Introduction
Fraud is often associated with weak ethics. In reality, many frauds occur because of weak processes.
One experience early in my career completely changed the way I evaluate financial controls. I was never involved in the fraud, nor did I receive any personal benefit from it. However, I unknowingly became part of a payment process that was later exploited by someone who understood its weaknesses.
It taught me a lesson that every finance professional should remember:
A trusted process without proper verification can become an opportunity for fraud.
The Situation
After joining an organization, I inherited an existing payment process involving two group companies.
Due to temporary operational circumstances, payment transactions for one company had to be processed through an existing banking platform that I could access. The arrangement was already in place before I joined and continued only until the company’s independent banking setup became operational.
My role was straightforward.
The finance representative of the other company would send payment instructions supported by management approval, and I would execute the payment through internet banking.
I was not responsible for selecting vendors, approving payments, verifying commercial transactions, or maintaining that company’s accounting records. My responsibility was limited to processing transactions that appeared to have been duly authorized.
The process worked smoothly.
Or so everyone believed.
The Truth Came Out
One day I received a request for a vendor refund.
Since no approval was attached, I immediately contacted the concerned person and explained that payment requests should always include proper authorization before they could be processed.
From that point onward, every payment request arrived with what appeared to be approval emails from senior management.
The email conversations looked authentic.
The approvals appeared genuine.
The payment requests followed the same established process every time.
Naturally, I processed the transactions.
“Several months later, I received an urgent call from our Managing Director.”
He asked me to explain the payment process I was following for that company.
After listening carefully, he informed me that a significant financial fraud had been uncovered.
I was stunned.
When I explained that every payment had been supported by management approvals, our Chartered Accountant requested that I immediately forward all the email communications.
The investigation revealed that every approval email had been fabricated.
The individual responsible had created fake approval chains that closely resembled genuine internal communication. Payments were being made to vendors working in collusion with him.
The fraud came to light only because an independent financial review identified unusual project losses. A deeper investigation exposed the entire scheme.
Throughout the investigation, I fully cooperated by providing all emails, documents, and explanations related to the payment process. A formal complaint was filed, and I recorded my statement before the investigating authorities.
One moment from that day has stayed with me ever since.
After understanding the complete process, my Managing Director simply said,
“Don’t worry. I trust you. I know you would never do something like this.”
Those words reinforced that integrity is built over years.
Unfortunately, the financial loss could never be recovered.
Lessons Learned
This experience changed my perspective on financial controls forever.
I realized that fraud does not always exploit dishonest people.
Sometimes it exploits honest people working within an imperfect process.
Today, whenever I review a payment process, I ask questions that I never asked before.
- Can an approval email be independently verified?
- Is there adequate segregation of duties?
- Could someone misuse this process without immediate detection?
- Are temporary arrangements creating permanent risks?
- Would analytical reviews detect unusual transactions early?
The strongest financial controls are not based on trust alone.
They are built on verification.
Key Takeaways
- Fraud often exploits process weaknesses rather than people.
- Email approvals should never be the sole basis for high-value payments.
- Independent verification significantly reduces fraud risk.
- Temporary business arrangements require stronger monitoring.
- Segregation of duties remains one of the most effective internal controls.
- Analytical reviews can uncover fraud that routine transaction processing cannot.
Final Thoughts
This experience was one of the most important lessons of my professional career.
It taught me that integrity and strong internal controls must work together.
People may be trustworthy, but every financial process should be designed with the assumption that someone may eventually try to exploit it.
Today, whenever I assess a finance process, one question always comes to mind:
“If someone intentionally tries to misuse this process, have we built enough controls to stop them?”
That question has influenced every finance process I have reviewed since.