10 Top employee frauds: types, red flags and the controls that stop them

Most employee fraud is not dramatic. It is a supplier that only one person ever deals with, an expense claim nobody checks, or an onboarding approval given because the customer was in a hurry.
In the ACFE's Occupational Fraud 2026: A Report to the Nations, the median scheme ran for 12 months before anyone noticed, and more than half of all cases involved either a lack of internal controls or the override of controls that already existed.
This guide sets out the ten most common types of employee fraud, the warning signs that usually appear first, and the controls that reduce exposure, including what employee fraud means for regulated businesses in the UAE and Saudi Arabia.
Types of Employee Fraud - Key Takeaways |
|
|
|
|
|
|
|
|
What is employee fraud?
Employee fraud is using a position inside an organisation for personal gain through deception, misuse of assets, or abuse of authority. It covers stealing money or property, falsifying records to obtain a benefit, taking payments from third parties in exchange for decisions, and deliberately bypassing controls to hide any of the above.
Two things sit outside the definition. Honest mistakes are not fraud, however expensive. Poor performance is not fraud either.
The distinguishing feature is intent: the person knew what the process required and chose to work around it.
For banks and other financial institutions, the same conduct has a second name.
Under the Basel Committee's operational risk framework, internal fraud is a formal loss event type, covering acts intended to defraud, misappropriate property, or circumvent regulations, the law or company policy, where at least one internal party is involved. That last phrase matters, and we return to it below: circumventing a control is itself the event, not just the route to one.
Employee fraud, internal fraud, occupational fraud, insider fraud: what is the difference?
In practice, these terms describe the same conduct. They differ mainly by professional context, and knowing which one your audience uses makes conversations with auditors, risk teams and regulators considerably easier.
Term | Who uses it | What it covers |
Employee fraud | Business, HR, finance | Fraud committed by staff against their employer |
Occupational fraud | Fraud examiners, the ACFE | The same conduct, across all levels including owners and executives |
Internal fraud | Banking, operational risk, regulators | A formal loss event category, used for risk reporting and capital purposes |
Insider fraud | Fraud and security teams | Often used where data, systems or access are the main asset at risk |
How is employee fraud different from management fraud?
The schemes overlap; the scale does not. The ACFE's 2026 study found that employees and managers each committed fraud in 41% of cases, and owners or executives in 16%.
But median losses caused by owners and executives were more than nine times greater than those caused by employees.
Authority changes severity rather than frequency. Senior people can approve their own exceptions, instruct others, and suppress the reporting that would otherwise surface the problem. A control framework that only watches junior staff will catch the common cases and miss the expensive ones.
Is employee theft the same as employee fraud?
Theft is one route into fraud, not the whole of it. Taking stock from a warehouse is theft. Creating a supplier that does not exist and paying it is fraud without anything being physically removed.
The practical difference is the control: theft is usually addressed by physical and stock controls, fraud by process design, approval separation and record-keeping.
How common is employee fraud, and what does it cost?
The ACFE estimates that organisations lose around 5% of annual revenue to occupational fraud each year. Its 2026 study analysed 2,402 real cases across 143 countries, with total losses of more than USD 3.4 billion, a median loss of USD 104,000 per case and an average exceeding USD 1.4 million. The median scheme lasted 12 months before it was detected.
The more useful finding, though, is the inversion between how often a scheme happens and how much it costs.
Category | Share of cases | Median loss | Typical schemes |
Asset misappropriation | 90% | Lowest of the three categories | Billing, payroll, expenses, skimming, payment tampering, theft of assets |
Corruption | 45% | Between the other two | Bribery, kickbacks, undisclosed conflicts of interest |
Financial statement fraud | 6% | Around USD 1 million | Revenue inflation, concealed liabilities, period-end manipulation |
Read together with duration, this tells you where to spend effort. Fraud detected within the first six months had a median loss of USD 40,000.
Schemes that ran for more than five years produced median losses above USD 1.1 million. Detection speed, not scheme type, is the variable that determines cost.
All figures in this section are from the ACFE's Occupational Fraud 2026: A Report to the Nations. Percentages exceed 100% because a single case often involves more than one category.
What are the 10 most common types of employee fraud?
