<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Development of an IT-supported Anti-Fraud-Framework for SMEs: An Architectural Concept for Risk Management Using the 'Man-Technology-Organization' Approach</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Michaela K. Trierweiler</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Johannes Kepler University</institution>
          ,
          <addr-line>Altenberger Straße 69, Linz, 4040</addr-line>
          ,
          <country country="AT">Austria</country>
        </aff>
      </contrib-group>
      <fpage>204</fpage>
      <lpage>215</lpage>
      <abstract>
        <p>Small and medium enterprises (SMEs) are an important economic factor in many countries. In the European Union, they represent the majority of companies, provide two thirds of all jobs, and drive a lot of innovation. This makes them attractive for perpetrators of fraud; limited resources in terms of money, staff, and IT knowledge make them vulnerable. This research deals with the question of how to minimize fraud as a specific risk to SMEs. In concrete terms, it sets out how a framework should look and establishes the guidance that should be given in the context of fraud prevention. This study is set up as a design science research project with the aim of producing a concrete framework as a solution and contributing artifact. Previous research shows that there is a gap in academic research regarding fraud prevention concepts tailored to SMEs. This assumption seems valid as an integrative literature review revealed only a few appropriate papers plus a great deal of non-academic or semi-academic literature. In particular, information systems research is underrepresented in this area. Existing SME-related fraud prevention frameworks concentrate more on internal related fraud risks rather than on fraud committed by external parties, such as cybercrime. This suggests that a comprehensive fraud prevention concept is missing for SMEs and is worthy of being developed, especially considering that any enterprise is a socio-technical system. Keeping in mind that such a framework must be generic enough to cover different fraud risks and company situations while also giving concrete advice, this research applies domain-specific modeling principles to find the best notation and style of presentation. This work-in-progress paper proposes a preliminary architectural model for a new fraud prevention concept suitable for SMEs.</p>
      </abstract>
      <kwd-group>
        <kwd>1 fraud prevention</kwd>
        <kwd>framework</kwd>
        <kwd>SME</kwd>
        <kwd>MTO</kwd>
        <kwd>risk management</kwd>
        <kwd>socio-technical system</kwd>
        <kwd>design science</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction and Research Scope</title>
      <p>
        Small and medium enterprises (SMEs) are considered to be the engine of many economies. In the
European Union, nine out of 10 enterprises are SMEs and they generate two thirds of all jobs [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. SMEs
drive innovation and are seen as a key factor in driving competitiveness and employment. Therefore,
they are lucrative targets for criminals [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]–[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Analysis of the fraud situation in SMEs (as recorded by
the Association of Certified Fraud Examiners in their bi-annual Report to Nations) proves the
importance of fraud prevention for SMEs. Over the last several years, they were the most common
victims of fraud with an approximately share of 30%. Since 2018, SMEs have suffered the highest
financial losses and thus the biggest negative impacts compared to companies of other sizes [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ],
[
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. In addition, SMEs face different fraud risks than those faced by larger companies [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Therefore,
they need different fraud risk management concepts (or at least tailored countermeasures) that are suited
to the personnel resources, organization and technical possibilities of SMEs.
      </p>
      <p>
        In legal terms, fraud is part of the field of white-collar crime. The main elements are intention,
deception, and damage to another party in the sense of financial loss (see, for example, §263 and §263a
of the German criminal law [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] or §146 of the Austrian criminal law [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]). The bandwidth of
whitecollar crime is huge and includes both delicts that harm a company directly (such as paying too much
salary) and delicts that may seem beneficial for a company at first glance, such as corruption to gain a
large and profitable deal [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. In 2007, Joseph T. Wells developed a classification system for
occupational fraud and abuse in business contexts that is known as the fraud tree [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. This system
covers most kinds of misconduct by executives, managers, and employees [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. The model has been
refined over the years and is now considered to be one of the state-of-the-art fraud definition concepts.
All types of fraud considered in this taxonomy could be summarized as non-compliant and as a
undesired behavior because they harm either an organization [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] or an individual.
      </p>
      <p>
        The existing literature discusses different fraud theories and concepts about the facilitators of fraud.
Although very different fraud models have been developed in recent decades [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], the widely accepted
perception follows the approach of Cressey, developed in the 1950s, where three critical elements must
apply: incentive/pressure, opportunity, and attitude/rationalization [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. This concept, known as the
fraud triangle, was further developed by Wolfe and Hermanson [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] by supplementing a fourth
dimension and is now commonly known as the fraud diamond. The added fourth dimension of
capability (defined as intelligence, creativity, and experience [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]) could be interpreted in the
sense of technical and computational skills. It is therefore relevant when considering cybercrime and
IT-based fraud. In recent research, such as [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]–[
        <xref ref-type="bibr" rid="ref20">20</xref>
        ], a fifth dimension of arrogance is discussed, along
with its impact on fraud management. This leads to an approach named the fraud pentagon.
      </p>
      <p>
        Fundamentally, small companies are more likely to lack internal controls [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], have no proper risk
management systems in place, and lack staff in IT functions, because the focus of employment lies in
staffing the core roles and functions that are critical for running and developing the business. Micro
SMEs [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ], defined as those that have fewer than ten employees, have a very flat organizational
structure and often combine functions in one role. This makes active fraud prevention (or even a simple
thing such as the four-eyes principle when signing documents or releasing payment requests) difficult
to establish. In SMEs, a compliant corporate culture, including fraud prevention and detection, is
usually practiced by example or just because it is seen as commonly accepted good manners. It is seldom
methodically established as a part of enterprise risk management. The most well-protected and legally
regulated area is accounting because this is the most lucrative part. Besides accounting fraud (e.g.,
fraudulent statements) there are many other forms of occupational fraud, such as identity theft, bribery,
asset misappropriation, and corruption [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. The existing fraud risk situation is currently fostered by
the COVID-19 crisis: the sudden rise of rapidly implemented information and communication
techniques (ICT) makes it easier for fraudsters to attack [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] and a significant increase in cyber fraud,
payment fraud, or identity theft [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]–[
        <xref ref-type="bibr" rid="ref27">27</xref>
        ] is projected.
      </p>
      <p>
        Increasing digitalization, and the omnipresence of apparently straightforward IT tools such as email
programs in daily business transactions, results in a reciprocal relationship between IT and fraud
prevention. IT tools often are vectors for fraud attacks (e.g., email phishing attempts); on the other hand,
specific software and hardware tools, real-time or big data analytics [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ], [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ], or even AI [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ] can help
to prevent and detect fraud. However, highly technological or ERP-based measures are seldom used in
SMEs. The literature review reveals a lack of discussion of IT-related fraud prevention measures, which
is notable considering the importance of IT in today’s business world. Many researchers focus on
organizational measures and do not deliver comprehensive guidelines or pursue a generalized research
approach. Furthermore, in many cases, research in this area is neither related to information systems
(IS) research nor considers fraud risk as a problem in an enterprise that has an ICT landscape embedded
within a socio-technical business environment where people and technology working jointly together.
