top of page
Search

Snakes in Suits and Internal Auditing: How Auditors Should Respond to Manipulation, Deception, and Destructive Leadership

Internal Auditors Audit Systems—But People Can Defeat the Best-Designed Systems

Internal auditors are trained to evaluate:

  • Governance

  • Risk management

  • Internal controls

  • Compliance

  • Fraud risk

  • Operational performance


Most audit methodologies assume that people generally act within the organization’s established structure. Management sets objectives, employees perform controls, supervisors monitor results, and governance bodies receive reliable information.


That assumption does not always hold.


Some individuals are highly skilled at manipulating perceptions, controlling information, exploiting organizational politics, taking credit for other people’s work, shifting blame, and presenting themselves as competent and trustworthy while damaging the organization behind the scenes.


Paul Babiak and Robert D. Hare explore this problem in Snakes in Suits: When Psychopaths Go to Work. The book examines how individuals exhibiting pronounced psychopathic characteristics may use charm, deception, manipulation, and organizational weaknesses to obtain influence and power. The revised edition also discusses the B-Scan 360, a workplace research instrument developed to assess patterns of behavior associated with corporate psychopathy.


For internal auditors, the book’s value is not that it enables them to diagnose coworkers or executives.


It does not.


Its value is that it helps auditors recognize a difficult governance reality:

A persuasive executive may not be a reliable executive. A confident explanation may not be supported by evidence. An impressive presentation may conceal weak performance, misconduct, or control failure.

Internal auditors should use the lessons in Snakes in Suits to improve professional skepticism, strengthen evidence gathering, protect the independence of the audit function, and identify governance environments in which destructive behavior can thrive.


They should not use the book to label people as psychopaths.


What Snakes in Suits Says About the Corporate Environment

The book describes how some organizational environments can reward characteristics that appear positive during recruitment, promotion, and executive interactions.


An individual may initially appear:

  • Charismatic

  • Confident

  • Articulate

  • Decisive

  • Innovative

  • Persuasive

  • Politically skilled

  • Comfortable with risk


Those characteristics do not indicate psychopathy. Many effective leaders possess them.


The concern arises when the attractive presentation is accompanied by repeated patterns such as:

  • Deception

  • Manipulation

  • Exploitation

  • Lack of accountability

  • Shallow emotional responses

  • Disregard for organizational rules

  • Taking credit for success

  • Blaming others for failure

  • Building alliances for personal advantage

  • Discarding people after using them


Research involving corporate professionals found that psychopathic characteristics could be positively associated with evaluations of charisma and presentation style while being negatively associated with responsibility, teamwork, management skills, and overall performance.


That finding has direct relevance to internal auditing.


The person who performs best in a meeting may not be the person whose department has the strongest controls.


The executive who gives the most polished Audit Committee presentation may not be providing the most accurate information.


The manager who appears decisive may be overriding controls, suppressing bad news, or shifting responsibility to subordinates.


Internal auditors must distinguish presentation competence from control competence.


Internal Auditors Must Not Diagnose Employees or Executives

This boundary is critical.


Psychopathy is a psychological construct assessed through specialized professional methods. The Hare Psychopathy Checklist–Revised is used in clinical and forensic settings, and Hare’s own materials specifically address the potential for misuse. Individual scores can have serious consequences and require appropriate training, records, interviews, and professional judgment.


An internal auditor is generally not qualified or authorized to diagnose:

  • Psychopathy

  • Narcissistic personality disorder

  • Antisocial personality disorder

  • Any other psychological condition


An auditor should not write:

  • “The CFO is a psychopath.”

  • “The manager has psychopathic traits.”

  • “The superintendent is clinically manipulative.”

  • “The employee failed the Hare test.”


Those statements are outside the normal scope of internal auditing and may create substantial ethical, employment, reputational, and legal concerns.


The auditor should evaluate observable workplace conduct and its effect on governance, risk, and controls.


Appropriate audit language includes:

  • Management provided inconsistent explanations.

  • The executive withheld information requested by the Audit Committee.

  • Responsibility for the failed control was repeatedly reassigned.

  • Management’s representations were inconsistent with available records.

  • Employees reported fear of retaliation.

  • Significant exceptions were removed from the report without documented justification.