Almost all employee fraud falls into three families: taking something that belongs to the organisation, using the position to obtain a benefit from outside it, or misstating records to conceal either.
The ten schemes below are the specific forms those families take. The first eight follow the standard occupational fraud taxonomy; the last two reflect how insider risk now presents in digital and regulated businesses.
Scheme | How it works | One early red flag | Primary control |
Billing schemes | Payments to a fake or complicit supplier | A vendor only one person deals with | Separate vendor setup from payment approval |
Payroll fraud | Ghost employees, inflated hours or pay | Two staff sharing bank details | Reconcile payroll to HR records |
Expense fraud | Personal or inflated claims reimbursed | Round-number, receipt-free claims | Risk-based sampling, not blanket approval |
Skimming and cash larceny | Cash taken before or after recording | Unexplained till or float variances | Independent reconciliation, surprise counts |
Payment tampering | Altered instructions or unauthorised transfers | Payee changed after approval | Locked payment files, callback verification |
Theft of non-cash assets | Stock, devices, fuel, company property | Frequent write-offs and adjustments | Stock reconciliation, exception reporting |
Corruption and kickbacks | Payments for favourable decisions | A supplier that always wins tenders | Conflict declarations, tender controls |
Financial statement fraud | Results deliberately misstated | Unusual period-end entries | Independent review, audit committee |
Theft of customer data | Records taken, sold or misused | Bulk exports outside normal duties | Least-privilege access, access logging |
Abuse of compliance controls | Checks skipped, alerts suppressed | Alerts closed with no rationale | Separate investigation from approval |
1. Billing schemes and fake vendors
An employee creates a supplier that does not exist, or works with a real one, and arranges payments for goods or services that were never delivered. Variants include inflated invoices, duplicate submissions, and personal purchases routed through a genuine vendor account.
Billing schemes are among the common types of employee fraud and also the most damaging when you weigh frequency against loss, because they look exactly like normal business.
The invoice is well formed, the approval exists, and the payment reconciles.
The failure is almost always structural: the same person onboards the vendor, receives the invoice and approves the payment.
Separate vendor creation from payment approval, run duplicate-payment and round-number testing, and treat any change to a supplier's bank details as a controlled event requiring independent verification with a known contact.
2. Payroll fraud
Payroll fraud covers ghost employees added to the payroll, inflated hours or overtime, unauthorised salary or commission changes, and payments that continue after someone has left. It runs quietly because payroll is confidential, which means fewer people look at it.
The classic version is the ghost employee: a fictitious record, or a real leaver kept active, with payments directed to an account the perpetrator controls.
Effective controls are mechanical, not clever. Reconcile the payroll file to HR joiners and leavers every cycle. Test for duplicate bank account numbers, addresses and contact details across employee records.
Require an independent approver for any change to pay, bank details or headcount, and review overtime outliers by manager rather than by employee.
3. Expense reimbursement fraud
Staff submit personal costs as business expenses, inflate genuine ones, duplicate claims across expense and card systems, or alter receipts.
Individually, the amounts are small, which is precisely why the schemes survive: approving managers do not want to challenge a colleague over a taxi fare.
Expense fraud is also the most common entry point into more serious conduct. Someone who has quietly inflated claims for two years has already established that nobody checks.
Blanket approval is the problem, not the solution. Build policy limits into the submission workflow so out-of-policy claims cannot simply be waved through, sample a proportion of claims properly rather than reviewing all of them superficially, and reconcile corporate card statements against submitted claims to catch duplicates.
4. Cash skimming and cash larceny
The two are often confused, and the distinction determines which control works.
Skimming removes cash before it is recorded: an unregistered sale, a payment taken and never entered. Larceny removes cash after it has been recorded, which leaves a discrepancy.
Larceny shows up in reconciliation. Skimming does not, because there is nothing to reconcile against: the transaction never entered the system.
For larceny, independent daily reconciliation and surprise cash counts are effective. For skimming, you need indirect indicators:
unusual patterns of voided or no-sale transactions
gross margin drift in a single location or shift
customer complaints about receipts
comparison of one cashier's ratios against peers doing the same job
5. Cheque and payment tampering
Historically, this meant forged or altered cheques. In most businesses today, it means altered payment instructions: a beneficiary changed after approval, an amended payment file uploaded to the bank, or a transfer initiated using another person's credentials.
