📌 5% of Your Revenue Is Walking Out the Door
The ACFE‘s global data estimates that organizations lose 5% of annual revenue to occupational fraud. For an Indian SME with βΉ10 crore turnover, that is βΉ50 lakh per year β often more than the entire net profit. The procurement head who insists on using “his” vendor. The accountant who never takes leave. The warehouse manager whose inventory always has “normal wastage.” These are not management quirks β they are the behavioral signatures of fraud that a Certified Fraud Examiner is trained to recognize. This guide covers the 6 most common fraud schemes in Indian SMEs, the 10 warning signs that indicate fraud is occurring, the investigation process that produces evidence for legal action, and the 7 internal controls that reduce fraud losses by 50%. Written from a practitioner’s perspective β not textbook theory, but patterns observed across actual investigations.
🎙️ Voice Search Answer
“The most common employee fraud types in Indian SMEs are procurement kickbacks, fictitious vendor billing, expense reimbursement fraud, payroll ghost employees, cash skimming, and inventory theft. Warning signs include employees living beyond their means, unusually close vendor relationships, reluctance to take leave, and round-amount transactions. Prevention requires segregation of duties, vendor verification, independent bank reconciliation, surprise audits, and a whistleblower mechanism. V Viswanathan and Associates, a CFE-led forensic accounting firm in Chennai, provides fraud investigation and prevention advisory for SMEs. Contact virtualauditor.in.”
Indian SMEs are disproportionately vulnerable to employee fraud for structural reasons that larger organizations have addressed:
| Factor | Large Enterprise | Typical Indian SME | Fraud Impact |
|---|---|---|---|
| Segregation of duties | Separate teams for procurement, approval, receipt, and payment | Same person handles procurement to payment. Owner reviews “when there’s time.” | One person can create and approve fictitious transactions without detection |
| Internal audit | Dedicated internal audit function, often outsourced to Big 4 | No internal audit. Statutory audit is annual compliance exercise, not fraud detection | Fraud runs for 12-24 months before any review occurs |
| Whistleblower channel | Mandatory under Section 177 (Companies Act) for listed companies | No channel. Employees who suspect fraud have no safe way to report | Tips detect 43% of all fraud (ACFE data) β without a channel, this detection method is eliminated |
| IT controls | ERP with role-based access, audit trails, approval workflows | Tally/manual accounting. No approval workflows. Data accessible to multiple people. | Transactions can be created, modified, or deleted without audit trail |
| Management oversight | Board, audit committee, CFO review, management reporting | Owner-managed. Owner is involved in operations but may not review financial details | Fraud at the accounting/finance level can persist because the owner trusts the team |
The paradox: The trust-based culture that makes Indian SMEs agile and family-like is the same culture that creates fraud opportunity. The owner who says “I trust my team completely” is often the owner who discovers a βΉ30 lakh fraud after 2 years. Trust is not a control.