  • The manager repeatedly overrode established approval procedures.

  • Performance claims could not be reconciled to operational results.


The auditor reports what people did, not what psychological condition they might have.


The Correct Audit Focus: Behavior, Control Effect, and Evidence

The principles in Snakes in Suits should lead the auditor to ask three questions.


What behavior occurred?

Examples:

  • Misrepresentation

  • Intimidation

  • Information suppression

  • Management override

  • Retaliation

  • Blame shifting

  • Manipulation of performance data

  • Selective disclosure

  • Inconsistent explanations


How did the behavior affect the organization?

Examples:

  • Controls did not operate.

  • Employees stopped reporting problems.

  • Risks were hidden from the Board.

  • Financial information became unreliable.

  • Corrective actions were delayed.

  • Competent employees resigned.

  • Fraud opportunities increased.

  • Internal Audit independence was impaired.


What evidence supports the conclusion?

Examples:

  • Emails

  • System logs

  • Meeting minutes

  • Approval histories

  • Whistleblower reports

  • Exit interviews

  • Performance records

  • Audit trails

  • Contradictory management representations

  • Repeated control overrides


This keeps the audit within its professional mandate.


Manipulative Leaders Often Manage Perception Before They Manage Performance

A recurring theme in Snakes in Suits is impression management.


A manipulative leader may work aggressively to influence how others perceive them.


This can include:

  • Creating a compelling personal narrative

  • Claiming expertise that is difficult to verify

  • Associating with powerful executives

  • Taking visible ownership of successful projects

  • Distancing themselves from failures

  • Presenting ordinary work as exceptional achievement

  • Controlling who receives information

  • Characterizing critics as disloyal or incompetent


Internal auditors should be particularly cautious when management’s reputation depends heavily on narrative rather than measurable results.


Useful audit questions include:

  • What objective evidence supports the claimed improvement?

  • Were the performance measures changed?

  • Who validated the reported results?

  • What information was excluded?

  • Do employee accounts agree with management’s presentation?

  • Did the claimed improvement continue after the reporting period?

  • Were unfavorable trends reclassified or removed?

  • Who received credit, and who performed the work?


A polished executive dashboard does not prove performance.


The auditor should reconcile the story to the data.


Charm Is Not a Control

Some individuals are exceptionally effective in interpersonal settings.


They remember names, build rapport quickly, tell engaging stories, and appear to understand exactly what each audience wants to hear.


That ability can become dangerous when it causes:

  • Auditors to reduce skepticism

  • Audit Committee members to accept unsupported statements

  • Executives to overlook repeated failures

  • Employees to excuse misconduct

  • Hiring managers to ignore inconsistent credentials


The auditor should not react negatively to charm.


The auditor should simply refuse to treat it as evidence.


A useful discipline is:

The more persuasive the representation, the more carefully the auditor should identify the evidence supporting it.

When an executive states:

“This department has the strongest controls in the organization.”

The auditor should ask:

  • What performance measures support that conclusion?

  • How many exceptions occurred?

  • What were the results of prior audits?

  • How many findings remain open?

  • What employee turnover has occurred?

  • What complaints or hotline reports were received?

  • How frequently did management override controls?


Confidence does not reduce audit risk.


Watch for the Creation of Pawns and Patrons

Snakes in Suits describes how manipulative individuals may form relationships with two broad categories of people.


They may cultivate patrons—powerful individuals who provide protection, credibility, access, or advancement.


They may also use pawns—employees or associates who provide information, perform tasks, defend the individual, or absorb blame.


An internal auditor may observe similar organizational patterns.


Possible patron relationships

  • A senior executive consistently shields one manager from review.

  • The Audit Committee receives information only through the protected executive.

  • Significant findings involving that person are repeatedly downgraded.

  • Human Resources does not investigate complaints involving a favored leader.

  • Internal Audit’s access is limited when a politically connected executive is involved.


Possible pawn relationships

  • Subordinates defend a manager using identical language.

  • Employees perform questionable tasks but cannot explain the purpose.

  • Staff members take responsibility for decisions made by management.

  • One employee becomes the designated cause of multiple departmental failures.

  • Employees are encouraged to report colleagues’ activities directly to the manager.


