Asset misappropriation fraud — employees or insiders stealing or misusing an organization’s resources — accounts for roughly 89% of occupational fraud cases, with a median loss of $120,000 per incident.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations The warning signs are specific and observable, and the prevention playbook is well established: segregate financial duties, reconcile independently, run a confidential tip line, and monitor transactions with basic analytics. Organizations that do these things lose far less money to fraud than those that trust their people and hope for the best.
The Schemes You’re Defending Against
You can’t spot what you don’t recognize. Asset misappropriation falls into a small number of recurring patterns.
Skimming is theft of incoming payments before they hit the books. A customer pays, no receipt is issued, and the transaction never exists on paper. Cash larceny is the same theft after the payment has been recorded, which is why routine reconciliation catches it faster.
Billing schemes cause the company to pay invoices it shouldn’t — typically through a shell vendor set up by an employee who can both approve purchases and process payments. Median loss: $100,000. Check and payment tampering — forged signatures, altered payees, intercepted payments — runs higher at $155,000.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations
Expense reimbursement fraud and payroll fraud (ghost employees, inflated hours) each carry lower per-incident losses around $50,000, but they show up in roughly 13% and 10% of cases respectively.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations
Non-cash theft covers inventory, equipment, and — the one that should worry leadership most — intellectual property. Customer lists, formulas, and product designs can be copied to a thumb drive in minutes, and the loss may not surface for months.
Business email compromise sits at the edge of the category. An attacker impersonates an executive or vendor and tricks an employee into wiring funds. It exploits the same weaknesses as internal billing schemes: weak payment verification, email-only authorization, no callback procedure when banking details change.
Behavioral Warning Signs
Red flags don’t prove fraud. They tell you where to look.
The most persistent signal is an employee whose visible lifestyle exceeds their salary — new cars, luxury travel, expensive purchases — with no obvious outside explanation. Employees who refuse to share duties, resist cross-training, or never take vacation are also worth close attention. That’s the practical case for a mandatory vacation policy: it forces someone else to handle the work temporarily, which is often when irregularities surface.
Unusually close relationships with specific vendors or customers can signal a kickback arrangement. Financial pressure — debt problems, addiction, an expensive divorce — doesn’t make anyone a criminal, but it creates one of the three conditions fraud researchers consistently identify alongside opportunity and rationalization.
Accounting and Documentary Signals
Inventory shortages that survive reconciliation against normal shrinkage are the clearest signal of non-cash theft.
On the cash side, watch for a high volume of voided transactions or credit memos concentrated under a single employee’s login. Missing original documentation is another persistent sign: photocopied invoices, receipts without sequential numbering, purchase orders without proper authorization. A pattern of small, round-dollar expense claims sitting just below the approval threshold is a classic expense fraud signature.
Late-period journal entries posting directly to expense accounts and bypassing normal purchasing workflows are frequently tied to billing schemes. Investigate any vendor with only a P.O. Box address, no web presence, or banking details that match an employee’s information.
Internal Controls That Actually Prevent Fraud
The single most cited factor enabling fraud is a lack of internal controls, present in 32% of cases studied. Another 19% of cases involved someone overriding controls that already existed.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations That second number matters. Controls that leadership ignores in practice are worse than no controls, because they create a false sense of security.
Segregation of Duties
No single person should control an entire transaction. Three functions belong to three different people: authorization (who approves), recording (who books it), and custody (who touches the asset). Whoever approves a purchase should not process the payment, and neither should reconcile the resulting account.
For cash, the person who opens the mail and logs incoming payments should not be the person who makes the bank deposit, and a third person should reconcile the bank statement. When one person handles all three steps, they can steal and erase the evidence.
Physical and Access Controls
Store high-value or easily resold inventory in secured areas with restricted access and sign-in/sign-out logs. Cash collection points need locked drawers and surprise counts. Blank check stock stays under lock with a short list of authorized personnel.
On the IT side, user permissions should mirror the segregation framework. If someone doesn’t need access to the vendor master file, they shouldn’t have it. Financial systems should enforce multi-factor authentication, and system logs should be monitored for after-hours access, unusually large data exports, and repeated failed logins. Automated payment limits — capping the dollar amount a single user can approve — shrink the exposure from any one disbursement scheme.
Reconciliation and Independent Review
Bank reconciliations should happen monthly, performed by someone not involved in receipts or disbursements. Surprise cash and inventory counts should happen at random intervals; scheduled audits are easy to game. Every balance sheet account should be reconciled monthly, and unexplained variances should trigger a follow-up review, never a quiet write-off.
Periodic reviews of the vendor master file are one of the most underused controls available. Scan for duplicate addresses, vendors sharing banking information with employees, and recently added vendors with no purchase history. These reviews surface billing schemes before they entrench.