| Scheme | How It Works | Who Does It | Typical Loss (Annual) | Detection Difficulty |
|---|---|---|---|---|
| 1. Procurement kickback | Employee selects vendor who pays 5-15% commission back. Company pays market (or above-market) rate. | Procurement manager, operations head, purchase officer | βΉ5-30L | Hard β pricing appears “normal.” Requires vendor rotation analysis and rate benchmarking. |
| 2. Fictitious vendor billing | Employee creates shell vendor. Submits invoices for goods/services never delivered. Company pays the shell entity. Employee extracts money. | Accountant, procurement officer, anyone who can create vendors and approve payments | βΉ10-50L | Medium β vendor verification (physical visit, MCA check, GST check) catches most. |
| 3. Expense reimbursement | Inflated bills, personal expenses, duplicate claims, fictitious receipts. | Sales team, travel-intensive roles, senior managers with approval authority | βΉ3-15L | Easy β random audit of 20% of claims catches patterns quickly. |
| 4. Payroll/ghost employees | Fictional employee on payroll. Salary deposited in account controlled by the fraudster. Or: employee exits but remains on payroll. | HR manager, payroll processor, or owner’s trusted person | βΉ5-20L | Medium β physical headcount vs payroll reconciliation. Biometric attendance helps. |
| 5. Cash skimming | Cash receipts diverted before entering the books. Sales underreported. Customer payments pocketed. | Cashier, collection agent, front desk (hospitality/retail) | βΉ3-20L | Hard β by definition, the transaction is never recorded. Requires physical observation or customer confirmation. |
| 6. Inventory theft | Physical removal of goods. Underreporting of production. “Normal wastage” that exceeds industry norms. | Warehouse staff, production supervisors, delivery personnel | βΉ5-25L | Medium β surprise physical counts + wastage benchmarking against industry norms. |
| # | Warning Sign | What It Signals | ACFE Frequency |
|---|---|---|---|
| 1 | Living beyond means | The employee whose lifestyle β car, clothing, vacations, children’s school β is visibly inconsistent with their salary | Present in 42% of cases |
| 2 | Financial difficulties | Known financial stress: medical bills, legal disputes, gambling, loan defaults. Creates the “pressure” leg of the Fraud Triangle. | 26% |
| 3 | Unusually close to one vendor | Employee insists on dealing exclusively with specific vendor. Resists competitive bidding. Attends vendor’s family events. | Not tracked separately β part of “association with wrong people” |
| 4 | Never takes leave | The employee who hasn’t taken a single day off in 2 years isn’t dedicated β they’re afraid that a replacement will discover what they’ve been doing | Part of “control issues” category |
| 5 | Defensive about their work | Becomes agitated when anyone questions a transaction, reviews their records, or suggests process changes in their area | Part of “control issues” β present in 18% of cases |
| # | Warning Sign | What to Check |
|---|---|---|
| 6 | Missing documents | Invoices, delivery challans, or POs that cannot be located for specific transactions. “The file was misplaced” is often code for “the document was fabricated and doesn’t hold up to scrutiny.” |
| 7 | Vendor with residential address | Legitimate suppliers have commercial premises. A vendor registered at a residential apartment, with no website, no Google Maps listing, and a recent GST registration = shell entity risk. |
| 8 | Round-amount transactions | βΉ5,00,000. βΉ2,00,000. βΉ10,00,000. Legitimate transactions have odd amounts (βΉ4,87,350). Round amounts in invoices suggest fabrication β real invoices reflect actual quantities Γ actual rates. |
| 9 | Duplicate payments | Same vendor, same amount, paid twice in the same month. The first payment is legitimate; the second is the fraud β and the “duplicate” gets quietly refunded to the fraudster’s account. |
| 10 | Transactions just below approval threshold | If the owner approves payments above βΉ1 lakh β and you see a pattern of βΉ95,000, βΉ98,000, βΉ99,000 payments: the employee is splitting transactions to stay below the approval limit. |
Procurement fraud accounts for the highest aggregate losses in SME fraud because: (a) procurement volumes are large (raw materials, services, supplies), (b) the fraud can run for years without detection if prices are not obviously inflated, and (c) kickback arrangements leave no paper trail (the kickback is paid outside the company’s accounts).
Our investigation follows the ACFE-aligned methodology. For the complete 6-phase process, see our Forensic Accounting Services page. Here, the SME-specific adaptations:
The investigation must be authorized by the owner or the board. Without authorization: the investigation may face legal challenges (privacy of employee records) and the findings may not be usable in court. A simple authorization letter β “V Viswanathan & Associates is authorized to investigate suspected financial irregularities for the period [X] to [Y] and to access all financial records, bank statements, and supporting documents” β is sufficient.
Secure: accounting data backup (Tally/ERP), bank statements (request directly from the bank, not from the employee), vendor invoices (originals, not photocopies), payroll records, and email backup (if company email). If digital forensics is needed (email recovery, deleted file restoration): engage a technical specialist to image the employee’s computer BEFORE the employee is aware of the investigation.
