To prevent embezzlement, build overlapping layers of defense so that no single employee can both steal money and hide the theft: separate financial duties across people, require two approvals on payments, run independent bank reconciliations, tighten vendor and payroll setup, restrict system access, run scheduled and surprise audits, and give employees a trusted anonymous channel to report suspicions. The Association of Certified Fraud Examiners estimates organizations lose about 5% of annual revenue to fraud, with a median single case costing $145,000 and small businesses seeing a median loss of $141,000.1Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations2Association of Certified Fraud Examiners. Occupational Fraud 2024: A Report to the Nations No single control stops theft on its own. The layers do.
Separate the People Who Handle Money
The single most effective structural defense is making sure no one person controls a financial transaction from beginning to end. Segregation of duties splits three functions across different people: who authorizes a transaction, who records it, and who has physical custody of the money or assets. When those roles overlap in one person, that person can steal and cover the evidence without anyone else touching the paperwork.3Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet
In practice, the employee who approves a purchase order should not be the same person who writes the check or records the transaction in the accounting system. The person who reconciles the bank statement should have no involvement in receiving or disbursing cash.
Small organizations sometimes argue they lack the headcount for this. Even a five-person office can rotate duties, cross-train employees, or have the owner independently review bank statements each month. The point is not perfection but friction: making it so committing fraud requires at least two people to cooperate.
Force People Out of Their Seats
Many embezzlement schemes require the perpetrator to be at their desk every day to keep the fraud concealed. A mandatory vacation policy of at least two consecutive weeks forces someone else to handle those duties, and that substitute often stumbles across the irregularity the original employee was hiding. The Federal Reserve Bank of New York has long recommended this practice for employees in sensitive banking positions, noting that most embezzlement schemes require the “continual presence of the wrongdoer.”4Federal Reserve Bank of New York. Required Absences from Sensitive Positions
The important detail: someone else must actually process the absent employee’s daily work during the absence. A vacation where the work piles up until they return accomplishes nothing.
Require Two Approvals and an Independent Reconciliation
Require two approvals for any expenditure above a defined threshold. That can mean two physical signatures on a check or two digital approvals in your accounting software. Set the threshold low enough that a meaningful theft would trigger the requirement, but not so low that most payments slip through unchecked.
Independent bank reconciliation is equally important. Someone with no role in receiving payments or making disbursements should compare the company’s books against the bank’s records each month. When the same person who handles cash also reconciles the bank statement, you have effectively asked the fox to audit the henhouse.
Lock Down Vendor Setup
Two schemes deserve their own controls because they exploit specific blind spots. The first is the fictitious vendor scheme, where an employee creates a fake company in the vendor master file, submits invoices from it, and routes the payments to a bank account they control. These schemes can run for years if nobody scrutinizes the vendor list.
The defense is a formal vendor onboarding process and regular audits of the vendor master file. Before adding any new vendor, verify the tax identification number, confirm the business name matches that ID, and check for a verifiable physical address and standard contact information.
Periodically review the entire vendor file for red flags:
- Vendors missing tax IDs
- Vendor addresses matching employee addresses
- Round-dollar invoices
- Multiple invoices paid to the same vendor on the same date
- Sudden unexplained changes to a vendor’s bank account information
Separating the person who adds vendors from the person who approves payments makes this scheme significantly harder to execute alone.
Lock Down Payroll
Ghost employee fraud works by adding a fictitious person to the payroll, or keeping a terminated employee on it, and diverting the paychecks. Warning signs include employees sharing the same bank account or home address, former employees still appearing on payroll, and rising payroll costs that do not correspond to new hires.
The most important control is separating the HR, payroll, and accounting functions so no single person can both add an employee to the system and authorize their paycheck. Regular payroll reconciliations, where someone outside the payroll department reviews the roster against HR records, catch discrepancies quickly. Some organizations also require verified identification for physical paycheck pickups, which makes it harder to collect a check for someone who does not exist.
Restrict System Access and Watch for Anomalies
Every user’s permissions should follow the principle of least privilege: grant only the minimum access someone needs to do their job, and nothing more. If an accounts payable clerk does not need the ability to modify vendor bank account details, revoke that access. If a bookkeeper does not need to approve journal entries, lock them out of that function.
Multi-factor authentication should be mandatory for every login to financial systems. A stolen password alone should never be enough to reach the accounting software. Monitor system access logs for unusual patterns, particularly after-hours logins, repeated access to restricted modules, and bulk data exports. Encrypt stored financial data and any data sent outside the internal network, and keep offsite encrypted backups.
Behavioral Anomaly Detection
Newer fraud detection tools use machine learning to build behavioral baselines for specific vendors, employees, and departments. Instead of relying on rigid rules like “flag every invoice over $50,000,” these systems learn what normal activity looks like and alert you when something deviates. The system might ignore a large invoice from a trusted supplier during business hours but flag a much smaller invoice from the same supplier if it is suddenly routed to an unfamiliar bank account or submitted at an unusual time.
These tools are effective at catching duplicate invoices, missing approvals, unusual journal entries, and vendor bank account changes that coincide with suspicious timing. Organizations using AI-based fraud monitoring report significant reductions in undetected duplicate payments and invoice fraud.
