Introduction
Financial fraud can impact businesses of all sizes ranging from small businesses with a few employees to large corporations with thousands of transactions and several branches, with complex accounting departments. Fraud is committed when someone knowingly misleads an organization, its customers, investors, lenders, regulators or other stakeholders for personal or financial benefit. Fraud schemes can come in many shapes and forms, but common pitfalls are inadequate supervision, lack of good segregation of duties, weak documentation, access to financial systems, ineffective approval processes, and a lack of awareness among employees that such practices will be caught. Financial statement fraud is one such type of fraud that can be particularly harmful, whereby the financial information is manipulated to present an incorrect view of the financial performance or position of an organization. Knowing the nature of these frauds can help company leaders put in place controls that prevent them from getting significantly hurt.
Internal controls refer to policies, procedures, systems and monitoring activities that protect the assets of an organization, ensure accurate accounting records, enhance its efficiency of operations and ensure compliance with laws and regulations. Effective controls do not just make fraud harder to commit after it happens, they are intended to make fraud more challenging (before it happens), discover odd behavior promptly and create accountability across the organization. A good control environment means there is both preventive (authorization requirements, segregation of duties, etc.) and detective (reconciliations, audits, exception reports, etc.) controls in place. Business leaders should also be aware that no individual control can be considered foolproof in achieving total prevention of fraud. Sometimes, staff can collaborate, managers can bypass the procedures and advanced schemes can go undetected for years. The goal, then, is to establish a succession of complementary level of protection, which will make it more difficult for fraudulent actions to be carried out and easier to be recognized.
1. Asset Misappropriation
One of the most well-known types of organizational fraud is asset misappropriation, a fraud scheme in which an employee, manager, contractor or other individual steals or misappropriates the organization’s assets. The assets might be cash, inventory, equipment, supplies, company vehicles, intellectual property or other valuable assets. Theft of cash can take the form of money being taken from a cash register, receipts being taken before they are entered into the register, diverting money from customers or withdrawing money without permission. Stock can go missing when employees take items out of warehouses, falsify inventory records or arrange for items to be delivered to an unauthorized location. The red flags may be unexplained shortfalls in inventories, abnormally frequent write-offs, missing documentation, employees who do not allow independent inspection of inventories under their control, or physical inventories being below the record inventories that are kept. Often asset misappropriation involves direct access to the company’s resources, making it critical that there are controls implemented to restrict access and ensure that all money or assets movement to or from the company is traced.
Internal controls create a high level of separation between who has access to assets and who records the transactions, who authorizes transactions, and this separation can go a long way to eliminate asset misappropriation. For instance, one employee should not be in charge of cash while the other is in charge of recording the transactions and reconciling the bank account. Regular staff of independent members of staff should undertake an inventory with any material differences investigated and documented. Restricted access, security cameras, inventory management systems, asset registers, serial numbers and periodic surprise checks are other ways to safeguard physical assets. Receipting, daily deposits, documented cash counts and independent cash reconciling should be part of cash handling procedures. Management should consider unusual adjustments and repeated shortages as evidence that there has been a fault and take steps to investigate. These measures can provide an audit trail and limit the chance of one individual stealing an asset and altering the records to hide his or her misappropriation.
2. Payroll Fraud
Payroll Fraud is when an individual tricks an organization into giving him or her money that is not rightfully theirs. This may be due to fake employees, salary hike, overtime hours, fake overtime, double pay, or ghost workers. One prevalent fraud is a ghost employee: someone who does not really work is listed on the payroll and the payroll money is collected by a person associated with the fraud. Another common type of payroll fraud is when an employee records overtime hours not worked, or registers overly inflated hours on his or her own time to get overtime approval from a supervisor or manager. Some of the potential red flags include but are not limited to: Unusual changes in employee master files, payments to employees with no corresponding personnel records, duplicate bank account data, unexpected overtime increases, payroll increases with no documentation and employees payroll information not matching with human resource information. Large-scale businesses can be especially susceptible since the amount of the fraudulent payment can be small but may go unnoticed with frequent payroll processing.
