Snakes in Suits and Internal Auditing: How Auditors Should Respond to Manipulation, Deception, and Destructive Leadership
- John Blackshire
- Aug 3
- 17 min read
Internal Auditors Audit Systems—But People Can Defeat the Best-Designed Systems
Internal auditors are trained to evaluate:
Governance
Risk management
Internal controls
Compliance
Fraud risk
Operational performance
Most audit methodologies assume that people generally act within the organization’s established structure. Management sets objectives, employees perform controls, supervisors monitor results, and governance bodies receive reliable information.
That assumption does not always hold.
Some individuals are highly skilled at manipulating perceptions, controlling information, exploiting organizational politics, taking credit for other people’s work, shifting blame, and presenting themselves as competent and trustworthy while damaging the organization behind the scenes.
Paul Babiak and Robert D. Hare explore this problem in Snakes in Suits: When Psychopaths Go to Work. The book examines how individuals exhibiting pronounced psychopathic characteristics may use charm, deception, manipulation, and organizational weaknesses to obtain influence and power. The revised edition also discusses the B-Scan 360, a workplace research instrument developed to assess patterns of behavior associated with corporate psychopathy.
For internal auditors, the book’s value is not that it enables them to diagnose coworkers or executives.
It does not.
Its value is that it helps auditors recognize a difficult governance reality:
A persuasive executive may not be a reliable executive. A confident explanation may not be supported by evidence. An impressive presentation may conceal weak performance, misconduct, or control failure.
Internal auditors should use the lessons in Snakes in Suits to improve professional skepticism, strengthen evidence gathering, protect the independence of the audit function, and identify governance environments in which destructive behavior can thrive.
They should not use the book to label people as psychopaths.
What Snakes in Suits Says About the Corporate Environment
The book describes how some organizational environments can reward characteristics that appear positive during recruitment, promotion, and executive interactions.
An individual may initially appear:
Charismatic
Confident
Articulate
Decisive
Innovative
Persuasive
Politically skilled
Comfortable with risk
Those characteristics do not indicate psychopathy. Many effective leaders possess them.
The concern arises when the attractive presentation is accompanied by repeated patterns such as:
Deception
Manipulation
Exploitation
Lack of accountability
Shallow emotional responses
Disregard for organizational rules
Taking credit for success
Blaming others for failure
Building alliances for personal advantage
Discarding people after using them
Research involving corporate professionals found that psychopathic characteristics could be positively associated with evaluations of charisma and presentation style while being negatively associated with responsibility, teamwork, management skills, and overall performance.
That finding has direct relevance to internal auditing.
The person who performs best in a meeting may not be the person whose department has the strongest controls.
The executive who gives the most polished Audit Committee presentation may not be providing the most accurate information.
The manager who appears decisive may be overriding controls, suppressing bad news, or shifting responsibility to subordinates.
Internal auditors must distinguish presentation competence from control competence.
Internal Auditors Must Not Diagnose Employees or Executives
This boundary is critical.
Psychopathy is a psychological construct assessed through specialized professional methods. The Hare Psychopathy Checklist–Revised is used in clinical and forensic settings, and Hare’s own materials specifically address the potential for misuse. Individual scores can have serious consequences and require appropriate training, records, interviews, and professional judgment.
An internal auditor is generally not qualified or authorized to diagnose:
Psychopathy
Narcissistic personality disorder
Antisocial personality disorder
Any other psychological condition
An auditor should not write:
“The CFO is a psychopath.”
“The manager has psychopathic traits.”
“The superintendent is clinically manipulative.”
“The employee failed the Hare test.”
Those statements are outside the normal scope of internal auditing and may create substantial ethical, employment, reputational, and legal concerns.
The auditor should evaluate observable workplace conduct and its effect on governance, risk, and controls.
Appropriate audit language includes:
Management provided inconsistent explanations.
The executive withheld information requested by the Audit Committee.
Responsibility for the failed control was repeatedly reassigned.
Management’s representations were inconsistent with available records.
Employees reported fear of retaliation.
Significant exceptions were removed from the report without documented justification.
The manager repeatedly overrode established approval procedures.
Performance claims could not be reconciled to operational results.
The auditor reports what people did, not what psychological condition they might have.
The Correct Audit Focus: Behavior, Control Effect, and Evidence
The principles in Snakes in Suits should lead the auditor to ask three questions.
What behavior occurred?
Examples:
Misrepresentation
Intimidation
Information suppression
Management override
Retaliation
Blame shifting
Manipulation of performance data
Selective disclosure
Inconsistent explanations
How did the behavior affect the organization?