These patterns do not prove psychopathy.


They may indicate governance risk, concentration of influence, retaliation exposure, or unreliable reporting lines.


Internal Auditors Should Map Influence, Not Just Authority

An organizational chart shows formal authority.


It may not show who actually controls decisions.


A politically skilled individual may exercise influence through:

  • Personal relationships

  • Access to senior management

  • Control over information

  • Budget authority

  • Informal alliances

  • Fear

  • Loyalty networks

  • Control over promotions

  • Possession of sensitive information


During governance or culture audits, Internal Audit should consider:

  • Who can stop an issue from being escalated?

  • Who changes reports before they reach the Board?

  • Which executive can bypass normal approvals?

  • Who controls access to the CEO or governing body?

  • Which employees are considered untouchable?

  • Who receives information first?

  • Who is excluded from important meetings?

  • Who benefits when responsibility remains unclear?


Influence mapping can reveal control risks that do not appear in formal policies.


Triangulate Every Significant Representation

A manipulative person may tailor different stories to different audiences.


The Audit Committee hears one explanation.


Employees hear another.


The external auditor receives a third.


The regulator receives a fourth.


The internal auditor should use triangulation.


For any significant representation, compare:

  1. What management said

  2. What employees said

  3. What the records demonstrate


For example:

Management representation

The department has completed all corrective actions.

Employee account

Employees were told to mark the actions complete, although the revised procedure has not been implemented.

Documentary evidence

The closure record contains a new policy but no evidence that the control operated.


The audit conclusion should follow the evidence.


Triangulation is particularly important when the subject involves:

  • Executive performance

  • Ethics complaints

  • Fraud allegations

  • Corrective-action closure

  • Management override

  • Regulatory compliance

  • Employee turnover

  • Control failures


Be Alert to Strategic Inconsistency

A person attempting to manipulate the audit may not tell one large, obvious falsehood.


They may provide a series of individually plausible statements that do not fit together.


Examples include:

  • The control is described as automated, but no one can identify the system rule.

  • Management says the risk is immaterial, but substantial resources were used to conceal the incident.

  • A manager claims no authority over a process while personally approving every exception.

  • The department claims a staffing shortage while eliminating positions that performed oversight.

  • Management says an issue is isolated, but similar exceptions appear across multiple periods.

  • An executive claims not to remember a transaction but provides a detailed justification for it.


Internal auditors should build timelines and relationship maps when explanations become complex.


Chronology is difficult to manipulate when supported by:

  • System timestamps

  • Emails

  • Calendar entries

  • Approval records

  • Transaction histories

  • Document metadata

  • Meeting minutes


Blame Shifting Is an Audit Signal

One pattern described in destructive workplace behavior is the transfer of responsibility to others.


During an audit, this may sound like:

  • “The employee misunderstood.”

  • “The system caused it.”

  • “Internal Audit never told us.”

  • “The prior manager created the problem.”

  • “The vendor failed.”

  • “The Board approved it.”

  • “The policy was unclear.”

  • “Finance should have detected it.”


Any of these explanations may be partly true.


The auditor should convert blame into process analysis.


Ask:

  • Who owned the control?

  • Who had authority to correct the problem?

  • When was the risk first known?

  • Who received the information?

  • What action was taken?

  • What evidence supports the claimed delegation?

  • Was responsibility documented?

  • Did management monitor completion?

  • Were similar failures identified earlier?


Blame shifting frequently reveals weaknesses in:

  • Accountability

  • Role definition

  • Escalation

  • Management oversight

  • Corrective-action governance


Manipulators May Attack the Credibility of Internal Audit

An internal auditor who identifies uncomfortable facts may become a target.


Possible responses include:

  • Questioning the auditor’s competence

  • Accusing the auditor of bias

  • Claiming the audit exceeded its scope

  • Complaining about minor procedural issues

  • Withholding information

  • Contacting senior management privately

  • Encouraging employees not to cooperate

  • Reframing the finding as a personality dispute

  • Pressuring the Chief Audit Executive to reassign the auditor

  • Attempting to remove language from the final report


Internal Audit should not assume every disagreement is manipulation. Legitimate criticism must be considered fairly.


However, the function should recognize when criticism follows a consistent pattern designed to divert attention from evidence.