Some simple best practices for payroll control should start with separation of duties between human resources, payroll processing, timekeeping and payment authorization. HR employees should be free to create, dismiss, adjust payroll details of employees and payroll personnel should process the payrolls only after receiving approval from HR. Payroll should be checked for unusual overtime and attendance, duplicate bank accounts, terminated employees receiving payroll, and large deviations from previous periods of payroll; and overtime and attendance should be approved by the manager prior to payroll processing. Payroll audits can be conducted periodically and verify selected employees and the payroll records on their own, and in comparison with personnel records. Payroll systems should be accessed based on job functions and changes to the system should be recorded and monitored. If an employee is leaving the company, termination information should be communicated to payroll ASAP to ensure timely termination of the employee’s payments from the company. These controls render fictionalization of workers and manipulation of compensation more challenging.
3. Expense Reimbursement Fraud
Expense reimbursement fraud is when employees intentionally make false, inflated, duplicate or unauthorized business expenses to get reimbursed from their employer. The scheme could involve, for instance, simply claiming a personal purchase as a business expense, or it could be more complex, such as making up receipts, claiming expenses that were not incurred, or claiming the same receipt twice. There is also a possibility that employees may overestimate their mileage, may expense entertainment for a meeting that never took place or may seek reimbursement for expenses greater than those allowed by company policy. Indications of trouble include receipts with oddly misspaced dates, multiple transactions that include the same expenses, unusually high mileage claims, round number expenses, claims that are close to reporting deadlines, and odd expenses that don’t seem related to legitimate business activity. It is particularly important to be mindful of these factors when employees have high levels of discretion in their spending and claims are approved by managers without a good level of scrutiny of the supporting documentation. Even a receipt attached method of reimbursement, which may be strictly a requirement, could be susceptible since a fraudulent receipt can be easily created or fabricated.
By creating written expense policies that specify what can be claimed for the business, the cost limits, expenses that must be itemized, approval levels and time limits for expenses to be submitted, businesses can lower the risk of expense reimbursement fraud. Claims for expenses should be considered by a person other than the employee who made the expense and for larger amounts of money or for unusual expenses, a further authorization should be necessary. Expense management software can detect duplicate expense receipts, unusual transactions, repeat vendors, and amounts that are over budgeted and beyond certain limits. Corporate cards with merchant restrictions and transaction monitoring can also help minimize the amount of personal outlay required by employees for large transactions and the hassle of chasing them back to the company for reimbursement. Managers should be mindful of trends and not sign claims off as if by rote. Regular audits can review costs and travel plans, meeting minutes, project activity and other documentation. The appearance that claims are being reviewed for consistency and any irregularities are that much smaller.

4. Financial Statement Fraud
Financial statement fraud is the deliberate attempt to alter a company’s financial statements and/or financial reporting to make it look more profitable, stable, or valuable than it actually is. The difference between accounting errors and financial statement fraud is one of intent – financial statement fraud is intentional. Management can over report revenue, record sales before they are earned, hide liabilities, over inflate assets, manipulate estimates, delay the recognition of expenses, and otherwise manipulate financial information. It could be to achieve financial goals, get financing, please investors, boost salaries for executives, adhere to loan agreements or make the company look better for a buyout. Red flags can involve, for instance, revenue problems around the end of a reporting period, transactions that do not have commercial substance, changes in accounting estimates that are not explained, significant differences between cash flow and reported profit, pressure on accounting staff to generate certain results and/or last-minute journal entries. This is particularly difficult to detect with typical transactional controls as senior management may be part of the fraud.
It’s not enough to rely on accounting staff to prevent financial statement fraud – it requires financial reporting governance and financial reporting controls. All critical journal entries (CJEs) should be accompanied by proper authorization and supporting documentation, as well as entries close to the end of the period. Account reconciliations should be done regularly and independently reviewed and unusual increases or decreases in revenue, expense, receivables, liabilities and other accounts should be investigated. Organizations should have well-defined accounting policies and have the complex estimates appropriately reviewed technically. There may be further scrutiny through independent internal audit functions, audit committees, external audits and board level oversight. Employers should also foster a culture where employees voice suspicions without persecution or fear of consequences, as they may be the first to notice something is amiss when handling transactions. Most significantly, organizational culture is important: If leadership only cares about profits and allows employees to manipulate profits, even the best controls can be circumvented by management override.