      </p>
      <p>This research aims to contribute to filling this gap through a design science research project. The
project is setup in three major stages, starting with an integrative literature review to examine the state
of existing research and to build a knowledge base. This is followed by designing an alternative fraud
prevention concept as new artifact that overcomes potential limitations found in existing concepts. The
research concludes with an evaluation based on piloting the new framework in some SMEs and
gathering feedback in terms of understandability, complexity, and integration in order to refine the
framework to its final state.</p>
      <p>Based on the assumption that bigger companies have a greater need for fraud prevention than smaller
companies (as well as more workers and resources with which to establish anti-fraud controls and
countermeasures), the following research questions (RQs) have been defined:</p>
      <p>RQ 1. What kinds of SME-tailored fraud management frameworks can be found in the existing
literature? What fraud types do they consider and how are IT-related fraud risks discussed?
RQ 2. What does an IT-supported fraud prevention framework need to look like in order to fit into
an SME to cover the individual fraud risk and consider given resources? What IT security
concepts can be applied to such a new framework as an artifact to be created?
RQ 3. How does this newly developed IT-supported fraud prevention framework perform in
different SME contexts? Where are the limitations of the framework and what adjustments
are necessary?</p>
      <p>
        This research contributes to the existing field in two ways: first, it bridges epistemic research and
applied sciences by creating a new artifact; second, this artifact supports practitioners in SMEs to
minimize fraud risks in their individual contexts. This new approach is based on the
man-technologyorganization (MTO) concept of Strohm and Ulich [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. An effective anti-fraud management system is
a socio-technical system in the sense that it requires collaboration between technology (e.g., IT security
aspects), organizational procedures (e.g., the four-eyes principle), and workers (e.g., awareness training
and ethical culture). Therefore, a new framework must be comprehensive, science-based, compatible
with SMEs’ fraud risk needs, and understandable for non-academics.
      </p>
      <p>This objective has a major influence on the design and notation used for describing the new
framework model. The relevance and benefits of such a framework are based on the fact that SMEs
have limited know-how on such controls; they could easily lose reputation and money in the event of
fraud. Existing IT frameworks are often very complex and do not meet the requirements of SMEs or
are beyond the knowledge base of SMEs. Therefore, a more practical and tailored guidance is required.
The present work-in-progress paper describes the development and evaluation of a new concept and
proposes a preliminary architectural draft for an SME-appropriate fraud prevention approach that
includes IT-related risks and countermeasures.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Methodology and Research Design</title>
      <p>This section describes the methodologies used in the present research.
2.1.</p>
    </sec>
    <sec id="sec-3">
      <title>Literature Review</title>
      <p>The literature review in context of this research fulfilled three aims. The first aim was to establish
the current state of academic research and to find potential existing frameworks. The second aim was
to verify the gap-spotting approach in terms of clarifying the research focus and to define the research
entry point for the design science procedure. The third aim was to find the best resources in order to
design a new framework for a universal fraud prevention concept for SMEs.</p>
      <p>
        An integrative literature review was performed in several stages, starting with the application of
structured literature review principles as suggested by Kitchenham [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ], Massaro et al. [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ], and Fink
[
        <xref ref-type="bibr" rid="ref34">34</xref>
        ] using three academic databases (Compliance Digital [German language], EBSCOhost, and
Scopus). Strict search strings were used (containing “fraud | framework | SME”) to find peer-reviewed
research papers. The number of results was very small, which suggested a gap in research. To clarify
this outcome and to obtain robust results for the definition of the academic resource pool, a second
round of systematic searching was performed. In this round, the search strings were more generic and
additional databases (IEEE, ResearchGate, Academia) were used along with snowballing and free
searches. After this second round, the literature review showed a gap in terms of academic research in
the field of fraud prevention frameworks for SMEs. It also revealed a large amount of case-descriptive
or consultancy-related literature. Based on the used search strings,736 hits were found; after reading
titles, abstracts, and skim-reading the text, only 33 items were found to be relevant. Especially the third
target of building an adequate resource pool as baseline for the design phase required to include more
practitioners’ view (reflected in textbooks) and to add non-academic (so called grey literature) works
as well. The final source pool consists of 61 items. These sources were assessed according to guidelines
from Snyder [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ] and Garousi et al. [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ]. Four academic works were excluded because of their poor
empirical base, one journal article was not available, one publication was a doublet based on same
research, and one of the grey literature items was excluded due to missing contribution to my research.
Consequently, the final core pool of literature consisted of 54 items that were screened and classified
according to the following criteria:
• Schematic allocation of relevant keywords (define scoping and relevance of each source)
• Geographic coverage (check transferability to European economy)
• Empirical base (decide on the meaningfulness of the scientific work)
• Qualifiers for content (e.g., what the source discusses)
• Qualifiers for intended use during the further research steps.
      </p>
      <p>
        The geographical coverage of the sources (generic, North America, and Asia) suggested the need
for adaption before doing a transfer to European requirements because economical situations differ.
The small number of design science approaches showed that there was a lack of concrete frameworks.
The quantitative analyses carried out by some researchers were often based on a small number of valid
answers (with N ranges from 37 to 250). This low empirical base and evidence needed to be considered
when adapting information to the present research. In terms of content, most of the papers related to the
search term “fraud and SME” contained descriptive statistics about the fraud situation in certain
countries or business areas. However, they did not give a holistic prevention approach that included
ITsupported prevention measures. Most of the sources concentrated on organizational or internal control
aspects. These sources were used in the present research for problem statements or for explaining
important background aspects. Sources that mention a concrete framework or guideline often referred
to existing frameworks, such as Internal Control – Integrated Framework, published by Committee of
Sponsoring Organizations of the Treadway Commission (COSO-2013) [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ]. Many other authors have
used the COSO-2013 as justification for their own introduction or problem statement. The concentration
on accounting fraud (or other very specific fraud types such as payroll fraud or employee fraud)
indicated a lack of research in handling certain fraud types (especially IT-related or
cybersecurityrelated fraud attempts). The concentration on specific industry sectors also suggested a missing holistic
or universal approach.
      </p>
      <p>To summarize, the fact that only a limited number of scientific papers and sources deal with all three
scope-criteria (fraud, framework and SME) indicated a gap in the academic discourse in that area.
Because of this small scientific base, grey-literature and textbooks from fraud prevention or auditing
experts were added to the information pool for this research (always keeping in mind that such texts are
often written in the context of the Anglo-American economic situation). In addition, established
frameworks from other disciplines will be analyzed to find useful concepts to be transferred into the
present approach during the design phase of this research.
2.2.</p>
    </sec>
    <sec id="sec-4">
      <title>Design Science Research Concept</title>
      <p>
        In order to design a framework model in a structured way, this research project is conducted by
following the design science principles of Hevner et al. [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ] and the design science process model
(DSPM) from Peffers et al. [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ]. The final artifact will obtain proof-of-concept during the evaluation
phase in a specific SME context that is yet to be defined. The socio-technical approach is in line with
Hevner’s [
        <xref ref-type="bibr" rid="ref38">38</xref>
        ] three-cycle view of design science as reflected in the relevance cycle connecting the
environment with the designing phase.
      </p>
      <p>Six fraud management frameworks dedicated to SME were found during the literature search. This
information defined the entry point of this research as an objective-centered solution. This entry point
enables the planning of a new (or improved) prevention framework. It was necessary to analyze and
compare existing anti-fraud frameworks in order to identify gaps and add missing technology and
aspects. Useful content could be found by evaluating well-established auditing frameworks such as the
Sarbanes-Oxley Act (2002) or the US National Institute of Standards and Technology (NIST)
cybersecurity framework (2014).</p>
      <p>The framework developed in this way is the artifact in the sense of the design science approach.
