Most fraud advice given to small businesses is unusable, because it recommends separating duties among people the business does not employ. The data supports a different and more actionable conclusion: the loss is a function of how long the scheme runs, and there are controls that compress duration without requiring headcount a small business does not have.
Key Takeaway
The ACFE's Occupational Fraud 2026: A Report to the Nations analyses 2,402 cases across 143 countries, representing more than $3.4 billion in losses, with a median loss of $104,000 per case and an average exceeding $1.4 million. Organisations lose an estimated 5% of annual revenue to fraud each year and the average scheme runs about 12 months before discovery. Duration drives loss: schemes detected within six months produce a median loss of $40,000, while those lasting five or more years exceed $1.1 million, and the report's velocity analysis puts the cost of each additional undetected month at approximately $9,400. While 85% of large organisations have an established whistleblowing mechanism, only 25% of small businesses do, and organisations without one suffered a median loss of $150,000 and took 17 months to detect. Median losses caused by owners and executives were more than nine times greater than those caused by employees, and 84% of perpetrators displayed at least one behavioural red flag before detection.
Duration Is The Variable
The finding that should reorganise how a small business thinks about fraud risk.
Fraud detected within six months results in a median loss of $40,000, while schemes lasting five or more years produce median losses above $1.1 million[1]. The report's velocity analysis puts it in per-month terms: every month a fraud continues undetected costs an organisation approximately $9,400 on average[2]. The average scheme continues for approximately 12 months before being discovered[3].
The ratio between those two medians is roughly twenty-seven to one, and it is produced by time rather than by the nature of the scheme.
That reframes the objective. Preventing fraud entirely is not achievable, and a business that treats prevention as the only goal will conclude that its options are unaffordable and do nothing. Compressing detection time from years to months is achievable, is cheap relative to the exposure, and delivers most of the available benefit.
One source draws the same conclusion from the regulatory side: organisations should focus not only on preventing fraud but on strengthening their ability to identify suspicious activity quickly[3].
Everything operational in this article follows from that, and it is why the reporting channel discussed below matters more than any other single control for a business of limited size.
The Numbers
The scale, from the 2026 study.
The ACFE's Occupational Fraud 2026: A Report to the Nations, the fourteenth edition, analyses 2,402 real occupational fraud cases investigated by Certified Fraud Examiners across 143 countries and territories, collectively causing more than $3.4 billion in losses, with a median loss of $104,000 per case and an average loss exceeding $1.4 million[4]. The mean, pulled upward by large schemes, reaches $1.457 million, and the ACFE estimates that organisations globally lose approximately 5% of their annual revenue to fraud each year[5].
Two observations before the detail.
The gap between the median and the mean is the important feature of this distribution. A median of $104,000 against a mean above $1.4 million tells you that most cases are moderate and a minority are catastrophic. Planning against the median understates tail risk substantially.
And the 5% of revenue estimate is the figure that translates the abstraction into something a Canadian owner can act on. Applied to a business with $8 million of revenue it implies $400,000 annually, which is not a rounding error and is larger than most of the control investments that would address it.
One source makes the size point explicitly: a median loss of that magnitude lands differently at a small business than at a large one, representing a far greater share of annual revenue[5]. Earlier ACFE data recorded that companies with fewer than 100 employees had a median loss of $141,000, the second largest among the organisational size categories[6].
Three Types, Inverse Frequency
The taxonomy, which has a consistent and useful structure.
Asset misappropriation is the most prevalent type, appearing in 90% of fraud cases. Corruption, including bribery and conflicts of interest, shows up in 45% of cases. Financial statement fraud is the rarest at 6% of cases, but causes the most damage, with median losses reaching $1 million per incident[1]. Asset misappropriation schemes often involve the theft or misuse of cash or other assets, and while they generally result in lower median losses than other fraud types, their frequency makes them a significant risk for organisations of all sizes[7].
The inverse relationship between frequency and severity holds across all three categories, and it has a practical consequence for control design.
