search

Internal Fraud in Banking: Building a Culture of Compliance

6/5/2026

Internal fraud is the least frequent category of bank fraud and the most expensive per event. It runs longer before discovery than any external scheme — often years — because the person committing it understands the controls, has legitimate access, and is trusted.

It is also the category institutions are least willing to discuss honestly, which is precisely why the controls that address it get relaxed.

The Common Schemes

Cash theft. Teller drawer manipulation, vault theft, and ATM cash. Usually small and usually caught quickly by balancing, which is why sustained cash theft almost always involves falsified entries to conceal it.

Fictitious accounts and loans. Accounts or loans created for nonexistent customers, with the proceeds directed to the employee. Requires enough system access to originate and to suppress the reporting that would surface it.

Unauthorized transactions on customer accounts. Withdrawals, transfers, or fee reversals on accounts belonging to real customers — frequently dormant accounts, estates, or elderly customers who do not review statements.

Lapping. Concealing a shortage by applying a later customer's payment to the earlier customer's account, requiring continuous maintenance. This is why mandatory absence works: the scheme collapses when the perpetrator is away.

Loan fraud. Approving loans outside authority, falsifying documentation, nominee borrowers, or kickbacks from borrowers or vendors.

Vendor and expense schemes. Fictitious vendors, inflated invoices, or kickbacks from real vendors.

Information theft. Customer data taken for sale or for use by a competitor. Often committed by a departing employee, and frequently the hardest to quantify.

Collusion with outsiders. An employee providing account information, disabling a control, or approving a transaction for an external party. Collusion defeats segregation of duties, which is why it produces the largest losses.

Why It Runs So Long

Three reasons, and each suggests a control.

Legitimate access. Nothing the perpetrator does looks anomalous to a system that authorized them to do it. The control that addresses this is review by a second person, not tighter system permissions.

Knowledge of the controls. An employee knows which reports are reviewed, which thresholds trigger attention, and which reconciliations are performed carelessly. The control is unpredictability — rotating review, varying samples, and occasional unannounced testing.

Trust. Long-tenured, well-liked, dependable employees are not suspected, and supervisors explain away anomalies. The control is process that does not depend on suspicion: mandatory absence, rotation, and dual control applied to everyone without exception.

Red Flags

Behavioral — these come first and are visible to supervisors rather than to systems:

  • Refusing to take vacation, or taking it while continuing to work remotely
  • Resisting job rotation or cross-training
  • Unusual interest in areas outside their responsibilities
  • Working unusual hours without an operational reason
  • Reluctance to share duties or documentation
  • Living visibly beyond apparent means
  • Known financial pressure — debt, medical costs, gambling, addiction
  • Unusually close relationships with specific customers or vendors
  • Defensiveness about routine questions

Transactional:

  • Transactions on accounts of relatives, acquaintances, or their own accounts
  • Frequent overrides, corrections, or reversals
  • Activity on dormant accounts, estates, or accounts with no statement delivery
  • Round-dollar or repetitive entries with no business explanation
  • Customer complaints clustering around one employee
  • Reconciling items that age without resolution
  • Access to systems outside their function

The behavioral signals are the leading ones, and they are noticed by colleagues who usually say nothing. Which makes the reporting culture the actual control.

Controls That Work

Mandatory absence. A consecutive block away from the institution, with duties performed by someone else and system access suspended. This is the single most effective internal fraud control available, because concealment schemes require maintenance. It has to be genuinely enforced — including for officers, who most often exempt themselves.

Job rotation and cross-training. Fresh eyes on a process, and a second person who knows how it works.

Segregation of duties. No individual both initiates and approves, or both maintains records and holds assets.

Dual control over cash, vault, negotiable instruments, wire release, and system entitlement changes.

Independent reconciliation by someone who does not perform the underlying transactions, with aged items escalated rather than carried.

Access reviews on a defined cycle, with prompt removal on role change — accumulated access from prior roles is a standing exposure.

Exception and override reporting reviewed by someone independent, with trends by employee rather than only by transaction.

Employee account monitoring, disclosed in policy, covering employees' own accounts and known related accounts.

Background screening at hire, and re-screening for sensitive positions where lawful.

A confidential reporting channel that is genuinely anonymous and visibly acted upon.

Investigating Without Destroying the Case

When suspicion arises, the first hours determine whether the institution has a case, a lawsuit, or both.

Do not confront the employee. Confrontation destroys evidence, allows concealment, and can create employment claims.

Preserve access logs, transaction records, and system data before changing anything, including before suspending access, which can alter logs.

Involve counsel and human resources immediately, and conduct the investigation under privilege where possible.

Limit knowledge to those who need it. Internal fraud investigations leak, and the leak reaches the subject.

Document contemporaneously, in factual terms.

Consider whether to suspend access — weighing evidence preservation against ongoing loss. There is no universal answer, and it should be a documented decision.

Assess SAR obligations independently. Insider abuse is explicitly within the scope of suspicious activity reporting, and the standard is assessed on its own terms regardless of employment outcome.

Coordinate with bonding and insurance carriers, whose notice requirements have their own deadlines.

Structured coverage is available through the Certificate in Fraud Prevention, Fraud Examination, and Financial Crimes Red Flags Training.