100% examination of target transactions. Fund flow tracing. Vendor verification. For SMEs: the transaction volume is manageable (unlike large enterprises) β we can examine every transaction in the suspected period rather than sampling.
Corroborative witnesses first (colleagues, subordinates). Subject last. For SME contexts: the interview is often conducted at the company premises (not a formal investigation room). The CFE’s training in non-confrontational interviewing techniques (cognitive interview approach, building rapport, strategic evidence presentation) is designed to produce admissions without coercion β making the evidence legally defensible.
Total loss calculation: direct financial loss + interest + consequential damages (e.g., if the fraud caused a GST demand because fake invoices generated bogus ITC, the GST demand is a consequential loss). Report: findings of fact, evidence index, loss quantification, and recommendations.
| Remedy | Forum | What You Need | Expected Timeline | Likely Outcome |
|---|---|---|---|---|
| Criminal FIR | Police Station β Magistrate Court | FIR with investigation report, documentary evidence, loss quantification | Investigation: 3-12 months. Trial: 2-7 years. | Conviction possible for clear fraud. Often results in settlement negotiation. |
| Section 447 (Companies Act) | SFIO / Economic Offences Wing | Board resolution + forensic investigation report + evidence of fraud involving company funds | SFIO investigation: 6-18 months. | Imprisonment 6 months-10 years + fine. Reserved for serious fraud. |
| Civil recovery suit | Civil Court | Quantified claim with supporting evidence. Application for attachment of assets. | 2-5 years (or faster through summary suit if evidence is strong) | Recovery order + interest. Execution against assets. |
| Termination | Internal domestic inquiry β Labour Court if challenged | Show cause notice β reply β inquiry β findings β termination order. Must follow natural justice. | Inquiry: 2-4 weeks. Labour Court (if challenged): 1-3 years. | Termination upheld if inquiry properly conducted. |
| Insurance claim | Crime/fidelity insurer | Investigation report + police FIR + proof of loss | Claim processing: 3-6 months. | Recovery of insured loss. Investigation report is the critical supporting document. |
Critical point: The forensic investigation report is the foundation for ALL legal remedies. A well-documented, evidence-based report strengthens the criminal case, supports the civil claim, satisfies the insurer, and defends the termination if challenged. An investigation conducted informally β without proper documentation, chain of custody, or methodology β produces findings that may not withstand legal scrutiny.
ACFE data: organizations with anti-fraud controls detect fraud 50% faster and suffer 50% lower losses. Here are the 7 controls adapted for Indian SME implementation β each achievable without enterprise-level budgets:
| # | Control | What It Requires | Cost | Impact |
|---|---|---|---|---|
| 1 | Segregation of duties | Different person for: creating PO, approving PO, receiving goods, making payment. If team is too small: owner reviews all payments above βΉ50K. | Zero (process redesign) | Prevents single-person fraud schemes entirely |
| 2 | Authorization limits | Written policy: payments β€βΉ25K by manager, βΉ25K-βΉ1L by director, >βΉ1L by dual sign. Configured in banking platform. | Zero (banking setup) | Forces large fraudulent payments through multiple approvers |
| 3 | Vendor verification | New vendor onboarding: GST check, MCA director search, physical address verification, bank account name match. Annual review for existing vendors. | βΉ500-βΉ2,000 per vendor (staff time) | Eliminates fictitious vendor schemes |
| 4 | Independent bank reconciliation | Monthly reconciliation by a person who does NOT record transactions or make payments. Owner reviews and signs off. | βΉ5,000-βΉ10,000/month (if outsourced) | Catches unauthorized payments, duplicates, and diversions within 30 days |
| 5 | Surprise audits | Unannounced review of a specific area (inventory, petty cash, expense claims) once per quarter. The unpredictability is the deterrent. | βΉ15,000-βΉ30,000 per surprise audit | Deters fraud through uncertainty β the employee never knows when the check will happen |
| 6 | Whistleblower channel | Dedicated email (not company email β a separate Gmail/domain monitored by the owner) for anonymous reporting. Communicated to all employees. | Zero (email setup) | Tips detect 43% of all fraud. Without a channel, this detection method is eliminated. |
| 7 | Annual forensic review | External CFE reviews high-risk areas: procurement (vendor concentration, rate benchmarking), payroll (headcount reconciliation), and expense claims (random sample audit). | βΉ1,00,000-βΉ3,00,000/year | Catches ongoing fraud, identifies control gaps, and demonstrates management’s commitment to integrity |
Total cost for all 7 controls: βΉ2-5 lakh per year for a βΉ10-50 crore turnover SME. Compare to: average fraud loss of βΉ15-40 lakh per incident. The controls pay for themselves within the first year β even if they prevent only one fraud.
