internal controls to prevent theft

Most businesses that suffer employee theft had controls in place. They had a policy manual, an approval process, maybe even an annual audit. The problem was that those controls looked good on paper but never actually got in a thief’s way.

The data backs this up. The ACFE’s Occupational Fraud 2026: A Report to the Nations analyzed 2,402 cases across 143 countries and found that organizations lose an estimated 5% of revenue to fraud each year. The typical scheme ran for 12 months before anyone caught it, with a median loss of $104,000. Most telling of all, roughly 70% of the frauds studied traced back to a lack of internal controls, an override of existing controls, or a lack of management review.

So the real question is not whether you have internal controls to prevent theft. It is whether the ones you have actually work. Here is what the evidence says.

Why Many Internal Controls Fail in Practice

Controls fail for predictable reasons. Most of the time, it is not the design. It is how the control is used day to day.

According to the ACFE 2026 data, the top control weaknesses behind fraud were:

  • Lack of internal controls: 33% of cases
  • Override of existing controls: 19% of cases
  • Lack of management review: 18% of cases

Override is the one that surprises most owners. A trusted manager tells the bookkeeper to “just process it,” and the approval step disappears. That is why effective internal controls to prevent theft must be designed so that no single person, however senior, can bypass them alone. Our guide to the fraud triangle explains why opportunity is the one side of that triangle you can truly control.

The Controls That Actually Stop Theft

Not all internal controls to prevent theft are created equal. These have the strongest evidence behind them.

1. Surprise Audits

Fraudsters rely on predictability. If they know when the review comes, they clean up beforehand. According to summaries of the ACFE 2026 findings, surprise audits were linked to roughly 50% lower median losses, yet fewer than half of the organizations studied used them. An unannounced cash count or a random pull of vendor invoices costs little and changes behavior fast.

2. A Formal, Easy Reporting Channel

Tips detected 43% of frauds in the 2026 study, and more than half came from employees. Organizations with a formal reporting mechanism had a median loss of $100,000 and detected fraud in about 11 months. Those without one lost a median of $150,000 and took about 17 months. Web and email channels are now used more than phone hotlines, so make reporting simple and confidential. Learn more about how to report corporate fraud anonymously.

3. Segregation of Duties and Dual Control

The person who approves a vendor should not be the person who pays it. The person who deposits cash should not reconcile the bank account. Among internal controls to prevent theft, few are as reliable. Splitting these duties forces collusion, which is harder and riskier for a thief. We break this down in our post on how a dual control policy stops internal theft.

4. Independent Bank Reconciliations

Independent reconciliation is one of the oldest internal controls to prevent theft, and still one of the best. Someone outside the payment process should review bank statements monthly, ideally with images of cleared checks. Many long-running embezzlement cases collapse the moment an outsider looks at the statements. See how this played out in a bookkeeper embezzlement case caught by reconciliation.

5. Proactive Data Monitoring

Accounting software can flag duplicate payments, round-dollar invoices, new vendors sharing an employee’s address, and after-hours entries. The ACFE found this control in 58% of large organizations but only 17% of small ones, which is a major gap for smaller businesses, since software-based monitoring is one of the most affordable internal controls to prevent theft.

6. Fraud Awareness Training

Organizations that trained both staff and managers reported median losses of $84,000, compared with $150,000 for those providing no training. Trained employees recognize red flags, know where to report them, and become a living part of your internal controls to prevent theft.

The Controls That Look Good but Often Don’t

Some internal controls to prevent theft create a false sense of security. Watch for these:

  • Rubber-stamp approvals: A signature that is given without reviewing support is not a control.
  • A code of conduct no one reads: Policies matter, but only when they are trained, enforced, and backed by consequences.
  • Relying on the external audit: Financial statement audits are not designed to find most employee theft.
  • Blind trust in one long-tenured employee: The ACFE found that 84% of fraudsters showed at least one behavioral red flag, such as living beyond their means, that trusting colleagues overlooked.
  • Shared passwords and system access: If you cannot tell who made an entry, you cannot hold anyone accountable.
  • Controls that exist only on paper: A policy that is routinely overridden is worse than none, because it gives false comfort.

A Real-World Scenario: How Good Controls Would Have Helped

Consider a pattern that appears in many embezzlement cases. A small company’s office manager handles vendor setup, invoice approval, and payments. Over two years, she creates a fake supplier and pays it small, regular invoices. No one notices because she also reconciles the bank account.

Three internal controls to prevent theft would likely have stopped it early: separating vendor setup from payment, an independent reconciliation, and data monitoring that flags new vendors. Our article on fake vendor and fictitious supplier fraud walks through how these schemes are uncovered.

Practical Steps You Can Take This Month

You can strengthen internal controls to prevent theft without a large budget:

  1. Map who can move money. List everyone who can add vendors, approve payments, sign checks, or change payroll.
  2. Break single-person control. Split at least one duty in every high-risk process.
  3. Schedule one surprise review. Pick a random month and review vendor payments or petty cash.
  4. Launch a reporting channel. Offer a simple web or email option and tell employees it exists.
  5. Require vacations. Many schemes surface when the perpetrator is away. Read how an embezzler was caught during a vacation.
  6. Test, do not assume. Check quarterly that controls are actually being followed.

For a broader framework, see our guide to building an anti-fraud policy that actually stops employee theft.

Conclusion: Controls Only Work When They Are Real

The best internal controls to prevent theft are not the most complicated. They are the ones that are unpredictable, independent, and consistently followed. Surprise audits, clear reporting channels, segregated duties, and independent reconciliations consistently outperform paper policies and blind trust.

If you are unsure whether your controls would stand up to a determined insider, an independent review can tell you before a loss does. FraudOrder’s forensic accountants and fraud investigators can assess your controls, test them against real-world schemes, and help you protect your organization with confidence.

Frequently Asked Questions

1. What is the single most effective control against employee theft?

No single control is enough, but the ACFE data consistently points to tips and surprise audits as high-impact tools. Combining a confidential reporting channel with segregation of duties and independent review gives the strongest protection.

2. Can small businesses realistically segregate duties with few employees?

Yes, with some creativity. Owners can review bank statements personally, use an outside accountant for reconciliations, or require dual approval in banking software. Even partial separation meaningfully reduces risk.

3. How often should internal controls be tested?

High-risk areas like payments, payroll, and vendor setup should be tested at least quarterly. A full review is wise annually and after any major change in staff, systems, or growth.

4. What should we do if a control reveals possible theft?

Preserve records, restrict the suspect’s system access quietly, and avoid confronting anyone before you understand the facts. Contact qualified counsel and an independent investigator to protect evidence and your legal position.

5. Can FraudOrder review our existing internal controls?

Yes. FraudOrder assesses controls against real fraud schemes, identifies gaps where theft could occur, and provides clear, prioritized recommendations. We focus on practical fixes that fit your size and budget.

6. How is a controls review different from a fraud investigation?

A controls review is preventive and looks for weaknesses before a loss occurs. A fraud investigation responds to suspected wrongdoing, quantifies losses, and documents evidence. FraudOrder provides both, and we can advise on which you need.

References

Disclaimer

This article is for informational purposes only and is not legal, financial, or professional advice; reading it does not create a client relationship with FraudOrder. The scenario described is illustrative. Consult qualified professionals about your specific situation. For questions about FraudOrder services, visit https://fraudorder.co/