Fight fraud with six levels of authentication

Published Tue, Nov 25, 2014 · 09:50 PM

I REFER to the article, "In audits, if something feels wrong, it probably is" (BT, Nov 21), especially the point "One example of a tool that supports such objectives is the multi-factor authentication that is ubiquitous in e-commerce".

I believe this is the panacea that could help detect fraud and, more importantly, prevent deception due to collusion by executives. All must remember it is not the responsibility and role of external auditors to detect fraud.

Many major commercial frauds like at China Aviation Oil and the latest one at OW Bunkers could have been prevented if there were not just three but six levels of authentication. However, we are aware that too tight a control will stifle commercial enterprise. Some will say there are a thousand and one ways for top management or employees of a company to conceal, cheat and deceive the investing public, some of whom are CPF members. It affects the creditors, too, causing a chain effect. Many mutual funds, CPF members' nest eggs and their hard-earned money invested in good faith could be exposed in public listed companies (PLCs), which could go bust any time as a result of unscrupulous executives. This must be urgently fixed.

I hope the Monetary Authority of Singapore (MAS) will take action to make the following steps mandatory to tighten corporate governance of our listed companies and the controls of our financial markets by using electronic financial trading systems with encrypted passwords to ensure confidentiality in disclosing transactions. Singapore, as one of the region's top financial centres, should not sit back and wait to follow the US and Britain.

Electronic trading systems can easily be set up to do this, and the threshold for each trading tranche should be set up within controllable limits so as to not overload the system of reporting. Corporate fraud is getting more sophisticated and complex. With e-commerce, detection has become more difficult and challenging when top executives can easily forge and conceal documents and information from the Singapore Exchange (SGX) and the investing public. It is more pressing for a six-party automatic authentication to be put in place as soon as possible.

Unless this is made mandatory, no one can confidently say that the recent case at Ow Bunkers will be the last white-collar fraud to rock the financial market.

Unless made mandatory by law, leaving the board and the managements of financial institutions and PLCs to enforce good corporate governance on their own cannot assure anyone that such fraud and collusion among top executives of contracting parties will not happen again.

The six-party authentication process will ensure that collusion is made that much more difficult if not impossible to cover up any wrongdoings. Relying on whistle-blowers to expose fraud will not be enough and no better than an angler waiting patiently for a bite.

Past fraud cases have proven that relying on one-sided internal control is little better than flying blindfold, and hoping that auditors will be sharp enough to detect and expose fraud in the course of their audit is unrealistic. The recent fraud at Ow Bunkers has proven again that relying on corporate self-policing is wishful thinking.

Tan Kok Tim