Fraud Examiner Handbook

How occupational fraud actually gets caught.

A complete working reference on fraud inside organisations — how the schemes are built, the signals that give them away, how a case is properly worked from suspicion to report, the controls that stop the next one, and where all of this meets anti-money-laundering. Written to be read start to finish, with no prior background assumed.

01 — Foundations

The concepts that hold up.

Start here. Everything further down assumes these six ideas.

A

What fraud is, precisely

Fraud is not simply loss, and it is not the same as error. It has four parts, and all four have to be present: a false statement or deliberate concealment of a material fact; knowledge that it was false at the time it was made; someone relying on it; and damage flowing from that reliance.

The dividing line between fraud and a mistake is intent. A duplicate payment made by a tired clerk and a duplicate payment engineered by that same clerk look identical in the ledger. The difference lives in the pattern around it — repetition, concealment, who benefited, what was done when questions were asked. That is why fraud work is rarely about finding a single transaction and almost always about establishing a pattern.

B

The fraud triangle, and the fourth side

The long-standing frame holds that three conditions tend to coincide when an otherwise honest person commits fraud:

  • Pressure — a financial problem the person feels they cannot share: debt, a medical bill, gambling, an addiction, a lifestyle they cannot sustain, or a target they cannot hit.
  • Opportunity — a control gap they can see and reach. Crucially, the person has to believe they can take the money and not be caught. Perceived detection risk matters more than actual detection risk.
  • Rationalisation — a story that recasts the act as something other than theft. "It's a loan." "They underpay me." "Everyone expenses personal travel." Almost nobody starts by deciding to be a criminal.

A fourth condition is usually added: capability — the position, technical skill, ego and nerve to execute the scheme and keep it hidden over time. This is why the costliest frauds are so often committed by senior, long-tenured, well-regarded people. They have the access to do it and the standing to stop anyone from looking.

The practical use of this model is preventive. You cannot control someone's pressure and you cannot audit their rationalisation. Opportunity is the only side of the triangle the organisation owns outright — which is where every control below is aimed.

C

Occupational fraud versus external fraud

Occupational fraud is committed by people inside the organisation, using their position against the employer: an employee, a manager, an executive, sometimes an owner. External fraud comes from outside — customers, applicants, vendors, organised crime.

The distinction matters because the defences are completely different. Against outsiders you build screening, verification and detection at the perimeter: identity checks, transaction monitoring, device and behavioural analytics. Against insiders the perimeter is useless, because the insider is already through it and their activity is authorised by definition. Insider defence is structural: separation of duties, independent review, forced absence, and analytics run on your own staff's activity.

Most organisations invest heavily in the first and thinly in the second, which is precisely why insider schemes tend to run for a long time before anyone notices.

D

Who actually does it

The profile is uncomfortable, because it is the opposite of the one most people imagine. The typical internal fraudster has no criminal record, has been with the organisation for years, is well liked, and is frequently the person others describe as indispensable.

Two relationships hold consistently. Loss scales with seniority — an executive-level scheme costs many multiples of a junior one, because authority removes the need to defeat controls at all. And loss scales with duration — schemes are rarely one event; they start small, succeed, and grow. Every month a scheme runs undetected costs more than the last.

Collusion breaks the model. Almost every control described in this handbook assumes two people are not working together. When they are — approver and requester, buyer and vendor, front office and back office — separation of duties fails silently, and detection has to come from data or from a tip rather than from the control framework.

E

How fraud is actually discovered

This is the finding that should shape where money goes, and it consistently surprises people: tips outrank every other detection method, by a wide margin — more than internal audit, external audit, management review, account reconciliation and pure accident combined in many datasets. Most tips come from employees; a substantial share come from customers and vendors.

The operational conclusions follow directly:

  • A confidential reporting channel is the single highest-return anti-fraud control available, and it is cheap.
  • It must be genuinely anonymous, available to outsiders as well as staff, and visibly acted upon — a hotline nobody trusts produces nothing.
  • External audit is a weak detection mechanism for occupational fraud. It is not designed for it, and treating it as fraud cover is a category error.

Meanwhile the median scheme runs for somewhere around a year or more before it is found — long enough that by the time anyone is looking, the trail is cold and the money is usually gone.

F

The paper trail is the finding

An examiner's conclusion is only ever as strong as the record a stranger could follow to reach the same conclusion independently. That means contemporaneous notes rather than reconstructed ones, a documented chain of custody for anything gathered as evidence, and a hard separation in the write-up between what was observed and what was inferred.

Work that is right but undocumented loses at a tribunal, loses in a civil claim, and loses in a disciplinary hearing. Assume from the first hour that every note you take will be read aloud by someone hostile to your conclusion.