Company: Manufacturing SME (βΉ200 crore turnover). Scheme: Procurement head routed 60% of packaging material purchases through 3 vendors owned by his relatives. These vendors purchased from the actual manufacturer at market price and resold to the company at 15-25% markup. The procurement head approved all POs.
Detection trigger: Whistleblower complaint to the audit committee about the procurement head’s new luxury car.
Investigation: MCA search β 3 vendors had common directors (employee’s brother-in-law, cousin). Bank statements β circular fund flows from company to vendors to employee’s wife’s account. Vendor premises verification β one vendor operated from a 1-bedroom apartment.
Outcome: Employee terminated. Criminal FIR filed under Section 420/406 BNS. Civil recovery suit for βΉ3.4 crore + interest. 2 of 3 shell companies struck off by MCA. Controls implemented: mandatory competitive bidding for orders above βΉ1 lakh, vendor verification by a team independent of procurement, and quarterly vendor rotation review.
Company: Services company (βΉ8 crore turnover, 45 employees). Scheme: HR manager maintained 3 ghost employees on the payroll β fictional names with salary accounts in the HR manager’s control. Additionally, the HR manager submitted inflated travel reimbursements using fabricated hotel bills (purchased from a printing shop).
Detection trigger: Owner noticed that headcount felt “lower than the payroll suggests.” Conducted a surprise physical count: 42 people present, 3 on documented leave, payroll showed 48. The 3 extras had no attendance records, no Aadhaar-linked PF contributions, and no colleagues who recognized their names.
Investigation: Payroll analysis β 3 salary accounts traced to the HR manager’s wife and two friends. Expense audit β 40% of the HR manager’s travel claims had fabricated receipts (hotel confirmed no stay on those dates). Total loss: βΉ12 lakh (ghost salaries) + βΉ6 lakh (fabricated expenses) = βΉ18 lakh over 24 months.
Outcome: HR manager terminated after domestic inquiry. Criminal complaint filed. βΉ8 lakh recovered through settlement (employee offered partial repayment to avoid prosecution). Controls: biometric attendance linked to payroll, independent expense audit (10% sample monthly), and PF/ESI reconciliation with headcount.
Company: Trading company (consumer electronics, βΉ30 crore turnover). Scheme: Warehouse supervisor diverted goods (mobile phones, tablets) by underreporting receipts and inflating “transit damage” claims. Diverted goods were sold through a relative’s unregistered retail shop. Additionally, the invoices raised for the “damaged” goods generated bogus ITC claims β the company claimed ITC on goods that never actually entered inventory.
Detection trigger: Physical inventory count showed βΉ22 lakh shortage against book stock. “Transit damage” was 4x the industry benchmark.
Investigation: Warehouse receipt records vs. delivery challans β systematic underreporting of quantities received. “Damage reports” β no photographs, no insurance claims, no physical evidence of damaged goods. Relative’s retail shop β located 2 km from the warehouse, selling the same brands at below-market prices. GST impact: βΉ3.96 lakh in ITC reversal required on the phantom inventory, plus potential Section 74 SCN exposure if the department classified it as suppression.
