The fraud triangle is taught as three words and used as a checklist, which wastes it. Its actual value is as a diagnostic that tells you where you have leverage — because an organization's ability to influence the three legs is wildly unequal.
Pressure is largely private. An employee's debt, medical crisis, addiction, or divorce is invisible to the employer and none of the employer's business until it produces behavior.
Rationalization can be influenced, slowly, through culture and through how the organization treats its own rules.
Opportunity is the only leg an organization controls directly.
Which is why every practical fraud program is fundamentally about opportunity — and why "hire good people" is not a control.
The motivation to commit the act. Categories that recur in real cases:
Financial pressure — debt, medical expenses, a family member's crisis, addiction, gambling, divorce, or a failed outside business. This is the most common source and the least visible.
Lifestyle maintenance. Not a crisis but a standard of living the person cannot sustain on their compensation, frequently one they acquired gradually.
Work pressure — an unrealistic target, a bonus threshold, or the fear of failing publicly.
And the one people forget: pressure to meet a legitimate business goal. This is what drives financial statement fraud rather than theft. A covenant that will be breached, an earnout that will be missed, a forecast given to a lender or an investor, a loss that would trigger a consequence. The person committing it frequently takes nothing personally and believes they are protecting the organization — which is precisely why it is harder to detect and more damaging.
The control weaknesses that make it possible, plus two multipliers organizations consistently underestimate:
Long tenure in the same role. Someone who has performed a function alone for many years knows exactly where the gaps are, has established that nobody checks, and has usually built a reputation that makes questions feel insulting.
A position nobody questions. The trusted bookkeeper, the founder's relative, the executive whose numbers are accepted. Authority is an opportunity multiplier, which is why controls that exempt senior people are not controls.
The structural weaknesses themselves are covered in our post on designing internal controls: absent segregation, no independent review, complexity that obscures, unrestricted access, and no rotation or mandatory coverage.
The narrative that lets a person who does not consider themselves dishonest act dishonestly. The recurring ones, and each is a diagnosis of something:
"I'm only borrowing it." The most common, and the reason many frauds start small and escalate — the person genuinely intends repayment, cannot repay, and continues.
"I'm underpaid for what I do." Points at a compensation or recognition problem, and it is worth noting that a person who believes this is frequently correct about the recognition part.
"The company can afford it." Common in profitable organizations and in those seen as impersonal.
"Everyone does it." The most dangerous, because it is usually a report on the culture. Where expense padding, personal use of company resources, or minor rule-breaking is normalized and unaddressed, the boundary has already moved.
"They treated me badly." Frauds frequently begin after a perceived injustice — a passed-over promotion, a disciplinary action, a demotion.
A fourth element some frameworks add — capability. Pressure, opportunity, and rationalization explain motivation; capability explains execution. The person must be positioned to do it, competent enough to conceal it, confident enough to sustain the deception, and able to handle the stress of maintaining it. This is why the most damaging frauds are committed by capable, senior, trusted people rather than by the most desperate ones.
Occupational fraud sorts into three categories whose frequency and cost run in opposite directions — a pattern worth understanding because it dictates where to spend effort.
Asset misappropriation is by far the most frequent and the least costly per incident. Cash skimming, larceny, fraudulent disbursements, billing schemes, payroll schemes, expense reimbursement fraud, check tampering, and inventory theft. This is what most small entity fraud is.
Corruption — bribery, kickbacks, illegal gratuities, conflicts of interest, bid rigging — sits between the two on both dimensions, and it is the category most often invisible in the accounting records, because the transaction itself frequently looks normal. The loss is in the terms, not in a missing amount.
Financial statement fraud is the least frequent and by a wide margin the most costly. Improper revenue recognition, understated liabilities, overstated assets, improper estimates, and concealed related-party transactions.
The practical implication: a small organization should concentrate on asset misappropriation controls, because that is what will happen to it. A larger organization with covenants, incentives, and external expectations must also address financial statement fraud, because the pressure leg exists there in a way it does not at a five-person business.
Detection differs by category, and one finding applies across all of them.
Tips detect more occupational fraud than audits do. This is consistently the most common detection method across studies of the subject, and it has a direct programmatic consequence: a functioning reporting channel is the highest-return fraud control available, ahead of any analytic or audit procedure. Organizations spend on detection technology and neglect the mechanism that finds the most.
For asset misappropriation: the bank statement reviewed by someone outside accounting, independent reconciliation review, vendor and employee master data matching, duplicate payment analysis, surprise counts, and the analytics described in our post on audit data analytics.
For corruption: vendor-level analysis rather than transaction-level — sole-source awards, pricing that diverges from market, a vendor whose share of spend grew without a competitive process, split purchases just below approval thresholds, and unusual concentration of a buyer's spend with one supplier. Plus conflict-of-interest disclosure that is actually collected and checked, and attention to lifestyle indicators in purchasing roles.
For financial statement fraud: journal entry interrogation, estimate patterns across periods, disaggregated analytics, and — critically — monitoring the pressure indicators. A covenant approaching breach, an earnout period ending, a bonus threshold within reach, or a pending transaction are all reasons to increase scrutiny, and they are knowable in advance.
Given that tips find the most fraud, the channel deserves more attention than it usually gets. What makes one work:
Anonymity available, genuinely, without a technical trail that defeats it.
Multiple routes, including at least one that bypasses the person a report might concern. A single channel routing to the controller is useless for reporting the controller.