Audit on a Schedule and by Surprise
Controls only work if someone checks whether they are being followed. External audits by independent CPA firms validate financial statements and test whether internal controls are functioning. They rely on transaction sampling, so they are not designed to catch every instance of fraud, but they provide a credible deterrent and a periodic reality check.
Internal audits fill the gaps external audits leave. An internal audit function can conduct targeted deep-dive reviews of high-risk areas continuously rather than once a year. Both types of audits should test the controls themselves, not just the numbers those controls are supposed to protect.
Surprise Reviews and Variance Analysis
Surprise audits are disproportionately effective because they catch people off guard. A scheduled audit gives a potential embezzler time to clean up. An unannounced review of petty cash, inventory counts, or payroll records does not. Target surprise reviews at the areas with the highest inherent risk.
Variance analysis compares actual financial results against budgeted or expected results. When vendor payments to a particular supplier spike unexpectedly, or an expense category grows without a clear business explanation, variance analysis flags the discrepancy for investigation. The goal is to shrink the window between when fraud begins and when someone notices. The longer a scheme runs, the more it costs.
Build a Tip Line People Will Actually Use
Tips from employees, vendors, and customers are the most effective fraud detection method, uncovering 43% of all occupational fraud cases, more than three times the rate of the next most common detection method.5Association of Certified Fraud Examiners. 2024 ACFE Report to the Nations To capture those tips you need two things: an anonymous reporting channel and a credible promise that reporters will not face retaliation.
The reporting channel can be a phone hotline, an online portal, or both. An independent third-party operator increases trust and participation because employees do not have to worry that their boss will recognize their voice or track their submission. Make the system accessible to vendors and customers too.
The non-retaliation promise is what makes people actually use the system. Federal law provides some protection here. The Sarbanes-Oxley Act prohibits retaliation against employees of publicly traded companies and their subsidiaries who report securities fraud.6Whistleblower Protection Program. 18 USC 1514A – Civil Action to Protect Against Retaliation in Fraud Cases The Dodd-Frank Act broadened those protections and gave the SEC authority to take enforcement action against employers who retaliate against whistleblowers.7U.S. Securities and Exchange Commission. Whistleblower Protections Private companies that are not publicly traded should still adopt a written non-retaliation policy and enforce it visibly. A hotline nobody trusts is just an expense.
Investigate every tip promptly and confidentially through someone objective, whether that is an internal audit team or an outside forensic accounting firm. Ignoring tips or handling them carelessly destroys trust in the system fast and permanently.
Screen Before Hiring
Before placing anyone in a role with access to money or financial systems, run a thorough background check. This is basic due diligence, but it carries a legal requirement most employers overlook. Under the Fair Credit Reporting Act, you must give the applicant a standalone written disclosure that you plan to obtain a consumer report, and you must get their written authorization before proceeding.8Office of the Law Revision Counsel. 15 USC 1681b – Permissible Purposes of Consumer Reports The disclosure has to be its own document, not buried in a stack of onboarding paperwork. If you decide not to hire someone based on the report, you must also follow specific adverse-action notice procedures before and after making that decision final.
Background checks are not foolproof. A first-time offender will have a clean record. But they filter out repeat offenders and candidates who misrepresent their history, which materially reduces risk in positions that handle cash, sign checks, or manage vendor relationships.
Buy Insurance as a Backstop
Even the best controls can fail. Fidelity bonds and commercial crime insurance provide a financial safety net when an employee steals despite your prevention efforts. A fidelity bond specifically covers losses caused by an employee’s dishonest acts, including theft of money, property, and misuse of financial data. Commercial crime insurance typically offers broader coverage extending to forgery, computer fraud, funds transfer fraud, and in some cases social engineering scams.
Fidelity bonds are relatively inexpensive, often costing roughly 1% of the coverage amount annually. Coverage limits vary widely, from a few thousand dollars to several million.
Organizations that sponsor employee benefit plans have a separate legal requirement. ERISA mandates that anyone who handles plan funds be bonded for at least 10% of the funds they handle, with a minimum bond of $1,000 and a maximum of $500,000, or $1,000,000 for plans holding employer securities.9Office of the Law Revision Counsel. 29 US Code 1112 – Bonding
Review your coverage annually. A bond purchased five years ago may not reflect your current cash flow, headcount, or risk profile. Read the policy carefully: fidelity bonds generally do not cover crimes committed by third parties outside the organization, and most policies require prompt reporting once theft is discovered.
If You Suspect Theft Right Now
Prevention sometimes fails, and the response in the first 48 hours matters. Move too quickly or too publicly and you can expose your organization to defamation liability. Move too slowly and the perpetrator destroys evidence or moves money out of reach.
The first priority is separating the suspected employee from access to financial systems and records by placing them on administrative leave or suspending them. Do not accuse them in front of coworkers or escort them out with a public display that implies criminal conduct before you have evidence. Statements that an employee “stole from the company” can give rise to a defamation claim if you cannot prove them, and even the manner of removal can create legal exposure.
At the same time, secure all documentary evidence: financial records, access logs, emails, and any surveillance footage. Engage a forensic accountant to determine the scope of the loss. If the amount is substantial, file a police report and provide supporting documentation to the investigator. Keep the circle of people who know about the investigation as small as possible to preserve confidentiality and protect the integrity of the evidence.