FIN 470 Week 5 Internal Controls, Compliance and Securities Regulation Example

Reviewed by Davina Cresswell, MBA · University of Phoenix · Updated

This FIN 470 Week 5 example redesigns an organization's internal controls after a fraud and explains the securities rules that would apply if it became part of a public company. University of Phoenix FIN 470 closes with internal controls, compliance and securities regulation, and in this final FIN/470 assignment BS in Finance students connect prevention to the laws that govern public company reporting. The case is the composite Ohio distributor that lost $412,000 to a branch manager's shell company and is now in talks to be acquired by a publicly traded company. The paper uses the COSO framework's five components to diagnose the failures, redesigns vendor, approval and monitoring controls, adds a reporting hotline, explains what Sarbanes-Oxley would require after an acquisition and describes the SEC whistleblower program and its effect on internal reporting.

CourseFIN 470 Fraud Examination and Forensic Accounting (FIN/470)
Week5
Paper typeInternal control and securities regulation paper
Lengthabout 1,023 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Finance
UpdatedOctober 2026

Free sample paper for FIN 470 Week 5

1

Closing the Door Midstate Walked Through: A COSO-Based Control Redesign at Buckeye Comfort Supply and What Sarbanes-Oxley and SEC Whistleblower Rules Would Add if a Public Company Buys It

[Student Name]

University of Phoenix

FIN/470: Fraud Examination and Forensic Accounting

Week 5 Assignment

[Instructor Name]

[Date]

Buckeye Comfort Supply and its controls are composites written for a model paper; frameworks, laws and research findings are summarized generally from the sources listed.

What this part is doingThe title connects the specific fraud to both the fix and the regulations, previewing the paper's two halves.
2

Buckeye Comfort Supply, the composite Ohio distributor, recovered most of its $412,300 loss through insurance and restitution, as Week 4 described. Its board now faced two pressures. It wanted to make sure no one could repeat the Midstate scheme, and a publicly traded building products company had offered to acquire it, which would bring Buckeye under public company reporting rules. The fraud showed exactly where Buckeye's controls failed, which made it the best possible guide to fixing them. This paper redesigns the controls and explains the regulations that would follow an acquisition.

Diagnosing the Failures With COSO

The framework issued by COSO (2013) organizes internal control into five components. In the control environment, Buckeye had a code of conduct but no training on it and no conflict of interest disclosures. In risk assessment, no one had considered how a branch manager could abuse approval authority. In control activities, one person could set up a vendor request, approve its invoices and receive confirmation of work. In information and communication, no channel existed for employees to report concerns. In monitoring, no one reviewed vendor activity across branches. Each component had a gap that the scheme passed through.

Vendor Setup

New vendors will be created only by a central vendor management team, never by the person who requests them. The team will verify each vendor's legal registration, tax identification number, physical address and bank account, reject post office box-only vendors for services without a site visit and screen every new vendor against employee addresses, phone numbers and bank accounts. Branch managers will sign annual conflict of interest disclosures.

What this part is doingSeparating the request, setup and approval of a vendor removes the single opportunity that made the Midstate scheme possible.
3

Approvals and Matching

Maintenance and repair invoices will require a matching work order created before the work, signed by the technician who observed it, before payment. Invoices between $5,000 and $10,000 will need a second approver at the regional level, and the approval limit will no longer be disclosed in the branch manual, reducing gaming. The payables system will block payment of service invoices without a work order reference.

Monitoring

The analytic tests from Week 2 will run monthly: vendor and employee matching, threshold clustering, sequential invoice numbers and duplicates. The internal audit function, a new two-person team, will review results, visit four branches each quarter and report to the board's audit committee. Mandatory vacations of at least five consecutive days for anyone with approval authority will give others a chance to see their work.

A Reporting Channel

The Association of Certified Fraud Examiners (2024) reported that tips led all other detection methods, and that organizations with hotlines detected frauds faster and with smaller losses than those without. Buckeye will contract with an outside hotline provider offering anonymous reporting by phone and web, with reports going to the audit committee chair and counsel. Training will tell employees what to report and that retaliation is prohibited.

The Board's Role

The board will form an audit committee of two directors, one an outside member with accounting experience, to oversee internal audit, the hotline and the external auditor. Tone at the top matters: the chief executive will address the Midstate case openly in training, without naming individuals, to show that controls protect everyone.

Sarbanes-Oxley After an Acquisition

If the public company acquires Buckeye, Buckeye's results become part of the parent's financial statements, and its controls become part of the parent's internal control over financial reporting. Section 302 of the 2002 statute requires the parent's chief executive and chief financial officer to certify each quarter that the reports are accurate and that they have evaluated disclosure controls. Under Section 404, management assesses internal control effectiveness annually, and for larger companies the external auditor attests to it. Newly acquired businesses can often be excluded from the first year's assessment, but Buckeye's controls will need to meet the parent's standards, with documentation, testing and remediation, within about a year. Coates (2007) noted that these requirements raised compliance costs, especially for smaller firms, while aiming to improve reporting reliability.

The SEC and Whistleblowers

The Securities and Exchange Commission enforces securities laws, including requirements for accurate reporting and internal controls. The Dodd-Frank Act created a whistleblower program that pays qualifying whistleblowers between a tenth and three tenths of any SEC sanctions that exceed $1 million to individuals who provide original information leading to successful enforcement, and protects them from retaliation. Dyck et al. (2010) found that employees ranked high among those who first exposed frauds at large companies and that monetary incentives appeared to increase whistleblowing. An effective internal hotline gives employees a way to raise concerns inside the company first, which helps management address problems early.