Most occupational fraud isn't caught by audit. It's caught because someone noticed something didn't add up.
Which makes the reporting channel, not the control matrix, the highest-yield investment most organisations are under-funding.

02 — Scheme types

Three families of scheme.

Nearly every internal fraud is a variation on one of these. Knowing the variation tells you where to look.

Most common

Asset misappropriation

Theft or misuse of the organisation's resources. The most frequent family by a long way, and the cheapest per case — which is exactly why it is tolerated for years before anyone adds it up.

  • Skimming — cash taken before it is recorded. There is no entry to find, which makes it the hardest form of cash theft to detect from the books alone.
  • Cash larceny — cash taken after it has been recorded, so it leaves a hole that reconciliation should catch.
  • Lapping — covering a stolen customer payment with a later customer's payment, then covering that one with the next. It requires constant maintenance and collapses the moment the person takes leave.
  • Billing schemes — invoices from a shell company the employee controls, inflated invoices from a real vendor, or personal purchases run through the company account. Usually the single largest asset-misappropriation exposure.
  • Cheque and payment tampering — altering payees, forging endorsements, or redirecting electronic payments.
  • Payroll schemes — ghost employees, falsified hours, inflated commission.
  • Expense reimbursement — fictitious, inflated, duplicated or personal expenses claimed as business.
  • Register disbursements — false refunds and voided sales that release cash.
  • Non-cash — inventory, equipment, data, customer lists and intellectual property.
Hardest to see

Corruption

Using influence in a transaction to gain a personal benefit. It sits in the middle on both frequency and cost, and it is the hardest of the three to find in the accounts — because frequently there is no fraudulent entry in your books at all. The money moves outside them.

  • Bribery — payment to influence a business decision.
  • Kickbacks — a vendor returns part of an inflated invoice to the employee who approved it. The invoice itself looks legitimate; only the price is wrong.
  • Bid rigging — steering a tender. Common forms: bid suppression (a competitor is paid to withdraw), complementary bidding (deliberately uncompetitive bids submitted to make one look reasonable), and bid rotation (competitors take turns winning).
  • Conflicts of interest — undisclosed ownership of, or a relationship with, a counterparty the employee influences.
  • Economic extortion — the reverse of bribery: the employee demands payment for a favourable decision.
  • Illegal gratuities — a reward given after a decision rather than to procure it.

Detection here rarely starts in the ledger. It starts with relationships, lifestyle, tender outcomes that never change, and tips.

Most costly

Financial statement fraud

Deliberate misstatement of what the organisation reports. The rarest family and by a wide margin the most expensive — the losses are measured in market value and institutional survival, not in stolen cash.

  • Fictitious revenue — sales that never happened, or that were booked to entities with no ability or intention to pay.
  • Timing differences — revenue pulled into the current period or costs pushed into the next. Includes channel stuffing and cut-off manipulation at period end.
  • Concealed liabilities and expenses — obligations kept off the balance sheet, capitalising costs that should be expensed, or simply not recording invoices received.
  • Improper asset valuation — inventory, receivables or goodwill carried above what they are worth; reserves that move to fit the target rather than the facts.
  • Improper disclosure — omitted related-party transactions, contingent liabilities or subsequent events.

The motive is almost always external pressure translated into internal pressure: debt covenants, analyst expectations, an acquisition in progress, or executive compensation tied to a number.

03 — Red flags

Where to look, by function.

None of these prove anything on their own. Each one tells you what question to ask next.

Payments

Disbursements

  • Amounts clustering just below an approval threshold — the clearest single signal in any payment file
  • Vendor bank details changed shortly before a large payment
  • A vendor address, phone number or bank account matching an employee's
  • Payments to a vendor with no purchase order, no contract, or no goods-received record
  • Urgency or secrecy framing on an otherwise routine payment
  • Round-sum invoices, sequential invoice numbers from one supplier, or invoices with no tax registration
Procurement

Vendors and tenders

  • A newly incorporated entity winning a disproportionately large contract
  • The same vendor winning repeatedly with narrow, consistent margins over the same rivals
  • A single point of contact who resists verification, site visits or reference checks
  • Documentation that is complete but unverifiable against any independent record
  • Scope creep and change orders that quietly exceed the original tender value
  • A buyer who insists on owning the vendor relationship personally and resists rotation
Payroll

People and expenses

  • Employees with no tax deductions, no benefit elections, or no leave ever taken — the classic ghost-employee signature
  • Two employee records sharing a bank account or address
  • Expense claims clustering just below the receipt-required threshold
  • The same expense submitted in two periods, two systems or two cost centres
  • Overtime concentrated in one team, approved by one person
  • Terminated staff still on the payroll run
Revenue