6. Procurement and Vendor Fraud.
Procurement fraud is when an employee or other insider alters the purchasing process to his or her own, or someone else’s, advantage. Schemes may consist of forming fake vendors, receiving kickbacks, directing the contract to a friend or family company, overvaluing procurement prices, ordering unneeded goods, or authorizing payments for goods and/or services which are never delivered. One of the more significant risks is when an employee can establish vendors, make purchases, accept items and make payments. This focus of power puts one individual at the centre of the procurement process, putting them under too much pressure. Some of the red flags that might indicate this include the sharing of addresses or bank details with employees, employees purchasing the same product over and over from the same supplier but at a higher price, repeated purchases just below the product’s approval level, contracts always being awarded to a single supplier without valid justification, or especially the procurement of products in a rush without any competitive bidding. Vendor information should thus be considered financial master data subject to the same protection as other important accounting data.
Internal controls can be used to deter procurement fraud by having distinct duties for creating the vendor, ordering, receiving and paying for it. New vendors must be verified prior to being placed on the approved supplier list and changes to vendor’s bank information must be confirmed by third parties. Significant purchases should be made through competitive bidding process and exceptions should be documented and approved by authorized personnel. The purchase order, receiving report and supplier invoice can be compared in a three-way matching process prior to the release of payment. Automated systems are also able to detect duplicate invoices, unusual prices, duplicate bank accounts and transactions that are above certain thresholds. Procurement staff should report any conflicts of interest and management should audit relationships with vendors that are likely to present conflict of interest. The performance of the suppliers and the pricing should be also monitored on a regular basis. These controls provide numerous “brakes” preventing the employee from easily arranging a fraudulent invoice, confirming receipt of nonexistent goods and causing the organization to pay the invoice without another employee or system noticing the discrepancy.
6. Accounts Payable & Payment Fraud
Accounts payable fraud is when fake or bogus payments are added to an organization’s payment system. Accounts payable fraud doesn’t necessarily involve the procurement relationship, as is frequently the case with procurement fraud. They could issue fake invoices, provide for the same invoice several times, change payment details, pay for personal expenses using company credit cards, or pay and the fraudster could have an account that they had opened with the company. When businesses deal with thousands of transactions per month, it can be hard to notice that there are duplicate invoices. Red flags are duplicate invoice numbers; repeated invoice amounts; payments to unfamiliar vendors; no purchase orders on the invoice; sudden change in the banking information for the vendors; transaction timing that is unusual; and transactions that are very near the approval limit. With one employee having too much access to accounting software and online banking platforms, payment fraud can also happen where payment preparation is not separated from the process of payment approval.
A good accounts payables system must ensure that supporting documentation is present before the invoice is paid, and that the authorizing of the bank, the actual preparation for payment, the invoice authorization and the invoice entry are separated. Automated systems can cross reference invoice numbers, amounts, supplier names, and dates to detect any potential duplicate invoices. All payment files should be checked and authorized prior to any transfer and bank statements should be reconciled separately from the accounting files. Payment details never be changed without proper verification with trusted contact information and not just those provided in an email asking for the change. Organizations should also limit access to payment systems based on their job function, and review logs of the system for unusual activity. Periodic supplier statement reconciliation may be able to identify the following: Invoices that have been included in the company’s records but have not been included in the supplier’s records; and/or payments that may have been diverted. These controls, when used in conjunction, will minimize the risk of financial losses from receiving unauthorized invoices or changed payment instructions.
7. Consumer Fraud (Issues and Scams)
Cash and banking fraud relates to transactions that are not authorized by the organization and the use of cash, banking or electronic funds. The category poses a high risk as cash is easily moved and once it has been paid out it may be hard to retrieve. A staff member or another party can make unauthorized transfers, alter checks, steal customer checks, break the security of online banking or use vulnerability in your online banking to steal petty cash. The following are listed as “red flags”: Unusual or unexplained banking transactions, transactions to or from individuals who are not “usual” for the business, transactions outside the normal business hours, frequent cash account adjustments, missing deposit documents, discrepancies between bank and business records. Businesses with a high manual banking volume and/or where multiple employees have access to an account may be more vulnerable as it can be hard to trace the origin or approval of a transaction. Therefore, banking access should be regarded as a high risk function that should be well authenticated, have limited access, independent review and ongoing monitoring.