The response should be procedural and evidence-based:

  • Confirm the approved objective and scope.

  • Document information requests.

  • Preserve relevant communications.

  • Apply established rating criteria.

  • Obtain supervisory review.

  • Escalate access limitations.

  • Record unresolved disagreements.

  • Brief the Audit Committee when independence is threatened.


Internal Audit’s protection comes from methodology, documentation, and functional reporting—not from winning a personal confrontation.


Never Fight Manipulation with Emotion

A destructive manager may provoke the auditor deliberately.


The individual may:

  • Interrupt

  • Insult

  • Challenge credentials

  • Ridicule findings

  • Misstate what the auditor said

  • Threaten escalation

  • Create urgency

  • Attempt to force an immediate concession


The auditor should avoid:

  • Arguing

  • Becoming sarcastic

  • Responding defensively

  • Making accusations

  • Speculating about motives

  • Trying to out-manipulate the individual


A controlled response is more effective:

“Let us return to the specific condition, the applicable criterion, and the evidence.”

Or:

“I will document your disagreement and evaluate the additional evidence you provide.”

Or:

“The engagement’s scope was approved by the Chief Audit Executive. Any requested change will be handled through that process.”

The objective is to prevent the meeting from becoming a contest of personalities.


Use Two Auditors for High-Risk Interviews

When the interview involves:

  • Senior executives

  • Fraud allegations

  • Retaliation concerns

  • Contradictory representations

  • Possible document destruction

  • Serious ethical concerns


Internal Audit should consider having two professionals present.


One auditor can lead the questioning.


The other can:

  • Take notes

  • Observe inconsistencies

  • Monitor whether questions were answered

  • Identify follow-up points

  • Provide corroboration concerning what occurred


Where permitted and properly authorized, recording or transcription tools may also help. However, recordings must comply with organizational policies, privacy requirements, legal restrictions, and retention procedures.


Do Not Reveal Every Piece of Evidence Too Early

An auditor should generally be transparent about the engagement’s purpose.


That does not mean every document or contradiction must be disclosed at the beginning of an interview.


When serious misconduct is possible, revealing all evidence immediately may allow a person to:

  • Coordinate explanations

  • Alter records

  • Influence witnesses

  • Destroy evidence

  • Create retrospective documentation

  • Prepare a misleading narrative


The auditor should coordinate with:

  • The Chief Audit Executive

  • Legal counsel

  • Human Resources

  • Compliance

  • Fraud investigation specialists


Evidence sequencing should be planned when the matter may become an investigation.


A normal audit interview should not be turned into a covert interrogation. But neither should the auditor unknowingly compromise an investigation by disclosing sensitive evidence carelessly.


Focus on Corroboration, Not Confession

Internal auditors do not need an executive to admit wrongdoing before reaching an evidence-based conclusion.


A confession may never occur.


The auditor may establish the condition through:

  • Transaction records

  • Access logs

  • Approval histories

  • Emails

  • Witness accounts

  • Financial analysis

  • Data analytics

  • Document versions

  • Meeting records


The audit objective is not:

Make the person admit what happened.

The objective is:

Determine what happened and what the organization must do about it.

An individual skilled in manipulation may never concede.


The evidence can still support the finding.


Evaluate the Control Environment Around Powerful Individuals

The most damaging risk may not be the individual.


It may be the organizational environment that enables the behavior.


A manipulative leader becomes more dangerous when:

  • The Board receives filtered information.

  • Internal Audit lacks direct access to the Audit Committee.

  • Human Resources reports to the individual involved.

  • Whistleblowers fear retaliation.

  • Performance measures are controlled by management.

  • Executive sessions do not occur.

  • Related-party disclosures are weak.

  • Management override is not monitored.

  • Corrective actions can be closed without validation.

  • Senior leaders are exempt from ordinary controls.


The auditor should evaluate whether governance mechanisms operate independently of personality.


A strong governance system should be able to withstand:

  • A dishonest executive

  • A charismatic executive

  • An aggressive executive

  • An incompetent executive

  • A dominant executive


Controls that function only when leaders behave ethically are not strong controls.


Audit the Tone at the Top—and the Mood in the Middle

Tone at the top matters, but employees experience culture primarily through their direct supervisors.