Regarding the nominal process sequence, Table 1 shows the six stages of the design science process
model (DSPM) plus an iteration, and briefly declares the use respectively to the present research work.</p>
      <sec id="sec-4-1">
        <title>As part of enterprise risk management, fraud prevention measures could be</title>
        <p>transferred from existing fraud-fighting concepts and from other areas such as</p>
      </sec>
      <sec id="sec-4-2">
        <title>IT security or generic compliance recommendations. These must be tailored to</title>
        <p>the needs and resources of SMEs. Such a framework must contain concrete
measures, checklists, and action plans outlining the steps an SME should take
against different types of fraud within their industry.
(This phase contributes to answering RQ-2).</p>
      </sec>
      <sec id="sec-4-3">
        <title>The notation of this framework will apply domain-specific modeling principles.</title>
      </sec>
      <sec id="sec-4-4">
        <title>It must be understandable for scientists and practitioners.</title>
      </sec>
      <sec id="sec-4-5">
        <title>The architectural structure is presented with this paper.</title>
        <p>(This phase contributes to answering RQ-2).</p>
      </sec>
      <sec id="sec-4-6">
        <title>A conceptual model and drafts will be presented at relevant conferences and in discussions with practitioners (e.g., compliance managers) from the business network (expert evaluation). (This phase contributes to answering RQ-3).</title>
        <p>The core evaluation is planned as a pilot implementation with two SMEs of
different sizes and from different industries. The aim is to get a real-life
proofof-concept for completeness, practicability, and understandability. Such an
evaluation is an interactive method and requires collaboration between the
researcher and the piloting company. Therefore, the method of action research
seems to be the best approach. A second, more theoretical approach is to
apply an SME-related IT security maturity model to evaluate the feasibility of
an IT-supported fraud prevention framework.
(This phase contributes to answering RQ-3).</p>
        <p>The feedback from demonstrations and evaluation phases will be used to
rework and refine the artifact.</p>
      </sec>
      <sec id="sec-4-7">
        <title>Communication is planned in the form of a scholarly publication and a</title>
        <p>professional publication (textbook). Parts of it will be written bi-lingually in</p>
      </sec>
      <sec id="sec-4-8">
        <title>German and English to allow access by a broader audience.</title>
        <p>2.3.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Evaluation of the New Framework in Certain SME Contexts</title>
      <p>
        Once the new framework is created, an evaluation will be required to ensure utility, efficacy,
understandability, and completeness. This evaluation will also identify potential limitations. Some
literature [
        <xref ref-type="bibr" rid="ref39">39</xref>
        ]–[
        <xref ref-type="bibr" rid="ref41">41</xref>
        ] suggests different methods suitable for evaluation purposes in design science
research contexts; these include benchmarking, expert evaluation, experiments, action research,
prototyping, and case studies. Several strategies for selecting the appropriate method are proposed by
IS researchers [
        <xref ref-type="bibr" rid="ref42">42</xref>
        ]–[
        <xref ref-type="bibr" rid="ref44">44</xref>
        ]. These take into consideration aspects of risk, effectiveness, efficacy, and
technical aspects with the aim of evaluating how well the artifact performs. After comparing possible
evaluation methods by their intended use, the concept of action research seems to be the best approach
for this current research because it allows a practical problem to be solved through the joint cooperation
of science and practice [
        <xref ref-type="bibr" rid="ref45">45</xref>
        ], [
        <xref ref-type="bibr" rid="ref46">46</xref>
        ]. The latter, in this context, would be a SME willing to pilot,
implement, and utilize the new framework. In contrast, a case study approach [
        <xref ref-type="bibr" rid="ref47">47</xref>
        ] does not seem to be
suitable in this research because no hypothesis with variables on an individual or single existing
phenomenon shall be validated. The aim of this research is to test the artifact implementation in a
realworld situation, which results in a concrete and tailored instance of the framework for the piloting SME.
Action research can provide scientific knowledge but also improve organizational problems where
some technology is adopted or even built from scratch, supported by state-of-the-art corresponding
knowhow [
        <xref ref-type="bibr" rid="ref48">48</xref>
        ]. Action research is an interactive method that considers both the practical concerns of
people working with the framework and the goals of the researcher in order to obtain feedback on how
the artifact performs; it is set up as an iterative process [
        <xref ref-type="bibr" rid="ref49">49</xref>
        ]. The cyclic approach of action research was
interpreted by Checkland as an approach where the researcher is interested in a certain research theme
that is related to a real-world problem situation and where the researcher participates the situation
(consultancy to the piloting SME during implementation) to enable reflections that will lead to findings
related to the research theme [
        <xref ref-type="bibr" rid="ref50">50</xref>
        ]. This approach seems suitable for the present research because the
framework of ideas (the new artifact), the methodology, and the area of concern are defined in advance.
      </p>
      <p>
        Regarding the answer to RQ-3, proper planning and acquisition of piloting SMEs is necessary. The
approach in this study is to present, discuss, and implement the new fraud prevention framework in two
piloting SMEs of different sizes and in different industries. Potential partners will need to come from
very different areas in order to obtain diverse feedback regarding understandability,
comprehensiveness, and applicability (in the sense of implementation while running the daily work and
not to interfere with current business processes). The intention is to pilot the framework with a small
SME with less than 20 employees and a medium-sized SME with more than 100 employees [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. The
different numbers of employees impacted by the framework will allow conclusions to be drawn about
the practicability of the framework and the impact on given resources. In terms of industry sectors, the
aim is to run one pilot implementation in a more technology-oriented company (such as a software
development company with a high level of digital maturity) and to perform a second evaluation in a
more traditional industry. This will test the applicability of the prevention framework for different types
of fraud risks. If the framework is suitable for very different company situations, this may indicate that
it provides a generic prevention concept that could be applied to various SME situations. Feedback
about applicability will be captured by interviewing the piloting companies about their experiences
during the implementation phase and some month after in order to gather feedback about its usability
during daily work.
      </p>
      <p>Finding piloting partners may be difficult because the SME must see clear benefits in undertaking
the effort of such a scheme. Therefore, this research will be supported by presentations and through
discussion of the framework with experts from related domains (such as compliance, auditing, and IT
security). In addition, a theoretical evaluation will be conducted by applying digital maturity models to
the framework for the question about necessary IT prerequisites a SME must have to be able to
implement such an IT-supported fraud prevention framework; especially if the SME might not have an
own dedicated IT or security department but needs to implement dedicated software and other IT-related
tools to better protected against fraud attempts.