The Culture Part, Honestly

"Building a culture of compliance" is easy to say and is usually operationalized as an annual attestation nobody reads. What actually distinguishes institutions where internal fraud is caught early is narrower and harder.

Controls apply to everyone, visibly. The moment an executive is exempted from mandatory absence, dual control, or access review, the control has become a statement about hierarchy rather than a control. Staff notice immediately, and it licenses smaller exemptions throughout the organization.

Reporting a colleague is survivable. Most employees who suspect a coworker say nothing, and the reason is rarely loyalty — it is fear of being wrong, of being identified, and of working alongside that person afterward. A confidential channel addresses part of this. What addresses the rest is the institution having visibly handled a prior report well: investigated quietly, protected the reporter, and reached a defensible conclusion.

Anomalies get explained, not excused. The recurring pattern in long-running internal fraud is that someone noticed something and accepted a plausible explanation from a person they trusted. Training supervisors to ask for evidence rather than for an account — "show me the reconciliation" rather than "is everything fine?" — is a small change with disproportionate effect.

Pressure is treated as a risk factor, not a character judgment. Financial distress, addiction, and personal crisis precede a large share of employee fraud. An institution with genuinely accessible employee assistance, and managers who notice difficulty without treating it as suspicion, prevents some of these cases before they start.

None of this appears in a control matrix, and all of it determines whether the matrix works.

Departure and Role Change: The Two Riskiest Moments

Most internal fraud controls are designed for steady state, and the two transitions where exposure spikes are frequently ungoverned.

Role change. An employee moving from lending to operations, or from teller to new accounts, routinely keeps the access they had before. Over a career of internal moves, an individual accumulates entitlements that no single role would ever justify, and the combination frequently breaks segregation of duties in ways nobody designed or noticed. The control is an access review triggered by the role change itself — removing prior entitlements as a required step in the transfer, rather than waiting for the next periodic review to catch it.

Departure. The window between an employee deciding to leave and the institution knowing is the highest-risk period in the employment lifecycle, and it is the one the institution cannot see. What it can control is what happens once notice is given: immediate review of recent activity on accounts the employee could reach, monitoring of data movement in the preceding weeks, prompt access termination timed to the actual departure rather than to payroll convenience, and recovery of devices and credentials.

Data theft concentrates here specifically. Customer lists, pricing information, and pipeline data leave with departing employees far more often than money does, and it is rarely detected because nothing is missing — the information was copied, not taken. Institutions that log and review bulk data access and export activity find this; those relying on the honor system do not.

Two further practices worth adopting. Exit interviews that ask directly about outstanding items, unreconciled work, and anything the person wants to disclose — a surprising number of small schemes surface here when the person is leaving anyway. And a review of the departed employee's portfolio or accounts performed by their successor with fresh eyes, which is the mechanism that catches what a colleague covering temporarily would not question.

A closing word on proportionality. Small institutions frequently conclude that textbook segregation of duties is impossible with six people in operations, and they are right — one person genuinely will both post entries and reconcile. The answer is not to abandon the control but to substitute compensating ones and to say so in writing: supervisory review of the reconciliation by someone outside the function, periodic sampling by a director or the audit committee, mandatory absence enforced without exception, and dual control on the highest-consequence actions even where it is inconvenient. Examiners accept compensating controls; what they do not accept is a gap that nobody identified, documented, or addressed. The institutions that get into trouble here are rarely the ones that lacked staff. They are the ones that treated the shortage as a reason not to think about it.

Frequently Asked Questions

What is the most effective control against internal fraud?

Mandatory absence — a consecutive block away from the institution with duties reassigned and system access suspended. Concealment schemes such as lapping require daily maintenance, so they collapse when the perpetrator is away. Its effectiveness depends entirely on genuine enforcement, including for officers, who most often exempt themselves.

What are the earliest warning signs of employee fraud?

Behavioral rather than transactional: refusing vacation or working through it, resisting rotation or cross-training, unusual interest in areas outside their duties, living beyond apparent means, known financial pressure, and unusually close relationships with particular customers or vendors. These are visible to supervisors and colleagues before anything appears in a report.

Why does internal fraud go undetected for so long?

Because the perpetrator has legitimate access, so nothing they do appears anomalous to the systems that authorized it; because they know which reports are actually reviewed and which reconciliations are performed carelessly; and because trusted, long-tenured employees are not suspected and their anomalies get explained away.

Should we confront an employee we suspect?

No. Confrontation destroys evidence, allows concealment, and can create employment claims. Preserve access logs and transaction records first, involve counsel and human resources, conduct the investigation under privilege where possible, limit who knows, and make the decision about suspending access deliberately — recognizing that suspension itself can alter logs.

Does a SAR need to be filed for internal fraud?

Assess it independently of the employment outcome. Insider abuse is expressly within the scope of suspicious activity reporting, and the filing standard is applied on its own terms. Resolving the matter through termination or restitution does not discharge the reporting obligation.

How do you get employees to report a colleague?

By making it survivable. A genuinely confidential channel is necessary but insufficient — what changes behavior is the institution having visibly handled an earlier report well, investigating quietly, protecting the reporter, and reaching a defensible conclusion. Most people who stay silent do so from fear of being wrong and identified, not from loyalty.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026