An organization’s ethics policy may be excellent while middle management creates an environment characterized by:

  • Fear

  • Favoritism

  • Retaliation

  • Information suppression

  • Unrealistic performance expectations

  • Blame

  • Competition among employees

  • Tolerance of rule breaking


Internal Audit should examine culture through multiple sources:

  • Employee surveys

  • Exit interviews

  • Hotline reports

  • Turnover

  • Absenteeism

  • Litigation

  • Grievances

  • Ethics complaints

  • Performance-rating patterns

  • Transfer requests

  • Overtime

  • Corrective-action delays


The same department repeatedly losing strong employees may have a leadership problem that does not appear in financial reports.


Turnover Can Be a Governance Indicator

Manipulative or abusive leaders may drive away employees who:

  • Challenge unsupported claims

  • Refuse improper instructions

  • Possess institutional knowledge

  • Report control weaknesses

  • Maintain professional independence


The employees who remain may be:

  • Loyal to the leader

  • Fearful

  • Dependent

  • Politically aligned

  • Unwilling to challenge management


Internal Audit should examine unusual turnover patterns, particularly when they coincide with:

  • Increased control failures

  • Loss of segregation of duties

  • Hotline complaints

  • Delayed reporting

  • Repeated reorganizations

  • Concentration of authority

  • Replacement of experienced staff with personally selected employees


Turnover alone does not prove misconduct.


It may identify an area requiring governance review.


Watch for the Destruction of Capable Employees’ Credibility

A manipulative executive may neutralize potential critics before they can raise concerns.


Tactics may include:

  • Labeling the employee “not a team player”

  • Giving unexpectedly poor evaluations

  • Excluding the employee from meetings

  • Reassigning responsibilities

  • Withholding information

  • Creating impossible deadlines

  • Attributing organizational failures to the employee

  • Encouraging complaints from selected coworkers


Auditors reviewing retaliation or culture concerns should compare:

  • Prior performance evaluations

  • Timing of complaints

  • Changes after the employee raised concerns

  • Email records

  • Assignment changes

  • Objective performance data

  • Treatment of comparable employees


The timing of negative actions can be significant.


Management Override Deserves Special Attention

Individuals who believe rules do not apply to them may use override authority routinely.


Examples include:

  • Bypassing procurement

  • Approving their own expenses

  • Directing journal entries

  • Selecting vendors without competition

  • Hiring without required review

  • Changing performance data

  • Closing audit findings without validation

  • Ordering employees to ignore policy

  • Using emergency authority for routine activities


Internal Audit should identify:

  • Who can override each significant control

  • Whether overrides are logged

  • Who reviews them

  • How frequently they occur

  • Whether one executive’s overrides are unusually high

  • Whether override reasons are valid

  • Whether override monitoring reaches the Audit Committee


An override may be authorized.


A pattern of overrides can indicate that the control system is being displaced by personal authority.


Audit Committees Need Unfiltered Information

A manipulative executive may control what reaches the governing body.


The Audit Committee should receive information directly from:

  • The Chief Audit Executive

  • The external auditor

  • Compliance

  • Risk management

  • Legal counsel

  • Whistleblower channels


The Chief Audit Executive should have the ability to meet privately with the Audit Committee without management present.


Important matters include:

  • Scope limitations

  • Management interference

  • Significant disagreements

  • Retaliation concerns

  • Unresolved high-risk findings

  • Repeated management override

  • Information withheld from Internal Audit

  • Concerns involving senior executives


The IIA’s current fraud guidance emphasizes that addressing fraud risk is an organization-wide responsibility and that Internal Audit can contribute through assurance over fraud-risk governance and management.


The B-Scan 360 Is Not an Internal Audit Checklist

The publisher describes the B-Scan 360 as a research tool designed for workplace use, and academic studies have examined its factor structure and relationship with leadership and employee outcomes.


Internal auditors should not casually copy its concepts into a workpaper and assign scores to executives.


Doing so may create several problems:

  • The auditor may lack appropriate training.

  • Respondents may be biased.

  • The tool may be used outside its intended purpose.

  • Scores may be treated as clinical conclusions.

  • Employment decisions may be influenced improperly.