2.4.</p>
    </sec>
    <sec id="sec-6">
      <title>Notation of Framework: Use of Domain-Specific Modeling Principles</title>
      <p>
        After first drawings of the components, their interconnections, and related sub-process and possible
content for the current fraud-prevention framework, it got clear to design and describe the framework
in its own notation by applying principles for domain specific modelling suggested by Kelly and
Tolvanen [
        <xref ref-type="bibr" rid="ref51">51</xref>
        ]. The framework will consist of several layers and types of information (such as
flowcharts) to show dependencies, business workflows, checklists, step plans, and recommendations
for software tools. It will also be necessary to include a glossary outlining the different types of fraud
and the proven countermeasures that an SME could implement. This combination of graphical and
textual content must find a form of notation that is both understandable and abstract enough to allow
existential generalizations [
        <xref ref-type="bibr" rid="ref52">52</xref>
        ]. IT-specific notations such as Unified Modelling Languages (UML) or
the concept of BPMN 2.0 would cover only parts of the framework; others, such as ArchiMate®, are
too complex to be understood by those who are not IT experts.
      </p>
    </sec>
    <sec id="sec-7">
      <title>3. Summary of Findings to Date and Current State of Artifact Design</title>
      <p>
        The first examination of the six fraud prevention frameworks dedicated to SMEs revealed that these
concepts showed a narrow scope and offered little advice on prevention measures. These concepts either
concentrated on a very specific context [
        <xref ref-type="bibr" rid="ref53">53</xref>
        ], [
        <xref ref-type="bibr" rid="ref54">54</xref>
        ], or only covered employee fraud [
        <xref ref-type="bibr" rid="ref55">55</xref>
        ], [
        <xref ref-type="bibr" rid="ref56">56</xref>
        ] and not
external fraud risks. One case study [
        <xref ref-type="bibr" rid="ref57">57</xref>
        ] pursued a more behavioral approach by developing a code of
conduct and incident response chains, while another study [
        <xref ref-type="bibr" rid="ref58">58</xref>
        ] concentrated on reporting options for
fraud. An alternative prevention concept must also consider external fraud vectors. Internal control
mechanisms must be supplemented by IT techniques to detect fraud at an early stage.
      </p>
      <p>
        When looking into existing and well-established frameworks from other disciplines, some
transferable information seems promising. For instance, the IT management and IT governance
framework COBIT-2019 (Control Objectives for Information and Related Technologies) developed by
the Information Systems Audit and Control Association allows different perspectives and focus areas,
one of which is related to SMEs [
        <xref ref-type="bibr" rid="ref59">59</xref>
        ], [
        <xref ref-type="bibr" rid="ref60">60</xref>
        ]. The NIST Cybersecurity Framework [
        <xref ref-type="bibr" rid="ref61">61</xref>
        ], [
        <xref ref-type="bibr" rid="ref62">62</xref>
        ] allows SME
specific security approaches. As an example, a transfer of the five stages of NIST cybersecurity
framework (identify, protect, detect, respond, recover) [
        <xref ref-type="bibr" rid="ref63">63</xref>
        ] into fraud prevention measures including a
classifying of these measures as man-, technology- or organization-related. The MTO classification
allows the creation of different cluster for the implementation and makes it easier for SMEs to decide
what prevention measure to be installed and in what order. With regard to the implementation itself, the
use of the ISIS12 (Information Security Management System in 12 steps) concept [
        <xref ref-type="bibr" rid="ref64">64</xref>
        ] could be adapted
to create a roadmap for implementing a fraud-prevention framework.
      </p>
      <p>An in-depth analysis of the six concepts found during the literature review and a detailed review of
established frameworks from other disciplines is currently in progress. Therefore, the present
architectural fraud prevention framework (as visualized in Figure 1) is at a preliminary stage. It consists
of five connected dimensions (Tier 1). The framework deals with risk management in order to allow
the SME to identify the individual fraud risk. It touches on fraud forensics because the need for risk
management is often realized after an incident has occurred. The core part of the framework discusses
and describes the fraud types and their countermeasures along the MTO concept to enable the selection
of suitable measures. In addition, the proposed framework gives ideas of where to find external support
and suggests a roadmap for implementation. A continuous improvement cycle must follow the
implementation in order to keep the implemented measures up to date.</p>
      <p>Figure 1 illustrates the different components, connections, and interplay. But a second
conceptualization is helpful to understand the layers of granularity in each tier. This information will
be worked out in detail for the final publication and the concrete guideline for SME practitioners.</p>
      <p>Figure 2 shows the content-related structure consisting of six layers (I–VI) with an increase in
granularity for each level. For example, Layer VI will contain concrete recommendations and references
or weblinks, whereas Layers I and II are more introductory and will provide background overviews.
Layers III–VI build the core of the framework and will offer a concrete toolbox for selecting and
implementing the most suitable countermeasures for the individual fraud risk as identified during the
risk assessment. Layers III – VI reflect the Tier 2 containing all sub-processes and a high level of content
and detailed information.</p>
    </sec>
    <sec id="sec-8">
      <title>4. Conclusion, Limitations and Further Research</title>
      <p>This research project concentrates on finding the best measures and activities for preventing or
detecting fraud in small and medium organizations. It is supplemented with related aspects of IT
security, risk management, and implementational aspects. The present work-in-progress paper gives an
idea of why a comprehensive fraud-fighting framework is valuable for SMEs. It also shows why this
framework must be created in a generalized and flexible manner to enable SMEs to choose the fraud
prevention activities that are most suitable for their business model and resource situation. Therefore,
the final framework might include advice for modifications of some suggested fraud prevention
measures to make them applicable to micro-SMEs, as well.</p>
      <p>Limitations might occur if a generic framework cannot be created, since different fraud types or
industries would require very different prevention approaches. This would increase complexity and
might reduce the applicability and understandability of the framework.</p>
      <p>Upcoming steps during this design science research project will include an in-depth analysis of the
six fraud prevention concepts found during the literature review and the evaluation of existing
frameworks from other disciplines. These insights will be incorporated into the design and creation of
the Tier 2 details for the above-mentioned five dimensions (Tier 1 boxes). The MTO approach will be
used to enable manageable cluster for the implementation of different measures that will interplay and
build a fraud prevention and detection framework for the SME. The SME context for the evaluation
will be defined (e.g., the use of very different industry partners) and a roadmap for evaluation will be
prepared according to the principles of action research in order to acquire piloting SME partners and to
prepare for expert evaluation.</p>
    </sec>
    <sec id="sec-9">
      <title>5. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>European</given-names>
            <surname>Commission</surname>
          </string-name>
          , “
          <article-title>User guide to the SME Definition,” Publications Office of the European Union</article-title>
          , Luxembourg, Aug.
          <year>2020</year>
          . Accessed: Feb.
          <volume>12</volume>
          ,
          <year>2021</year>
          . [Online]. Available: https://ec.europa.eu/docsroom/documents/42921
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>D.</given-names>
            <surname>Kempf</surname>
          </string-name>
          , “Ohne Schutzschild,” IT-Security Channel Compendium, Jun.
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Ponemon</surname>
          </string-name>
          ,
          <article-title>“2017 State of Cybersecurity in Small &amp; Medium-Sized Businesses (SMB),”</article-title>
          <string-name>
            <surname>Ponemon Institute</surname>
            <given-names>LLC</given-names>
          </string-name>
          ,
          <year>Sep</year>
          .
          <year>2017</year>
          . Accessed: Nov.
