Towards a Unified Quantitative Framework for Fraud Risk: Integrating the Intrinsic-Extrinsic Triangle, Bounded Probability Logics, and Siphonable Capital Allocation


Towards a Unified Quantitative Framework for Fraud Risk: Integrating the Intrinsic-Extrinsic Triangle, Bounded Probability Logics, and Siphonable Capital Allocation

Author: David J. James FCA MA (Cantab) PIBR

Published: July 2026



1. Introduction: The Qualitative Failure of Modern Auditing

For decades, forensic accountants, internal auditors, and risk professionals have evaluated occupational fraud through standard frameworks that trace back to the mid-20th century. Chief among these is Donald R. Cressey’s foundational study on embezzlement, Other People’s Money: A Study in the Social Psychology of Embezzlement (1953), which laid the groundwork for what is universally known as the Fraud Triangle. Subsequent academic and practical expansions—most notably W. Steve Albrecht’s Fraud Scale (developed via a seminal 1984 study) and David T. Wolfe and Dana R. Hermanson’s Fraud Diamond (2004)—have consistently sought to refine our understanding of white-collar crime.

Yet, a profound limitation continues to plague these frameworks: they have rarely been forced into a rigid mathematical model. In practical execution, the auditing profession routinely defaults to superficial, qualitative questionnaires. These tick-and-flick checklists evaluate systemic vulnerability using arbitrary textual markers, entirely failing to capture how individual psychology and corporate environments dynamically interact.

This descriptive approach runs contrary to the fundamental rule of scientific advancement, famously articulated by Lord Kelvin (William Thomson) during his lecture On the Six Standards of Measure at the Institution of Civil Engineers on May 3, 1883:

“When you can measure what you are speaking about, and express it in numbers, you know something about it, when you cannot express it in numbers, your knowledge is of a meager and unsatisfactory kind; it may be the beginning of knowledge, but you have scarcely, in your thoughts advanced to the stage of science.”

Today’s auditing profession remains trapped in that meager, pre-scientific domain of qualitative guesswork. This paper represents a definitive attempt to break that cycle, move past the limitations of purely descriptive models, and shift fraud theory into a rigorous, quantitative direction.

By dividing the three vertices of the fraud triangle into explicit Intrinsic (individual) and Extrinsic (environmental) vectors, we translate qualitative diagnostics into a bounded mathematical algorithm (F = P · O · R). We then link this calculated probability directly to a treasury-bounded liquidity metric to establish a strictly justified forensic budget baseline.

2. The Architecture: The Intrinsic-Extrinsic Matrix

Rather than expanding the geometric profile of the classic triangle into a diamond or pentagon—which dilutes its conceptual clarity—the framework retains the three fundamental pillars but bisects each into internal and external considerations. This yields a highly structured operational matrix:

VertexIntrinsic Factor (The Individual)Extrinsic Factor (The Organization)
Pressure (P)Personal (Pᵢ): Financial distress, addiction, or non-economic psychological impulses (e.g., kleptomania, ego, or intrusive, hacker-style curiosity).Occupational (Pₑ): Corporate mandates, aggressive targets, market expectations, or debt covenant thresholds.
Opportunity (O)Capability (Oᵢ): The individual’s unique technical skill, systemic intelligence, administrative authority, and capacity to exploit loopholes.Control Deficiencies (Oₑ): Lax internal controls, unverified modeling links, unmonitored systems, or missing audit trails.
Rationalization (R)Personal Values (Rᵢ): The individual’s baseline moral shield, ethical threshold, and capacity for self-deception.Perceived Unfairness (Rₑ): Toxic corporate culture, management double-standards, or acute workplace resentment.

