Fraud Scale: Triangle, Diamond, and Pentagon Models Compared

The fraud triangle, diamond, and pentagon are three related models that explain why people commit occupational fraud, each one building on the last. The triangle, developed by criminologist Donald Cressey, identifies three conditions that must converge before a trusted employee crosses the line: pressure, opportunity, and rationalization. The diamond adds a fourth element, capability, to explain why some people can actually pull off what others only contemplate. The pentagon adds a fifth, arrogance, aimed at the mindset behind large executive-level schemes. Together they move from a simple model of motive to a fuller picture of who commits fraud and why they think they can get away with it.

The Fraud Triangle

Cressey built the original framework from interviews with 133 convicted embezzlers in federal prisons in the late 1940s, and published his findings in 1953 in Other People’s Money: A Study in the Social Psychology of Embezzlement. His conclusion was that trusted employees become trust violators when three conditions exist at the same time.1University of Portsmouth Research Portal. Deconstructing the Origins of Cressey’s Fraud Triangle Remove any one of them, and the theory holds that fraud becomes far less likely.2AGA. The Fraud Triangle

Cressey himself never used the phrase “fraud triangle” in his published work. The visual came later, but his name is now inseparable from it, and the framework has been referenced in more than 8,500 academic papers and professional training programs.1University of Portsmouth Research Portal. Deconstructing the Origins of Cressey’s Fraud Triangle

Pressure

Cressey called this a “non-shareable financial problem.” The perpetrator faces a financial crisis they believe they cannot tell anyone about. Common triggers include medical debt, gambling losses, substance abuse, or the need to maintain a lifestyle beyond legitimate income. The problem feels non-shareable because disclosing it would mean losing status, a relationship, or a job. The key word is perceived. Outsiders might see obvious solutions, but the person under pressure has convinced themselves that no legitimate option exists.

Opportunity

The second element is the perpetrator’s belief that they can commit fraud without being caught. This perception almost always stems from weaknesses in internal controls: missing management reviews, no independent reconciliation, or a failure to separate incompatible duties. When one person controls both the recording and custody of assets, they can misappropriate funds and cover their tracks in the same workflow.3University of Pennsylvania Office of Audit, Compliance and Privacy. Operational Internal Controls – Section: Segregation of Duties

The opportunity doesn’t need to be real. It needs to feel real to the person considering fraud. A manager who knows they’re the only one reviewing a particular expense account perceives an opening, even if an audit would eventually catch the discrepancy.

Rationalization

The third element is the internal story the perpetrator tells themselves to justify crossing the line. This psychological bridge lets someone who considers themselves honest commit a dishonest act. The most common rationalizations: telling themselves they’re just “borrowing” the money and will pay it back, believing they deserve the compensation because they’re underpaid, or blaming the organization for treating them poorly enough to justify it.

Rationalization is the hardest element for an organization to detect because it happens entirely inside someone’s head. It’s also the element most likely to collapse on its own, as guilt or cognitive dissonance eventually catches up with many perpetrators.

The Fraud Diamond

The triangle explains the conditions that motivate fraud, but it doesn’t account for why some people pull it off while others don’t. In 2004, David Wolfe and Dana Hermanson proposed the fraud diamond, adding a fourth element: capability.4The CPA Journal. The Fraud Diamond – Considering the Four Elements of Fraud

Capability refers to the personal traits and abilities that determine whether someone can actually execute a scheme. Even when pressure, opportunity, and rationalization are all present, not everyone has the skills to exploit the situation. The diamond shifts the analysis from why someone would commit fraud to who is equipped to carry it out.

What Capability Involves

Capability isn’t just technical knowledge. It combines several traits:

  • Position and function that grant access to assets, systems, or financial reporting processes.
  • Intelligence to understand the financial systems well enough to identify and exploit control weaknesses.
  • Confidence and ego, a belief in one’s ability to succeed without detection.
  • Coercion skills, the ability to pressure or manipulate others into participating or staying silent.
  • Effective lying, meaning a consistent false narrative that holds up under scrutiny.
  • Stress tolerance to handle the ongoing anxiety of concealment without visible behavioral changes.
5The CPA Journal. The Fraud Diamond

This distinction matters for risk assessment. The employee who skims $50 from a cash register operates on pure opportunity. The executive who manipulates revenue recognition across multiple quarters for years has all three triangle elements plus the capability to build and sustain a sophisticated concealment strategy. Designing controls only around opportunity misses the reality that high-capability individuals can often override them.