Tampering is comparatively rare but expensive, and it depends on a window between approval and execution in which the instruction can still be changed.
Close the window. Payment files should be locked once approved, with any subsequent change forcing re-approval.
Bank-detail changes should be verified by callback to a contact held on file, never to a number supplied in the instruction itself.
Credentials must not be shared, and system logs should show who initiated, who approved and who released every payment.
6. Theft and misuse of non-cash assets
A top employee fraud: why? Because it targets company stock, equipment, devices, fuel, materials and consumables; all leave the business without cash ever moving.
Misuse belongs in the same category: company vehicles, software licences or premises used for personal or side-business purposes.
Theft of non-cash assets is one of the more significant risks when frequency and loss are considered together, and it is frequently concealed within legitimate-looking adjustments.
Look at the concealment rather than the theft. Unusually frequent write-offs, damage claims, stock adjustments or returns processed by the same person are the signal.
Require independent approval for adjustments above a threshold, rotate who performs stock counts, and reconcile asset registers rather than assuming they are accurate.
7. Corruption: bribery, kickbacks and conflicts of interest
Corruption appeared in 45% of ACFE 2026 cases, a substantial rise over the past three decades. It covers accepting payments to steer a decision, receiving a share of an inflated contract value, and undisclosed personal interests in a supplier, customer or counterparty.
Corruption differs from the other schemes in one important way: the organisation may suffer no visible loss. The invoice is paid, the goods arrive, the service is delivered. The loss is embedded in a price that should have been lower or a decision that should have gone elsewhere.
Because there is no discrepancy to find, controls have to be preventive: annual conflict-of-interest declarations that are actually read, genuine competitive tendering with an independent evaluator, due diligence on third parties, and a gifts and hospitality register with defined thresholds.
Related content: What is PEP screening?
8. Financial statement fraud
Revenue is recognised early or invented, liabilities and expenses are concealed, reserves are manipulated, or assets are overstated. It appeared in just 6% of cases in the 2026 study but carried the highest median loss, around USD 1 million.
This is predominantly a management-level scheme, because it requires the authority to instruct accounting treatment and the standing to discourage challenge. Pressure is a common driver: covenant thresholds, bonus targets, investor expectations.
Segregation of duties will not address it, because the people involved sit above the process. The controls that matter are governance controls:
an audit committee with genuine independence
external audit with unrestricted access
analytical review of unusual period-end entries
manual journals, a route for finance staff to raise concerns that does not pass through the person they are concerned about.
9. Theft and misuse of customer data
Employees with legitimate access sometimes steal sensitive data, such as customer lists, account details, identity documents, and transaction histories. They may then sell this information, share it with competitors, take it to a new employer, or use it to commit fraud, such as account takeovers.
This is the point where insider and external fraud meet. Many account takeover and social engineering attacks work because someone inside supplied the detail that made the approach credible.
Access is the control. Apply least privilege, so staff can see only the records their role requires.
Review entitlements whenever someone changes role, not only when they leave. Log and alert on bulk exports, unusual search volumes and access to records with no related case or transaction.
For regulated firms, this overlaps directly with data protection obligations, which are assessed separately.
Read also: Methods of stealing identity
10. Abuse of compliance controls: onboarding override, alert suppression and tipping off
In a regulated business, there is a tenth top employee scheme that rarely appears in general fraud guidance, and it is the one with consequences beyond the loss itself.
It includes approving a customer without completing client due diligence, forcing a screening match to "no match" without proper review, closing monitoring alerts without investigation, back-dating records to pass an audit, and warning a customer that they are being reviewed or reported.
Sometimes the motivation is straightforward corruption. More often it is commercial pressure: a valuable client, a sales target, a relationship manager who wants the account open by Thursday.
The consequence is different in kind. These acts can constitute regulatory breaches in their own right, independently of whether the organisation lost money. Tipping off, in particular, is a specific offence in most AML regimes.
Controls should ensure that the person who investigates an alert is not the person who closes it, that overrides require documented senior approval, and that every approval, exception and alert closure is logged with a rationale that someone else can review.

What does employee fraud look like in different industries?
The schemes are universal; the exposure is not:
A bank's insider risk concentrates in account access and payment authority.