  • Confidentiality may be compromised.


Where an organization has a legitimate need to assess destructive leadership behavior, it should involve qualified organizational psychologists, legal counsel, Human


Resources, and appropriate governance oversight.


Internal Audit may audit the process.


It should not invent its own psychological assessment program.


Practical Red Flags for Internal Auditors

The following behaviors should not be treated as evidence of psychopathy. They may, however, indicate increased governance, fraud, or control risk when they occur repeatedly and are supported by evidence.


Communication red flags

  • Different stories are given to different audiences.

  • Questions are answered with personal attacks.

  • Routine information requests produce disproportionate resistance.

  • Explanations change after evidence is presented.

  • Bad news is consistently minimized.

  • Responsibility is repeatedly shifted.


Governance red flags

  • The individual is exempt from ordinary controls.

  • Oversight functions are weakened.

  • Audit findings disappear or are downgraded.

  • The Board receives information only through one executive.

  • Employees fear direct communication with governance bodies.

  • Whistleblower complaints involving the individual are not investigated independently.


Performance red flags

  • Results depend heavily on self-reported data.

  • Successes are personalized while failures are externalized.

  • Metrics change frequently.

  • Reported achievements cannot be reconciled to operational results.

  • High turnover follows the individual from one department to another.

  • Projects are announced dramatically but poorly completed.


Fraud and control red flags

  • Frequent management override

  • Related-party relationships

  • Unsupported expenses

  • Pressure to alter reports

  • Missing documentation

  • Retroactive approvals

  • Unusual vendor selections

  • Suppression of exceptions

  • Retaliation against employees who report concerns


The auditor should investigate the underlying behavior and control implications.


A Practical Audit Approach

Step 1: Define the audit objective

Do not start with the hypothesis that a specific person is a psychopath.


Start with an auditable objective such as:

  • Evaluate executive-expense controls.

  • Assess management override.

  • Review ethics and retaliation processes.

  • Evaluate the reliability of performance reporting.

  • Assess governance over corrective-action closure.

  • Review organizational culture and employee reporting channels.


Step 2: Establish criteria

Possible criteria include:

  • Policies

  • Codes of conduct

  • Delegations of authority

  • Employment requirements

  • Audit Committee charters

  • Regulatory rules

  • COSO principles

  • The IIA Global Internal Audit Standards

  • Whistleblower protections


Step 3: Gather evidence from multiple sources

Do not rely on the subject’s explanation or the complainant’s allegation alone.


Use:

  • Interviews

  • Documents

  • System records

  • Data analysis

  • Emails

  • Minutes

  • Performance reports

  • Independent confirmations


Step 4: Identify patterns

One disagreement or override may be ordinary.


Repeated behavior across time, processes, and employees may indicate a systemic issue.


Step 5: Evaluate control impact

Determine how the behavior affected:

  • Reliability

  • Compliance

  • Financial exposure

  • Employee reporting

  • Governance oversight

  • Fraud risk

  • Operational performance


Step 6: Report objectively

Avoid psychological labels.


Describe:

  • Condition

  • Criteria

  • Cause

  • Consequence

  • Corrective action


Example Audit Finding: Management Override

Condition

The executive approved six purchases from a selected vendor without required competitive procurement. Three purchases were divided into amounts below the approval threshold.


Criteria

The procurement policy requires competitive bids and approval by an independent executive for purchases exceeding the established threshold.


Cause

The organization’s purchasing system permits senior executives to bypass the automated workflow. Overrides are not included in a report reviewed by the Board or Audit Committee.


Consequence

The control weakness increases the risk of favoritism, conflicts of interest, excessive pricing, unauthorized purchases, and concealment of related-party activity.


Corrective Action

Management should require independent review of executive procurement activity, implement automated reporting of overrides and split transactions, and provide periodic results to the Audit Committee.

Notice what the finding does not say:

“The executive displayed psychopathic behavior.”

The finding identifies the observable conduct and control consequence.


That is Internal Audit’s job.


Protecting the Internal Audit Team

When dealing with a highly manipulative or retaliatory individual, the Chief Audit


Executive should protect staff through:

  • Clear scope authorization

  • Documented reporting lines

  • Supervisory participation

  • Controlled communication

  • Evidence preservation

  • Legal consultation

  • Direct Audit Committee access

  • Rotation of staff where necessary

  • Monitoring for retaliation


Junior auditors should not be left alone to manage serious executive misconduct.


