Authored by Desiré Carroll, CPA, CA(SA), Senior Director, Professional Practice at the Center for Audit Quality
In an era defined by rapid technological change, evolving regulatory expectations, and increasing business complexity, organizations must continually adapt their approaches to fraud risk oversight.
As a member of the Anti-Fraud Collaboration (AFC), the Center for Audit Quality (CAQ) develops resources to help organizations strengthen their anti-fraud efforts and brings together stakeholders from across the financial reporting ecosystem to share leading practices for deterring and detecting fraud.
At the 2026 ACFE Global Fraud Conference, I observed the AFC’s Executive Workshop focused on the evolving fraud risk environment, the role of technology and AI, and the importance of coordinated action across the financial reporting ecosystem. The discussion brought together perspectives from audit committee members, internal and external auditors, forensic experts, and other leaders to explore how organizations can effectively identify, assess, and respond to these risks.
While regulatory priorities and business risks continue to evolve, the responsibility of the financial reporting ecosystem to maintain strong controls, exercise professional skepticism, and respond quickly to potential misconduct remains important. Here are four of my key takeaways from the session:
1. Regulatory and market developments do not reduce the need for vigilance
SEC enforcement priorities and areas of focus can evolve over time, but those shifts should not be interpreted as a reason for companies to relax their focus on compliance, disclosure, and controls. Informal information requests from the SEC remain ongoing. Whistleblower reports, short-seller activity, and other external signals can also quickly draw attention to potential financial reporting issues.
Participants emphasized that in an environment where regulatory focus can change quickly, maintaining disciplined risk management and internal control processes helps organizations avoid being caught flat-footed or needing to spend significant amounts of time and money to reinstate relevant processes and controls.
2. Non-GAAP measures, disclosures, and management integrity remain areas of focus
The workshop also highlighted continued attention by the SEC on MD&A, earnings materials, investor communications, and non-GAAP measures. These areas often require significant judgment and warrant careful attention from company management, auditors, and audit committees.
Participants also emphasized the importance of timely communication with external auditors when a company receives an SEC information request or identifies a potential issue. Even if management initially believes the matter is immaterial or straightforward, auditors will need to understand what the company has done to investigate the issue, assess the potential impact on financial reporting, and consider any implications for management integrity, competency, and internal control over financial reporting.
3. Culture, pressure, and growth strategies can increase fraud risk
Through a case study discussion, the workshop explored how pressure to deliver growth, expansion into new geographic markets, inadequate compliance investment, and weak communication channels can combine to create conditions in which fraud risk increases.
Participants pointed to several red flags in the scenario, including:
- Insufficient understanding of a new geographic market;
- Language and local compliance challenges;
- Limited investment in compliance infrastructure, and
- Business units operating in silos.
These themes reinforce the need for management, internal audit, legal, compliance, and the audit committee to remain connected as companies pursue growth opportunities to identify potential issues more quickly. When potential issues arise, integrated team connection enables organizations to move quickly and ensure that the right parties are involved in determining a path forward.
4. Artificial intelligence can both elevate and obscure fraud risk
The case study also prompted a robust discussion about the role of AI tools in fraud risk. Participants noted that AI can reduce friction, accelerate analysis, and help detect issues faster, but at the same time, ad-hoc or poorly governed AI use introduces new risks. These include reduced critical thinking, obscured accountability, and a potential lack of appropriate testing, approval, oversight, and controls.
When emerging technologies are used in business operations or financial reporting, humans must remain in the lead. AI-generated summaries, translations, or analyses should not replace professional judgment, review of underlying documents, or the need to understand the business context. All stakeholders should understand how the organization is using AI, how AI tools are governed, and how related risks are incorporated into enterprise risk management and internal control processes. This ensures that AI is used responsibly and that stakeholders can trust the information and systems they have long relied on.
The session emphasized the importance of remaining vigilant amid changing regulatory conditions, exercising sound judgment, fostering a culture that mitigates fraud risk, and thoughtfully governing the use of AI. Members of the financial reporting ecosystem who focus their organization’s anti-fraud efforts on these principles will be better equipped to navigate uncertainty and uphold trust in financial reporting.
Follow the CAQ and AFC on LinkedIn for additional resources and insights into how to deter and detect fraud.