Somebody has just told you they think the bookkeeper is stealing.
What happens in the next few hours largely determines whether the matter ends in a documented recovery or in an unprovable suspicion, a wrongful termination claim, and a denied insurance claim. Almost every instinct at that moment is wrong.
Do not confront the suspect. Not to "give them a chance to explain," not to gauge their reaction. A confronted employee deletes records, alters files, warns an accomplice, retains counsel, and stops the flow of new evidence — and an untrained accusatory conversation creates exposure for the employer.
Do not announce the investigation.
Do not let the employee resign quietly to make the problem go away, which is the single most common employer decision and causes three separate harms: it forfeits the documentation, it usually voids the insurance claim, and it delivers an unwarned employer their next embezzler.
Do not start deleting, reorganizing, or "cleaning up" anything.
Do not touch the suspect's computer yourself. Powering a machine on changes it. Preservation is a specialist function.
Engage counsel, and have counsel engage you. The most important structural decision available. Work performed at the direction of counsel may be protected by privilege and work product doctrine; the same work performed directly for management may be fully discoverable. Since the engagement's output may end up in litigation, an employment claim, or an insurance dispute, that distinction has consequences from the first document.
Preserve, quietly. Images of relevant systems, email, accounting data files including prior backups, bank records, and physical documents — with chain of custody documented from the moment each item is secured. Backups matter especially, because accounting systems permit changes and the historical file may show what the current one does not.
Establish who has access to what, including remote access, banking credentials, and the ability to alter the accounting records.
Notify the insurer. See the section below; this is the deadline nobody meets.
Decide scope and objective with counsel and the client: quantification for recovery, support for termination, referral for prosecution, an insurance claim, or all four. They require different evidence, and the objective determines the procedures.
The distinction that determines whether the ledger can help you at all.
On-book schemes leave a trace in the accounting records: a false vendor is paid, a check is written, a journal entry conceals it. The records contain the evidence, and analytical testing works.
Off-book schemes — most commonly skimming, where cash or a payment is taken before it is ever recorded — leave no trace in the ledger, because the transaction never entered it. No amount of general ledger analysis finds them.
Off-book schemes are found instead by comparing the records to something outside them: shipping records against sales, inventory against recorded cost of sales, register tapes against deposits, customer statements and complaints, deposit composition over time, gross margin trends, and the customer who insists they paid an invoice the system shows as open.
Knowing which category you are in is the first analytical decision, and it is the one that stops a team from spending three weeks in a general ledger that cannot contain the answer.
Billing schemes — fake vendors and inflated invoices — tend to produce the largest losses, because they scale in a way that petty theft does not. The corresponding tests are specific and cheap:
Vendor master analysis. Compare vendor addresses to employee addresses in the payroll master. Look for vendors with a PO box or a residential address, vendors sharing a bank account with an employee, vendors with no phone number or website, vendors added recently that immediately received large payments, and vendors whose name closely resembles a legitimate vendor's.
Payments just under approval thresholds, which is the fingerprint of someone who knows the approval limits.
Round-dollar payments, which are unusual in genuine commerce.
Duplicate payments — same vendor, same amount, near dates — which finds both fraud and error.
Sequential or unusual invoice numbering from a single vendor, indicating the vendor invoices nobody else.
Payments to vendors with no purchase order or receiving record.
Vendor activity by the person who can create vendors, which is the segregation question in a single query.
Journal entry analysis. Entries posted by the person who also reconciles the account; entries posted at odd hours or on non-business days; entries to suspense, clearing, or miscellaneous accounts; entries with no or generic description; entries that reverse shortly after a period closes; and manual entries to accounts that are normally system-generated.
Bank reconciliation review. The reconciliation prepared and reviewed by the same person is the enabling condition for most schemes. Examine outstanding items that persist, unexplained adjusting entries, and — importantly — whether anyone independent has ever compared the reconciliation to the actual bank statement rather than to a printout supplied by the preparer.
Payroll tests. Employees with no deductions or withholding; duplicate direct deposit accounts across employees; employees added and terminated within a period; overtime concentrated in one approver's area; and terminated employees still receiving pay.
Expense reimbursement patterns. Amounts just under receipt thresholds, duplicate submission across periods, weekend and personal-location charges, and a claimant whose volume is out of line with peers. The expense reimbursement rules session covers the control side of this.
Credits, voids, refunds, and write-offs, by employee. In a cash environment these conceal skimming; in receivables they conceal lapping.
Digital analysis — including Benford's law on payment populations — is useful as a screening technique to direct attention, not as evidence of anything by itself.
Structured method is covered in the fraud examination course, the Certificate in Forensic Accounting, and the forensic accounting training courses catalog. Payroll-specific schemes are treated in how to prevent payroll fraud.
The person who does this is generally not the person a client is watching for.
They are usually long-tenured and trusted, often the single most indispensable person in the finance function, frequently with no prior record — which is why background checks do not prevent this — and commonly working alone in a role where nobody else understands the process.
The behavioural indicators that actually correlate:
They never take vacation, and resist anyone covering their duties. An ongoing scheme usually requires continuous maintenance.