          <volume>28</volume>
          ,
          <year>2020</year>
          . [Online]. Available: https://www.csrps.com/wp-content/uploads/2019/03/2017-
          <article-title>Ponemon-State-of-Cybersecurity-in-Smalland-Medium-Sized-Businesses-SMB</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4] ACFE, “
          <article-title>Report to the Nations -</article-title>
          2020
          <source>Global Fraud Study on Occupational Fraud and Abuse</source>
          ,”
          <article-title>Association of Certified Fraud Examiners Inc</article-title>
          ., Austin - Texas - USA,
          <year>2020</year>
          . Accessed: Dec.
          <volume>01</volume>
          ,
          <year>2020</year>
          . [Online]. Available: https://acfepublic.s3
          <article-title>-us-west-2</article-title>
          .amazonaws.com/2020-
          <article-title>Report-to-the-</article-title>
          <string-name>
            <surname>Nations</surname>
          </string-name>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M.</given-names>
            <surname>Barth</surname>
          </string-name>
          et al., “Spionage, Sabotage und Datendiebstahl - Wirtschaftsschutz in der vernetzten Welt,” Bitkom e.V., Berlin,
          <year>Studienbericht 2020</year>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Ernst</given-names>
            <surname>&amp; Young Fraud Investigation</surname>
          </string-name>
          &amp; Dispute Services, “
          <source>Global Forensic Data Analytics Survey</source>
          <year>2018</year>
          :
          <article-title>How can you disrupt risk in an era of digital transformation?</article-title>
          ,”
          <year>2018</year>
          . [Online]. Available: https://assets.ey.com/content/dam/ey-sites/ey-com/en_gl/topics/assurance/assurance-pdfs/ey-globalfda-survay.pdf
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7] ACFE, “
          <article-title>Report to the Nations on Occupational Fraud</article-title>
          and Abuse - 2016
          <string-name>
            <surname>Global Fraud</surname>
            <given-names>Study</given-names>
          </string-name>
          ,” Association of Certified Fraud Examiners, Austin - Texas - USA,
          <year>2016</year>
          . Accessed: Apr.
          <volume>07</volume>
          ,
          <year>2018</year>
          . [Online]. Available: https://www.acfe.com/rttn2016/docs/2016-report
          <article-title>-to-the-nations</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8] ACFE, “
          <article-title>Report to the Nations -</article-title>
          2018
          <source>Global Fraud Study on Occupational Fraud and Abuse</source>
          ,” Association of Certified Fraud Examiners, Austin - Texas - USA,
          <year>2018</year>
          . Accessed: May 15,
          <year>2018</year>
          . [Online]. Available: https://s3-us
          <article-title>-west-2</article-title>
          .amazonaws.com/acfepublic/2018-report
          <article-title>-to-the-nations</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Bundesamt</surname>
            <given-names>für Justiz</given-names>
          </string-name>
          , “§ 263a StGB - Einzelnorm.” https://www.gesetze-iminternet.de/stgb/__263a.
          <source>html (accessed Mar</source>
          .
          <volume>07</volume>
          ,
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10] jusline.at, “§ 146 StGB (Strafgesetzbuch), Betrug - JUSLINE Österreich.” https://www.jusline.at/gesetz/stgb/paragraf/146 (accessed Mar.
          <volume>07</volume>
          ,
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Heißner</surname>
          </string-name>
          , “Täter und Delikte,” in Erfolgsfaktor Integrität, Wiesbaden: Springer Fachmedien Wiesbaden,
          <year>2014</year>
          , pp.
          <fpage>37</fpage>
          -
          <lpage>70</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>658</fpage>
          -05608-
          <issue>7</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <article-title>Association of Certified Fraud Examiners, “The Fraud Tree - occupational fraud and abuse classification systems,” The Fraud Tree - Occupational Fraud and Abuse Classification System</article-title>
          ,
          <year>2016</year>
          . https://www.acfe.com/rttn2016/images/fraud-tree.
          <source>jpg (accessed Mar</source>
          .
          <volume>07</volume>
          ,
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>K.</given-names>
            <surname>Henselmann</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.</given-names>
            <surname>Hofmann</surname>
          </string-name>
          ,
          <article-title>Accounting fraud: case studies and practical implications</article-title>
          . Berlin: Erich Schmidt,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>J.</given-names>
            <surname>Marks</surname>
          </string-name>
          , “Fraud Pentagon - Enhancements to the Three Conditions Under Which Fraud May Occur,” BoardAndFraud, May
          <volume>21</volume>
          ,
          <year>2020</year>
          . https://boardandfraud.com/
          <year>2020</year>
          /05/21/fraud-pentagonenhancements
          <article-title>-to-the-fraud-triangle-and-under-which-fraud-may-occur/ (accessed Jan</article-title>
          .
          <volume>05</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>D. T.</given-names>
            <surname>Wolfe</surname>
          </string-name>
          and
          <string-name>
            <given-names>D. R.</given-names>
            <surname>Hermanson</surname>
          </string-name>
          , “
          <article-title>The Fraud Diamond: Considering the Four Elements of Fraud,”</article-title>
          <source>CPA Journal</source>
          , vol.
          <volume>74</volume>
          .12, pp.
          <fpage>38</fpage>
          -
          <lpage>42</lpage>
          ,
          <year>2004</year>
          , [Online]. Available: https://digitalcommons.kennesaw.edu/cgi/viewcontent.cgi?article=2546&amp;context=facpubs
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>N.</given-names>
            <surname>Christian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y. Z.</given-names>
            <surname>Basri</surname>
          </string-name>
          , and W. Arafah, “
          <article-title>Analysis of Fraud Triangle, Fraud Diamond and Fraud Pentagon Theory to Detecting Corporate Fraud in Indonesia,”</article-title>
          <source>The International Journal of Business Management and Technology</source>
          , vol.
          <volume>3</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>73</fpage>
          -
          <lpage>78</lpage>
          , Aug.
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>K.</given-names>
            <surname>Fuad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Lestari</surname>
          </string-name>
          , and R. T. Handayani, “
          <article-title>Fraud Pentagon as a Measurement Tool for Detecting Financial Statements Fraud,” Vung Tau City</article-title>
          , Vietnam,
          <year>2020</year>
          . doi:
          <volume>10</volume>
          .2991/aebmr.k.
          <volume>200127</volume>
          .017.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>S.</given-names>
            <surname>Maulidiana</surname>
          </string-name>
          and
          <string-name>
            <given-names>T.</given-names>
            <surname>Triandi</surname>
          </string-name>
          , “
          <article-title>Analysis of Fraudulent Financial Reporting Through the Fraud Pentagon Theory</article-title>
          ,” South Tangerang, Indonesia,
          <year>2020</year>
          . doi:
          <volume>10</volume>
          .2991/aebmr.k.
          <volume>200522</volume>
          .042.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Muhsin</surname>
            , Kardoyo, and
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Nurkhin</surname>
          </string-name>
          , “What Determinants of Academic Fraud Behavior? From Fraud Triangle to Fraud Pentagon Perspective,” KSS, vol.
          <volume>3</volume>
          , no.
          <issue>10</issue>
          , p.
          <fpage>154</fpage>
          ,
          <string-name>
            <surname>Oct</surname>
          </string-name>
          .
          <year>2018</year>
          , doi: 10.18502/kss.v3i10.