A real estate business's risk concentrates in client funds and transaction records.
Designing controls against a generic list, rather than against your own exposure, is how organisations end up well protected against risks they do not have.
Industry | Highest-exposure schemes | Where the control usually fails |
Banking | Unauthorised account access, payment tampering, onboarding override, data theft | Entitlements never reviewed after internal moves |
Fintech and payments | Onboarding override, collusion with mule account networks, refund and chargeback abuse | Speed of onboarding prioritised over control evidence |
Exchange houses and money services | Skimming, structuring on behalf of customers, unrecorded transactions | Branch cash handled and reconciled by the same staff |
Real estate | Misuse of client funds, undisclosed commissions, falsified buyer documentation | Source of funds checks treated as paperwork, not control |
Law firms | Client account misuse, billing manipulation, conflicts not declared | Partner-level activity subject to little independent review |
Asset and fund managers | Undisclosed related-party dealings, expense allocation, investor onboarding shortcuts | Valuation and approval concentrated in a small team |
If you want the banking view in more depth, see our guide to fraud detection in banking.
Fraud committed from outside the organisation, phishing, business email compromise, vendor impersonation, is covered separately in our overview of the types of business fraud.

What are the warning signs of employee fraud?
Warning signs fall into three groups: behavioural, transactional and process.
The ACFE found that 84% of perpetrators displayed at least one behavioural red flag before detection, meaning the signals are usually present and missed.
Before the lists, one essential qualification. A red flag is a reason to look, not evidence that someone has done anything wrong.
Most people showing any single indicator below have done nothing at all.
Treating an indicator as proof creates its own legal, employment and reputational risk, and it destroys the trust that makes staff willing to report genuine concerns.
Behavioural indicators
Living visibly beyond known income
Unwillingness to take leave or to share responsibilities
Unusually close, exclusive relationships with particular suppliers or customers
Defensiveness about routine questions on their own area of work
Known financial pressure, where the organisation is already aware of it
Transactional indicators
Payments just below an approval threshold
Suppliers sharing an address, bank account or contact detail with an employee
Unexplained variances, write-offs, voids or adjustments concentrated with one person
Activity clustered at period end or outside normal working hours
Round-number or duplicated claims and invoices
Process indicators
Repeated use of override or exception routes by the same person
Reconciliation performed by whoever records the transactions
Screening or monitoring alerts closed with no recorded rationale
Vendor or payroll bank details changed without independent verification
A process that only one person understands, and that nobody has audited
Read also: AML red flags
How is employee fraud usually detected?
Not by audit. In the ACFE's 2026 study, tips were the leading detection method, accounting for 43% of cases, with more than half of those tips coming from employees.
Internal audit and management review followed. Notably, email and web-based reporting channels have now overtaken telephone hotlines as the most common way concerns are raised.
The reason is simple. Colleagues see what the ledger cannot: the supplier nobody else deals with, the approval that felt wrong, the reconciliation that the same person always does.
Training changes the numbers materially. Employees who received fraud awareness training submitted more than twice as many tips.
Organisations that trained both staff and management reported a median loss of USD 84,000 per case, against USD 150,000 where neither group was trained.
If you do one thing after reading this article, make it easier for people to raise a concern and make sure they know what to raise. Our guide to AML training for employees covers how to structure it.
How can organisations prevent employee fraud?
Prevention works by removing opportunity. The strongest single finding of the 2026 study is that more than half of cases involved either missing internal controls or the override of existing ones: so the objective is not simply more controls. It is controls that cannot be quietly bypassed, and evidence that they were not.
The following are risk-based good practices rather than legal requirements. What is mandatory for your organisation depends on your jurisdiction, activity and supervisor.
Segregation of duties and maker-checker approval. No single person should be able to create, approve and record the same transaction.
Employee screening at hiring, and periodically for sensitive roles. Identity, qualifications, employment history and regulatory standing, proportionate to the role's authority.
Least-privilege access, reviewed on role change. Most excess access is accumulated internally, not granted on day one.
Mandatory leave and job rotation in high-exposure roles. Many schemes require continuous maintenance and surface the moment someone else does the job.
Independent reconciliation. Performed by someone other than the person who records the underlying transactions.