Examples:
Controls did not operate.
Employees stopped reporting problems.
Risks were hidden from the Board.
Financial information became unreliable.
Corrective actions were delayed.
Competent employees resigned.
Fraud opportunities increased.
Internal Audit independence was impaired.
What evidence supports the conclusion?
Examples:
Emails
System logs
Meeting minutes
Approval histories
Whistleblower reports
Exit interviews
Performance records
Audit trails
Contradictory management representations
Repeated control overrides
This keeps the audit within its professional mandate.
Manipulative Leaders Often Manage Perception Before They Manage Performance
A recurring theme in Snakes in Suits is impression management.
A manipulative leader may work aggressively to influence how others perceive them.
This can include:
Creating a compelling personal narrative
Claiming expertise that is difficult to verify
Associating with powerful executives
Taking visible ownership of successful projects
Distancing themselves from failures
Presenting ordinary work as exceptional achievement
Controlling who receives information
Characterizing critics as disloyal or incompetent
Internal auditors should be particularly cautious when management’s reputation depends heavily on narrative rather than measurable results.
Useful audit questions include:
What objective evidence supports the claimed improvement?
Were the performance measures changed?
Who validated the reported results?
What information was excluded?
Do employee accounts agree with management’s presentation?
Did the claimed improvement continue after the reporting period?
Were unfavorable trends reclassified or removed?
Who received credit, and who performed the work?
A polished executive dashboard does not prove performance.
The auditor should reconcile the story to the data.
Charm Is Not a Control
Some individuals are exceptionally effective in interpersonal settings.
They remember names, build rapport quickly, tell engaging stories, and appear to understand exactly what each audience wants to hear.
That ability can become dangerous when it causes:
Auditors to reduce skepticism
Audit Committee members to accept unsupported statements
Executives to overlook repeated failures
Employees to excuse misconduct
Hiring managers to ignore inconsistent credentials
The auditor should not react negatively to charm.
The auditor should simply refuse to treat it as evidence.
A useful discipline is:
The more persuasive the representation, the more carefully the auditor should identify the evidence supporting it.
When an executive states:
“This department has the strongest controls in the organization.”
The auditor should ask:
What performance measures support that conclusion?
How many exceptions occurred?
What were the results of prior audits?
How many findings remain open?
What employee turnover has occurred?
What complaints or hotline reports were received?
How frequently did management override controls?
Confidence does not reduce audit risk.
Watch for the Creation of Pawns and Patrons
Snakes in Suits describes how manipulative individuals may form relationships with two broad categories of people.
They may cultivate patrons—powerful individuals who provide protection, credibility, access, or advancement.
They may also use pawns—employees or associates who provide information, perform tasks, defend the individual, or absorb blame.
An internal auditor may observe similar organizational patterns.
Possible patron relationships
A senior executive consistently shields one manager from review.
The Audit Committee receives information only through the protected executive.
Significant findings involving that person are repeatedly downgraded.
Human Resources does not investigate complaints involving a favored leader.
Internal Audit’s access is limited when a politically connected executive is involved.
Possible pawn relationships
Subordinates defend a manager using identical language.
Employees perform questionable tasks but cannot explain the purpose.
Staff members take responsibility for decisions made by management.
One employee becomes the designated cause of multiple departmental failures.
Employees are encouraged to report colleagues’ activities directly to the manager.
These patterns do not prove psychopathy.
They may indicate governance risk, concentration of influence, retaliation exposure, or unreliable reporting lines.
Internal Auditors Should Map Influence, Not Just Authority
An organizational chart shows formal authority.
It may not show who actually controls decisions.
A politically skilled individual may exercise influence through:
Personal relationships
Access to senior management
Control over information
Budget authority
Informal alliances
Fear
Loyalty networks
Control over promotions
Possession of sensitive information
During governance or culture audits, Internal Audit should consider:
Who can stop an issue from being escalated?
Who changes reports before they reach the Board?
Which executive can bypass normal approvals?
Who controls access to the CEO or governing body?
Which employees are considered untouchable?
Who receives information first?
Who is excluded from important meetings?
Who benefits when responsibility remains unclear?
Influence mapping can reveal control risks that do not appear in formal policies.
Triangulate Every Significant Representation
A manipulative person may tailor different stories to different audiences.
The Audit Committee hears one explanation.
Employees hear another.
The external auditor receives a third.
The regulator receives a fourth.
The internal auditor should use triangulation.