          <fpage>3126</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>M.</given-names>
            <surname>Nindito</surname>
          </string-name>
          , “
          <article-title>Financial Statement Fraud: Perspective of the Pentagon Fraud Model in Indonesia,” Academy of Accounting and Financial Studies Journal</article-title>
          , Jun.
          <year>2018</year>
          , Accessed: Jan.
          <volume>02</volume>
          ,
          <year>2021</year>
          . [Online]. Available: https://www.abacademies.org/abstract/financial
          <article-title>-statement-fraud-perspective-ofthe-pentagon-fraud-model-in-indonesia-7319</article-title>
          .html
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>European</surname>
            <given-names>Commission</given-names>
          </string-name>
          , “SME definition,” Internal Market, Industry, Entrepreneurship and SMEs - European
          <string-name>
            <surname>Commission</surname>
          </string-name>
          , Jul.
          <volume>05</volume>
          ,
          <year>2016</year>
          . https://ec.europa.eu/growth/smes/sme-definition_
          <source>en (accessed Feb</source>
          .
          <volume>12</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>P.</given-names>
            <surname>Schöber</surname>
          </string-name>
          and
          <string-name>
            <given-names>P.</given-names>
            <surname>Schmitz</surname>
          </string-name>
          , “
          <article-title>Hochkonjunktur für die Schatten-</article-title>
          IT,” IT-Business, Oct.
          <volume>23</volume>
          ,
          <year>2020</year>
          . https://www.it-business.de/hochkonjunktur-fuer
          <article-title>-die-schatten-</article-title>
          <string-name>
            <surname>it-</surname>
          </string-name>
          a-
          <volume>973554</volume>
          (accessed Oct.
          <volume>23</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23] ACFE, “
          <article-title>Fraud in the Wake of COVID-19:</article-title>
          <string-name>
            <surname>Benchmarking</surname>
            <given-names>Report</given-names>
          </string-name>
          ,” Jun.
          <year>2020</year>
          . https://www.acfe.com/covidreport.aspx (accessed
          <year>Jun</year>
          .
          <volume>18</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24] ACFE, “
          <source>Fraud in the Wake of COVID-19: Benchmarking Report December Edition</source>
          ,” Dec.
          <year>2020</year>
          . https://www.acfe.com/covidreport.aspx (accessed
          <year>Mar</year>
          .
          <volume>14</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>D.</given-names>
            <surname>Buil-Gil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Miró-Llinares</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Moneva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kemp</surname>
          </string-name>
          , and
          <string-name>
            <surname>N.</surname>
          </string-name>
          <article-title>Díaz-Castaño, “Cybercrime and shifts in opportunities during COVID-19: a preliminary analysis in the UK</article-title>
          ,” European Societies, pp.
          <fpage>1</fpage>
          -
          <lpage>13</lpage>
          , Aug.
          <year>2020</year>
          , doi: 10.1080/14616696.
          <year>2020</year>
          .
          <volume>1804973</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Deloitte</surname>
            <given-names>Poland,</given-names>
          </string-name>
          “
          <article-title>The impact of COVID-19 on the fraud risks faced by organisations</article-title>
          .
          <source>” Apr</source>
          .
          <year>2020</year>
          . Accessed: Mar.
          <volume>14</volume>
          ,
          <year>2021</year>
          . [Online]. Available: https://www2.deloitte.com/content/dam/Deloitte/pl/Documents/Brochures/pl_COVID_19_Fraud%20 Risks_EN_newApril2020.pdf
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>L.</given-names>
            <surname>Pasculli</surname>
          </string-name>
          , “
          <article-title>COVID19-related fraud risks and possible anti-fraud measures (Written evidence submitted to the Treasury Committee on the Economic Impact of Coronavirus)</article-title>
          ,” Coventry University, EIC0792, Jun.
          <year>2020</year>
          . [Online]. Available: https://www.researchgate.net/publication/345760552_COVID19
          <article-title>- related_fraud_risks_and_possible_antifraud_measures_Written_evidence_submitted_to_the_Treasury_Committee_on_the_Economic_Impa ct_of_Coronavirus</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>F.</given-names>
            <surname>Holzenthal</surname>
          </string-name>
          , “
          <article-title>IT-gestützte Geldwäsche- und Betrugsbekämpfung in Banken und Versicherungen Mehrwert durch einen holistischen GRC-Ansatz,” ZRFC</article-title>
          , vol.
          <volume>3</volume>
          /14, pp.
          <fpage>140</fpage>
          -
          <lpage>143</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>O.</given-names>
            <surname>Derksen</surname>
          </string-name>
          , “
          <article-title>Fraud Analyse von Massendaten in Echtzeit,” in Big Data - Systeme und Prüfung, Deggendorfer Forum zur digitalen Datenanalyse</article-title>
          , Ed. Berlin: Schmidt,
          <year>2013</year>
          , pp.
          <fpage>45</fpage>
          -
          <lpage>59</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>M.</given-names>
            <surname>Spindler</surname>
          </string-name>
          and
          <string-name>
            <given-names>H.</given-names>
            <surname>Kögel</surname>
          </string-name>
          , “
          <article-title>Erkennung von Versicherungsbetrug mit künstlicher Intelligenz,” Bitkom Bundesverband Informationswirtschaft, Telekommunikation und neue Medien e</article-title>
          .V., Berlin, Faktenpapier No.
          <volume>9</volume>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>E.</given-names>
            <surname>Ulich</surname>
          </string-name>
          , “Arbeitssysteme als Soziotechnische Systeme - eine
          <string-name>
            <surname>Erinnerung</surname>
          </string-name>
          ,
          <source>” Journal Psychologie des Alltagshandelns</source>
          , vol.
          <volume>6</volume>
          , no.
          <issue>1</issue>
          ,
          <year>2013</year>
          , [Online]. Available: http://www.allgemeinepsychologie.info/cms/images/stories/allgpsy_journal/Vol%
          <volume>206</volume>
          %20No%
          <fpage>201</fpage>
          /Arbeitssystem_Ulich.pdf
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>B.</given-names>
            <surname>Kitchenham</surname>
          </string-name>
          , “
          <article-title>Guidelines for performing systematic literature reviews in software engineering</article-title>
          ,” EBSE,
          <source>Technical Report, Ver. 2.3</source>
          ,
          <year>2007</year>
          . Accessed: Oct.
          <volume>07</volume>
          ,
          <year>2017</year>
          . [Online]. Available: https://pdfs.semanticscholar.org/e62d/bbbbe70cabcde3335765009e94ed2b9883d5.pdf
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>M.</given-names>
            <surname>Massaro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dumay</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Guthrie</surname>
          </string-name>
          , “
          <article-title>On the shoulders of giants: undertaking a structured literature review in accounting</article-title>
          ,” Accounting, Auditing &amp;
          <source>Accountability Journal</source>
          , vol.
          <volume>29</volume>
          , no.
          <issue>5</issue>
          , pp.
          <fpage>767</fpage>
          -
          <lpage>801</lpage>
          , Jan.