Controls on changes to vendor and payroll bank details. Independent verification against contacts already held on file.
Surprise audits and proactive data monitoring. Unpredictability is itself a deterrent; scheduled testing is easy to work around.
An accessible reporting channel. Email and web options alongside any hotline, with genuine protection for the person reporting.
Fraud awareness training for staff and management. Training only junior staff leaves the costliest cases uncovered.
Monitoring of control overrides and alert closures. If more than half of cases involve override, then override itself is a control point and must be logged, reported and reviewed.
Related content:
What should you do if you suspect employee fraud?
Move carefully and in the right order. The most common early mistakes: confronting the person, or asking their manager to "look into it"; destroying evidence and giving the individual time to alter records.
Preserve records first. Secure system logs, files, emails and transaction data before anyone becomes aware there is a concern.
Restrict access without alerting. Use routine-looking measures where possible, applied through IT rather than through the person's own team.
Escalate through a defined route. To compliance, legal, internal audit or the board, depending on who is involved. Never through the area under review.
Appoint an independent reviewer. Someone with no reporting line into, and no working relationship with, the function concerned.
Assess reporting obligations separately. Whether the facts trigger a report to a regulator or financial intelligence unit is a distinct question from any internal disciplinary process, and it is not answered by the outcome of that process. Our guide to suspicious transaction reports explains how that assessment works.
Document every decision and its reasoning. Including decisions not to act. A supervisor reviewing this later will assess the process, not only the conclusion.
Reporting duties and employment consequences are specific to jurisdiction, entity type and facts. Take qualified legal and compliance advice before acting, and confirm your obligations with your own supervisor.

Where technology helps with employee fraud
Technology cannot stop someone taking stock from a warehouse or inflating a lunch receipt. Those need physical controls, sampling and supervision.
What technology does well is reduce the discretion that makes schemes possible, and leave evidence of who did what.
That distinction matters most in regulated businesses, because the insider schemes with regulatory consequences run through customer onboarding, screening and monitoring. The controls people override when the process is inconvenient.
Where a compliance platform contributes:
Digital onboarding flows that apply the same checks to every customer, so approval is driven by rules rather than individual judgement under pressure
Monitoring that runs continuously rather than depending on someone remembering to perform a check
Alert and case workflows that record who reviewed what, on what basis, and when
Audit trails and records that let a supervisor, auditor or board see how a decision was actually reached
Where it does not: it is not employee monitoring software, a payroll or expense control system, or a whistleblowing hotline.
Those are separate tools, and any vendor suggesting a single platform covers all insider risk is overselling.
azakaw is a compliance platform covering Digital KYC, Digital KYB, Digital Onboarding, Transaction Monitoring and Corporate Compliance.
For most of the top employee frauds in this article that run through customer onboarding and monitoring, it supports consistent, configurable workflows and the records that show those controls were applied, which is what a supervisor asks for after an internal control failure.

Scale With Confidence
See how azakaw supports end-to-end AML and compliance workflows to safeguard your business from both employee and customer fraud. The most advanced AI-powered AML solution in the market.
Why employee fraud is a regulatory problem, not only an HR problem
For a regulated business, employee fraud engages the internal controls regime directly.
Where an insider bypasses a check, suppresses an alert or conceals activity, the organisation has a loss and potentially a compliance failure: one that a supervisor may view as evidence the control framework does not work as described.
The international standard sits in FATF Recommendation 18, which requires financial institutions to maintain internal policies, procedures and controls, including compliance management arrangements and adequate screening procedures to ensure high standards when hiring employees, alongside ongoing staff training and an independent audit function to test the framework.
One qualification matters here.
A FATF Recommendation is an international standard that countries implement through their own laws. It is not itself national law. What follows is how two GCC jurisdictions have given it effect. Obligations differ by country, entity type and supervisor.

What the UAE framework expects
The UAE's AML framework was rebuilt in 2025. Federal Decree-Law No. 10 of 2025 on combating money laundering, terrorist financing and the financing of proliferation came into force on 14 October 2025, repealing and replacing Federal Decree-Law No. 20 of 2018. Its executive regulations were issued by Cabinet Resolution No. 134 of 2025, replacing Cabinet Decision No. 10 of 2019.
