Collusion in Accounting: Schemes, Red Flags, and Forensic Detection

Detecting collusion in accounting takes more than a clean audit, because collusion is built specifically to defeat the controls and audits that catch lone bad actors. Two or more people coordinating a scheme can divide the work so every checkpoint gets a green light: one person creates a fake vendor, another approves the invoice, a third processes the payment, and each piece looks normal in isolation. Catching it depends on layering financial analysis, behavioral awareness, forensic analytics, and a working tip channel. The Association of Certified Fraud Examiners has found that tips uncover roughly 43% of occupational fraud cases, more than any other method.

Why Collusion Slips Past Ordinary Controls

A single employee who pockets cash or inflates an expense report leaves a trail. The transaction doesn’t reconcile, a supervisor notices, and the scheme unravels. Collusion works differently. When the person responsible for checking is in on the scheme, the control still fires, the sign-off still happens, and the paperwork still matches. The failure is invisible from the outside.

Participants can be entirely internal, entirely external, or a mix. The most dangerous internal combination is a senior executive directing the scheme with accounting staff executing the entries. External parties often include vendors submitting fictitious invoices or customers signing side agreements that alter the real terms of a sale. When independent auditors are compromised, detection becomes extraordinarily difficult, because the people hired to find the fraud are helping conceal it.

The Schemes You’re Looking For

Revenue Manipulation

Revenue fraud tends to cause the largest investor losses. Channel stuffing pressures distributors to buy far more product than they can sell, often with secret side agreements granting generous return rights. Accounting books the shipments as revenue immediately, knowing much of it will come back. Revenue gets borrowed from future quarters to inflate the current one.

Fictitious sales go further. Sales creates fake customer accounts or shell entities, the warehouse signs off on shipments that never leave the dock, and accounting records the revenue. Every document looks legitimate because each person built their piece to match the others. These schemes often collapse when the fake receivables age and nobody can explain why the “customers” never pay.

Inventory Inflation

Inventory schemes require warehouse personnel and finance staff working together. Warehouse employees falsify count tags or log nonexistent items into the inventory system. The inflated count flows to the balance sheet, overstating assets, and simultaneously understates cost of goods sold, making profits look higher than they are. Inventory is inherently hard to verify from the outside, especially for companies with goods across multiple locations.

Expense Concealment

Hiding expenses is the mirror image of inflating revenue. One of the most common methods is misclassifying routine operating costs as long-term assets. When a company treats ordinary repair work as a capital improvement, the cost doesn’t hit the income statement right away. It gets spread over years through depreciation, and current-period profits jump. Facilities staff mischaracterize the work and accounting books it to the wrong accounts. Textbook collusion.

Financial Red Flags

The numbers almost always tell on the fraudsters eventually, even when the paperwork looks clean. Knowing which numbers to watch matters more than watching everything.

Days sales outstanding (DSO) is one of the most reliable early indicators. DSO measures how long it takes a company to collect payment after making a sale. When DSO climbs steadily with no change in credit policies or customer base, the company may be booking revenue that isn’t converting to cash. That pattern fits both channel stuffing and fictitious sales. A declining inventory turnover ratio tells a similar story on the balance sheet side, pointing to inventory that may not actually exist or that has become unsellable.

The most revealing comparison is between reported net income and cash flow from operations. Accrual-based income is relatively easy to manipulate through journal entries, timing games, and classification tricks. Cash flow tracks actual money moving in and out and is much harder to fake. When a company reports strong earnings quarter after quarter but operating cash flow lags well behind, something is propping up those earnings artificially. That gap should trigger a deeper investigation.

Related-party transactions deserve special attention whenever they appear. A company routing revenue through entities controlled by insiders, or buying services from vendors with undisclosed connections to management, creates the perfect cover for collusion. These transactions aren’t inherently fraudulent, but when they lack a clear business purpose or carry unusual terms, they warrant serious scrutiny.

Control and Behavioral Red Flags

Collusion turns controls into theater. The controls appear to function, but the people operating them have agreed to let specific transactions pass unchallenged. Recognizing that pattern means looking at how controls actually operate, not how they read on paper.

Management override is the single most dangerous control failure. When a senior executive can bypass normal approval for vendor payments, journal entries, or contract terms, the control environment becomes decorative. A three-way match between purchase order, receiving report, and invoice is meaningless if a vice president can authorize payment without it. Test whether management has used override authority and examine what went through that channel.

Poor separation of duties creates the conditions for collusion even when nobody originally intends fraud. When one person can authorize a purchase, confirm receipt, and approve payment, the temptation to exploit that access grows. In a collusive scheme, poor separation also means fewer people need to be recruited. Overly centralized decision-making, where a small group controls all significant accounting judgments, has the same effect.

High volumes of manually created journal entries posted outside business hours or at period-end deserve close examination. The PCAOB has flagged several attributes as suspicious: entries to accounts rarely used in normal operations, entries made by people who don’t normally post journal entries, entries with round-number amounts, and post-closing entries with little or no description.1Public Company Accounting Oversight Board. Audit Focus: Journal Entries A cluster of entries matching those descriptions is a strong signal that someone is manipulating the financial statements.

Behavior fills in what the data can’t. Intense pressure from executives to hit specific earnings targets is the most common precondition for collusive fraud. When bonuses, promotions, or continued employment ride on hitting a number, accounting staff start rationalizing entries they know are wrong. Unusual turnover in finance and internal audit roles is another telling pattern. Employees who see something and lack a channel to report it often just leave. Cycling through controllers or internal auditors faster than normal can reflect people unwilling to participate in what they’re seeing.