Restricted access and separation of duties are the first steps to effective cash and banking controls. Only one person should be responsible for authorizing and disbursing a payment; this individual should not be the preparer of the payment. Individual logins, multi-factor authentication, transaction caps, and double checks on large transactions are all important features of an online banking platform that should be employed. Bank reconciliation should be done timely with employees who are not involved in cash operation and cash payment processes; items that are unusual should be investigated, and not just reconciled. There must be a maximum amount, written receipts and random checks of petty cash. Checks should be kept in a safe and secured place and should be accessed by only a few persons. Organizations can also set up alerts on their banking systems for transactions that exceed a certain amount, new beneficiaries, unusual transactions or anything else deemed risky. These controls establish separation between an employee’s access to accounting information and access to actual funds, making unauthorized transfers more difficult and the chance of suspicious activity being identified and caught early greater.
8. Inventory/Asset Theft
Theft of physical assets and inventory is the misappropriation of organization assets (such as items or equipment) by employees or others for their own or their own personal benefit. The threat can impact retailers, manufacturers, wholesalers, construction companies, healthcare providers, hotel and hospitality firms, and any other company that has physical products. Items can be taken from the store, while in transit, be declared as damaged, or simply be hidden by having poor stock records. It is also possible for equipment and supplies to disappear if the organization fails to have a reliable asset register and fails to physically inspect equipment and supplies. Unusual inventory shrinkage, frequent claims for damage, odd adjusting entries, inconsistencies between the system and physical inventory, missing equipment, and unusually high losses in specific departments/locations are examples of warning signs. One should explore any recurring discrepancies and not assume they are due to waste from normal business operations. If there are several small variations, it may be a continuing scheme which can be costly over time.
Inventory and physical asset internal controls should include accurate records, access limitations, physical security and independent checks. Organizations should keep full inventories and asset registers that record the number, location, serial number, department (if applicable), and acquisition date of each asset. Physical inventory counts should be made periodically and by employees not responsible for daily inventory. If there is any significant discrepancy between the physical count and the accounting record, be sure to investigate and record the discrepancy. Controlled access, with surveillance as appropriate, and documented procedures for receiving, transferring, returning and disposing of goods in the warehouse. A tag should be used to mark high value equipment and this should be checked regularly against the asset register. If the inventory is damaged or obsolete, it must be written-off and proof and authorization must be obtained. These controls ensure that adjustments to inventory and physical assets are being recorded and there’s a paper trail to support the adjustments, making it more difficult to hide the theft of inventory through unsupported write offs and/or unauthorized adjustments.
9. Bribery, Kickbacks, and Conflicts of Interest
Bribery and kickback schemes are when someone is given something of value in return for an improper influence over a business decision. The benefit can be a cash award, gifts, commissions, entertainment, personal services, discounts or other benefits. For instance, a member of staff who is tasked with deciding on suppliers may take money from a supplier for giving them contracts at higher prices. The same conflicts of interest can happen when a company employee is involved in the decision-making process of a company they have a relationship of any kind with, without being aware of that. Indicators of vendor favoritism range from the use of unusually generous gifts to vendors to unusually favorable contracts, awarded repeatedly despite higher prices, to employees who do not like competitive bidding to vendors who enter into personal relationships without these relationships being disclosed when procurement decisions are made. These schemes can result in organizations paying too much for products and services and establishing a negative reputation and legal/regulatory liability.
The following are areas in which organizations can mitigate these risks: codes of conduct, conflict of interest policies, gift and entertainment policies, supplier due diligence, competitive procurement processes and employee training. All employees who have high-risk purchasing, contracting, sales or other relationships, or financial interests, should report these relationships and interests periodically. There needs to be clear parameters and approval processes for significant gifts/hosting and suspicious vendor relationships should be investigated. Decision on procurement should be based on objective criteria and major contracts should be subject to an independent review. It is also important to have whistleblower channels because the accounting records may not be sufficient to detect bribery and kickback arrangements. Staff should be able to report any allegation of misconduct without fear of reprisal. Educating within the context of the ethical standards, as well as implementing practical transaction controls, enables organisations to limit the opportunities for individuals to gain personal benefit from business relationships.
10. Cyber-Enabled Financial Fraud
Financial fraud is an emerging risk for organizations with the advent of cyber technology, as financial fraudsters can use technology to defraud payments, steal credentials, impersonate an executive, or gain unauthorized access to financial systems. One type of fraud where a criminal masquerades as an executive or supplier and asks an employee to pay or alter banking details is business email compromise. Other schemes might include stolen passwords, malware, and unauthorized access to the accounting platforms or changing the electronic records. Red flags involve urgent requests to pay without prior authorization, asking to skip typical review steps, changes in bank account information, login activity that doesn’t seem to match, access to financial systems by unknown devices and emails that are pressuring or rush decisions without verification. The risk is heightened if workers think that any message that looks like it has come from a senior management or a trusted supplier will be legitimate. While technology will enhance controls, organizations need to implement technology along with human verification controls.
