top of page
Search

How Fraud Starts: The Financial Blind Spots Every Organization Has

Fraud rarely begins with a dramatic theft. It begins with a small opportunity that no one notices.

By Dr. Gabrielle Juba, CPA, CFE  |  Founder, Juba Forensics PLLC

 

Imagine the person at your dentist’s front desk. She has worked there for 25 years. She knows your name, schedules your appointments, answers your questions, and feels like part of the practice. Then one day, you learn she stole hundreds of thousands of dollars—money patients believed they were paying to the dentist.

That story is shocking because the person does not match the image many of us have of a fraudster. She was not a stranger lurking outside the organization. She was trusted, experienced, and deeply familiar with its systems.

That is exactly the point: fraud is not always a bad-person problem. Very often, it is a systems problem.


Fraud can happen in any organization

Occupational fraud—the misuse of a position for personal gain—affects businesses, nonprofits, government entities, and organizations of every size. The Association of Certified Fraud Examiners’ 2026 global study examined 2,402 cases across 143 countries and territories. Those cases caused more than $3.4 billion in losses, with a median loss of $104,000 per case.

The same study found that a typical fraud scheme continued for 12 months before detection. Forty-three percent of cases were detected through a tip, and more than half of those tips came from employees. The lesson is not that leaders should distrust everyone. It is that leaders cannot rely on trust alone.

Trust people. Verify processes.

The fraud triangle: why fraud becomes possible

Most occupational fraud involves three conditions, commonly described as the fraud triangle:

·    Pressure: A financial, personal, or workplace problem creates a perceived need. Examples may include job loss in the household, medical expenses, addiction, divorce, debt, performance targets, or lifestyle expectations.

·    Opportunity: The person sees a weakness in the organization’s processes and believes the act can be committed and concealed.

·    Rationalization: The person explains the behavior to themselves: “I will pay it back,” “I am underpaid,” “No one appreciates me,” or “The organization will never miss it.”


Leaders cannot control every pressure an employee or volunteer may face, and they cannot always control how someone rationalizes a decision. They can, however, reduce opportunity. That is the purpose of strong internal controls.


Five financial blind spots that allow fraud to grow

1. One person controls an entire financial process

When one person can initiate, approve, record, and reconcile a transaction, that person can both commit an error or fraud and conceal it. This is called a lack of segregation of duties.


Consider cash receipts. If one employee opens the mail, collects customer payments, prepares the deposit, takes it to the bank, and records it in the accounting system, there is no independent checkpoint. The same risk exists when one employee adds new workers to payroll, enters hours, submits payroll, and approves the final reports.

Small organizations may not have enough staff to separate every responsibility perfectly. That does not mean they have no options. An owner, executive director, treasurer, or board member can review bank activity, payroll change reports, new vendors, or supporting documents as a compensating control.


2. No one reviews the financial statements each month

Financial statements are not merely reports for the accountant or the annual audit. They are one of management’s most useful monitoring tools.

Fraud often begins with a small amount. A $100 irregularity may not stand out in a large organization, but monthly and year-over-year comparisons can reveal a pattern. Leaders should review unexpected changes, unusual account balances, unexplained journal entries, new vendors, duplicate payments, payroll fluctuations, and expenses that do not fit the organization’s operations.


An annual financial statement audit is valuable, but it is not a substitute for management’s ongoing responsibility to prevent and detect fraud.


3. Bank reconciliations are prepared—but not independently reviewed

A bank reconciliation confirms that the organization’s accounting records agree with the bank. It can also reveal missing transactions, unusual adjustments, old outstanding checks, duplicated entries, and suspicious “plug” journal entries used to force the records to balance.


The person who prepares the reconciliation should not be the only person who reviews it. At minimum, an owner or other authorized leader should confirm each month that all accounts were reconciled, scan the outstanding items, review unusual adjustments, and document approval.


4. Board members and leaders do not ask questions

Board members and executives do not need accounting degrees to exercise financial oversight. They do need to receive understandable reports and ask thoughtful questions.


Professional credentials should not end the conversation. Accountants, bookkeepers, auditors, and CPAs can make mistakes, misunderstand an organization’s operations, or recommend an entry that creates unintended consequences. A strong leader asks, “Why does this make sense?” and “How will this affect our records going forward?”


Questioning a professional is not an accusation. It is responsible governance. The goal is to understand the recommendation, test whether it fits the organization, and resolve concerns before they become larger problems.


5. “We have always done it this way” becomes the control

A process is not effective simply because it is familiar or because the organization has never discovered a problem. Roles change. Technology changes. Staff members gain new access. Organizations grow. A control that worked five years ago may no longer address today’s risks.


At least annually, leaders should map major financial processes, identify who has access and approval authority, test whether controls are working, and update procedures. The review should include cash receipts, vendor setup and payments, credit cards, payroll, bank access, accounting-system permissions, and financial reporting.


A real payroll lesson: expertise does not eliminate blind spots

I once oversaw the finances of an organization where a long-term payroll employee issued herself an unauthorized bonus as she left. I am a CPA and a Certified Fraud Examiner, yet the organization did not have a process requiring an independent review of the payroll administrator’s final payroll run.


The amount was not enormous, but the lesson was. Knowing about fraud risk is not the same as building a control that works every time. Afterward, we changed the process so that the same weakness could not be used again.


Good controls do more than protect the organization. They also protect honest employees and volunteers from suspicion, protect leaders and board members from avoidable governance failures, and make responsibilities clear.


Why small weaknesses become large losses

Fraud rarely starts with someone stealing thousands of dollars on day one. It usually starts with a small opportunity: a little cash taken from a deposit, an extra payment, a personal purchase on a company card, or an unauthorized payroll adjustment.


If no one notices, the behavior can escalate. One hundred dollars becomes five hundred. Five hundred becomes one thousand. The longer the scheme continues, the larger the loss can become—and recovery is often difficult because the money has already been spent on bills, gambling, shopping, addiction, or lifestyle expenses.


Prevention is usually less costly than investigation, disruption, legal action, reputational damage, and attempted recovery after the fact.


One practical step to take this week

You do not have to rebuild your entire financial system today. Start by answering two questions:

·    Who has access to each bank account?

·    Who prepares and independently reviews each bank reconciliation?


If the same person controls both responsibilities—or if no review is documented—you have identified an opportunity that needs attention. Next, decide who can provide an independent review and what evidence will show that the review occurred.


Then repeat the exercise for payroll, vendor payments, credit cards, cash receipts, and accounting-system access.


Fraud prevention starts before fraud does

You are allowed to trust the people who work beside you. In fact, healthy organizations depend on trust. But trust is a relationship, not an internal control.

Strong organizations trust their people and verify their processes. They separate key duties where possible, review financial information regularly, encourage questions, provide safe ways to report concerns, and improve systems before a small weakness becomes a major loss.

Ready to identify your organization’s blind spots?

Download the free Financial Fraud Risk Assessment Checklist, then schedule a 15-minute consultation if you would like help evaluating your controls.

Visit JubaForensics.com  |  Schedule a consultation


About the author

Dr. Gabrielle “Gabi” Juba is a CPA, Certified Fraud Examiner (CFE), Doctor of Business Administration, and founder of Juba Forensics PLLC. She helps businesses and nonprofit organizations strengthen internal controls, understand their financial information, prevent fraud, and bring clarity to complex financial situations.

 

Source: Occupational Fraud 2026: A Report to the Nations. Copyright 2026 by the Association of Certified Fraud Examiners, Inc.

 
 
 

Comments


  • Facebook
  • Youtube
  • LinkedIn

©2025 by Gabi Juba, Juba Forensics PLLC

bottom of page