What this part is doingLinking the whistleblower program to the internal hotline shows why internal reporting matters more after an acquisition.
4

Controls That Do Not Overreach

Every control has a cost in time as well as money. Branch managers worried that work orders and second approvals would slow emergency repairs in winter, when a failed heater in a customer's building cannot wait. The redesign therefore allows emergency work to proceed on a manager's approval, with the work order completed within two business days and every emergency invoice reviewed by internal audit. That keeps the business running while closing the gap, because the review happens after the fact but before patterns can build. Controls that people work around protect no one, so the redesign was tested with three branch managers before rollout.

What this part is doingDesigning an exception for emergencies shows that controls must fit how the business actually operates.
5

Costs and Timeline

The new controls will cost about $340,000 a year, mostly the internal audit team, the vendor management role and the hotline, against a single fraud that cost about $511,000 including investigation and interest. Vendor controls and the hotline will be in place within 60 days, the work order requirement within 90 days and the audit committee within six months.

Conclusion

Buckeye's fraud passed through gaps in every COSO component. Separating vendor setup from approval, requiring work orders, monitoring with analytics, adding a hotline and an audit committee close those gaps. If Buckeye joins a public company, Sarbanes-Oxley certification and control reporting, SEC enforcement and whistleblower rules will add obligations that the redesigned controls are built to meet.

6

References

Association of Certified Fraud Examiners. (2024). Occupational fraud 2024: A report to the nations. https://legacy.acfe.com/report-to-the-nations/2024/

Coates, J. C., IV. (2007). The goals and promise of the Sarbanes-Oxley Act. Journal of Economic Perspectives, 21(1), 91-116. https://doi.org/10.1257/jep.21.1.91

COSO. (2013). Internal control: Integrated framework. Committee of Sponsoring Organizations of the Treadway Commission. https://www.coso.org

Dyck, A., Morse, A., & Zingales, L. (2010). Who blows the whistle on corporate fraud? The Journal of Finance, 65(6), 2213-2253. https://doi.org/10.1111/j.1540-6261.2010.01614.x

What the FIN 470 Week 5 instructions ask

The final FIN 470 assignment generally asks students to recommend internal controls that prevent and detect fraud and to explain the regulatory framework, especially for public companies. Common requirements include the COSO internal control framework and its components, preventive and detective controls, segregation of duties, the role of the board and audit committee, anti-fraud programs such as hotlines, the Sarbanes-Oxley Act's requirements for management certification and internal control reporting, the SEC's enforcement role and whistleblower provisions. Many versions tie the analysis to a case, often one studied earlier in the course. Link each control to a specific weakness, weigh cost against benefit and cite frameworks, laws and research in APA format.

How this FIN 470 Week 5 example is built

A fraud that has been investigated and reported leaves one question: how to stop the next one. The paper diagnoses Buckeye's failures using COSO's five components, finding gaps in each. Controls are then redesigned where the scheme succeeded: vendor setup, approval limits, matching invoices to work and monitoring. A hotline addresses the finding that coworkers noticed red flags but had nowhere to report them. The pending acquisition brings in public company rules, so the paper explains management certifications and internal control reporting under Sarbanes-Oxley, the SEC's role and the whistleblower program. Research on who detects fraud supports the design. The paper ends with costs and a timeline.

FIN 470 Week 5 grading rubric: where the points go

Grading in this final week tends to reward controls tied to specific weaknesses, organized by a recognized framework, and an accurate account of the regulatory environment. Instructors look for a diagnosis using COSO components, controls that would have prevented or detected the actual scheme, attention to both preventive and detective measures and a realistic view of cost and burden. Explaining Sarbanes-Oxley requirements and SEC whistleblower rules correctly and generally, and how they would apply to the company, shows understanding. Using research on detection methods to support recommendations adds depth. A control table, timeline and APA references complete a strong paper. Graders also value a cost comparison, since controls the company cannot afford to keep will not protect it for long.

FIN 470 Week 5 help: mistakes to avoid

The weakest final FIN 470 papers recommend generic controls, such as more oversight, without linking them to how the fraud actually worked. Start from the scheme and close each gap. Another frequent gap is ignoring cost; controls that slow every purchase may be abandoned. Weigh benefit against burden. Students also describe Sarbanes-Oxley as applying to every company; its main requirements apply to public companies. Explain when they would apply. Avoid relying only on preventive controls; detection matters too, and tips detect many frauds. Include the board's role. Finally, give a timeline and owner for each control, and say how the board will know each one is working.

Related FIN 470 sample papers

Other FIN 470 week samples

More BS in Finance sample papers

FIN 470 Week 5 questions, answered

What does FIN 470 Week 5 usually cover?

It usually covers internal controls for fraud prevention and detection, the COSO framework, anti-fraud programs, the Sarbanes-Oxley Act, the SEC's role in securities regulation and whistleblower protections and awards.

Where can I find a free FIN 470 Week 5 sample paper?

The control redesign for a distributor after a shell company fraud, with COSO, Sarbanes-Oxley and whistleblower rules explained in the margin, is posted here and free to read. Request a free draft on your case.

What are the five components of the COSO framework?

The control environment, the assessment of risks, the control activities themselves, the flow of information and communication, and ongoing monitoring, which together support reliable operations, reporting and compliance.

What does Sarbanes-Oxley Section 404 require?

Management of a public company must assess and report on the effectiveness of internal control over financial reporting each year, and for larger companies the outside auditor must attest to that assessment.

How does the SEC whistleblower program work?

It pays awards of 10 to 30 percent of sanctions above $1 million to people who give original information leading to a successful enforcement action, and it protects them from retaliation.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.