The inverse is equally concerning. A long-tenured employee who refuses to take vacation, delegates nothing, and guards their processes obsessively may be protecting a scheme that would unravel in their absence. Fraud researchers have identified capability as the factor distinguishing who actually commits fraud from who merely has opportunity. Successful collusion requires someone with enough technical knowledge to identify control weaknesses, enough authority to recruit or coerce others, and enough composure to consistently mislead auditors and board members. When those traits sit in a single person who also controls key financial processes, the risk profile changes.

Forensic Techniques That Go Beyond a Normal Audit

Journal Entry Testing at Population Scale

Forensic accountants don’t just review journal entries for proper authorization. They analyze the full population looking for statistical patterns human reviewers would miss. The PCAOB attributes above can be filtered and flagged across millions of transactions.1Public Company Accounting Oversight Board. Audit Focus: Journal Entries The power is in the aggregation. One round-number entry to an unusual account means nothing. Two hundred of them, posted in the final week of the quarter by the same user, is a pattern worth investigating.

Benford’s Law Analysis

Benford’s Law predicts the expected frequency of leading digits in naturally occurring numerical datasets. In any large set of real financial transactions, the digit 1 appears as the first digit about 30% of the time, while 9 appears only about 5% of the time. When humans fabricate numbers, they tend to distribute digits more evenly or cluster around psychologically comfortable amounts, and those deviations are statistically detectable.

Forensic accountants apply Benford’s Law to journal entry populations, general ledger balances, and expense reports. The analysis works best with datasets of at least 5,000 records. Significant deviation from the expected distribution signals that some entries may be fabricated or manipulated. The technique doesn’t prove fraud by itself, but it efficiently identifies which accounts or transaction types warrant deeper investigation. Round-number spikes often correlate with manually created entries designed to hit specific targets.

Data Analytics and Network Analysis

Modern fraud detection increasingly relies on analytics that process entire transaction populations rather than samples. Clustering groups similar transactions and surfaces outliers that don’t fit normal business patterns. Continuous monitoring systems flag anomalies in real time rather than waiting for a quarterly audit cycle.

Network analysis is particularly valuable against collusion because it maps relationships between people, vendors, accounts, and transactions. When the same vendor address appears across multiple supposedly independent suppliers, or the same bank account receives payments from several entities within the company, network analysis surfaces those connections. Those relationship patterns are almost impossible to detect through line-by-line auditing but become obvious when visualized as a network graph.

Why the Annual Audit Won’t Catch It On Its Own

An external audit is not designed to guarantee detection of every material fraud, and professional auditing standards say so directly. Collusion is the main reason. Fraud involves deliberate concealment, and collusion allows multiple people to fabricate corroborating evidence that appears genuine.

An auditor’s ability to detect fraud depends on the skill of the perpetrators, how frequently they manipulate records, how many people are involved, and how senior those people are. When senior management orchestrates the scheme, they can direct which documents the auditor sees, control which employees the auditor interviews, and override the very controls the auditor is testing. That is a structural limitation, not a failure of standards, and it makes whistleblower channels and forensic analytics essential supplements rather than optional add-ons.

Tips: The Highest-Yield Detection Channel

Because audits have inherent limits against collusion, insider tips remain the most effective detection method. If you build one thing beyond financial monitoring, build a reporting channel people will actually use, and protect the people who use it.

At public companies, federal law provides two overlapping layers of protection and incentive. Under Section 21F of the Securities Exchange Act, anyone who voluntarily provides the SEC with original information leading to a successful enforcement action can receive a monetary award between 10% and 30% of the total sanctions collected, as long as those sanctions exceed $1 million.2Office of the Law Revision Counsel. 15 U.S. Code 78u-6 – Securities Whistleblower Incentives and Protection Awards come from collected sanctions, not taxpayer funds.3U.S. Securities and Exchange Commission. Annual Report to Congress: SEC Whistleblower Program The program also prohibits retaliation through termination, demotion, suspension, or harassment, and a whistleblower who experiences retaliation can sue in federal court within six years to recover reinstatement, double back pay, and attorney fees.

Separately, SOX Section 806 protects employees of public companies who report conduct they reasonably believe violates federal fraud statutes or SEC rules. Protection covers disclosures made internally to a supervisor, externally to a federal agency, or to Congress. A SOX retaliation complaint must be filed with OSHA within 180 days of the retaliatory act or the date the employee became aware of it. Successful claimants are entitled to reinstatement, back pay with interest, and compensation for special damages including litigation costs and attorney fees.4Office of the Law Revision Counsel. 18 U.S. Code 1514A – Civil Action to Protect Against Retaliation in Fraud Cases That 180-day window is tight. Missing it can forfeit the claim.

The SEC accepts tips through its online submission system, which generates a confirmation number for your records.5U.S. Securities and Exchange Commission. Report Suspected Securities Fraud or Wrongdoing To qualify for an award, the information must be original, meaning not already known to the SEC from another source. Preserve copies of any documents supporting your concerns before filing, but don’t remove proprietary records in ways that violate your employment agreement. An attorney experienced in whistleblower cases can help navigate that line.

One boundary worth naming: the SEC whistleblower program and SOX Section 806 apply to public companies and securities violations. Private-company accounting fraud may still expose participants to criminal and civil liability under other statutes, but the specific award program and the SOX anti-retaliation cause of action are not the vehicle for reporting it.