For any significant representation, compare:
What management said
What employees said
What the records demonstrate
For example:
Management representation
The department has completed all corrective actions.
Employee account
Employees were told to mark the actions complete, although the revised procedure has not been implemented.
Documentary evidence
The closure record contains a new policy but no evidence that the control operated.
The audit conclusion should follow the evidence.
Triangulation is particularly important when the subject involves:
Executive performance
Ethics complaints
Fraud allegations
Corrective-action closure
Management override
Regulatory compliance
Employee turnover
Control failures
Be Alert to Strategic Inconsistency
A person attempting to manipulate the audit may not tell one large, obvious falsehood.
They may provide a series of individually plausible statements that do not fit together.
Examples include:
The control is described as automated, but no one can identify the system rule.
Management says the risk is immaterial, but substantial resources were used to conceal the incident.
A manager claims no authority over a process while personally approving every exception.
The department claims a staffing shortage while eliminating positions that performed oversight.
Management says an issue is isolated, but similar exceptions appear across multiple periods.
An executive claims not to remember a transaction but provides a detailed justification for it.
Internal auditors should build timelines and relationship maps when explanations become complex.
Chronology is difficult to manipulate when supported by:
System timestamps
Emails
Calendar entries
Approval records
Transaction histories
Document metadata
Meeting minutes
Blame Shifting Is an Audit Signal
One pattern described in destructive workplace behavior is the transfer of responsibility to others.
During an audit, this may sound like:
“The employee misunderstood.”
“The system caused it.”
“Internal Audit never told us.”
“The prior manager created the problem.”
“The vendor failed.”
“The Board approved it.”
“The policy was unclear.”
“Finance should have detected it.”
Any of these explanations may be partly true.
The auditor should convert blame into process analysis.
Ask:
Who owned the control?
Who had authority to correct the problem?
When was the risk first known?
Who received the information?
What action was taken?
What evidence supports the claimed delegation?
Was responsibility documented?
Did management monitor completion?
Were similar failures identified earlier?
Blame shifting frequently reveals weaknesses in:
Accountability
Role definition
Escalation
Management oversight
Corrective-action governance
Manipulators May Attack the Credibility of Internal Audit
An internal auditor who identifies uncomfortable facts may become a target.
Possible responses include:
Questioning the auditor’s competence
Accusing the auditor of bias
Claiming the audit exceeded its scope
Complaining about minor procedural issues
Withholding information
Contacting senior management privately
Encouraging employees not to cooperate
Reframing the finding as a personality dispute
Pressuring the Chief Audit Executive to reassign the auditor
Attempting to remove language from the final report
Internal Audit should not assume every disagreement is manipulation. Legitimate criticism must be considered fairly.
However, the function should recognize when criticism follows a consistent pattern designed to divert attention from evidence.
The response should be procedural and evidence-based:
Confirm the approved objective and scope.
Document information requests.
Preserve relevant communications.
Apply established rating criteria.
Obtain supervisory review.
Escalate access limitations.
Record unresolved disagreements.
Brief the Audit Committee when independence is threatened.
Internal Audit’s protection comes from methodology, documentation, and functional reporting—not from winning a personal confrontation.
Never Fight Manipulation with Emotion
A destructive manager may provoke the auditor deliberately.
The individual may:
Interrupt
Insult
Challenge credentials
Ridicule findings
Misstate what the auditor said
Threaten escalation
Create urgency
Attempt to force an immediate concession
The auditor should avoid:
Arguing
Becoming sarcastic
Responding defensively
Making accusations
Speculating about motives
Trying to out-manipulate the individual
A controlled response is more effective:
“Let us return to the specific condition, the applicable criterion, and the evidence.”
Or:
“I will document your disagreement and evaluate the additional evidence you provide.”
Or:
“The engagement’s scope was approved by the Chief Audit Executive. Any requested change will be handled through that process.”
The objective is to prevent the meeting from becoming a contest of personalities.
Use Two Auditors for High-Risk Interviews
When the interview involves:
Senior executives
Fraud allegations
Retaliation concerns
Contradictory representations
Possible document destruction
Serious ethical concerns
Internal Audit should consider having two professionals present.
One auditor can lead the questioning.
The other can:
Take notes
Observe inconsistencies
Monitor whether questions were answered
Identify follow-up points
Provide corroboration concerning what occurred
Where permitted and properly authorized, recording or transcription tools may also help. However, recordings must comply with organizational policies, privacy requirements, legal restrictions, and retention procedures.
