20 November 2025 • 4 min read

Employee fraud thrives when internal controls come under pressure

Employee fraud is most likely to occur when internal controls are weak, inconsistently applied or placed under strain during periods of change. As South African claim trends show, strong governance, resilient processes and ongoing oversight remain essential to protecting businesses from financial, operational and reputational damage.

iTOO

iTOO

In an increasingly complex and volatile business environment, companies across South Africa are being urged to re-examine their internal processes, not only during times of crisis, but as a matter of routine governance. The stark reality is that when internal controls are weak or inconsistently applied, they create fertile ground for employee dishonesty, fraud and theft.

The Association of Certified Fraud Examiners (“ACFE”) is the world’s largest anti-fraud organization which provides education, training, and professional certification for fraud examiners.

In March 2024, the ACFE released its Occupational Fraud 2024: A Report to the Nations. This is a biennial report. The report was an analysis of 1,921 real cases of occupational fraud investigated between January 2022 and September 2023.

The key findings of the above Report, indicate that occupational fraud is very likely the largest and most costly form of financial crime in the world, with estimated annual costs in the trillion of dollars. Such crimes are a threat to every type of organization in all industries in every region throughout the world. Its estimates that organizations lose 5% of revenue to fraud each year. Occupational Fraud includes Asset Misappropriation, Corruption and Financial Statement Fraud. Asset Misappropriation Schemes are the most common but least costly. Whereas Financial Statement Fraud are the least common but most costly. Corruption however was reported in almost half of all cases.

So whilst the mentioned report is a global study, this article focuses on the trends and observations identified by claim specialists within an Insurer/Underwriting Manager.

Shushie Vencatachellam, Senior Claims Specialist at iTOO Special Risks, “iTOO”, explains that every organisation, regardless of size or sector, will encounter periods of operational strain, such as business restructuring or rapid growth, remote working and the absence or death of key personnel.

“It is precisely during these moments, when attention is diverted and stress levels are high, that employees may exploit procedural gaps or manipulate systems. Senior personnel, too, may inadvertently bypass controls, further compounding the risk,” says Venca

The COVID-19 pandemic serves as a good recent example of a business disruption that left companies vulnerable to employee fraud; however, the broader issue lies in how businesses respond to change and whether their internal processes are resilient enough to adapt.

Venca urges organisations to proactively review and reinforce their internal controls, both in the normal course of business and during times of upheaval. This includes:

  • Identifying and closing procedural loopholes
  • Amending processes to reflect new operational realities
  • Implementing mitigation tools such as segregation of duties and audit trails
  • Ensuring early disclosure of risks and maintaining adequate insurance cover

“In addition to the above reinforcements and other related controls, a tailor-made iTOO commercial crime policy provides a safety net for businesses, from an insurer that remained resilient and became an expert throughout the years and even through some of the most challenging times of this critical of cover, became a leader in the product innovation and development”

“With that said, insurance should not be seen as a replacement for effective governance; rather, it serves as a protective safety net. However, for this safety net to function effectively and provide genuine security, it must be underpinned by a strong and comprehensive framework of compliance and accountability,” she adds.

“This framework ensures that policies and regulations are adhered to consistently, fostering an environment where responsible practices are prioritised and upheld. Without such a foundation, the value of insurance diminishes, as it cannot adequately mitigate the risks associated with poor governance and oversight.”

Siphamandla Magubane, Claims Manager at iTOO Special Risks, warns organisations not to underestimate the risk posed by long-standing, trusted employees; those often described by directors as “like family.”

“Trust alone is not a safeguard. In fact, unquestioned trust can become a blind spot. What we are emphasising is that trust should never replace robust compliance and audit protocols. If your organisation consistently applies its internal controls, adheres to its compliance policies, and enforces audit measures, then trust becomes irrelevant to risk mitigation, because the systems are doing the work,” he says.

Magubane also points out that the consequences of employee theft extend far beyond financial loss. When criminal charges are laid, these matters often enter the public domain, attracting media attention and scrutiny for the Insured members, their business associates and family members.

The reputational damage can be severe, leading to business closure or retrenchments, suspension of employee bonuses or benefits and the loss of investor confidence and access to credit. These are not hypothetical risks; they are real outcomes that have affected South African businesses across sectors.

“Employee dishonesty is not a reflection of character alone; it is often a symptom of systemic failure. By embedding resilience into internal processes and fostering a culture of compliance, businesses can and must protect themselves, their people and their reputations,” concludes Magubane.