Skip to main content

KPM

fraud controls

Are Your Fraud Controls Keeping Pace With Business Change?

Fraud risks can shift as your business grows, operations change, and external conditions evolve. Controls that once worked may no longer fit if you have added employees, revised payment methods, switched vendors, or opened new locations. Fraud schemes also continue to become more sophisticated, especially when perpetrators try to gain access to business systems, payment processes, or financial records.

A formal fraud risk assessment can help your organization identify control gaps, review areas of concern, and strengthen procedures related to asset misappropriation, financial misstatement, and corruption schemes. Professional advisors can provide objective guidance as your organization reviews fraud risks, evaluates internal controls, and determines appropriate next steps.

Review Records & Controls

Forensic accountants are often engaged to conduct a focused, objective review of fraud risks and the controls designed to address them. This assessment may include discussions with management and employees to understand how transactions are authorized, processed, and recorded. Examples of documents that forensic accountants may review are:

  • Bookkeeping records
  • Invoices
  • Bank statements
  • Payments
  • Journal entries
  • Financial reports

 
The assessment may also cover vendor and payroll files, electronic payment records, and user-access logs. Management can assist by providing access to records and personnel. Unexplained delays, inconsistent explanations, and missing or incomplete documents can be red flags that warrant further attention.

The engagement’s scope should reflect your business’ size, systems, industry, and risks. Although a fraud-risk assessment can help you identify and address vulnerabilities, it won’t uncover every instance of fraud. So, ongoing vigilance is essential.

Follow The Transactions

Depending on the risks identified, forensic accountants may look for altered, forged, or missing documents, management overrides, unusual transaction patterns, and other anomalies. For example, unusual or unsupported journal entries may warrant closer scrutiny, particularly if they’re inconsistent with normal business activity or posted by unexpected individuals. Unreconciled accounts and differences between the general ledger and subsidiary ledgers also warrant attention. An independent count of inventory or cash can help identify missing assets.

Payroll deserves particular attention. Missing or unaccounted-for workers could indicate “ghost” employees — nonexistent workers whose pay is diverted by a perpetrator. Management can help identify these schemes by reconciling payroll to human resources records and tax filings, confirming active workers with supervisors, reviewing duplicate bank accounts or addresses, and independently approving payroll changes.

Management should also watch for behavioral red flags. For instance, fraud perpetrators may avoid taking vacation or sick time for fear someone will uncover their activities, or they may become defensive. Such behavior isn’t necessarily proof of wrongdoing and should be evaluated alongside transactional evidence and other facts.

Protect The Investigation

If a fraud-risk assessment uncovers suspicious activity, a separate investigation may be appropriate. Management should preserve relevant evidence and consult legal counsel and a qualified forensic specialist before confronting a suspected employee. A documented investigation plan can help maintain confidentiality, protect evidence, and address legal and employment considerations. Management also shouldn’t assume that one employee acted alone because fraud may involve collusion among employees or people outside the business.

Warning signs don’t necessarily indicate fraud. Accounting irregularities may stem from genuine errors or an ill-designed process. Honest mistakes can be corrected and avoided in the future with better training, process improvements, or more effective controls.

Make Reporting Safe & Accessible

According to the Association of Certified Fraud Examiners’ Occupational Fraud 2026: A Report to the Nations, tips were the initial detection method in 43% of the cases studied, and more than half of those tips came from employees. The median fraud scheme lasted 12 months before detection, reinforcing the value of giving people practical ways to speak up.

If your business hasn’t established a process for employees, vendors, customers, and others to report suspected misconduct, consider doing so. Your reporting process should provide accessible channels, route allegations away from anyone who may be implicated, prohibit retaliation consistent with applicable law and protect confidentiality to the extent reasonably possible.

Turn Findings Into Stronger Controls

A fraud-risk assessment should conclude with an action plan: Assign responsibilities, set deadlines for correcting deficiencies, and follow up to confirm that revised controls are working. An external forensic accountant can provide an independent perspective, but management remains responsible for the business’ fraud controls and response procedures. Periodic reassessment can help those controls keep pace as the business and its fraud risks change. Contact us to discuss your business’ fraud risks and determine whether your existing controls adequately address them.

Related Articles

Get Help From an Expert​
Keith Seiwert, CPA | Member
Have questions about this article? Our team is ready to help.

Talk with the pros

Our CPAs and advisors are a great resource if you’re ready to learn even more.