Sales and receivables

  • Revenue spikes in the final days of a period, reversed early in the next
  • Receivables growing materially faster than sales
  • Credit notes and write-offs concentrated around one salesperson or customer
  • Customers with no credit history taking unusually large volumes
  • Unusual shipping terms, side letters, or contract amendments held outside the system
In the data

Anomalies worth testing

  • Duplicate payments — same amount, same vendor, near-same date
  • Gaps and out-of-sequence numbering in cheques, invoices or receipts
  • Entries posted at weekends, overnight, or on public holidays
  • Manual journal entries near period end, especially round-numbered ones
  • Digit-distribution testing: naturally occurring figures follow a predictable pattern of leading digits, and invented ones usually do not
  • Master-file matching: employee records against vendor records, on bank account, address, phone and tax number
  • Dormant accounts or vendors suddenly reactivating
Behavioural

The person-level signal

  • Living visibly beyond a known salary
  • Refusal to take leave, or to let anyone else run a process — the strongest single behavioural flag, because most schemes need daily maintenance
  • Unusual irritation at routine questions, audit requests or new oversight
  • Close, undisclosed relationships with a vendor or customer
  • Control over an entire cycle end to end — raising, approving and reconciling
  • Known personal financial pressure, or a sudden change in circumstances

Treat these as prompts to verify, never as conclusions. Behaviour is context, not evidence.

04 — Examination

How a case is worked.

From first suspicion to a report that survives challenge.

A

Predication comes first

An examination should begin from a reasonable, articulable basis to believe fraud has occurred, is occurring, or will occur — not from a hunch, an office rivalry, or a manager's dislike of a colleague. Write the predication down before any work begins.

Two reasons. It protects the subject, who may well be innocent and whose career you are handling. And it protects the organisation, because an examination launched without stated grounds is the first thing an employment lawyer will attack.

B

Work from a theory, not a fishing net

The efficient method is iterative rather than exhaustive: analyse the available data, form a specific hypothesis about how the scheme would have to work, test that hypothesis against evidence, then revise it. Concretely — "if this were a shell-vendor billing scheme, the vendor would have no premises, its bank account would be recently opened, its invoices would lack detail, and one approver would appear on every payment." Each of those is checkable.

Scoping matters as much as method: decide up front what period, which systems, which entities and which people are in scope, and who needs to know. Uncontrolled scope destroys both timelines and confidentiality.

C

Evidence, and how not to ruin it

Three kinds. Documentary — invoices, contracts, statements, system records, emails. Testimonial — what people tell you in interviews. Physical or digital — devices, hardware, access logs, images.

  • Preserve originals; work from copies. Never annotate an original.
  • Maintain chain of custody from the moment anything is collected: what was taken, by whom, when, from where, and everyone who has held it since. A gap in that record is enough to have the item excluded.
  • Image devices forensically before examining them. Browsing a suspect's laptop directly alters metadata and can destroy the evidential value of the very thing you are trying to prove.
  • Issue a hold on relevant records and mailboxes early, before routine deletion policies do the destroying for you.
  • Take advice on privacy, employment and data-protection constraints before monitoring or accessing personal information — the legality of collection varies by jurisdiction and getting it wrong can sink an otherwise sound case.
D

Data analysis does the heavy lifting

Most modern cases are made or broken in the data long before anyone is interviewed. The workhorse tests are unglamorous and highly effective:

  • Duplicate and near-duplicate testing across payments, claims and invoices
  • Gap and sequence testing on numbered documents
  • Matching employee master data to vendor master data
  • Threshold analysis — clustering just under approval, review or receipt limits
  • Trend and ratio analysis against comparable periods, teams or branches
  • Timing analysis — entries outside working hours, or bunched at period end
  • Relationship mapping between approvers, requesters and counterparties

Run these proactively on a schedule, not only when suspicion already exists. Nearly all of them are cheap to automate and each one has caught real schemes.

E

Interviews, in the right order

Sequence matters. Work outward-in: neutral third parties first, then corroborating witnesses, then people close to the subject, and the person suspected last — once you already know most of the answers. Interviewing the subject early tips them off, and gives them time to align stories and destroy records.

  • Open questions before closed ones. Let people talk; do not lead them to your theory.
  • Never accuse, never threaten, and never promise leniency, confidentiality you cannot deliver, or an outcome you do not control.
  • Have a second person present. A one-on-one interview becomes one person's word against another's the moment it is disputed.
  • Document immediately afterwards, while recall is intact — and record what was said, not your interpretation of it.
  • Know when to stop. If a confession appears imminent, or the matter turns criminal, that is the moment for qualified legal advice, not improvisation.
F

Two different bars for two different jobs

This is where compliance teams moving between disciplines most often go wrong.