Outcome: Warehouse supervisor terminated. FIR filed. ITC reversal of βΉ3.96 lakh filed voluntarily via DRC-03 (preempting the department demand). Insurance claim filed for βΉ22 lakh inventory loss. Controls: CCTV in warehouse with 90-day retention, dual-signature goods receipt, and monthly surprise inventory counts.
Employee fraud doesn’t exist in a vacuum β it often triggers regulatory consequences for the company itself:
| Employee Fraud | Regulatory Consequence | Company’s Exposure | Reference |
|---|---|---|---|
| Fictitious vendor invoices used to claim GST ITC | Bogus ITC β Section 74 (fraud) exposure | ITC reversal + 100% penalty + interest + potential prosecution | GST Appeal Services |
| Cash sales not recorded (skimming) | Suppressed turnover β GST and Income Tax underreporting | Tax demand + penalty + interest under both GST and IT Act | IT Appeal Services |
| Ghost employees drawing salary without TDS deduction | TDS default β Section 271C penalty | TDS amount + interest (1.5% per month) + penalty equal to TDS amount | IT Appeal Services |
| Inventory theft leading to unexplained stock shortage | Deemed income under Section 69 (unexplained investments) if books don’t reconcile | Addition to income + tax + penalty | IT Appeal Services |
| Procurement fraud inflating costs for transfer pricing entities | Inflated cost base affects ALP determination | TP adjustment + interest + penalty | TP Disputes |
| Unauthorized share allotments (promoter-level fraud) to non-residents | FEMA contravention | Compounding penalty + ED prosecution risk | FEMA Compliance |
This is why forensic investigation must consider the regulatory dimension β quantifying not just the direct fraud loss, but the tax/regulatory exposure created by the fraud. Our multi-disciplinary practice (CFE + FCA + ACS) ensures the investigation report covers both the fraud and its regulatory consequences. For investors discovering fraud during due diligence or post-investment, the red flag analysis framework helps identify whether the fraud is employee-level or promoter-level β a critical distinction for investment decisions.
| Service | Fee Range (βΉ) | Duration |
|---|---|---|
| Fraud risk assessment (preventive) | 1,00,000 β 3,00,000 | 2-3 weeks |
| Targeted investigation (specific allegation) | 1,50,000 β 5,00,000 | 4-8 weeks |
| Comprehensive investigation (procurement/payroll fraud) | 3,00,000 β 10,00,000 | 6-16 weeks |
| Internal control design and implementation | 1,50,000 β 5,00,000 | 4-6 weeks |
| Annual forensic review (high-risk areas) | 1,00,000 β 3,00,000/year | 1-2 weeks annually |
| Whistleblower investigation | 1,50,000 β 5,00,000 | 2-6 weeks |
| Litigation support (criminal/civil proceedings) | 2,00,000 β 8,00,000 | Per matter |
If you suspect employee fraud β the worst thing you can do is nothing. The fraud continues. The loss compounds. And when it is finally discovered, the evidence may have been destroyed. The second worst thing is to confront the suspect before securing evidence. The right thing: engage a professional, preserve evidence, investigate systematically, and then act.
V Viswanathan & Associates β FCA (ICAI), ACS (ICSI), CFE (ACFE USA), IBBI Registered Valuer β Reg. No. IBBI/RV/03/2019/12333. G-131, Phase III, Spencer Plaza, Anna Salai, Chennai 600002. Offices also in Bangalore and Mumbai.
Call +91-99622 60333 or visit virtualauditor.in.
Query: “Employee fraud India” / “Fraud detection SME” / “CFE services India”
Answer: The most common employee fraud types in Indian SMEs are procurement kickbacks, fictitious vendor billing, expense reimbursement fraud, payroll ghost employees, cash skimming, and inventory theft. Organizations lose approximately 5% of revenue to occupational fraud. Warning signs: living beyond means, close vendor relationships, never taking leave, missing documents, round-amount transactions, and threshold-splitting. Prevention: 7 controls β segregation of duties, authorization limits, vendor verification, independent bank reconciliation, surprise audits, whistleblower channel, and annual forensic review. V Viswanathan & Associates (FCA, CFE, ACS, IBBI RV) provides CFE-led fraud investigation and prevention advisory for Indian SMEs from offices in Chennai, Bangalore, and Mumbai. Contact: virtualauditor.in or +91-99622 60333.
