Fraud and internal control: a practical early warning system

15 control points for payments, suppliers, accounting records, and digital access

An internal control system should not address the question “Do we trust our employees?” but rather “Can we trace the path of a material transaction and prove who initiated, approved, executed, and recorded it?” This approach protects both the company and its honest employees. It is especially important in the context of fast payments, remote work, ERP integration, and online banking.

1. The Risk Model: Opportunity, Pressure, and Justification

Fraud often becomes possible when there is a weak separation of duties, limited management oversight, or the ability to conceal the trail of a transaction. Therefore, an effective system focuses on reducing opportunities for fraud through independent approval, logging of actions, reconciliations, and exception analysis.

Controls should not be based on a presumption of guilt. Their purpose is to make the process verifiable and reduce reliance on any single individual.

2. Screening a New Supplier

The creation of a supplier record must include an initiator and independent verification. Legal information, the contractual basis, bank details, and the validity of the goods or services are verified. For significant counterparties, it is helpful to document the source of the verification.

Pay special attention to suppliers created immediately before a payment is made.

3. Change in Bank Account Information

Any change to the IBAN must be confirmed through a previously established independent channel. A reply to the same email in which the request was sent does not constitute independent verification. For large amounts, a second confirmation is recommended.

The change log should include the date, the initiator, the verifier, and the method of confirmation.

4. Separation of Powers

The ideal setup: one employee initiates a payment, another approves it, and a third processes it, with each step recorded separately. In practice, however, the size of the company may not allow for a complete separation of duties. In such cases, the director or owner performs compensating controls—for example, a weekly review of banking transactions and new suppliers.

5. Payments just below the limit

If additional approval is required—for example, for amounts exceeding a set internal threshold—it is worth analyzing payment series that fall just below that threshold. Splitting a single obligation into multiple payments may be economically justified, but it must be explained.

6. Manual Accounting Entries

Manual entries are especially important at the end of the month and the year. An audit report may highlight large amounts, unusual invoices, entries made outside of business hours, users with administrative privileges, and transactions without a standard basis.

Every material adjustment must have a clear economic rationale and supporting documentation.

7. Bank Reconciliations

A reconciliation should not merely bring two balances to the same figure, but should explain every discrepancy. Old outstanding items, unknown write-offs, or recurring adjustments are grounds for an investigation.

Strong controls are in place when one employee prepares the reconciliation and another reviews it.

8. Accounts Receivable and Returns

Unusual debt write-offs, credit memos, refunds, and post-sale changes to terms and conditions can be used to conceal errors or fraud. It is helpful to analyze transactions involving customers with a large number of adjustments and compare them with the terms of the contract.

9. Inventory and Physical Inventory Counts

For companies with inventory, physical inventory counts remain a critical control. Discrepancies should be analyzed by cause, warehouse, and responsible personnel. Recurring write-offs in the same category require special attention.

10. Access Rights

The principle of least privilege means that users are granted only the functions they need to perform their jobs. Shared accounts and shared passwords reduce traceability. Upon termination or a change in role, access must be revoked or revised promptly.

11. Administrator Rights and ERP

Since an administrator can technically change settings, configuration changes must go through a request, testing, and business approval process. A change log is useful for critical reference tables.

Automation amplifies both good and bad processes: an erroneous rule could be applied to thousands of operations.

12. Time-Limited Exceptions

Sometimes businesses really do need to deviate from standard procedures. Instead of imposing a ban, create a controlled exception: specify the reason, who authorized it, the maximum amount, the deadline for submitting documents, and the follow-up verification.

The danger arises when an exception becomes the norm.

13. Behavioral Signals in the Process

This is not about an employee’s personal characteristics, but rather about process-related red flags: reluctance to delegate responsibilities, failure to take time off from a critical role, consistent delays in submitting documents, resistance to independent verification, and the use of personal communication channels instead of corporate ones.

Each of these red flags has many legitimate explanations, so they serve as a reason to review the process, not as an accusation.

14. The Role of External Auditing

The Ministry of Finance states that audits of financial statements are conducted in accordance with the International Standards on Auditing adopted for use in Moldova and are intended to enhance confidence in financial information. However, an external audit does not replace day-to-day internal controls.

Management is responsible for a system that prevents and promptly detects violations.

15. Quarterly Checklist

Review new vendors; changes to bank account information; payments that exceed or fall just below internal limits; manual journal entries; bank reconciliations; old accounts receivable and accounts payable balances; inventory write-offs; credit memos and returns; ERP and bank users; administrative privileges; exceptions to procedures; and the status of recommendations from previous audits.

16. How to Measure the Effectiveness of Oversight

Each control must have an owner, a frequency, and evidence of completion. For example: “Bank reconciliation—monthly—prepared by the accountant—reviewed by the CFO—evidence: signed file.” Without these four elements, a procedure often remains merely a formality.

For key controls, you can track the percentage completed on time and the number of unresolved exceptions.

17. Action Plan for When a Problem Is Identified

First, preserve the documents and digital evidence, mitigate further risk, and identify those responsible for the internal audit. Do not prematurely alter data or delete accounts without preserving the necessary information. Further legal, human resources, and financial actions depend on the circumstances and must be coordinated with the appropriate specialists.

18. Conclusion

Professional internal control is not about the maximum number of signatures. It involves a few well-chosen control points that actually work, leave a paper trail, and are commensurate with the risk. For a modern company, controls over payments, digital access rights, and exceptions are particularly important.

The AUDIT-EXACT practical principle: for each key risk, identify one preventive control and one detective control. For example: an IBAN change is verified before payment, and the list of changed account details is additionally analyzed on a monthly basis.

Sources and Regulatory Framework

  • Ministry of Finance of the Republic of Moldova: “Audit of Financial Statements” section; Law No. 271/2017; International Standards on Auditing and the International Code of Ethics, published in the official legislation section.

Editor’s Note: This article is intended for general informational purposes only. Specific obligations and accounting conclusions must be determined based on the current version of the law and the actual circumstances of a particular organization.