Filing a suspicious activity report requires only reasonable suspicion. You are not proving anything; you are passing a signal to an authority equipped to investigate it. Waiting for proof before filing is itself a regulatory failure.

An examination that ends in dismissal, civil recovery or a criminal referral is judged far higher: the balance of probabilities in civil and employment matters — more likely than not — and beyond reasonable doubt if a prosecution follows.

Confusing the two is a recurring, avoidable failure mode in both directions: treating an alert as though it already establishes fraud, or delaying a report while chasing examination-grade certainty that reporting never required.

G

The report, and what happens after

Write it assuming it will be read by a lawyer, a regulator or a court. State the scope, the methodology, the evidence relied on, and the findings of fact. Attach a schedule of the evidence itself.

Report what the evidence shows. Do not offer an opinion on guilt — that is not the examiner's determination to make, and asserting it undermines the credibility of everything factual in the document. Keep the language neutral, dated and specific.

Then close the loop that most organisations skip: quantify the loss, decide on recovery, insurance and referral, and — critically — fix the control gap the scheme exploited. A case that ends in a dismissal but leaves the opening intact has solved a person, not a problem.

05 — Prevention

Controls that earn their keep.

Ranked roughly by what they return for what they cost.

Highest return

A reporting channel people trust

Since tips find more fraud than every other method, the channel that receives them is the highest-yield control available.

  • Genuinely anonymous, and seen to be
  • Open to vendors and customers, not only staff
  • Multiple routes — phone, web, email
  • Visibly acted on, with feedback loops and hard protection against retaliation
Structural

Separation, leave and rotation

Nobody should own a full cycle end to end — raising, approving, paying and reconciling.

  • Split those four functions across people
  • Mandatory consecutive leave: schemes that need daily maintenance surface while the person is away
  • Rotate duties in high-risk roles, particularly buyers and reconcilers
  • Remove access the day a role changes, not the week after
Unglamorous

Master-file hygiene

The boring control that catches the most expensive family of scheme.

  • Independent verification before any new vendor is created
  • Dual authorisation for bank-detail changes, and call-back on a number you already held — never one supplied in the request
  • Periodic vendor-to-employee matching on bank, address and tax number
  • Regular purging of dormant vendors and terminated employees
Proactive

Continuous analytics

Run the tests in section 04 on a schedule rather than after the fact.

  • Threshold-clustering and duplicate tests every cycle
  • Alerts on bank-detail changes and new vendor creation
  • Out-of-hours and period-end journal review
  • Trend comparison across branches and teams to surface the outlier
Cultural

Tone, and honest risk assessment

Controls fail quietly where leadership signals that results matter more than how they were achieved.

  • Senior people visibly subject to the same rules — no override culture
  • A documented fraud risk assessment naming realistic schemes for your business, refreshed as the business changes
  • Incentive structures reviewed for the pressure they create
  • Training that teaches the specific schemes staff might actually encounter

06 — Overlap

Where fraud meets AML.

Two disciplines, usually two teams, one underlying set of facts.

Fraud generates proceeds. Laundering moves them. In most jurisdictions fraud is a predicate offence for money laundering, which means the same transactions frequently sit in both a fraud case and an AML case — typically in two different systems, worked by two different teams who never compare notes.

The typologies that live in both worlds at once:

  • Business email compromise and invoice redirection — a fraud at the point of payment, a laundering problem the moment the funds land and move on
  • Money mule networks — recruited account holders receiving fraud proceeds, often flagged first by fraud rules and only later by AML monitoring
  • Romance and investment scams — victim-initiated payments that defeat most fraud controls precisely because the victim authorises them
  • First-party and application fraud — false information at onboarding, which is simultaneously a KYC integrity failure
  • Trade-based schemes — mis-invoicing that serves as both the fraud and the laundering mechanism

The practical consequences for control design:

  • Join the data. A fraud alert and an AML alert on the same customer, raised the same week and never connected, is the most common structural failure in this space.
  • Respect the different thresholds. Reporting runs on reasonable suspicion; examination runs on proof. Neither standard should be imported into the other's process.
  • The tuning discipline is identical. Both sides are rule and model estates that decay: thresholds drift out of date, typologies stop matching behaviour, and false positives crowd out the alerts that mattered. Both need periodic tuning, documented rationale and quality assurance of the decisions analysts actually make.
  • Explainability is not optional in either. Whether the output is a report to an authority or a finding against an employee, someone will eventually ask why the system flagged it — and "the model said so" is not an answer that survives scrutiny.

