Key takeaways
- Individually, every item below has an innocent explanation. Clustering is the signal: same area, same person, sustained over time.
- An annual audit is not designed to detect fraud. Sampling and materiality mean a scheme below the threshold can run indefinitely.
- If you find something, the first move is preservation, not investigation. An informal internal inquiry frequently destroys the evidence.
- Most of these patterns are detectable by a competent monthly close. That is the cheapest fraud control there is.
A forensic engagement usually starts with a feeling rather than a fact: a margin that moved without an explanation, a supplier nobody recognizes, an employee who reacts oddly to a routine question. The job is then to turn that feeling into evidence, or to dispose of it.
What follows is what we look at first. Every item has a perfectly innocent explanation in isolation, and most of the time the innocent explanation is the correct one. The signal is clustering: several of these in the same area, involving the same person, sustained over time.
01. Manual journal entries posted after close
Manual journals are the only mechanism that can change a reported number without a corresponding real-world transaction. That makes them the natural instrument for financial statement manipulation, and the first population we extract.
The specific patterns worth attention: entries posted after the period was closed; round numbers, particularly ending in multiple zeros; entries posted by someone outside the accounting function; and, most telling of all, an entry posted, reversed in the following period, and posted again. That last pattern is a number being held at a level rather than reflecting anything that occurred.
Also look at descriptions. "Adjustment", "reclass", "correction" and blank descriptions are not evidence of anything, but a concentration of them by one preparer around a reporting date is worth ten minutes.
02. Vendor bank detail changes before a large payment
This is the single most common loss event we are called about, and it is now more likely to be an external attacker than an internal one.
The business email compromise pattern is consistent: an attacker gains access to a supplier's email, waits, and at the right moment sends a genuine-looking request to update remittance details. The next legitimate invoice (for goods actually delivered, at the correct amount) is paid to the attacker's account. Nothing about the transaction looks wrong except the destination.
The verification that stops it
Any change to vendor banking details must be verified by phoning the supplier on a number you already held, never the number in the email requesting the change. Urgency and requests for confidentiality are the signature of the scheme, not evidence of legitimacy. This one procedure prevents more loss than any other single control in the list.
03. Vendor details matching an employee
A supplier whose address, bank account, tax identification number or phone number matches an employee record is the signature of a fictitious vendor scheme, and it is easy to test for.
Run the vendor master against the employee master on each field. Watch for near-matches as well as exact ones: an apartment number added, a street abbreviated differently, a digit transposed. Also look for vendors with a PO box and no other detail, vendors with no tax identification number on file, and vendors whose invoices are always for round amounts and always for services rather than goods, since services leave no delivery trail.
04. Payments clustered just below an approval threshold
If your dual-approval threshold is $10,000, a single payment at $9,850 means nothing. A pattern of payments between $9,500 and $9,999, particularly to the same payee or approved by the same person, is deliberate structuring.
The test is straightforward: plot payment values as a distribution and look at the shape around each approval threshold. A genuine business produces a smooth distribution. Structuring produces a visible pile immediately below the line and a gap immediately above it.
The same logic applies to expense reimbursements sitting just under the receipt-required threshold, and to purchase commitments just under the level requiring a competitive quote.
| Indicator | May indicate | Preventive control |
|---|---|---|
| Post-close manual journals | Financial statement manipulation | Journal entry review by a non-preparer |
| Vendor bank detail change | Business email compromise; diversion | Out-of-band verification, second approver |
| Vendor matches employee | Fictitious vendor scheme | Vendor master change control |
| Sub-threshold clustering | Deliberate structuring | Distribution monitoring; variable thresholds |
| Credit memo or write-off spike | Skimming concealment | Independent approval of credits |
| Stale reconciling item | A plug hiding a growing gap | 60-day resolution rule on all items |
| Employee never takes leave | A scheme requiring continuous presence | Mandatory leave; rotation of duties |
05. Rising credit memos, refunds or write-offs
Skimming (taking cash before it is ever recorded) requires the receivable to disappear. The usual disposal routes are a credit memo, a refund or a bad debt write-off.
Look at credit memos and write-offs as a percentage of revenue over time, then break the figure down by who approved it and which customers it relates to. A steady rise, or a concentration with one individual, deserves an explanation. The version that most often turns out to be real: credits raised against customers who never complained, or write-offs of balances the customer's own records show as paid.
Confirming a sample of written-off balances directly with the customer is a fast and remarkably effective test.
06. A reconciling item that never clears
An unexplained difference that persists month after month, but changes value each time, is often a plug. It is the arithmetic residue of a gap that someone is managing rather than resolving.
The tell is that the item cannot be traced to a specific transaction. A real reconciling item is a named check, a specific deposit in transit, an identifiable timing difference. An item described as "difference" or "misc" that has been carried for eleven months is not a timing difference; it is a question nobody has asked.
Every long-running scheme we have investigated left a trace in a reconciliation. In almost every case, nobody independent was reviewing it.
07. The employee who never takes leave
This one is uncomfortable, and it must be handled carefully: a dedicated employee who does not take vacation is far more common than a fraudulent one. But it is statistically meaningful, for a mechanical reason.
Many schemes require continuous presence to sustain concealment. Lapping receivables, maintaining a fictitious vendor, holding a plug in a reconciliation: each needs someone to keep the plates spinning. Two consecutive weeks of absence, with someone else doing the work, is often when a scheme surfaces on its own.
Mandatory leave is therefore a genuine control, not an HR nicety. So is periodic rotation of duties within the finance function.
If you find one
The instinct is to look into it yourself. Resist it. An informal internal inquiry is the most common way evidence gets destroyed, and how the first forty-eight hours are handled materially affects whether findings are usable in an insurance claim or a prosecution.
- Do not confront anyone. Confrontation triggers deletion, and it creates employment law exposure before you know what you are alleging.
- Preserve the evidence. Secure backups of accounting data, email and relevant systems, and suspend routine deletion and retention policies immediately.
- Restrict access quietly, ideally within a broader access review so the change does not itself signal that something is under way.
- Call your attorney and a forensic accountant the same day. Being engaged through counsel can preserve privilege over the work product, and that decision must be made at the start.
Why your audit did not catch it
A question that comes up in almost every engagement. The answer is that an audit is not a fraud detection instrument, and was never designed to be.
An audit provides reasonable assurance that financial statements are free of material misstatement. It uses sampling and sets a materiality threshold, so a scheme taking amounts below that threshold can run for years without an audit having any realistic chance of finding it. Audits are also structurally poor at detecting collusion and management override, because both defeat the control reliance the audit approach depends on.
That is not a criticism of auditing. It is a description of scope. It does mean that relying on your annual audit as your fraud detection strategy leaves a gap, and the gap is filled by working controls and a competent monthly close rather than by more audit.
Most of the seven patterns above are visible in a properly run close. That remains the cheapest fraud control available to a small business, and the one most often absent in the cases we are called into.