3. The Quantification Algorithm

To move beyond subjective scoring, each of these six variables must be evaluated as a probability vector bounded strictly between 0.0 and 1.0. The baseline probability of fraud occurring (F) is modeled as a multiplicative system:

F = P · O · R

Because it functions as a product, the model operates as a “Zero-Gate.” If any single vertex drops to absolute zero, the entire fraud potential is completely neutralized (0.9 · 0.9 · 0 = 0). However, the internal operators of each vertex reflect distinct real-world behavioral logics:

A. The Pressure Vertex: Cumulative Overlap and Psychological Edge Cases

Pressure is cumulative. A fraudster can be driven independently by either immense occupational directives (Pₑ) or intense internal, intrinsic impulses (Pᵢ). Under this framework, Pᵢ explicitly captures both financial crises and acute psychological drivers. This includes clinical kleptomania or intrusive, hacker-style curiosity—the pathologically reckless impulse to manipulate or infiltrate a system purely to test its structural boundaries, expose system vulnerabilities, or satisfy the ego.

Because an economic need does not have to co-exist with a corporate mandate for pressure to be critical, a joint probability cannot exceed 1.0. Therefore, we deploy a Probability Union (or Fuzzy Logic OR operator):

P = Pᵢ + Pₑ − (Pᵢ · Pₑ)

If either a severe personal psychological impulse (Pᵢ = 1.0) or a crushing corporate threat (Pₑ = 1.0) exists independently, total pressure is driven perfectly to 1.0. If both are moderate (Pᵢ = 0.6, Pₑ = 0.5), they compound logically to yield an elevated total pressure vector of 0.8.

B. The Opportunity Vertex: Strict Dependency

Opportunity requires strict dependency. A wide-open system loophole or control deficiency (Oₑ = 1.0) is useless if the target individual lacks the technical capability or position to exploit and conceal it (Oᵢ = 0.0). They act as a multiplicative gate:

O = Oᵢ · Oₑ

C. The Rationalization Vertex: The Inversion Shield

An individual’s personal integrity (Rᵢ) acts as a literal shield against external organizational toxicity (Rₑ). If a person has absolute integrity (Rᵢ = 1.0), their capacity to rationalize fraud is zero, regardless of how unfairly they perceive the organization is treating them (Rₑ = 1.0). The mathematical inversion captures this relationship perfectly:

R = Rₑ · (1 − Rᵢ)

The Complete Bounded Equation

Bringing these independent structural logics together yields the finalized risk algorithm:

F = [Pᵢ + Pₑ − (Pᵢ · Pₑ)] · [Oᵢ · Oₑ] · [Rₑ · (1 − Rᵢ)]

4. Redefining the Questionnaire: From Text to Numbers

Adopting this framework does not mean abandoning diagnostic questionnaires; rather, it radically alters their output. Instead of open-ended textual narratives, auditors deploy targeted questions where every single response maps directly to a numerical weight contributing to one of the six variables.

For instance, assessments of employee turnover, executive behavior, or compensation fairness feed directly into Rₑ (Perceived Unfairness), while system validation checks and formula audits calculate Oₑ (Control Deficiencies). The ultimate output of the diagnostic tool is no longer a stack of notes, but a concrete percentage representing the overall fraud probability (F).

5. Justifying the Budget: Siphonable Capital and Liquidity Links

Once F is calculated, a forensic practice can solve its most persistent business constraint: matching the scale, procedures, and budget of an investigation to the reality of the asset exposure. Direct intervention is bound by three economic constraints:

A. The Maximum Siphonable Amount (S) Linked to Treasury

A routine transaction cycle (such as procurement, payroll, or treasury outflows) cannot entirely disappear without causing immediate operational or structural collapse. Therefore, the Maximum Siphonable Amount (S) is defined as the maximum percentage of a cycle’s total annual volume—typically capped at an operational friction ceiling of 10%—that can be covertly siphoned before triggering liquidity or P&L collapse.

Crucially, S must be linked directly to the organization’s macro liquidity profile (e.g., Free Cash Flow or its Operating Cash Buffer). If a company is experiencing a tight liquidity squeeze, the cash buffer shrinks, meaning even tiny asset diversions will trigger vendor payment failures or bounced checks. Thus, the tighter the entity’s liquidity, the lower its actual S, forcing a fraudster to steal less or risk immediate exposure.