07 — Case notes

What the record shows.

Concluded, public-record matters, summarised for the control lesson rather than the drama.

2001 — Statement fraud

Enron

Debt shifted into off-balance-sheet special-purpose entities while earnings were inflated, sustained by an audit relationship too commercially entangled to challenge it. The company collapsed in late 2001; its auditor was prosecuted, and although that conviction was later overturned on appeal, the firm had already ceased to exist. The affair produced the most significant overhaul of corporate reporting and auditor independence rules in a generation.

Lesson: complexity is a concealment tool. Structures nobody outside a small group can explain should be treated as a risk indicator, not as sophistication.

2002 — Statement fraud

WorldCom

Ordinary operating costs were recorded as capital expenditure, understating expenses and manufacturing profit. What surfaced initially as billions in misstatement grew substantially as the full picture emerged, and the company entered what was then the largest bankruptcy in US history. The chief executive was convicted and given a long custodial sentence. Notably, it was the internal audit team — working quietly and against discouragement — that found it.

Lesson: an internal audit function with genuine independence and a direct line to the board is worth more than one with a bigger budget and no protection.

1995 — Rogue trading

Barings Bank

A single trader in Singapore ran both the trading desk and its own settlement function, and used a concealed error account to hide escalating losses on futures positions. The losses ultimately exceeded the bank's entire capital; a 230-year-old institution was sold for a nominal sum.

Lesson: the textbook separation-of-duties failure. One person controlling both the transaction and the record of the transaction removes every check that would otherwise apply — and remote, profitable operations attract the least scrutiny precisely when they need the most.

2008 — Rogue trading

Société Générale

A trader took enormous unauthorised directional positions and concealed them with fictitious offsetting trades, using knowledge of back-office processes gained in a previous role to anticipate and evade the controls. The eventual loss ran to billions of euros.

Lesson: capability, in the fraud-triangle sense. Someone who knows exactly when and how a control is checked can time activity around it — which is why control design must assume the adversary understands the controls.

2020 — Fictitious assets

Wirecard

A payments company reported roughly €1.9bn held in trustee accounts in Asia. The money did not exist. Warnings from journalists and short sellers had been publicly aired for years and were treated as attacks to be defended against rather than claims to be tested. The company entered insolvency; senior executives were arrested, and one fled.

Lesson: confirm assets independently, at source, with the institution actually holding them. And treat persistent external allegations as a matter to investigate rather than a reputational problem to manage.

08 — Glossary

The words, defined.

Plain definitions for the terms used above, and in most fraud reporting.

Predication
The reasonable, stated basis for beginning an examination. Without it, an investigation is a fishing expedition.
Skimming
Cash removed before it is ever recorded, so no entry exists to reconcile against.
Cash larceny
Cash removed after it has been recorded, leaving a discrepancy that reconciliation should reveal.
Lapping
Concealing a stolen customer payment by applying a later customer's payment to the gap, repeatedly.
Shell company
An entity with no real operations, used to issue invoices for goods or services never supplied.
Ghost employee
A person on the payroll who does not work there — invented, or a leaver never removed — with wages routed to the fraudster.
Kickback
A share of an inflated invoice returned by a vendor to the employee who approved it.
Bid rigging
Manipulating a tender so a predetermined bidder wins, through suppressed, complementary or rotated bids.
Channel stuffing
Pushing more product to distributors than they can sell, to record revenue that will later reverse.
Segregation of duties
Splitting a cycle so no one person can raise, approve, pay and reconcile the same transaction.
Chain of custody
The unbroken documented record of who held an item of evidence, when, and where it was kept.
Tone at the top
What leadership's behaviour — not its policy documents — signals about acceptable conduct.
Red flag
An indicator that warrants a question. Never proof on its own, and never a finding.
Balance of probabilities
The civil standard of proof: more likely than not. The bar for most employment and recovery outcomes.
Suspicious activity report
A report to the relevant authority based on reasonable suspicion. It requires no proof and is not an accusation.
Money mule
Someone who receives and forwards criminal proceeds through their account, knowingly or otherwise.
Business email compromise
Impersonating an executive or supplier by email to induce a payment or a change of bank details.
First-party fraud
Fraud committed by the genuine account holder or applicant against the institution, using their own identity.

A note on this page

This handbook is original educational commentary on fraud examination as a discipline, written in a personal capacity. It contains no confidential or employer-specific information, and the case notes describe concluded matters of public record.

It is general guidance, not legal advice, and not a substitute for qualified counsel on a specific matter. If something here is unclear or wrong, tell me and I will correct it.