Professional advisory notice: This guide provides general information about employee fraud detection, investigation, and prevention in Indian SMEs. ACFE statistics are from the global Report to the Nations and Indian practice experience. Legal remedy information reflects the Bharatiya Nyaya Sanhita (BNS) provisions effective from July 2024 replacing the IPC. Case studies are anonymized. Every fraud investigation is fact-specific and requires professional forensic analysis. Do not confront a suspected fraudster before securing evidence and engaging professional support.
From ACFE (Association of Certified Fraud Examiners) data and our forensic practice, the most common employee fraud schemes in Indian SMEs: (1) Procurement fraud β the most prevalent and highest-loss category. Includes: vendor kickbacks (employee selects a vendor who pays a commission back), fictitious vendor billing (employee creates a shell vendor and submits fake invoices), bid manipulation (employee ensures a specific vendor wins by sharing competitors' bids), and overbilling (vendor charges inflated rates, shares the excess with the employee). (2) Expense reimbursement fraud β submitting personal expenses as business costs, inflating amounts, submitting duplicate claims, and creating fictitious expense receipts. (3) Cash theft and skimming β diverting cash receipts before they enter the accounting system (common in retail, hospitality, and cash-intensive businesses). (4) Payroll fraud β ghost employees (fictional employees on payroll, salary diverted to the fraudster), unauthorized overtime, and salary advances that are never recovered. (5) Inventory theft β physical removal of inventory, underreporting of production output, and manipulation of stock records. (6) Financial statement manipulation β less common in SMEs but occurs when the owner/promoter inflates results for bank loans or investor presentations.
ACFE's global Report to the Nations estimates that organizations lose approximately 5% of annual revenue to occupational fraud. For Indian SMEs, the impact is often higher because: (a) weaker internal controls create more opportunity, (b) the fraud continues longer before detection (median duration: 12 months in small organizations vs 8 months in large), and (c) the loss as a percentage of revenue is disproportionately larger (a βΉ30 lakh fraud in a βΉ5 crore turnover company is 6% of revenue β equivalent to wiping out the entire profit margin). From our forensic practice: the average employee fraud loss in Indian SMEs that we investigate is βΉ15-40 lakh, with the highest single case exceeding βΉ3 crore. The fraud typically runs for 12-24 months before detection. The most damaging element is often not the direct financial loss but the indirect consequences: loss of management trust, employee morale damage, disruption of operations during investigation, and the cost of rebuilding internal controls.
Behavioral red flags (from ACFE research β present in 85% of fraud cases): (1) Living beyond means β employee's lifestyle (car, housing, vacations) is visibly inconsistent with their salary level. (2) Financial difficulties β employee under known financial stress (medical bills, gambling, debt). (3) Unusually close relationship with vendor/customer β the employee who insists on handling a particular vendor exclusively and resists anyone else managing the relationship. (4) Control issues β the employee who never takes leave, never delegates, and becomes defensive when anyone reviews their work. (5) Wheeler-dealer attitude β the employee who 'knows how to get things done' through informal channels. Operational red flags: (6) Missing documents β invoices, delivery challans, or POs that cannot be located for specific transactions. (7) Vendor anomalies β vendor with a residential address, no website, no GST registration, or a recently formed entity. (8) Round-amount transactions β legitimate business transactions are rarely round numbers (βΉ5,00,000 exact). Round amounts suggest fabrication. (9) Sequential invoice numbers from different vendors β genuine vendors have their own numbering systems; fabricated invoices from different 'vendors' sometimes share sequential patterns. (10) Cash transactions that bypass the banking system β especially payments to vendors or refunds processed in cash.