Controls aimed at asset misappropriation address the overwhelming majority of incidents at modest average value: cash handling, expense reimbursement, payroll, vendor payments, inventory. These are the everyday transactional controls, and they are where a small business gets the most coverage per dollar spent.
Controls aimed at financial statement fraud address a rare event with a median loss ten times higher. These are governance controls, and they largely mean independent review of the financial statements by someone the preparer does not control.
The percentages exceed 100 because cases can involve more than one category, which is itself informative: a scheme that begins as misappropriation is frequently concealed through misstatement.
The Twenty-Five Percent Problem
The single starkest finding for the readership of this publication.
While 85% of large organisations have an established whistleblowing mechanism in place, only 25% of small businesses do, and the ACFE explicitly flags this as especially concerning given the importance of tips in detecting fraud. Small businesses are not immune to occupational fraud; they are often more vulnerable to it, because they typically have fewer internal controls and less separation of financial duties[2].
The gap is not marginal. Three-quarters of small businesses lack the control that the evidence identifies as the leading route to detection, and they lack it in the population that is structurally most exposed.
Earlier ACFE data quantified the detection role: 43% of detection, the highest percentage, resulted from tips, and 71% of cases involved victim organisations that had anonymous fraud reporting hotlines[6].
One source explains part of the gap as resource-driven and part as something else: the gap between large and small organisations on hotline adoption is partly a resource gap, and also in some cases a compliance gap that regulators are becoming less patient with, with an organisation lacking a formal reporting mechanism increasingly not just operationally exposed but potentially non-compliant[5].
We would add a third explanation, offered as our own analysis. In a small owner-managed business, a formal anonymous reporting channel can feel like an accusation against people the owner knows personally, and installing one feels like an expression of distrust toward a team of fifteen. That instinct is understandable and it is expensive, because the control exists to compress duration rather than to express suspicion.
The Reporting Channel Arithmetic
The case made in numbers rather than principle.
Organisations without a reporting mechanism suffered a median loss of $150,000, 50% higher, and took 17 months to detect the same fraud, an extra six months of undetected damage, and every month a fraud continues undetected costs approximately $9,400 on average[2]. The same source concludes that a reporting mechanism is not a compliance expense but a financial control[2].
Work the arithmetic through, since it is the most persuasive material available on this subject. Six additional months of detection delay, at roughly $9,400 per month, is approximately $56,000 of avoidable loss per incident. The median loss differential of $46,000, being $150,000 against $104,000, points in the same direction from a different measurement.
Against that, an anonymous reporting channel for a small business is among the cheapest controls available. It requires a means for someone to report without identifying themselves, a defined recipient who is not the person most likely to be implicated, and a commitment to act on what arrives.
We note that our source on this point is a provider of whistleblowing services and therefore has a direct commercial interest in the conclusion, and readers should weigh that. The underlying ACFE finding on tips as the leading detection method is independent of that interest[6], and the direction of the argument is corroborated by the professional commentary cited throughout.
The design point that matters most in a small business is the recipient. A channel reporting to the person with the greatest authority over financial operations is not a control, because the ACFE data on owner and executive losses says that person is capable of the largest scheme. An external recipient, whether the external accountant, counsel, or an independent director, is what makes the channel meaningful.
The Owner Multiplier
The finding that owner-managed businesses find least comfortable.
Fraud risk increases significantly with authority, tenure and collusion, and median losses caused by owners and executives were more than nine times greater than those caused by employees. Schemes involving multiple perpetrators resulted in substantially greater financial harm than those committed by a single individual[4].
The mechanism is not that senior people are less honest. It is that authority removes the constraints that limit what a junior perpetrator can take: approval limits, system permissions, the need to conceal from a supervisor, and the ability to override a control rather than evade it.
Tenure operates similarly. A long-serving employee knows which reconciliations are actually performed, which reports nobody reads, and which approvals are rubber-stamped. That knowledge is what converts an opportunity into a durable scheme rather than a single incident.
