Investigating suspected employee fraud starts with one rule: verify before you accuse. The moment a tip, anomaly, or gut feeling surfaces, your job is to quietly confirm whether a real discrepancy exists — not to confront the employee. A proper investigation follows a sequence: preserve evidence, secure records, run an independent audit of the affected accounts, document findings, and only then decide whether to escalate to legal counsel, law enforcement, or regulators. Done correctly, this process protects the company's money, its legal position, and its ability to recover losses through insurance or restitution. Done badly — as several recent public cases show — it can destroy evidence, trigger wrongful-termination lawsuits, and even let the fraudster walk free.
Start With the Red Flags, Not the Accusation
Also worth reading: What are the red flags of employee fraud, and how can an audit expose them? · How can organizations prevent internal employee fraud and detect financial discrepancies through proper audits? · What is the difference between a forensic audit vs financial audit, and which one does my organization actually need?
Most employee fraud investigations begin with a signal rather than a confession. Common triggers include vendor complaints about missing payments, unexplained variances between bank statements and bookkeeping records, an employee who refuses vacations or job rotation, lifestyle that outpaces salary, duplicate invoices, round-dollar disbursements, or journal entries posted at odd hours by unusual users. Industry data has long shown how widespread suspicion is: studies of auto insurance claims estimated that between 21 and 36 percent of claims contained elements of suspected fraud as far back as 1996, and occupational fraud research consistently finds that tips and internal audit detection uncover more cases than any other method.
The first practical step is to write down exactly what triggered the suspicion: which account, which date range, which transaction, who reported it, and what specifically looked wrong. This matters because vague suspicions lead to vague investigations. If a manager says "I think Maria is stealing," the investigation stalls. If they say "three payments to Apex Supplies in March don't match any purchase orders, totaling $14,200," you have something auditable. Treat every initial report as unverified until the numbers themselves confirm it.
Secure the Evidence Before Anyone Knows You're Looking
The single most common fatal mistake in employee fraud cases is tipping off the suspect too early. Once an employee knows they are under review, they can delete emails, shred documents, wipe laptops, alter books, or coordinate with accomplices. Before any visible action, take quiet steps to preserve evidence: image or snapshot relevant accounting data, export bank feeds and payment logs, preserve email archives and access logs, photograph physical documents, and restrict the suspect's system permissions discreetly where possible without alerting them.
Legal counsel should be involved at this stage, not later. Employment law varies sharply by jurisdiction, and actions like searching an employee's desk, monitoring their email, or suspending their access can violate privacy laws or labor agreements if done improperly. In unionized environments, contract rules may govern surveillance and suspension. Getting counsel's sign-off on your evidence-preservation plan costs a few hours of legal fees; getting it wrong can invalidate everything you collected.
Run an Independent Audit of the Affected Accounts
The core of any credible investigation is a focused financial audit of the areas where the suspected fraud occurred. This means reconciling bank statements against the general ledger line by line for the suspicious period, matching every disbursement to an approved invoice and purchase order, testing payroll against actual headcount, and reviewing journal entries for round amounts, entries just below approval thresholds (a classic sign of threshold gaming around limits like $5,000 or $10,000), and postings made by users who shouldn't have had authority.
The value of independence here cannot be overstated. If the person who handles the books also investigates the books, the fraudster may be the investigator. Bring in either your internal audit function (if it reports outside finance) or an external forensic accountant. Forensic specialists look for patterns ordinary bookkeepers miss: vendors with PO boxes instead of street addresses, multiple vendors sharing a bank account, employees whose addresses match vendor addresses, sequential invoice numbers from supposedly different suppliers, and expense reimbursements clustered just under per-diem caps.
A useful discipline is quantifying three things separately: the confirmed loss (transactions you can prove), the probable loss (patterns strongly suggesting additional transactions), and the exposure (how much could have been taken given the control gaps). Insurers, courts, and law enforcement all respond differently depending on which category your numbers fall into, so keep them distinct in your working papers.
Internal Review Versus External Forensic Investigation
Organizations face a genuine choice about who conducts the investigation, and the right answer depends on materiality, complexity, and politics. An internal review by a controller or internal auditor is faster, cheaper, and preserves confidentiality, but it carries credibility risk if the suspect is senior, if the reviewer reports to the suspect, or if the findings will ever need to support an insurance claim, prosecution, or regulatory response. An external forensic accountant costs more but produces documentation that banks, insurers, courts, and regulators will actually accept.
| Feature | Internal Review | External Forensic Firm |
|---|---|---|
| Typical cost | $0–$5,000 (staff time) | $10,000–$100,000+ depending on scope |
| Speed | Days to 2 weeks | 2–8 weeks for a full forensic examination |
| Credibility with insurers/courts | Low to moderate | High — workpapers meet professional standards |
| Confidentiality | Risk of leaks internally | Strong; outsiders have no internal loyalties |
| Best suited for | Small discrepancies, first-pass triage | Material losses, executive suspects, litigation or claims |
| Independence | Compromised if suspect is senior | Fully independent |
Interviewing: Sequence and Technique
Interviews come after the numbers, never before. The standard sequence is: interview the reporting party first, then neutral witnesses and process owners (people who touch the same workflow but aren't suspects), then the suspect last, when you already know the answers well enough to detect lies. Interviewing the suspect first hands them the chance to shape the narrative, warn accomplices, or resign and take evidence with them.