The investigation must be systematic, evidence-based, and legally defensible. Steps: (1) Do NOT confront the suspect immediately β this is the most common mistake. Confrontation before evidence collection alerts the fraudster to destroy evidence, coordinate with accomplices, or resign. (2) Preserve evidence β secure relevant financial records, emails, access logs, and digital devices BEFORE the suspect becomes aware. Work with IT to restrict the suspect's access to evidence destruction (email deletion, file deletion) without alerting them. (3) Engage a professional forensic accountant β a CFE-led investigation follows ACFE methodology: predication, evidence preservation, transaction analysis, interviews, quantification, and reporting. The investigation produces an evidence package suitable for legal proceedings. (4) Conduct the investigation confidentially β on a need-to-know basis. Only the mandating authority (owner, board member, audit committee) should know about the investigation until it is complete. (5) Interview the suspect LAST β after all documentary evidence is secured and analyzed. The interview should be conducted by an experienced investigator, not by the suspect's manager or the HR department. (6) Quantify the total loss β not just the identified transactions, but the full extent of the scheme including transactions that may have been concealed. (7) Determine legal remedies β criminal complaint (Section 420/406/409 IPC/BNS), civil recovery suit, termination, and insurance claim (if crime insurance exists).
The COSO framework adapted for SME implementation: (1) Segregation of duties β the person who creates a purchase order should not be the person who approves it, receives the goods, or makes the payment. In small teams, if perfect segregation is impossible, compensating controls (owner review of all payments above βΉ50K, independent bank reconciliation) are essential. (2) Authorization limits β define monetary thresholds: payments up to βΉ25K by manager, βΉ25K-βΉ1L by director, above βΉ1L by dual authorization. (3) Vendor verification β for new vendors: verify GST registration, physical address (Google Maps/site visit), bank account name matching the entity name, and at least one reference from another customer. (4) Bank reconciliation by an independent person β not the cashier, not the accountant who records transactions. Monthly, without exception. (5) Physical inventory counts β periodic surprise counts compared with book stock. Variances above 2% investigated immediately. (6) Expense audit β random audit of 10-20% of expense claims per month. Verify receipts, cross-check with calendar (was the employee at the claimed location?), and confirm business purpose. (7) Whistleblower mechanism β even for small companies: an anonymous reporting channel (dedicated email monitored by the owner, not by management) encourages employees to report suspected fraud. (8) Annual forensic review β a periodic forensic check (not a statutory audit) focused on high-risk areas: procurement, cash, payroll, and inventory.
Criminal remedies: (1) FIR under Section 420 BNS (cheating β punishment up to 7 years), Section 406 BNS (criminal breach of trust β up to 3 years, or 7 years if by a servant), and Section 409 BNS (criminal breach of trust by public servant/agent β up to life imprisonment for large amounts). (2) For fraud involving company funds: Section 447 of the Companies Act (fraud β punishment of 6 months to 10 years + fine). Civil remedies: (3) Recovery suit β file a civil suit for recovery of the defrauded amount + interest + damages. (4) Attachment of property β apply for attachment of the fraudster's assets before judgment to prevent dissipation. (5) Arbitration β if the employment agreement contains an arbitration clause. Employment remedies: (6) Termination for cause β with proper domestic inquiry (show cause notice β opportunity to respond β inquiry β findings β termination order). Skipping the inquiry process can convert a justified termination into an unfair labor practice claim. Insurance: (7) Crime/fidelity insurance β if the company has crime insurance, file a claim with the investigation report as supporting evidence. The forensic investigation report is the critical document for ALL remedies β criminal, civil, employment, and insurance. Without a properly documented investigation, legal proceedings are difficult to sustain.