And collusion defeats segregation of duties directly. Segregation works by requiring two people to agree; two people who have agreed are not constrained by it. That is why the data shows multi-perpetrator schemes producing substantially greater harm[4], and why controls that depend on a single person's independent judgment are more fragile than they appear.
The commentary draws the conclusion plainly: no one should be exempt from oversight, and segregation of duties, mandatory vacations, job rotation and independent reviews should apply at every level, especially at the top, because organisations that concentrate trust without corresponding accountability create the conditions for their most damaging fraud events[1].
The Governance Paradox
A structural difficulty specific to owner-managed businesses, which we set out as our own analysis.
Combine two findings. Owners and executives cause median losses more than nine times greater than employees[4]. And no one should be exempt from oversight[1].
In a Canadian owner-managed business, the person who would design and impose the control environment is the person whose conduct the data identifies as capable of the largest loss. There is no superior to require oversight of them, and no board in the meaningful sense where the owner controls the board.
We should be careful about the implication. The owner of a closely held business who takes money from it is in a different position from an employee stealing, since the owner is largely taking their own value, and the more common issues are tax characterisation and prejudice to minority shareholders or creditors rather than theft in the criminal sense.
But two real exposures remain. Where there are minority shareholders, or where the business has meaningful creditors, owner conduct that would be unremarkable in a wholly owned company can produce oppression claims and creditor consequences. And in the executive case short of ownership, a senior person with owner-like authority and no owner-like stake presents exactly the profile the data describes.
The practical resolution is external. An owner cannot supervise themselves, but they can accept a structure in which an external accountant reviews specified items, an independent director sees the bank reconciliations, or a reporting channel runs to someone outside management. Choosing that voluntarily is the only version of the control that exists in this setting.
When Segregation Of Duties Is Impossible
The honest treatment of the advice small businesses are most often given.
Basic control activities such as segregation of duties, management review, approval processes and ongoing monitoring continue to serve as some of the most effective defences against fraud[3], and prevention rests on strong internal controls starting with segregation of duties so that no one person controls a transaction end to end[5].
That is sound and it is frequently unimplementable. The sources acknowledge as much: structural challenges such as limited staffing, overlapping responsibilities and resource constraints often make segregation of duties difficult[7], and an employee who occupies multiple roles has more opportunity to exploit the gaps[2].
The canonical small business situation is one bookkeeper who enters bills, prepares payments, records receipts, performs the bank reconciliation and produces the management accounts. Every textbook control is violated. There is also nobody else to give the work to.
Telling that business to segregate duties is advice it cannot follow, and advice that cannot be followed is generally ignored in its entirety rather than partially. That is why we would frame the objective differently: the purpose of segregation is that no single person can both commit and conceal. Where duties cannot be split, the concealment half can still be broken by someone outside the process looking at the right things.
The controls in the next section are chosen on that basis. None requires additional staff.
Compensating Controls That Fit
What a business of ten or thirty people can actually do, drawn from the sources and our own practice framing.
The owner opens the bank statement. Unopened, directly from the bank or the portal, before anyone else sees it, and reviews the actual items. This single step breaks the concealment half of most misappropriation schemes because it removes the perpetrator's control over the record the owner sees.
Mandatory vacations and job rotation. Recommended at every level[1]. Their value is diagnostic rather than restorative: most ongoing schemes require continuous maintenance, and an uninterrupted two-week absence with someone else performing the role is when they surface. Resistance to taking leave is itself a red flag, as noted below.
Surprise audits. The ACFE material includes surprise audits among the measures backing segregation[5]. The deterrent value comes precisely from unpredictability, which means a scheduled annual review does not substitute.
An anonymous reporting channel with an external recipient. The highest-return control given the 25% adoption rate and the detection differential.
Independent reconciliation review. Where the bookkeeper prepares the reconciliation, someone else, including the external accountant, should examine it and the supporting items rather than accepting that it balances.
Vendor master control. Adding a new payee should require approval by someone who does not process payments. Fictitious vendor schemes depend on that control not existing.