Financial systems should be secured by implementing multi-factor authentication, access controls based on roles, policy of strong password use, security monitoring, software patching, user permissions review, and employee awareness training. Most importantly, payment instructions and supplier banking information changes should be independently verified via a trusted communication method. It’s not enough for an employee to just click through the same e-mail message that the customer sent to request a payment change; the account could be compromised. High value transfers should have two signatures and sensitive financial systems should have a log kept to enable any unusual activity to be investigated. Access to be withdrawn immediately when staff members leave or change jobs, and privileged accounts to be enhanced monitored. Frequent phishing exercises, and security training, can also help employees identify suspicious requests. These safeguards provide a man-made and technological divide between the two kinds of instructions, fraudulent and legitimate, and actual movement of organizational money.
Ways Business Leaders can Strengthen Anti-Fraud Controls
Fraud prevention is not done with a single accounting procedure or with the installation of a complex system of software. Business leaders should establish a control framework in which duties are clearly defined, business transactions are kept well recorded, unusual transactions are investigated, and employees are made aware that any financial irregularities will not be ignored. The first principle is segregation of duties; in as much as possible no one to be responsible for Authorization, Custody, Recording and Reconciliation for the same transaction. The second is authorization, that is, all important transactions should be approved by those with appropriate responsibility and authority. The third is independent verification, which involves periodic checks on records and activities by a person not responsible for their production. It’s also essential for businesses to have proper access controls, routinely reconcile accounts, audit exception reports, audit internal systems, and have confidential reporting systems in place. These controls should be in scale with the size of the organization and their risk profile and not simply be an exact replica of a different organization.
Management should also keep in mind that one of the dangers of internal controls is becoming complacent because the employees become used to circumventing them. If managers tend to approve transactions without checking supporting documentation, then a policy with three approvals is of little use. Likewise, if employees share passwords or if the controls can be easily bypassed by senior executives, without an audit trail, segregation of duties fails. The importance of the design of the control system is not different from that of the regular monitoring of it. The leaders should determine the organization’s most important processes, most important assets, and what parts of the organization are most susceptible to fraud, and determine if the existing controls are effective in practice. Data analytics can be used to flag unusual data trends across payroll, expenses, purchases, revenue and payments and surprise audits can serve as a further deterrent. Training should also be continuous as the risks of fraud evolve alongside of new technologies, payment methods, suppliers, and business models. A good control environment is dynamic, growing with the organization.
Conclusion
The effects of financial fraud can be much worse than the amount of money stolen. The resulting fraudulent transaction could result in financial reporting errors, tax issues, regulatory fines, strained relationships with suppliers, employee distrust, damage to reputation and costly investigations. The best solution is to not wait until fraud is discovered but, rather, to build business processes that will make it harder for a fraudster to execute and harder for them to get away with. Physical controls, reconciliations and the separation of duties can help mitigate asset misappropriation, independent verification of employees can help mitigate payroll fraud, documentation and analytical reviews can help mitigate expense reimbursement fraud, and proper financial reporting controls, independent oversight and an ethical culture within a company can mitigate financial statement fraud. Similar protection is needed for procurement, payments, banking, stock and bribery and cyber-enabled fraud.
In the end, internal controls are best when they’re not seen as a task that accounting staff have to endure but rather a piece of business management that helps the company run more smoothly. Business leaders should periodically question where the money, assets, information and the decision-making power is located, and if one person could corrupt a process without it being known. They should look for strange transactions, investigate control exceptions, revise access privileges, and promote the reporting of concerns by employees. While a control framework has no assurance that fraud will never occur, especially where individuals collude, or where management skips or circumvents the procedures, the framework can significantly increase the difficulty of committing the fraud and speed up the time from the fraud to its discovery. Organizations can safeguard their financial resources and foster a culture of responsible financial management, transparency, and accountability by recognizing the most frequent fraud schemes and relating them to the preventive or detective controls that can address each vulnerability.
Get more well researched information about types of financial fraud here.