Accessible to third parties, since vendors and customers observe things employees do not.
Non-retaliation stated and demonstrably honored. One retaliation incident ends the channel's usefulness permanently, whatever the policy says.
Publicized repeatedly. A channel nobody remembers exists is not a channel.
Triaged on a schedule by a named person, with a defined process for assessment, escalation, and documentation. Reports arriving into an unmonitored mailbox are worse than no channel, because the organization now has notice it did not act on.
Feedback to the reporter where possible, since a channel that swallows reports silently teaches everyone not to use it.
Indicators with genuine observational value, worth training managers to notice:
Living visibly beyond apparent means; known financial difficulties; an unusually close relationship with a vendor or customer; unwillingness to share duties or to be covered; refusal to take vacation; irritability or defensiveness at routine questions; working unusual hours alone; addiction or gambling indicators; and a marked change in behavior or circumstances.
The caution matters. These are prompts for professional attention to controls and transactions, not grounds for accusation, and most people displaying them are not committing fraud. Managers trained to notice indicators should be trained equally clearly on what to do — which is to raise it through a defined channel, not to investigate, confront, or speculate to colleagues.
The section most often missing from fraud material, and the point at which organizations do the most damage to their own position.
Do not confront the suspect. The instinct is powerful and it is wrong. Confrontation destroys evidence, allows concealment, invites a resignation that ends your access, and can create legal exposure.
Do not tip anyone off, including well-meaning colleagues.
Restrict access quietly — to systems, records, and the areas in question. This has to be done in a way that does not itself alert the person, which usually means involving IT under confidentiality rather than announcing a change.
Preserve evidence immediately. Suspend routine destruction, preserve email and system logs before retention cycles delete them, secure original documents, and document the chain of custody. Digital evidence is the most easily lost and the most easily challenged.
Involve counsel early, before interviews and before external communication. Privilege, employment law exposure, and the interaction with any eventual prosecution all argue for counsel being in the room from the start rather than being called to repair something.
Check the insurance notice requirement. Fidelity bonds and crime policies commonly require notice within a short period after discovery or suspicion, and late notice can void coverage. This is the deadline organizations most often miss while they are deciding what to do, and the recovery at stake frequently exceeds anything else available.
Decide the objective before acting. Recovery, termination, insurance claim, referral for prosecution, and quiet resolution are different objectives requiring different approaches, and pursuing them in the wrong order forecloses options. An interview conducted before the evidence is assembled, for example, may make a later claim or prosecution considerably harder.
Plan the interview — who conducts it, whether counsel or a qualified investigator should, what is asked, whether it is recorded, and what the employee's rights are. Interviewing well is a skill, and the internal investigation training and certification material covers it.
Consider whether a qualified forensic accountant is warranted, which for any material matter it usually is.
Structured coverage is available through the Certificate in Forensic Accounting, Fraud Examination, the fraud and forensic accounting training catalog, the forensic accounting courses listing, the Forensic Certified Public Accountant designation, and internal auditing training.
A small organization cannot implement most of this, and it does not need to. Four things carry most of the benefit:
The owner reviews the bank statement and cleared items, unopened, on a schedule.
Vendor additions and bank detail changes require the owner's approval.
Someone other than the bookkeeper opens the mail and logs receipts.
A way for an employee to raise a concern that does not go through the person they might be reporting — which at a five-person business may simply be the owner's direct line, stated explicitly and used without consequence.
Those four, performed consistently, address the great majority of what actually happens to small organizations.
The most useful single takeaway: you control opportunity, and tips find more than audits do. An organization that closes the specific opportunities its processes create, and gives people a safe route to report what they notice, has done most of what is available — and one that invests in detection technology while leaving the reporting channel unbuilt has skipped the highest-return control there is.
Opportunity. Pressure is largely private and invisible to the employer, and rationalization can only be influenced slowly through culture and through how consistently the organization enforces its own rules. That is why practical fraud programs are fundamentally about closing opportunities, and why "hire good people" is not a control.
Tips, consistently more than audits do. That has a direct programmatic consequence: a functioning reporting channel — anonymous, with multiple routes including one that bypasses the person a report might concern, publicized, and triaged by a named person on a schedule — is the highest-return fraud control available.
Their frequency and cost run in opposite directions. Asset misappropriation is most frequent and least costly per incident, financial statement fraud is least frequent and most costly, and corruption sits between — and is often invisible in the records, because the loss is in the transaction's terms rather than in a missing amount.
Pressure to meet a legitimate business goal: a covenant about to be breached, an earnout that will be missed, a forecast given to a lender, or a bonus threshold. The person frequently takes nothing personally and believes they are protecting the organization, which makes it harder to detect and more damaging — and it means the pressure indicators are knowable in advance and should trigger increased scrutiny.
Not confronting the suspect. Restrict access quietly, preserve evidence including email and system logs before retention cycles delete them, document chain of custody, involve counsel before any interview, check the insurance notice deadline — fidelity and crime policies often require notice shortly after discovery and late notice can void coverage — and decide the objective before acting, since recovery, termination, insurance, and prosecution require different sequences.
Four things carry most of the benefit: the owner reviews the bank statement and cleared items unopened on a schedule; vendor additions and bank detail changes require the owner's approval; someone other than the bookkeeper opens the mail and logs receipts; and there is a way to raise a concern that does not route through the person being reported — which at a small business may simply be the owner's direct line, stated explicitly and used without consequence.