Documented control ownership and annual testing. Document your control environment, assign clear ownership, and schedule testing at least annually, since controls only work when they are in place, functioning, and independently verified[1].
The Fraud Triangle
The explanatory model, and what it implies about where controls act.
Most occupational fraud can be understood through the fraud triangle, describing three conditions that typically come together when a trust violator offends. The first is pressure, often an unshareable financial need or personal financial difficulty. The second is opportunity, usually created by poor internal controls, a lack of segregation of duties or weak oversight. The third is rationalisation, the way an otherwise honest person justifies the act to themselves. Prevention works best when it removes opportunity through controls and reduces pressure and rationalisation through culture, support and a visible speak-up channel[5].
The distribution of effort matters. Controls act almost entirely on opportunity, which is one of three legs, and it is the only leg an employer can directly engineer.
The pressure leg is the one owners can influence more than they assume. An employee facing an unshareable financial difficulty is describing a problem they believe cannot be disclosed at work. Employers that have genuine, confidential support available, and that are known to respond to financial hardship without judgment, reduce the number of situations that become unshareable.
The rationalisation leg responds to consistency. The classic justifications, that it is a loan, that they are underpaid, that the company will not miss it, are harder to sustain in an environment where rules are applied uniformly including to the people at the top. An organisation with visible exceptions for senior people supplies the rationalisation directly.
Eighty-Four Percent Showed A Sign
The detection channel that operates before the numbers move.
The 2026 report found that 84% of perpetrators displayed at least one behavioural warning sign, with the most common red flags being living beyond one's means, financial difficulties, unusually close relationships with vendors or customers, and resistance to oversight or sharing of duties. Managers trained to recognise these patterns catch fraud earlier[1]. The report describes 84% displaying at least one behavioural red flag before detection, illustrating the value of awareness and early intervention[4].
The four listed flags map onto the fraud triangle in a way that is worth noticing. Living beyond one's means and financial difficulties are pressure indicators. Unusually close vendor or customer relationships is an opportunity indicator specific to corruption schemes. Resistance to oversight or to sharing duties is an indicator that the person is protecting a concealment mechanism.
That last one deserves emphasis because it is routinely misread as dedication. An employee who will not take leave, resists anyone else learning their process, insists on handling a particular reconciliation personally, and objects to a new control is displaying the most operationally significant flag on the list, and is frequently described by their employer as indispensable.
We would enter a caution. These are indicators, not evidence. Most people living beyond their means or experiencing financial difficulty are not committing fraud, and treating a personal circumstance as an accusation is both unjust and damaging. The appropriate response to a behavioural flag is to test whether the controls around that person's role are adequate, not to investigate the person.
Control Weakness And Override
The cause the data most consistently identifies.
More than half of the fraud cases in the 2026 report traced back to control weaknesses or overrides[1], and weak or nonexistent internal controls remain the leading contributor to fraud occurrences, with common issues including management override and insufficient review processes, highlighting the importance of both strong control design and consistent enforcement[7].
The pairing of weakness with override is the analytically important part, because they are different failures requiring different responses.
A control weakness means the control was never designed or never implemented. The remedy is design work, and it is the easier of the two.
An override means the control existed and was set aside, typically by someone with the authority to do so. That is a governance failure rather than a design failure, and adding more controls does not address it. A business whose approval threshold is routinely waived for urgent payments has a control on paper and none in practice.
The corollary is that documenting exceptions matters as much as documenting controls. An override that is recorded, justified and reviewed is a managed departure. An override that leaves no trace is indistinguishable from the control not existing, and it is the pattern that emerged in more than half of cases.
What Happens Afterward
A finding from the prior edition that bears on how fraud propagates between employers.
Pursuant to the 2024 report, previous offenders may be understated given that 86% of fraudsters in the ACFE study received no punishment from their employers, while 7% were terminated for fraudulent actions and 7% were previously punished by employers[6].
We report that from the 2024 edition and have not confirmed the equivalent 2026 figure, so it should be treated as indicative of a pattern rather than as current data.