Do Not Reveal Every Piece of Evidence Too Early
An auditor should generally be transparent about the engagement’s purpose.
That does not mean every document or contradiction must be disclosed at the beginning of an interview.
When serious misconduct is possible, revealing all evidence immediately may allow a person to:
Coordinate explanations
Alter records
Influence witnesses
Destroy evidence
Create retrospective documentation
Prepare a misleading narrative
The auditor should coordinate with:
The Chief Audit Executive
Legal counsel
Human Resources
Compliance
Fraud investigation specialists
Evidence sequencing should be planned when the matter may become an investigation.
A normal audit interview should not be turned into a covert interrogation. But neither should the auditor unknowingly compromise an investigation by disclosing sensitive evidence carelessly.
Focus on Corroboration, Not Confession
Internal auditors do not need an executive to admit wrongdoing before reaching an evidence-based conclusion.
A confession may never occur.
The auditor may establish the condition through:
Transaction records
Access logs
Approval histories
Emails
Witness accounts
Financial analysis
Data analytics
Document versions
Meeting records
The audit objective is not:
Make the person admit what happened.
The objective is:
Determine what happened and what the organization must do about it.
An individual skilled in manipulation may never concede.
The evidence can still support the finding.
Evaluate the Control Environment Around Powerful Individuals
The most damaging risk may not be the individual.
It may be the organizational environment that enables the behavior.
A manipulative leader becomes more dangerous when:
The Board receives filtered information.
Internal Audit lacks direct access to the Audit Committee.
Human Resources reports to the individual involved.
Whistleblowers fear retaliation.
Performance measures are controlled by management.
Executive sessions do not occur.
Related-party disclosures are weak.
Management override is not monitored.
Corrective actions can be closed without validation.
Senior leaders are exempt from ordinary controls.
The auditor should evaluate whether governance mechanisms operate independently of personality.
A strong governance system should be able to withstand:
A dishonest executive
A charismatic executive
An aggressive executive
An incompetent executive
A dominant executive
Controls that function only when leaders behave ethically are not strong controls.
Audit the Tone at the Top—and the Mood in the Middle
Tone at the top matters, but employees experience culture primarily through their direct supervisors.
An organization’s ethics policy may be excellent while middle management creates an environment characterized by:
Fear
Favoritism
Retaliation
Information suppression
Unrealistic performance expectations
Blame
Competition among employees
Tolerance of rule breaking
Internal Audit should examine culture through multiple sources:
Employee surveys
Exit interviews
Hotline reports
Turnover
Absenteeism
Litigation
Grievances
Ethics complaints
Performance-rating patterns
Transfer requests
Overtime
Corrective-action delays
The same department repeatedly losing strong employees may have a leadership problem that does not appear in financial reports.
Turnover Can Be a Governance Indicator
Manipulative or abusive leaders may drive away employees who:
Challenge unsupported claims
Refuse improper instructions
Possess institutional knowledge
Report control weaknesses
Maintain professional independence
The employees who remain may be:
Loyal to the leader
Fearful
Dependent
Politically aligned
Unwilling to challenge management
Internal Audit should examine unusual turnover patterns, particularly when they coincide with:
Increased control failures
Loss of segregation of duties
Hotline complaints
Delayed reporting
Repeated reorganizations
Concentration of authority
Replacement of experienced staff with personally selected employees
Turnover alone does not prove misconduct.
It may identify an area requiring governance review.
Watch for the Destruction of Capable Employees’ Credibility
A manipulative executive may neutralize potential critics before they can raise concerns.
Tactics may include:
Labeling the employee “not a team player”
Giving unexpectedly poor evaluations
Excluding the employee from meetings
Reassigning responsibilities
Withholding information
Creating impossible deadlines
Attributing organizational failures to the employee
Encouraging complaints from selected coworkers
Auditors reviewing retaliation or culture concerns should compare:
Prior performance evaluations
Timing of complaints
Changes after the employee raised concerns
Email records
Assignment changes
Objective performance data
Treatment of comparable employees
The timing of negative actions can be significant.
Management Override Deserves Special Attention
Individuals who believe rules do not apply to them may use override authority routinely.
Examples include:
Bypassing procurement
Approving their own expenses
Directing journal entries
Selecting vendors without competition
Hiring without required review
Changing performance data
Closing audit findings without validation
Ordering employees to ignore policy
Using emergency authority for routine activities
Internal Audit should identify:
Who can override each significant control
Whether overrides are logged
Who reviews them
How frequently they occur
Whether one executive’s overrides are unusually high
Whether override reasons are valid
Whether override monitoring reaches the Audit Committee
An override may be authorized.