Neutral-witness interviews should be framed as process reviews, not fraud hunts: "Walk me through how invoices get approved" yields more than "Have you seen anyone stealing?" Document each interview in writing the same day, noting who said what. When you finally sit down with the suspect, have your documented discrepancies in front of you, ask open questions, let inconsistencies surface naturally, and never promise leniency in exchange for confession — such promises can taint the admission's legal value. Two interviewers should always be present: one to ask questions, one to observe and take notes.
Deciding What To Do With What You Find
Once the audit confirms a discrepancy, you face a fork: handle it internally (termination plus civil recovery), report to law enforcement, notify insurers, or some combination. Each path has trade-offs. Criminal referral gives you prosecutorial muscle and possible restitution but surrenders control of timing and publicity. Civil recovery through demand letters or lawsuits keeps things quieter but depends on the employee having recoverable assets. Fidelity bond and crime insurance policies typically require prompt notice — often within 30 to 60 days of discovery — and require proof of loss supported by competent documentation, which is precisely what an external forensic audit provides.
Recent cases show both directions. Federal prosecutors in Ohio pursued alleged fraudsters who filed false health claims and purchased luxury cars, demonstrating how strong documentation enables criminal action. Conversely, the Minnesota school-meals fraud scandals showed the opposite failure mode: experienced state employees suspected meal-site fraud during COVID-era closures, tried to investigate, and reported that their efforts were stymied by leadership — allowing losses to balloon into the hundreds of millions before federal intervention. Hesitation has a price, and it compounds monthly.
Also weigh employment-law obligations. Terminating without cause documentation invites wrongful-dismissal claims; retaining a known fraudster because termination feels awkward invites repeat losses, since occupational fraud research shows repeat offenders escalate. Whatever you choose, document the decision, the rationale, and who approved it.
Fix the Control Gaps That Let It Happen
An investigation that ends at termination is half-finished. Every confirmed fraud maps to a specific control failure — usually segregation of duties (the same person initiating, approving, and recording payments), absent reconciliation, override authority, or no surprise audits. Post-investigation remediation should include separating initiation from approval of payments, requiring dual authorization above defined thresholds, mandating vacation and rotation for cash-handling roles, reconciling bank accounts monthly by someone independent of disbursements, and running periodic analytics for duplicate vendors, shared bank details, and below-threshold clustering.
The cost of these controls is trivial compared to typical losses. Median occupational fraud losses run roughly $120,000 per case in global studies, with schemes lasting a median of about 12 months before detection — meaning the average fraudster operates undetected for a full year. Controls that shorten detection time from 12 months to 3 months cut expected losses by roughly 75 percent. That arithmetic, not compliance theater, is the business case for remediation.
Common Mistakes That Sink Investigations
Several recurring errors deserve explicit warning. First, confronting the suspect before securing evidence, which destroys the case. Second, letting the suspect's own manager run the investigation, which invites both bias and cover-ups. Third, relying on verbal assurances — "she said it was a mistake" — instead of transaction-level verification. Fourth, failing to involve counsel early, leading to privacy-law violations during searches or interviews. Fifth, waiting too long to notify insurers and blowing the policy's notice window. Sixth, treating a small confirmed theft as isolated: schemes almost always start small and grow, so a $2,000 finding usually warrants looking back at least 24 months of history, not just the current quarter.
Finally, avoid overcorrecting into paranoia. Not every anomaly is fraud — honest errors, system migrations, and process changes create false positives constantly. The discipline of auditing the numbers first, accusing second, keeps you from damaging innocent employees' careers while still catching the guilty ones. Organizations that audit any financial record systematically and find discrepancies early spend a fraction on investigation and recovery compared to those that discover fraud through external shocks like a bank call, an auditor's finding, or a news story.
When To Act: Timing Rules Worth Following
Act within days, not months, once a credible discrepancy appears. Preserve evidence immediately, engage counsel within the first week, complete initial account reconciliation within two weeks, and make the insurer-notification decision within 30 days of confirmation. If losses exceed roughly $50,000, involve law enforcement consideration immediately — delay reduces recovery odds as funds get spent or moved. And if the suspect holds fiduciary or system-administrator access, revoke or supervise that access the same day the evidence is secured, since administrator credentials can erase the very records your investigation depends on. Speed, documentation quality, and independence are the three variables that determine whether an investigation ends in recovery or regret.