The organization has a duty to protect employees who perform authorized assurance work.


What Internal Auditors Should Learn from Snakes in Suits

The central lesson is not:

Learn how to identify psychopaths.

The useful audit lesson is:

Learn how destructive individuals exploit weak governance, unreliable information, organizational politics, and misplaced trust.

Internal auditors should use that insight to strengthen:

  • Professional skepticism

  • Interviewing

  • Corroboration

  • Management-override testing

  • Culture audits

  • Fraud-risk assessments

  • Audit Committee communication

  • Evidence-based reporting

  • Protection of whistleblowers

  • Internal Audit independence


The book encourages readers to look beyond charm, confidence, and organizational status. That is valuable advice for auditors because audit evidence should never depend on personal appeal or reputation. The publisher characterizes the book as an examination of how manipulative and deceptive workplace behavior can create organizational chaos.


The Final Principle: Audit the Conduct, Not the Personality

An internal auditor does not need to know whether an executive is clinically psychopathic.


The auditor needs to determine whether:

  • Information is reliable.

  • Controls operate.

  • Employees can report concerns safely.

  • Management override is monitored.

  • The Board receives complete information.

  • Decisions serve the organization.

  • Misconduct is investigated.

  • Corrective actions are implemented.

  • Internal Audit can operate independently.


That is enough.


A destructive personality becomes an organizational risk only when the governance and control environment allows destructive behavior to affect the organization.

Strong governance does not depend on every leader being ethical, humble, empathetic, or cooperative.


Strong governance assumes that some people may not be.


It establishes:

  • Independent oversight

  • Segregation of duties

  • Transparent reporting

  • Evidence-based decisions

  • Protected reporting channels

  • Monitoring of override

  • Accountability for misconduct

The most important message from Snakes in Suits for Internal Audit is therefore not psychological.

It is structural:

Never allow the organization’s system of governance to depend entirely on the character of one powerful individual.

Internal controls should protect the organization even when the person wearing the suit cannot be trusted.


Frequently Asked Questions

Can an internal auditor determine whether an executive is a psychopath?

No. Internal auditors should not diagnose psychological conditions unless they possess appropriate professional qualifications and are specifically authorized to conduct such an assessment. Internal Audit should evaluate observable conduct, evidence, control effects, and governance risk.


What is the most useful lesson from Snakes in Suits for auditors?

The book helps auditors understand how charm, manipulation, deception, blame shifting, alliance building, and impression management may conceal poor performance or misconduct. These observations should increase professional skepticism and lead to additional corroboration.


Should Internal Audit use the B-Scan 360?

Not casually. The B-Scan 360 is a specialized workplace research and assessment instrument. Any formal use should involve appropriately qualified professionals, legal review, Human Resources, confidentiality safeguards, and governance oversight.


How should an auditor document manipulative behavior?

Document specific, observable facts. Identify inconsistent statements, withheld information, override activity, unsupported representations, retaliation, or interference with the audit. Avoid labels and speculation about motives or psychological conditions.


What should an auditor do when a powerful executive interferes with an audit?

The auditor should document the interference, inform the Chief Audit Executive, preserve supporting evidence, follow established escalation procedures, and communicate significant scope limitations or independence threats to the Audit Committee.


How does corporate psychopathy relate to fraud risk?

Certain behavioral patterns discussed in corporate-psychopathy research—such as deception, lack of accountability, manipulation, and disregard for rules—may increase fraud or governance risk. They do not establish that fraud occurred. Fraud conclusions require sufficient, appropriate evidence.


How should Audit Committees respond?

Audit Committees should maintain direct communication with Internal Audit, conduct executive sessions, review management override, protect whistleblowers, monitor retaliation, and ensure significant concerns involving senior management are investigated independently.


 
 
 

Recent Posts

See All
How Arizona CPAs Actually Get in Trouble

Lessons From the Arizona State Board of Accountancy Most CPAs do not begin their careers expecting to face professional discipline. They pass the CPA examination. They satisfy experience requirements.

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page