B. The Iterative ROI Capping Constraint

If a procurement cycle processes $50,000,000 annually with a standard 10% siphonable threshold, the maximum capital exposure is $5,000,000. If the mathematically focused diagnostic yields a fraud probability (F) of 4%, the statistical expected loss is $200,000.

Operating on a strict, single-iteration framework:

  • Spending $200,000 to investigate represents a zero-gain initiative.
  • To achieve a reasonable expectation of a 2:1 return on investment, the active investigative budget must be capped at half the exposure: $100,000.
  • Spending significantly less than this threshold yields an underfunded, superficial review that serves merely as an ineffective compliance function.

C. The Sociotechnical Dissuasive Function

Scaling a forensic function purely against immediate short-term financial return ignores its broader sociological value. A highly skilled, visibly active forensic unit serves an environmental purpose: it permanently depresses Extrinsic Opportunity (Oₑ) and elevates the perceived risk of detection across all corporate layers. This structural deterrence protects systemic liquidity over time, justifying the fixed cost of an internal audit function even during iterations where immediate transactional recoveries are low.

6. Diagnostic Testing via Zero-Based Business Planning (ZBBP)

The most reliable, empirical way to get straight to the heart of operational fraud is to compare actual performance to a Zero-Based Business Plan (ZBBP). Traditional forecasting simply rolls forward historical baselines, unwittingly baking past fraud and structural siphoning into future budgets. A ZBBP strips the corporate model down to its absolute physical and engineering realities (e.g., matching physical raw material consumption or chemical run-rates to market spot prices).

When actual expenditures deviate from the zero-based expectation, the resulting unexplained variance serves as a direct, empirical indicator of Extrinsic Opportunity (Oₑ).

Furthermore, a ZBBP represents the single best framework for looking across multiple routine transaction cycles simultaneously. Because various cycles (Procurement, CapEx, Payroll) all draw from the same ultimate bottleneck—the company’s core liquidity—a unified ZBBP maps out the entire cash architecture.

Beyond fraud detection, forcing a zero-based discipline yields substantial strategic benefits:

  • It forces all operational managers involved to deeply understand both their own and adjacent business units, driving significantly better overall operational focus even in the total absence of fraud.
  • It diagnoses inherent, existential issues within the business model itself. By identifying structural gaps where actuals can never meet physical run-rate expectations, a ZBBP can expose a business line that has been disrupted to the point of being structurally broken. This grants leadership the clarity to proactively close down a unit that is unlikely ever to achieve economic payback.

7. Conclusion: The Intellectual Awakening of the Auditor

The external auditing profession, of which I am a member, is currently punching well below its intellectual weight. Successive statistical papers published by the Association of Certified Fraud Examiners (ACFE) and the International Accounting Standards Board (IASB) routinely highlight a sobering reality: the external audit is the primary discoverer of fraud in only about 4% of all detected cases. This staggeringly low efficiency is an indictment of modern auditing methodologies. If external auditors performed a more comprehensive job with their substantive analytical testing—elevating their work to the point of constructing rigorous ZBBP exercises—their rate of fraud detection would undoubtedly skyrocket.

The reason this is rarely done is clear: a zero-based analytical exercise requires intense thinking, deep industry research, and a profound understanding of the complex business lines making up the entity under examination. It is far more intrusive and vastly more labor-intensive—even in the age of artificial intelligence—than the standardized compliance testing that dominates the industry today.

Because of this intensive, operational nature, a ZBBP exercise is much closer to the natural competence of internal audit functions, especially when those functions are strategically linked to corporate controllership and budgeting. Ultimately, an organization or audit committee cannot deploy these resource-heavy exercises blindly. By utilizing the mathematical formulae and bounded probability models developed in this paper, corporate oversight boards can definitively calculate the threshold where a deep zero-based exercise is required. Whether to carry out a comprehensive ZBBP in the case of a given business line can now be mathematically confirmed or discarded—marrying economic reality to forensic science.

Your thoughts welcome, go ahead:

This site uses Akismet to reduce spam. Learn how your comment data is processed.