They insist on handling one thing personally — the mail, the bank statement, one vendor relationship, the reconciliation.
Lifestyle exceeds known income.
They are defensive about their area and resistant to review or systems change.
They are extremely helpful, taking on additional duties that happen to consolidate incompatible functions.
Our post on the fraud triangle covers the pressure-opportunity-rationalization framework; the operational point here is that opportunity is the only leg management controls, and it is controlled by breaking up the tasks one person performs.
If a client asks for one thing, it is this pair:
Mandatory time away, with duties actually performed by someone else. Not a vacation policy — a requirement that another person does the work while they are gone. A large proportion of these schemes are discovered exactly this way, because the maintenance stops.
Someone other than the preparer receives and opens the bank statement, and reviews it against the reconciliation.
Neither costs anything. Both are absent in nearly every case.
Supporting controls: dual authorization above a threshold, no vendor creation by anyone who processes payments, positive pay, restricted signature authority, review of the vendor master for changes, and an owner who periodically looks at the bank activity directly. Our post on internal controls covers design; in small entities the honest answer is that segregation is impossible and owner involvement substitutes for it.
The most avoidable loss in the whole sequence.
Fidelity bond and employee dishonesty coverage typically requires notice within a defined period after discovery, and imposes conditions on documentation and cooperation. Employers routinely spend two months investigating quietly before telling anyone — and then find the claim denied for late notice, having established the loss beautifully and lost the recovery.
Notify the carrier as early as the policy requires, before the investigation is complete, and read the policy's definition of discovery. Related points: an employee allowed to resign with no documented finding often cannot support a claim, and some policies require that the employer pursue the matter rather than settle privately.
Do not conduct an admission-seeking interview because you are the accountant who found it.
Those interviews are a trained skill with legal exposure attached — coercion allegations, false imprisonment claims, employment law issues, and, where prosecution is contemplated, the risk of rendering an admission useless. Sequence them with counsel: informational interviews with peripheral witnesses first, the subject last, with a second person present and a contemporaneous record.
Quantify by scheme and period, tied to source documents, with a schedule that a third party can follow — because it will be read by an insurer, a lawyer, possibly a prosecutor, and possibly a jury. Extrapolation may be appropriate for a sampled population but must be labeled as an estimate and never blended into the documented figure.
Then the client decides, on advice: termination, civil recovery, an insurance claim, restitution agreement, or criminal referral — and these interact. A quiet restitution deal can foreclose the insurance claim; a criminal referral takes control of the timeline away from the client; civil recovery depends on whether the money still exists.
That decision belongs to the client and counsel. The accountant's contribution is a documented, defensible number and a clear account of how the scheme worked — which is also what prevents the next one, because the control that failed is now named. Related credentials sit in the fraud and forensic accounting catalog and the Forensic Certified Public Accountant designation.
If your firm performed an audit, review, or compilation for this client, expect the question: why didn't you find it?
The professional answer is that an audit is not designed to detect all fraud, that a compilation and a review provide substantially less, and that concealed, collusive, or management-override schemes can escape a properly performed engagement. That answer is correct — and it is far more persuasive when the file shows that fraud risk was considered, that the specific control weakness was identified, and that it was communicated in writing to the client. Where it was, the conversation is short. Where the weakness was noticed and mentioned verbally, it is not.
The summary for the accountant who just got the call: say nothing to the suspect, get counsel to engage you before you look at anything, preserve the data and the backups with a documented chain of custody, tell the insurer immediately, and establish first whether the scheme is on-book or off-book — because that decides whether the ledger holds the answer or whether you need to compare it to the world outside it.
Not confront the suspect. Engage counsel and have counsel engage the accountant so the work may be privileged, preserve systems and accounting data including prior backups with a documented chain of custody, establish who has access to what, and notify the insurer. Confrontation ends the flow of evidence and creates employment law exposure.
It forfeits the documentation needed to support recovery, it usually voids the fidelity bond claim — many policies require the employer to pursue rather than settle privately — and it sends an unwarned employer their next embezzler. It is the most common employer decision and the most damaging.
On-book schemes leave a trace in the accounting records, so analytical testing of the ledger works. Off-book schemes — most commonly skimming, where money is taken before it is ever recorded — leave no trace, and are found only by comparing the records to something outside them: shipping records, inventory, register tapes, deposit composition, customer complaints, and margin trends.
Vendor-focused ones, since false-vendor billing scales. Compare vendor addresses to employee addresses, look for vendors with residential addresses or no phone, shared bank accounts, new vendors receiving immediate large payments, payments just under approval thresholds, duplicate payments, and vendor activity performed by whoever can create vendors.
Mandatory time away with the duties actually performed by someone else — because an ongoing scheme usually needs continuous maintenance, and it surfaces when the maintenance stops. Paired with having someone other than the preparer receive and open the bank statement, it costs nothing and is absent in nearly every case.
Fidelity bond and employee dishonesty policies generally require notice within a defined period after discovery. Employers commonly investigate quietly for weeks first and then find the claim denied for late notice — having documented the loss perfectly and lost the recovery. Notify the carrier before the investigation is complete, and read the policy's definition of discovery.