The internal controls requirement carries through: financial institutions, DNFBPs and virtual asset service providers are expected to maintain documented policies, procedures and controls, to apply screening procedures when hiring staff, to train employees, and to maintain an independent audit function.
Supervisory expectations are then set through guidance.
The Central Bank of the UAE publishes guidance for licensed financial institutions on customer due diligence and record-keeping, transaction monitoring and sanctions screening, and suspicious transaction reporting.
Which supervisor applies to you depends on your activity and licence: the CBUAE, the Ministry of Economy and Tourism, the Securities and Commodities Authority, the DFSA, the FSRA or VARA. Confirm your own position rather than assuming.

What Saudi Arabia expects
Saudi Arabia's AML addresses fraud through a dedicated supervisory framework.
The Saudi Central Bank (SAMA) issued its Counter-Fraud Framework by circular in October 2022, structured around four domains: Governance, Prevent, Detect and Respond, with member organisations expected to operate at maturity level 3 or higher and to have achieved full compliance by 29 June 2023.
A separate Counter-Fraud Fundamental Requirements Framework took effect on 13 April 2026, setting baseline standards for member organisations outside the original framework's scope.
SAMA's own definition of fraud is worth noting, because it removes any doubt that internal conduct is in scope. It covers intentional acts carried out to obtain an unlawful benefit or cause loss, including through the use of functional powers or the deliberate neglect or exploitation of weaknesses in systems and standards. That is employee fraud, as described by the regulator.
Oman, Bahrain, Qatar and Kuwait each maintain their own AML and financial crime frameworks. Requirements in the UAE or Saudi Arabia should not be assumed to apply in those markets.

Full Compliance Across Jurisdictions
Centralise, simplify, and scale your compliance efforts across jurisdictions and regulators. Use regulator-specific templates or create your own rules and workflows.
Frequently asked questions
What is the most common type of employee fraud?
Asset misappropriation (stealing or misusing organisational assets) appeared in 90% of cases in the ACFE's 2026 study. It is also the least costly of the three categories by median loss. High frequency, lower individual impact, which is why it should be addressed through routine process controls rather than escalation.
Which type of employee fraud causes the biggest losses?
Financial statement fraud. It appeared in only 6% of cases but carried the highest median loss, around USD 1 million. Authority is the multiplier more generally: median losses caused by owners and executives were more than nine times greater than those caused by employees.
How long does employee fraud usually go undetected?
The median scheme ran for 12 months before detection. Cases found within six months had a median loss of USD 40,000; those running beyond five years exceeded USD 1.1 million. Shortening the detection window is the most effective lever an organisation has over total cost.
How do you investigate suspected employee fraud?
Preserve evidence before anyone knows there is a concern, restrict access discreetly, escalate through a route that does not pass through the area under review, and appoint a reviewer independent of the function involved. Document every decision. This is general good practice: the correct legal process depends on your jurisdiction and should be confirmed with qualified advisers.
Does employee fraud have to be reported to a regulator?
It depends on the jurisdiction, your entity type and the facts. Where insider conduct involves suspicious activity or affects the integrity of AML controls, reporting obligations may arise independently of any internal disciplinary outcome. Some supervisors also require notification of significant fraud incidents.
Can AML or compliance software detect employee fraud?
Partly, and it is worth being precise about which part. It can surface anomalies in customer activity and in how controls are applied: approvals granted without completed checks, alerts closed without rationale, repeated use of override routes. It will not detect an inflated expense claim or missing inventory. Those require different kinds of controls.
Conclusion
Employee fraud is difficult to eliminate, but organisations can significantly reduce both its likelihood and its financial impact by limiting opportunity and detecting problems earlier.
The priority is not simply adding more controls. It is ensuring that no single person can create, approve and conceal the same activity, that overrides leave a clear audit trail, and that employees have a safe and accessible way to report concerns.
For regulated businesses, this goes beyond protecting revenue. An employee who bypasses onboarding, screening or monitoring controls can also expose the organisation to AML and regulatory failures.
Start with the areas where authority and access are concentrated: separate critical duties, review permissions, monitor exceptions and overrides, reconcile independently, and make reporting concerns easy. The earlier unusual activity is identified, the lower the potential loss and regulatory exposure.