The pattern it indicates is nonetheless important. If the great majority of detected perpetrators face no consequence from the employer, then employment history is a weak filter, and reference checking will not surface prior conduct because the prior employer neither recorded nor disclosed it.
The reasons employers decline to act are understandable: proceedings are expensive and slow, publicity is unwelcome, recovery is unlikely, and a quiet departure resolves the immediate problem. The aggregate consequence is that the risk is transferred to the next employer rather than removed.
For a Canadian business the practical implication is defensive. Do not assume that a candidate's clean employment record reflects clean conduct, and design controls that do not depend on having successfully screened for character. The controls above are designed on exactly that assumption.
A Worked Case: The Trusted Bookkeeper
A Canadian business of about twenty-five employees with a long-serving bookkeeper. The reconstruction illustrates how the findings combine rather than reporting a specific engagement.
The bookkeeper enters bills, prepares the payment run, records receipts, performs the bank reconciliation and produces the monthly accounts. Segregation of duties is impossible; there is no second finance person[7].
She has been there eleven years, has not taken more than a few consecutive days of leave in that period, prefers to handle the bank reconciliation personally, and was mildly resistant when the owner suggested the external accountant review it. Each of those is unremarkable individually. Together they describe resistance to oversight or sharing of duties, which is among the most common behavioural red flags[1].
The business has no anonymous reporting channel, which places it with the 75% of small businesses that do not[2]. A colleague who noticed something irregular would have to raise it directly with the owner, naming themselves, about a person the owner trusts.
If a scheme exists, the duration data governs the outcome. Detected within six months, the median loss is $40,000; running five years, it exceeds $1.1 million[1], with each undetected month costing roughly $9,400[2]. Without a reporting channel, the median detection period is 17 months[2].
Nothing here establishes wrongdoing, and the great majority of long-serving bookkeepers in this exact position are entirely honest. The point is that the business has no mechanism that would distinguish the two cases, and the controls that would create one, an unopened bank statement to the owner, enforced leave, an external reconciliation review and an anonymous channel, cost almost nothing and require no additional staff.
What To Build
Install an anonymous reporting channel with an external recipient. The adoption gap is 85% against 25%, tips are the leading detection route, and the absence of a channel is associated with 17-month detection and a 50% higher median loss.
Have the owner review the bank statement directly. Unopened, before anyone else, item by item. It breaks concealment without requiring a second employee.
Enforce consecutive leave and rotate roles. Two uninterrupted weeks with someone else in the seat is when maintained schemes surface, and it applies at every level.
Run surprise audits. Unpredictability is the mechanism; a scheduled review does not substitute.
Control the vendor master separately from payments. Adding a payee should require someone who does not process payments.
Apply everything at the top. Owner and executive losses are more than nine times the employee median, and exempting senior people supplies the rationalisation directly.
Record every override. More than half of cases traced to control weakness or override, and an unrecorded override is indistinguishable from having no control.
Train managers on the four behavioural flags. Living beyond means, financial difficulty, unusually close vendor relationships, and resistance to oversight. Respond by testing the controls around the role, not by investigating the person.
Document controls, assign ownership, test annually. Controls work only when in place, functioning and independently verified.
The Limits Of This Analysis
Several caveats matter. Figures throughout derive from the ACFE's Occupational Fraud 2026: A Report to the Nations as reported by professional and commercial commentators rather than from the report itself, and readers wanting authoritative figures should obtain it directly. Amounts are in United States dollars unless a source states otherwise, and the report is global rather than Canadian, so the distributions may not reflect Canadian conditions specifically. The punishment data is drawn from the 2024 edition and we have not confirmed the 2026 equivalent. Two cited sources are providers of whistleblowing or reporting services with a direct commercial interest in the reporting channel conclusion, and several others are accounting firms offering related advisory services; we have flagged these. The governance paradox section, the compensating controls framing and the analysis of why small businesses resist reporting channels are our own rather than sourced. This article does not address fraud investigation procedure, evidence preservation, employment law consequences of dismissal for cause, criminal referral, fidelity or crime insurance coverage, cyber-enabled payment fraud including business email compromise, vendor and procurement fraud schemes in detail, or the specific obligations of regulated entities and charities. Nothing here is legal, accounting or investigative advice; a business that suspects fraud should obtain legal advice before taking any step, including confronting the individual.