Tone at the Top
None of this works if leadership treats controls as optional. When executives bypass approval workflows or tolerate sloppy recordkeeping, employees notice, and some will exploit the gap. A written anti-fraud policy needs to be communicated to every employee and enforced consistently regardless of the offender’s rank. This part cannot be delegated to the accounting department.
A Tip Line Detects More Fraud Than Anything Else
Tips are responsible for detecting 43% of all occupational fraud, more than internal audits, management review, or any other detection method.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations That makes a confidential reporting channel the highest-yield tool available.
A whistleblower hotline, whether run internally or through a third party, needs to be genuinely anonymous, easy to use, and actively promoted. Employees who fear retaliation won’t call. Employees who don’t know the line exists can’t call.
For publicly traded companies, federal law adds a retaliation shield. Under the Sarbanes-Oxley Act, employees who report conduct they reasonably believe violates federal fraud statutes are protected against being fired, demoted, suspended, or harassed for reporting.2Office of the Law Revision Counsel. 18 USC 1514A – Civil Action to Protect Against Retaliation in Fraud Cases The complaint must be filed within 180 days of the employee learning of the retaliation. This specific protection applies to public companies; private employers should still expect state whistleblower protections and common-law retaliation claims, and should not rely on the absence of SOX coverage as license to punish reporters.
Data Analytics Cuts Losses Roughly in Half
Organizations that use proactive data analytics to monitor transactions experience fraud losses roughly 50% lower than those that don’t.3Association of Certified Fraud Examiners. Anti-Fraud Data Analytics Tests The idea is simple: instead of relying on manual review to spot anomalies, software continuously scans transactions for patterns associated with fraud.
Useful tests include flagging duplicate invoice numbers or amounts, matching vendor addresses and bank accounts against employee records, highlighting payments just below approval thresholds, and detecting unusual spikes in expense reimbursements or overtime. None require sophisticated AI. Most accounting packages and even spreadsheet tools can run them. The barrier isn’t technology. It’s committing to run the tests regularly and act on the results.
Compensating Controls for Small Businesses
Small organizations face a brutal mismatch. Median fraud loss for companies with fewer than 100 employees is $141,000, yet these organizations rarely have enough staff to segregate financial duties the way the framework calls for.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations When one person handles bookkeeping, deposits, and reconciliation, the classic framework collapses.
Compensating controls fill the gap:
- The owner or a trusted senior manager personally reviews bank statements, canceled checks, and credit card statements every month. This takes about 30 minutes and catches most schemes that rely on nobody looking at the details.
- Payments above a set dollar threshold require two approvals. The second approver can be a co-owner, board member, or outside accountant rather than another employee.
- An external bookkeeper or CPA performs the bank reconciliations, adding an independent set of eyes that an internal fraudster can’t easily manipulate.
- Expense management software enforces spending limits, invoice-matching tools verify purchases before payment, and payroll software flags unusual entries.
None of these match full segregation of duties. A small business that runs all of them together is still far better protected than one that runs none because “we trust our people.” Trust is not a control.
The Annual Audit Won’t Catch It
Many organizations assume the annual financial statement audit will find asset misappropriation. It usually won’t. An external auditor’s job is to obtain reasonable assurance that financial statements are free of material misstatement, not to find every instance of fraud.4Public Company Accounting Oversight Board. AS 2401: Consideration of Fraud in a Financial Statement Audit
Materiality is the key. An employee stealing $5,000 a month from a company with $50 million in revenue is almost certainly immaterial to the financial statements, and the auditor is not designing procedures to find it. The standard is explicit that preventing and detecting fraud is management’s responsibility, not the auditor’s.4Public Company Accounting Oversight Board. AS 2401: Consideration of Fraud in a Financial Statement Audit
If You Discover Fraud
The first 48 hours determine whether you preserve a viable case or destroy it. Coordinate every step with legal counsel.
Before the suspect knows anything is happening, secure the documentation. Create forensic copies of hard drives, preserve email archives, and physically gather original invoices, purchase orders, and bank records. Digital evidence degrades quickly. Files get deleted, emails purged, and system logs overwritten.
Revoke the suspect’s access to financial software, email, remote network access, and physical building access. Place the employee on administrative leave, framed as non-disciplinary so you don’t prejudge the outcome. Notify internal legal counsel, the audit committee if one exists, and the CFO. Keep the circle small.
Engaging an outside forensic accountant is worth the cost. They quantify the total loss, trace the flow of stolen funds, identify all participants, and produce documentation that will hold up in court or in front of a regulator.
One legal risk worth knowing about during the investigation: defamation. Accusing an employee of theft, particularly in front of coworkers or in writing, can expose the organization to a lawsuit if the accusation is wrong or made with malice. A qualified privilege generally protects good-faith statements made during a legitimate workplace investigation among people with a need to know. That privilege evaporates if the accusation is broadcast beyond that circle or made with ill will. Keep the details confidential and the audience narrow.