A pattern of overrides can indicate that the control system is being displaced by personal authority.
Audit Committees Need Unfiltered Information
A manipulative executive may control what reaches the governing body.
The Audit Committee should receive information directly from:
The Chief Audit Executive
The external auditor
Compliance
Risk management
Legal counsel
Whistleblower channels
The Chief Audit Executive should have the ability to meet privately with the Audit Committee without management present.
Important matters include:
Scope limitations
Management interference
Significant disagreements
Retaliation concerns
Unresolved high-risk findings
Repeated management override
Information withheld from Internal Audit
Concerns involving senior executives
The IIA’s current fraud guidance emphasizes that addressing fraud risk is an organization-wide responsibility and that Internal Audit can contribute through assurance over fraud-risk governance and management.
The B-Scan 360 Is Not an Internal Audit Checklist
The publisher describes the B-Scan 360 as a research tool designed for workplace use, and academic studies have examined its factor structure and relationship with leadership and employee outcomes.
Internal auditors should not casually copy its concepts into a workpaper and assign scores to executives.
Doing so may create several problems:
The auditor may lack appropriate training.
Respondents may be biased.
The tool may be used outside its intended purpose.
Scores may be treated as clinical conclusions.
Employment decisions may be influenced improperly.
Confidentiality may be compromised.
Where an organization has a legitimate need to assess destructive leadership behavior, it should involve qualified organizational psychologists, legal counsel, Human
Resources, and appropriate governance oversight.
Internal Audit may audit the process.
It should not invent its own psychological assessment program.
Practical Red Flags for Internal Auditors
The following behaviors should not be treated as evidence of psychopathy. They may, however, indicate increased governance, fraud, or control risk when they occur repeatedly and are supported by evidence.
Communication red flags
Different stories are given to different audiences.
Questions are answered with personal attacks.
Routine information requests produce disproportionate resistance.
Explanations change after evidence is presented.
Bad news is consistently minimized.
Responsibility is repeatedly shifted.
Governance red flags
The individual is exempt from ordinary controls.
Oversight functions are weakened.
Audit findings disappear or are downgraded.
The Board receives information only through one executive.
Employees fear direct communication with governance bodies.
Whistleblower complaints involving the individual are not investigated independently.
Performance red flags
Results depend heavily on self-reported data.
Successes are personalized while failures are externalized.
Metrics change frequently.
Reported achievements cannot be reconciled to operational results.
High turnover follows the individual from one department to another.
Projects are announced dramatically but poorly completed.
Fraud and control red flags
Frequent management override
Related-party relationships
Unsupported expenses
Pressure to alter reports
Missing documentation
Retroactive approvals
Unusual vendor selections
Suppression of exceptions
Retaliation against employees who report concerns
The auditor should investigate the underlying behavior and control implications.
A Practical Audit Approach
Step 1: Define the audit objective
Do not start with the hypothesis that a specific person is a psychopath.
Start with an auditable objective such as:
Evaluate executive-expense controls.
Assess management override.
Review ethics and retaliation processes.
Evaluate the reliability of performance reporting.
Assess governance over corrective-action closure.
Review organizational culture and employee reporting channels.
Step 2: Establish criteria
Possible criteria include:
Policies
Codes of conduct
Delegations of authority
Employment requirements
Audit Committee charters
Regulatory rules
COSO principles
The IIA Global Internal Audit Standards
Whistleblower protections
Step 3: Gather evidence from multiple sources
Do not rely on the subject’s explanation or the complainant’s allegation alone.
Use:
Interviews
Documents
System records
Data analysis
Emails
Minutes
Performance reports
Independent confirmations
Step 4: Identify patterns
One disagreement or override may be ordinary.
Repeated behavior across time, processes, and employees may indicate a systemic issue.
Step 5: Evaluate control impact
Determine how the behavior affected:
Reliability
Compliance
Financial exposure
Employee reporting
Governance oversight
Fraud risk
Operational performance
Step 6: Report objectively
Avoid psychological labels.
Describe:
Condition
Criteria
Cause
Consequence
Corrective action
Example Audit Finding: Management Override
Condition
The executive approved six purchases from a selected vendor without required competitive procurement. Three purchases were divided into amounts below the approval threshold.
Criteria
The procurement policy requires competitive bids and approval by an independent executive for purchases exceeding the established threshold.
Cause
The organization’s purchasing system permits senior executives to bypass the automated workflow. Overrides are not included in a report reviewed by the Board or Audit Committee.