Frequently Asked Questions
How much does occupational fraud actually cost?
What is the single most important variable?
Do small businesses really need a whistleblowing channel?
I cannot segregate duties with three staff. What do I do?
Should controls apply to the owner too?
What behaviours should managers watch for?
References
- Pease Bell CPAs. (2026, June 25). Fraud Detection Facts Every Business Should Know in 2026, reporting ACFE 2026 findings on the six-month and five-year median losses, the three fraud types and their frequencies and severities, the 84% behavioural red flag figure and the four most common flags, control weaknesses and overrides in more than half of cases, and the recommendations on universal oversight, mandatory vacations and job rotation. Note: published by an accounting firm. peasebell.com/insights/surprising-facts-about-fraud-detection
- Report It Now. (2026, May 13). What the ACFE Report to the Nations 2026 Tells Us About Stopping Fraud, on the 85% against 25% reporting mechanism adoption gap, the $150,000 median loss and 17-month detection without a mechanism, the approximately $9,400 monthly velocity figure, and small business vulnerability. Note: published by a provider of whistleblowing and reporting services, with a direct commercial interest in this conclusion. reportitnow-global.com/blog/2026/05/13/acfe-report-to-the-nations-2026
- Dean Dorton. (2026, June 10). ACFE's 2026 Report to the Nations Highlights Ongoing Fraud Risks for Organizations, on the study scope of 2,402 cases across 143 countries, the $3.4 billion and $104,000 figures, the 5% of revenue estimate, the approximately 12-month average scheme duration, and the effectiveness of basic control activities. Note: published by an accounting and advisory firm. deandorton.com/articles/acfes-2026-report-to-the-nations-highlights-ongoing-fraud-risks-for-organizations
- Association of Certified Fraud Examiners. Occupational Fraud 2026: A Report to the Nations, Key Findings, ACFE Insights Blog, on the study scope and headline losses, the finding that owner and executive median losses were more than nine times those of employees, the effect of authority, tenure and collusion, and the 84% behavioural red flag figure. acfe.com/acfe-insights-blog/blog-detail?s=key-findings-report-to-the-nations-2026
- Whispli. Occupational Fraud 2026: Key Insights from the ACFE Report, on the fraud triangle and where prevention acts, the $1.457 million mean and 5% of revenue estimate, the disproportionate impact of a median loss on a small business, the resource and compliance dimensions of the hotline gap, and the role of segregation, internal audits, management review and surprise audits. Note: published by a provider of whistleblowing software. whispli.com/blog/occupational-fraud-2026-acfe-report-to-the-nations-whistleblowing
- Anchin. (2024). Occupational Fraud 2024: A Report to the Nations summary, on the 43% tip detection rate, the 71% hotline prevalence among victim organisations, the median loss for companies with fewer than 100 employees, and the 86% no-punishment figure. Note: prior edition data, reported by an accounting firm. anchin.com/wp-content/uploads/2024/08/2024-ACFE-Occupational-Fraud-Report.pdf
- Kreischer Miller. (2026, August). What the 2026 ACFE Report Reveals About Fraud in Not-for-Profits, on asset misappropriation frequency, weak or nonexistent controls as the leading contributor, management override and insufficient review, and the structural obstacles to segregation of duties in resource-constrained organisations. Note: published by an accounting firm. kmco.com/insights/what-the-2026-acfe-report-reveals-about-fraud-in-not-for-profits
This article discusses occupational fraud research and internal control practice and is provided for general informational purposes. It is not legal, accounting or investigative advice. Figures derive from secondary reporting of the ACFE's 2026 Report to the Nations, are in United States dollars, and reflect a global rather than Canadian population. A business that suspects fraud should obtain legal advice before taking any step.