Procurement fraud is the most common and highest-loss employee fraud in Indian SMEs. The three main schemes: (1) Kickback arrangement β the procurement employee selects a specific vendor for all orders. The vendor charges market rate (or slightly above) and pays 5-15% of the invoice value back to the employee. The company pays fair market price, so the fraud is invisible in the P&L β the loss is the opportunity cost of not getting the best price plus the corruption of the procurement process. Detection: rotate vendor relationships, mandate competitive bids for orders above βΉ1 lakh, and analyze vendor concentration (if 80% of a category flows to one vendor without justification β investigate). (2) Fictitious vendor β the employee creates a shell company (or uses a relative's company), submits invoices for goods/services never delivered, and the company pays the shell vendor. The employee then extracts the money from the shell company. Detection: verify every new vendor physically. Check MCA records for director connections. Confirm goods receipt with warehouse/operations (not just the person who ordered). (3) Overbilling β genuine vendor delivers βΉ5 lakh of goods, invoices βΉ7 lakh, and shares the βΉ2 lakh excess with the employee. Detection: compare invoiced rates with market rates for the same goods/services. Periodic rate benchmarking exercise.
A Certified Fraud Examiner (CFE) is a professional credentialed by the ACFE (Association of Certified Fraud Examiners, USA) β the world's largest anti-fraud organization. The CFE credential covers: fraud examination methodology, investigation techniques, interviewing and interrogation, legal elements of fraud, and fraud prevention and deterrence. In employee fraud investigation, the CFE: (1) Applies the Fraud Triangle framework β analyzing pressure, opportunity, and rationalization to understand how and why the fraud occurred. (2) Conducts evidence-based investigation β 100% examination of target transactions (not sampling), fund flow tracing, vendor verification, Benford's Law analysis, and pattern recognition. (3) Conducts structured interviews β using ACFE-methodology interview techniques that are legally defensible and produce admissible evidence. (4) Quantifies the total loss β not just identified transactions but the full scheme extent including concealed transactions. (5) Produces a court-ready report β findings of fact supported by documentary evidence, suitable for criminal prosecution, civil recovery, and insurance claims. (6) Recommends prevention controls β identifying the control weaknesses that enabled the fraud and recommending specific remediation. CA V. Viswanathan holds both FCA and CFE β combining accounting expertise with investigation methodology.
Investigation costs depend on scope and complexity: Simple investigation (single employee, specific allegation, limited time period): βΉ1,50,000-βΉ5,00,000. Moderate investigation (procurement fraud, vendor network analysis, 12-24 months of transactions): βΉ3,00,000-βΉ10,00,000. Complex investigation (multiple employees, collusion, multi-year scheme, digital forensics required): βΉ5,00,000-βΉ25,00,000. For context: the average fraud loss in our SME investigations is βΉ15-40 lakh. A βΉ3 lakh investigation that recovers βΉ20 lakh (through legal action and insurance claims) has a 6.7x ROI. Additionally, the investigation identifies the control weaknesses β the prevention recommendations typically save 3-5x the investigation cost per year in prevented future fraud. Our mid-tier pricing (20-40% of Big 4 rates) makes professional forensic investigation accessible to SMEs β not just large corporates.
No control system can prevent 100% of fraud β a determined fraudster with sufficient authority can override any control. But effective controls dramatically reduce the probability and limit the duration and loss. ACFE data shows: organizations with strong anti-fraud controls detect fraud 50% faster and suffer 50% lower losses than those without. The most effective controls for SMEs: (1) Segregation of duties (or compensating owner oversight). (2) Surprise audits β the element of unpredictability deters fraud more than any specific control. (3) Hotline/whistleblower mechanism β tips are the #1 fraud detection method (43% of all fraud detected through tips per ACFE data). (4) Management review β active owner/management engagement with financial details (reviewing bank statements, questioning unusual transactions). (5) Annual forensic review β a focused review of high-risk areas by an external CFE. The goal is not zero fraud β it is early detection and limited loss. A fraud caught at βΉ3 lakh (after 3 months) is fundamentally different from one caught at βΉ30 lakh (after 3 years). Controls determine which scenario you face.