risk to preventive or detective controls, retained evidence, ownership, timing, and override escalation.
- claim discipline (20%): Treats the complaint as allegations and avoids turning control weakness alone into proof of fraud.
Your role and decision
Your company reviews every capital addition above a fixed dollar threshold. The audit committee asks whether that control is sufficient after reading that false entries can be split into smaller amounts. You must redesign the process without pretending that every small entry is suspicious.
Evidence packet
Use the SEC's complaint concerning HealthSouth. Extract allegations about entry generation, amount, classification, accounts, records, and management involvement. Preserve the complaint's legal posture.
Required work
- Map the alleged path from an earnings target or shortfall through entry creation, account selection, approval, ledger posting, financial statements, and supporting asset records.
- Explain why a per-entry threshold can be gamed. Design aggregation views by preparer, approver, account, facility, vendor, time, round amount, posting source, and proximity to the close.
- For each major risk, specify a control owner, frequency, evidence retained, reviewer independence, exception threshold, and escalation path.
- Design audit tests that combine ledger analytics with invoices, physical existence, subsequent activity, confirmations, access logs, and interviews.
Constraints
Do not infer fraud from an unusual entry alone. Do not recommend reviewing only items above a second threshold. Separate the historical complaint from current requirements and your proposed design.
Evaluation
The strongest brief explains both how collusion and management override weaken ordinary controls and how independent evidence, aggregation, and governance can make the pattern harder to conceal.