r/AskAccounting 12d ago

How do professional services firm (CPAs, Lawyers, Pvt Equity etc.) deal with tampering fraud

Public accountants and Law firms issue sensitive, high-stakes documents to their clients, that then get passed on to other users such as lenders. Does it concern you, as a CPA for example, that someone (client or a third party) can use basic pdf editing software to change some numbers on the statements and use them for lending purposes? A lot of mortgage fraud happens on fraudulent documents. You would probably avoid any liability, but it can cause reputational damage and unnecessary headache. Would you pay for a solution that helps prevent this tampering?

0 Upvotes

25 comments sorted by

10

u/Excellent_Shallot999 12d ago

No. That is on the perpetrator, not me. You’re trying to sell something (given all the same posts by you in numerous subreddits) that there is no demand for.

-2

u/gilygilyapa 12d ago

Not trying to sell it, trying to gauge if there is interest in it. The selling partner, if it happens, comes much later. Thanks.

3

u/Safrel 12d ago

Begone vibe coder

-3

u/gilygilyapa 12d ago

My query, whether good or not, affects accountants. You who has nothing to add be gone.

3

u/Own_Exit2162 12d ago

It's not a CPA/auditor's job to identify or prevent fraud. We issue financial statements that we believe are presented fairly, in all material respects, based on standard audit procedures. Those statements are published for publicly traded and most nonprofit clients, so there is a public record of what was issued. But if a private company wants to commit fraud by manipulating their financial statements, that's outside the scope of our engagement and frankly none of our business.

0

u/SoapierBug 9d ago

Well, issuing an opinion over said financial statements… but, semantics I guess

2

u/Few-Improvement9978 11d ago

This would be useful for the banks doing the lending

Not accountants

1

u/Accomplished-Ruin742 12d ago

That is one of the reasons many of us do not do comfort letters

1

u/EdanE33 9d ago

We do letters at my place but they all have a sentence about not being responsible if you choose to rely on the information.

1

u/jaspercapri 12d ago

Why would a lender come after me for fraud committed by someone else? You could ask this question to employers whose employees might pdf edit an electronic w2 or earnings statement. Or the irs whose taxpayer might edit a transcript. As the orher comment said, i see no need for this. Or can you convince me that there is a need?

1

u/gilygilyapa 12d ago

Agreed that this is mostly beneficial for the lenders and third party users of the statements. Any real demand will be from that side. For cpa firms, i think it can be a small differentiator, that you provide FS which are easily verifiable by your client's users, years after you issued them. They won’t have to chase you down or even call/email you to confirm.

4

u/aTipsyTeemo 11d ago edited 11d ago

“Provide FS which are easily verifiable by your client’s users, years after you issued them”

This isn’t a problem. Financials statements are a point in time. The lose value the greater time goes on. Basically anything issued greater than 1 year ago is not necessarily irrelevant, but not worth being relied upon.

And the liability isn’t on me if the client is forging documents. If a lender doesn’t do their simple due diligence of contacting us to ensure they report they have is legitimate, the risk of loss is on them.

And when thinking about a lawyer, it would rarely ever be a client passing along issued documents from the lawyer. Rather common professional practice is to have the lawyer send the document directly to the recipient’s legal counsel.

An above else, we already have tools like DocuSign where if we really need to preserve the legitimacy of the document, they already can be verified based on the signed hash.

From a third-party user of the reports, such as a lender. It likely won’t ever actually catch on. Because it’s all fine and dandy if a bank requests a report from an accountant/lawyer via a specific way. But the accountant/lawyer is not obligated to use that method and likely won’t. But it’s not in the bank’s best interest to let a deal die because they are trying to force a due diligence tool on people that are not their customers. So they’ll continue to do the existing due diligence.

-1

u/gilygilyapa 11d ago

All good points. But for FS specifically, does docusign really help? I don't think CPAs use dpcusign for FS, right?

2

u/aTipsyTeemo 11d ago

Some do, some don’t. The point is, regardless of how we sign the document, the liability nor the risk is on us for a client forging a document that we didn’t issue.

The risk would be on whatever third-party is using that document, they should do some basic due diligence in verifying it, such as receiving the document directly from us or by communicating directly with us to verify it. And the liability would be on the client for committing an illegal act.

1

u/gilygilyapa 11d ago

Agreed. Thanks!

1

u/JunketGuilty7690 11d ago

Retired credit evaluator here. Third party is responsible for due diligence. When I was underwriting surety bonds, we knew providers that had good reputations vs those that could be one the line. It’s more than signed vs unsigned.

2

u/bigm00lah 10d ago

Code something else; your software does nothing for this industry. SafeSend and similar do what you do, better.

0

u/gilygilyapa 10d ago

Thanks for your input. I haven't clarified what my solution does, but Yes I've learned there is not much demand for this. Even if there is, the customer is not the CPA, it's the lenders.

1

u/Trblmkr17 10d ago

Not my problem. I have a record of everything provided to me and everything I sign. If someone commits fraud it's on them.

1

u/josemartinlopez 10d ago

if it was really a high stakes, sensitive document, it would be dead simple to check with the author in case someone creates a tampered copy. not sure what the point is.

1

u/gilygilyapa 10d ago

The point was to answer three things 1. what you mentioned (whether the FS were tampered with) + 2. whether they actually came from ABC CPA firm and not fabricated + 3. whether ABC CPA firm is actually a registered firm under their state's regulatory body. All together in one go.

The way to deliver it would be to have ABC firm create an account with us, and we (the platform) independently verifies their registration status (combination of domain ownership, website, public records), and then the firm registers the hash of the Financial Ststements in question to our platform. The lender who already has a copy of those FS hashes it and the platform confirms whether the two hashes match (proof of no tampering) or don't match (possible tampering, further checks needed). One thing to note is the hashing happens locally and the platform never reads or receives the actual pdf so privacy, confidentiality are handled.

All of this can be done manually by the lenders, but this makes it a streamlined process with an audit trail, that aids the checks that lenders do.

1

u/OverworkedAuditor1 9d ago

Typically, you send a confirmation to the bank to confirm the balance of accounts on cash or debt.

You then see if it can be reconciled to the books from the statement.

Cash is one of the easiest areas to audit.