          <year>2016</year>
          , doi: 10.1108/AAAJ-01-2015-
          <year>1939</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>A.</given-names>
            <surname>Fink</surname>
          </string-name>
          ,
          <article-title>Conducting research literature reviews: from the internet to paper, Fifth edition</article-title>
          . Los Angeles: Sage,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <article-title>Committee of Sponsoring Organizations of the Treadway Commission (COSO), “Guidance on Internal Control,” www</article-title>
          .coso.org,
          <year>2013</year>
          . https://www.coso.org/pages/ic.aspx (accessed
          <year>Jun</year>
          .
          <volume>09</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Hevner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. T.</given-names>
            <surname>March</surname>
          </string-name>
          , J. Park, and S. Ram, “Design Science in Information Systems Research,” MIS Quarterly, vol.
          <volume>28</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>75</fpage>
          -
          <lpage>105</lpage>
          , Mar.
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>K.</given-names>
            <surname>Peffers</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Tuunanen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Rothenberger</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Chatterjee</surname>
          </string-name>
          , “
          <source>A Design Science Research Methodology for Information Systems Research,” Journal of Management Information Systems</source>
          , vol.
          <volume>24</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>45</fpage>
          -
          <lpage>77</lpage>
          , Dec.
          <year>2007</year>
          , doi: 10.2753/MIS0742-1222240302.
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Hevner</surname>
          </string-name>
          , “A Three Cycle View of Design Science Research,”
          <source>Scandinavian Journal of Information Systems</source>
          , vol.
          <volume>19</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>87</fpage>
          -
          <lpage>92</lpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>M.</given-names>
            <surname>Shaw</surname>
          </string-name>
          , “What Makes Good Research in Software Engineering?,
          <source>” STTT</source>
          , vol.
          <volume>4</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [40]
          <string-name>
            <given-names>A.</given-names>
            <surname>Cleven</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Gubler</surname>
          </string-name>
          , and
          <string-name>
            <surname>K. M. Hüner</surname>
          </string-name>
          , “
          <article-title>Design alternatives for the evaluation of design science research artifacts</article-title>
          ,”
          <year>2009</year>
          , p.
          <fpage>1</fpage>
          . doi:
          <volume>10</volume>
          .1145/1555619.1555645.
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          [41]
          <string-name>
            <given-names>K.</given-names>
            <surname>Peffers</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Rothenberger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Tuunanen</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Vaezi</surname>
          </string-name>
          , “Design Science Research Evaluation,”
          <source>in Design Science Research in Information Systems. Advances in Theory and Practice</source>
          , vol.
          <volume>7286</volume>
          , Berlin, Heidelberg: Springer Berlin Heidelberg,
          <year>2012</year>
          , pp.
          <fpage>398</fpage>
          -
          <lpage>410</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          - 29863-9_
          <fpage>29</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          [42]
          <string-name>
            <given-names>N.</given-names>
            <surname>Prat</surname>
          </string-name>
          ,
          <string-name>
            <surname>I.</surname>
          </string-name>
          <article-title>Comyn-Wattiau, and</article-title>
          <string-name>
            <given-names>J.</given-names>
            <surname>Akoka</surname>
          </string-name>
          , “
          <source>Artifact Evaluation in Information Systems Design Science Research - A Holistic View,” Jun</source>
          .
          <year>2014</year>
          , p.
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          [43]
          <string-name>
            <given-names>J.</given-names>
            <surname>Pries-Heje</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Baskerville</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J. R.</given-names>
            <surname>Venable</surname>
          </string-name>
          , “
          <source>Strategies for Design Science Research Evaluation,” ECIS 2008 Proceedings. 87</source>
          , p.
          <fpage>13</fpage>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          [44]
          <string-name>
            <given-names>J.</given-names>
            <surname>Venable</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Pries-Heje</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>R.</given-names>
            <surname>Baskerville</surname>
          </string-name>
          , “
          <article-title>FEDS: a Framework for Evaluation in Design Science Research,”</article-title>
          <source>European Journal of Information Systems</source>
          , vol.
          <volume>25</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>77</fpage>
          -
          <lpage>89</lpage>
          , Jan.
          <year>2016</year>
          , doi: 10.1057/ejis.
          <year>2014</year>
          .
          <volume>36</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref45">
        <mixed-citation>
          [45]
          <string-name>
            <given-names>T.</given-names>
            <surname>Wilde</surname>
          </string-name>
          and
          <string-name>
            <given-names>T.</given-names>
            <surname>Hess</surname>
          </string-name>
          , “Forschungsmethoden der Wirtschaftsinformatik: Eine empirische Untersuchung,
          <source>” WIRTSCHAFTSINFORMATIK</source>
          , vol.
          <volume>49</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>280</fpage>
          -
          <lpage>287</lpage>
          , Aug.
          <year>2007</year>
          , doi: 10.1007/s11576-007-0064-z.
        </mixed-citation>
      </ref>
      <ref id="ref46">
        <mixed-citation>
          [46]
          <string-name>
            <surname>K. C. Laudon</surname>
            ,
            <given-names>J. P.</given-names>
          </string-name>
          <string-name>
            <surname>Laudon</surname>
            , and
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Schoder</surname>
          </string-name>
          , Wirtschaftsinformatik: eine Einführung,
          <volume>3</volume>
          ., Vollständig überarbeitete Auflage. Hallbergmoos/Germany: Pearson,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref47">
        <mixed-citation>
          [47]
          <string-name>
            <given-names>N.</given-names>
            <surname>Döring</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Bortz</surname>
          </string-name>
          ,
          <article-title>Forschungsmethoden und Evaluation in den Sozial- und Humanwissenschaften, 5</article-title>
          . vollständig überarbeitete,
          <source>Aktualisierte und erweiterte Auflage</source>
          . Berlin Heidelberg: Springer,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref48">
        <mixed-citation>
          [48]
          <string-name>
            <surname>P. S. M. dos Santos</surname>
            and
            <given-names>G. H.</given-names>
          </string-name>
          <string-name>
            <surname>Travassos</surname>
          </string-name>
          , “
          <article-title>Action Research Can Swing the Balance in Experimental Software Engineering</article-title>
          ,” in Advances in Computers, vol.
          <volume>83</volume>
          ,
          <string-name>
            <surname>Elsevier</surname>
          </string-name>
          ,
          <year>2011</year>
          , pp.
          <fpage>205</fpage>
          -
          <lpage>276</lpage>
          . doi:
          <volume>10</volume>
          .1016/B978-0
          <source>-12-385510-7</source>
          .
          <fpage>00005</fpage>
          -
          <lpage>9</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref49">
        <mixed-citation>
          [49]
          <string-name>
            <given-names>J.</given-names>
            <surname>Recker</surname>
          </string-name>
          ,
          <article-title>Scientific research in information systems: a beginner's guide</article-title>
          . Heidelberg: Springer,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref50">
        <mixed-citation>
          [50]
          <string-name>
            <given-names>N. F.</given-names>
            <surname>Kock</surname>
          </string-name>
          , Ed.,
          <article-title>Information systems action research: an applied view of emerging concepts and methods</article-title>
          . New York, N.Y: Springer,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref51">
        <mixed-citation>
          [51]
          <string-name>
            <given-names>S.</given-names>
            <surname>Kelly</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.-P.</given-names>
            <surname>Tolvanen</surname>
          </string-name>
          ,
          <article-title>Domain-specific modeling: enabling full code generation</article-title>
          . Hoboken, N.J: Wiley-Interscience : IEEE Computer Society,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref52">
        <mixed-citation>
          [52]
          <string-name>
            <given-names>R. J.</given-names>
            <surname>Wieringa</surname>
          </string-name>
          ,
          <article-title>Design science methodology for information systems and software engineering</article-title>
          . New York, NY: Springer Berlin Heidelberg,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref53">
        <mixed-citation>
          [53]
          <string-name>
            <given-names>S.</given-names>
            <surname>Phuttima</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Rueangsirasak</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Chaisricharoen</surname>
          </string-name>
          , “
          <article-title>Fraud Detection System for Steel Logistic SME Business on Cloud Services Model,” in The 4th Joint International Conference on Information and Communication Technology, Electronic and Electrical Engineering (JICTEE), Chiang Rai</article-title>
          , Thailand, Mar.