The Fraud Pentagon

The pentagon, developed by Jonathan Marks of Crowe Horwath (now Crowe LLP), is the most recent evolution. It keeps all three triangle elements, absorbs the diamond’s capability concept under the label “competence,” and adds a fifth element: arrogance.6International Journal of Management, Accounting and Economics. Testing the Crowes Pentagon Theory of Fraud on Financial Statement Fraud The five elements are pressure, opportunity, rationalization, competence, and arrogance.

Arrogance as the Fifth Element

Marks defines arrogance as “an attitude of superiority and entitlement or greed on the part of a person who believes that internal controls simply do not personally apply.” This isn’t ordinary overconfidence. It’s the mindset of executives who view the organization’s assets as extensions of their own wealth and its rules as obstacles designed for lesser employees.7Association of Certified Fraud Examiners. The Mind Behind The Fraudsters Crime – Key Behavioral and Environmental Elements

The arrogant perpetrator often doesn’t need much rationalization. Where a mid-level employee might wrestle with guilt and construct elaborate justifications, the arrogant executive simply doesn’t believe the rules apply. That makes the pentagon particularly useful for analyzing financial statement fraud at the C-suite level, where schemes tend to be both larger and more brazen than asset misappropriation by lower-level employees.

How Arrogance Differs From Capability

The practical difference is psychological. The diamond’s capability element asks whether someone can commit a sophisticated fraud. The pentagon’s arrogance element asks whether someone believes they’re above the controls entirely. A capable fraudster might still worry about being caught. An arrogant one doesn’t seriously entertain the possibility. That distinction helps explain why some corporate scandals grow so large before detection: the perpetrator at the top genuinely believed they were untouchable.

Comparing the Three Models

Each framework keeps the earlier model intact and adds one new dimension.

  • Triangle (Cressey, 1953): pressure, opportunity, rationalization. Explains motive and conditions.
  • Diamond (Wolfe and Hermanson, 2004): adds capability. Explains why some people can execute what others can’t.
  • Pentagon (Marks): retains the triangle, treats capability as competence, and adds arrogance. Explains high-level financial statement fraud where the perpetrator feels exempt from the rules.

The models don’t compete. A forensic accountant assessing a low-level asset misappropriation may find the triangle sufficient. Analyzing a multi-year financial reporting fraud by senior management usually calls for the pentagon.

Why These Frameworks Matter in Practice

Cressey’s framework isn’t just academic theory. It’s embedded in the professional standards governing financial audits. AU-C Section 240, which establishes auditor responsibilities for detecting material misstatement caused by fraud, is built directly on the triangle’s three elements. The standard defines fraud risk factors as “events or conditions that indicate an incentive or pressure to perpetrate fraud, provide an opportunity to commit fraud, or indicate attitudes or rationalizations to justify a fraudulent action.” Auditors are required to evaluate whether one or more of these risk factors exist throughout the engagement.

In practice, every financial statement audit in the United States involves a structured assessment of the triangle’s elements: management pressure to hit unrealistic earnings targets, internal controls that could be overridden by someone in a position of trust, and a leadership attitude toward ethics that creates room for rationalization.

Using the Models to Prevent Fraud

The real value of these frameworks is designing an environment where fewer people reach the point of committing fraud. Each element suggests a different prevention strategy.

To reduce opportunity, separate the authorization of transactions from their recording and from the custody of assets. No single employee should control more than one of these functions.3University of Pennsylvania Office of Audit, Compliance and Privacy. Operational Internal Controls – Section: Segregation of Duties Mandatory vacations, surprise audits, automated reconciliation, and rotation of personnel in sensitive roles all reinforce the same principle: any control a single person understands completely is one they can eventually circumvent.

To reduce pressure, employee assistance programs, open-door management, and fair compensation practices address the financial strain that starts the triangle spinning. To weaken rationalization, leadership must model ethical behavior and enforce rules uniformly rather than exempting senior executives, so employees can’t tell themselves that “everyone does it.”

For the higher-level risks captured by the diamond and pentagon, governance structures do the heavy lifting. Separating the CEO and board chair roles prevents one person from accumulating unchecked authority. Independent audit committees with direct access to external auditors create oversight that a single executive can’t easily bypass. Background checks and ongoing monitoring of employees in high-risk positions help identify situations where capability and arrogance combine into serious exposure.