Consequence
The control weakness increases the risk of favoritism, conflicts of interest, excessive pricing, unauthorized purchases, and concealment of related-party activity.
Corrective Action
Management should require independent review of executive procurement activity, implement automated reporting of overrides and split transactions, and provide periodic results to the Audit Committee.
Notice what the finding does not say:
“The executive displayed psychopathic behavior.”
The finding identifies the observable conduct and control consequence.
That is Internal Audit’s job.
Protecting the Internal Audit Team
When dealing with a highly manipulative or retaliatory individual, the Chief Audit
Executive should protect staff through:
Clear scope authorization
Documented reporting lines
Supervisory participation
Controlled communication
Evidence preservation
Legal consultation
Direct Audit Committee access
Rotation of staff where necessary
Monitoring for retaliation
Junior auditors should not be left alone to manage serious executive misconduct.
The organization has a duty to protect employees who perform authorized assurance work.
What Internal Auditors Should Learn from Snakes in Suits
The central lesson is not:
Learn how to identify psychopaths.
The useful audit lesson is:
Learn how destructive individuals exploit weak governance, unreliable information, organizational politics, and misplaced trust.
Internal auditors should use that insight to strengthen:
Professional skepticism
Interviewing
Corroboration
Management-override testing
Culture audits
Fraud-risk assessments
Audit Committee communication
Evidence-based reporting
Protection of whistleblowers
Internal Audit independence
The book encourages readers to look beyond charm, confidence, and organizational status. That is valuable advice for auditors because audit evidence should never depend on personal appeal or reputation. The publisher characterizes the book as an examination of how manipulative and deceptive workplace behavior can create organizational chaos.
The Final Principle: Audit the Conduct, Not the Personality
An internal auditor does not need to know whether an executive is clinically psychopathic.
The auditor needs to determine whether:
Information is reliable.
Controls operate.
Employees can report concerns safely.
Management override is monitored.
The Board receives complete information.
Decisions serve the organization.
Misconduct is investigated.
Corrective actions are implemented.
Internal Audit can operate independently.
That is enough.
A destructive personality becomes an organizational risk only when the governance and control environment allows destructive behavior to affect the organization.
Strong governance does not depend on every leader being ethical, humble, empathetic, or cooperative.
Strong governance assumes that some people may not be.
It establishes:
Independent oversight
Segregation of duties
Transparent reporting
Evidence-based decisions
Protected reporting channels
Monitoring of override
Accountability for misconduct
The most important message from Snakes in Suits for Internal Audit is therefore not psychological.
It is structural:
Never allow the organization’s system of governance to depend entirely on the character of one powerful individual.
Internal controls should protect the organization even when the person wearing the suit cannot be trusted.
Frequently Asked Questions
Can an internal auditor determine whether an executive is a psychopath?
No. Internal auditors should not diagnose psychological conditions unless they possess appropriate professional qualifications and are specifically authorized to conduct such an assessment. Internal Audit should evaluate observable conduct, evidence, control effects, and governance risk.
What is the most useful lesson from Snakes in Suits for auditors?
The book helps auditors understand how charm, manipulation, deception, blame shifting, alliance building, and impression management may conceal poor performance or misconduct. These observations should increase professional skepticism and lead to additional corroboration.
Should Internal Audit use the B-Scan 360?
Not casually. The B-Scan 360 is a specialized workplace research and assessment instrument. Any formal use should involve appropriately qualified professionals, legal review, Human Resources, confidentiality safeguards, and governance oversight.
How should an auditor document manipulative behavior?
Document specific, observable facts. Identify inconsistent statements, withheld information, override activity, unsupported representations, retaliation, or interference with the audit. Avoid labels and speculation about motives or psychological conditions.
What should an auditor do when a powerful executive interferes with an audit?
The auditor should document the interference, inform the Chief Audit Executive, preserve supporting evidence, follow established escalation procedures, and communicate significant scope limitations or independence threats to the Audit Committee.
How does corporate psychopathy relate to fraud risk?
Certain behavioral patterns discussed in corporate-psychopathy research—such as deception, lack of accountability, manipulation, and disregard for rules—may increase fraud or governance risk. They do not establish that fraud occurred. Fraud conclusions require sufficient, appropriate evidence.
How should Audit Committees respond?
Audit Committees should maintain direct communication with Internal Audit, conduct executive sessions, review management override, protect whistleblowers, monitor retaliation, and ensure significant concerns involving senior management are investigated independently.
Comments