          <year>2014</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          . doi:
          <volume>10</volume>
          .1109/JICTEE.
          <year>2014</year>
          .
          <volume>6804088</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref54">
        <mixed-citation>
          [54]
          <string-name>
            <given-names>N. A.</given-names>
            <surname>Aris</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M. M.</given-names>
            <surname>Arif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Othman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Chantrathevi</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Tapsir</surname>
          </string-name>
          , “
          <article-title>Internal Control Mechanism Framework for Fraud Prevention in Small Medium Automotive Industry</article-title>
          ,” in
          <source>2013 IEEE Symposium on Humannities, Science and Engineering Research</source>
          (SHUSER), Malaysia, Jun.
          <year>2013</year>
          , pp.
          <fpage>594</fpage>
          -
          <lpage>598</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref55">
        <mixed-citation>
          [55]
          <string-name>
            <given-names>S.</given-names>
            <surname>Dawson</surname>
          </string-name>
          ,
          <article-title>Internal control/anti-fraud program design for the small business: a guide for companies not subject to the Sarbanes-Oxley Act</article-title>
          . Hoboken: Wiley,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref56">
        <mixed-citation>
          [56]
          <string-name>
            <given-names>L. D. A.</given-names>
            <surname>Yearwood</surname>
          </string-name>
          , “
          <article-title>A Conceptual Framework for the Prevention and Detection of Occupational Fraud in Small Businesses,”</article-title>
          <source>Master Thesis</source>
          , Concordia University College of Alberta, Alberta Canada,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref57">
        <mixed-citation>
          [57]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lincke</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Green</surname>
          </string-name>
          , “
          <article-title>Combating IS fraud: A teaching case study,” in AMCIS 2012 Proceedings</article-title>
          , Seattle, Washington, Aug.
          <year>2012</year>
          , vol.
          <volume>2</volume>
          , pp.
          <fpage>578</fpage>
          -
          <lpage>584</lpage>
          . [Online]. Available: http://aisel.aisnet.org/amcis2012/proceedings/ISEducation/2
        </mixed-citation>
      </ref>
      <ref id="ref58">
        <mixed-citation>
          [58]
          <string-name>
            <surname>K. T. Çalıyurt</surname>
          </string-name>
          , “
          <article-title>Reporting Fraud Using the Fraud-Free Company Model: A Case for the SMEs in Emerging Economies?</article-title>
          ,” in Emerging Fraud,
          <string-name>
            <given-names>K.</given-names>
            <surname>Çaliyurt</surname>
          </string-name>
          and
          <string-name>
            <given-names>S. O.</given-names>
            <surname>Idowu</surname>
          </string-name>
          , Eds. Berlin, Heidelberg: Springer Berlin Heidelberg,
          <year>2012</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>18</lpage>
          . Accessed: Dec.
          <volume>01</volume>
          ,
          <year>2020</year>
          . [Online]. Available: http://link.springer.com/10.1007/978-3-
          <fpage>642</fpage>
          -20826-
          <issue>3</issue>
          _
          <fpage>1</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref59">
        <mixed-citation>
          [59]
          <string-name>
            <given-names>M.</given-names>
            <surname>Andenmatten</surname>
          </string-name>
          , “
          <article-title>COBIT 2019 - Das neue Enterprise Governance Modell für Informationen und Technologien,” Disruptive agile Service Management</article-title>
          ,
          <source>Nov. 26</source>
          ,
          <year>2018</year>
          . https://blog.itil.org/
          <year>2018</year>
          /11/cobit-2019
          <string-name>
            <surname>-</surname>
          </string-name>
          das
          <article-title>-neue-enterprise-governance-modell-fuer-informationenund-technologien/ (accessed Jun</article-title>
          .
          <volume>19</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref60">
        <mixed-citation>
          [60]
          <string-name>
            <given-names>P. M.</given-names>
            <surname>Asprion</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Burda</surname>
          </string-name>
          , “COBIT - Enzyklopädie der Wirtschaftsinformatik,” Enzyklopädie der Wirtschaftsinformatik - Online
          <string-name>
            <surname>Lexikon</surname>
          </string-name>
          , Feb.
          <volume>27</volume>
          ,
          <year>2019</year>
          . https://www.enzyklopaedieder-wirtschaftsinformatik.de/wi-enzyklopaedie/lexikon/daten-wissen/Grundlagen-derInformationsversorgung/COBIT (accessed
          <year>Jun</year>
          .
          <volume>19</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref61">
        <mixed-citation>
          [61]
          <string-name>
            <given-names>C.</given-names>
            <surname>Johnson</surname>
          </string-name>
          , “
          <article-title>Sizing Up the NIST Cybersecurity Framework,” NIST Taking Measure</article-title>
          , Oct.
          <volume>31</volume>
          ,
          <year>2016</year>
          . https://www.nist.gov/blogs/taking-measure/
          <article-title>sizing-nist-cybersecurity-framework (accessed Jun</article-title>
          .
          <volume>19</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref62">
        <mixed-citation>
          [62] N. Keller, “Small and Medium Business Perspectives,” NIST, Feb.
          <volume>01</volume>
          ,
          <year>2018</year>
          . https://www.nist.gov/cyberframework/small-and
          <article-title>-medium-business-perspectives (accessed Jun</article-title>
          .
          <volume>19</volume>
          ,
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref63">
        <mixed-citation>
          [63]
          <article-title>The MEP National Network, “MANUFACTURERS GUIDE TO CYBERSECURITY - For Small and Medium-Sized Manufacturers,” THE MEP NATIONAL NETWORK</article-title>
          .
          <source>Accessed: Nov. 08</source>
          ,
          <year>2020</year>
          . [Online]. Available: https://www.nist.gov/system/files/documents/2019/11/14/mepnn_cybersecurity_guide_
          <fpage>10919</fpage>
          -
          <lpage>508</lpage>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref64">
        <mixed-citation>
          [64]
          <fpage>ISIS12</fpage>
          -Netzwerk, “
          <article-title>Handbuch zur effizienten Gestaltung von Informationssicherheit für Kleine und Mittlere Organisationen (KMO).” IT-Sicherheitscluster e</article-title>
          . V.,
          <volume>93053</volume>
          Regensburg, Apr.
          <volume>27</volume>
          ,
          <year>2020</year>
          . [Online]. Available: https://www.isis12.de
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>