-Sakshi Agarwal
Let’s start with a small story in this regard. Client B runs a highly successful, medium-sized manufacturing firm that produces industrial packaging. Because he spent most of his time on the factory floor and pitching to new clients, he entrusted his entire back-office operations to Mr. A, a loyal senior accountant who had been with the company for over a decade. Mr. A was considered part of the family; he rarely took vacations, worked late on weekends, and single-handedly managed vendor payments, payroll, and bank reconciliations.
The arrangement seemed perfect
until Client B’s auditor, CA X, was conducting a routine year-end tax audit. CA
X noticed a peculiar pattern: a steady stream of payments made to a relatively
unknown vendor for "consumable supplies." Every single invoice from
this vendor was remarkably priced just below the ₹30,000 threshold, effectively
bypassing the mandatory TDS (Tax Deducted at Source) requirements and keeping
it off the immediate tax radar. Upon conducting a deeper background check, CA X
discovered that the vendor’s registered GST address was actually Mr. A’s
residential apartment, and the bank account belonged to Mr. A's spouse. Over a
span of four years, the "loyal" accountant had siphoned off nearly
₹65 lakhs. Client B was devastated not just by the staggering financial loss,
but by the profound betrayal of a trusted confidant.
The
"Trusted Employee" Paradox
Employee embezzlement in Micro,
Small, and Medium Enterprises (MSMEs) rarely looks like a Hollywood heist. It
does not happen overnight, and it is almost never perpetrated by a new hire.
Statistically, the most damaging occupational frauds are committed by
long-tenured, highly trusted employees. This happens because MSMEs often suffer
from a severe lack of segregation of duties.
In a corporate environment, the
person who approves a vendor cannot be the same person who processes the
payment, and certainly cannot be the person who reconciles the bank statement.
In a small business, however, these roles are frequently consolidated into one
"super-user" to save costs and streamline operations. When an
employee has end-to-end control over the financial lifecycle, the opportunity
for fraud expands exponentially. Business owners mistakenly substitute blind
trust for robust internal controls, forgetting that trust is an emotion, not a
corporate governance strategy.
The Ghost
Vendor Illusion
The most common method of
extracting cash from a small business is the creation of a "ghost
vendor." The perpetrator sets up a fake entity in the accounting ERP,
often giving it a name that sounds suspiciously similar to a legitimate
supplier. For instance, if the company regularly buys from "Apex
Industrial Solutions," the fraudster might create a vendor named
"Apex Industries."
Once the ghost vendor is in the
system, the embezzler begins generating fabricated invoices for intangible
services or difficult-to-track consumables, like routine machinery maintenance,
packaging tape, or consulting fees. Because the fraudster also controls the
payment gateway, they simply approve the invoice and route the funds directly
into a proxy bank account. To avoid arousing the owner's suspicion, these
fraudulent invoices are carefully calibrated to fall just below the company's
mandatory management approval threshold or statutory tax deduction limits.
Skimming
and Phantom Payrolls
Beyond vendor fraud, payroll
manipulation is a highly lucrative avenue for embezzlement, especially in
businesses with a large blue-collar or contract workforce. The classic scheme
involves the "phantom employee." The accountant creates a fictitious
worker in the payroll system, or intentionally fails to remove a terminated
employee from the active roster. The salary is generated every month, but the
direct deposit routing number leads straight to an account controlled by the
fraudster.
In retail or cash-heavy
businesses, the threat shifts to skimming stealing cash before it is ever
recorded in the company’s ledger. An employee might process a cash refund for a
product that was never actually returned by a customer, pocketing the cash from
the register. Because the inventory system and the sales ledger are manipulated
simultaneously, the books appear to balance perfectly at the end of the day,
making the theft practically invisible to a traditional financial audit.
The
Camouflage of Circular Journal Entries
Fraudsters know that stealing the
money is only half the battle; the real challenge is hiding the theft so the
balance sheet still tallies at year-end. This is where manual journal entries
become a weapon of financial camouflage. Embezzlers use complex, multi-legged
journal vouchers to bury the missing cash in high-volume, low-scrutiny expense
accounts.
If an accountant steals cash from
the daily deposit, they might pass a manual journal entry debiting
"Miscellaneous Expenses," "Inventory Spoilage," or
"Customer Discounts," while crediting the cash ledger. To a casual
observer, the accounts balance. Traditional statutory audits, which often rely
on sampling and materiality thresholds, can easily gloss over these seemingly
routine write-offs. It requires a forensic mindset to question why a business
is suddenly writing off massive amounts of bad debt or experiencing
unprecedented inventory shrinkage.
[Visual
Guide: The Ghost Vendor Routing Mechanism]
- Phase 1: Infiltration
- ↳ Employee creates a fictitious supplier in
the ERP master data, matching it with a personal bank account.
- Phase 2: Extraction
- ↳ Fake invoices are generated for intangible
services, kept deliberately below management approval thresholds.
- Phase 3: Camouflage
- ↳ Payments are processed, and the fabricated
expense is buried within high-volume accounts like "Repairs" or
"Consumables."
A CA’s
Lens
For Chartered Accountants,
advising small businesses means we must actively look beyond the surface of a
perfectly balanced trial balance. We must transition from a purely statutory
mindset to a forensic one. During our audits, we need to leverage data analytics
to identify behavioral anomalies.
We should extract the entire
journal entry log and analyze the metadata. Are there manual journal entries
being posted at 2:00 AM on a Sunday? Are there multiple vendors sharing the
exact same bank account number as an employee on the payroll roster? Are there
sudden spikes in minor expenses just below the capitalization limit? We must
educate our MSME clients that our role is not just to file their taxes, but to
help them build a resilient financial architecture that protects their
hard-earned capital from internal bleeding.
Action
Checklist
- Enforce Mandatory Vacations:
Embezzlement requires constant maintenance to keep the illusion alive.
Force key financial personnel to take a consecutive two-week vacation;
frauds often unravel when someone else takes over their desk.
- Segregate Vendor Onboarding:
Never allow the person who processes payments to have the administrative
rights to add or modify vendor bank account details in the ERP system.
- Audit the Master Data: Run
an automated bi-annual check comparing the bank account numbers and IFSC
codes of all active vendors against the bank details of your employees.
- Review Manual Journal Entries:
Implement a strict policy where every manual journal entry over a certain
value requires the physical or digital countersignature of the business
owner.
- De-link Payroll and HR:
Ensure that the individual calculating the monthly payroll payouts is not
the same person authorized to add new employees to the Human Resources
master file.
- Conduct Surprise Reconciliations:
Have an external consultant or a non-accounting manager conduct
unannounced, random bank and petty cash reconciliations throughout the
financial year.
Closing
Insight
The true danger of employee
embezzlement is not just the immediate loss of capital; it is the silent
erosion of the company's competitive edge over time. A business hemorrhaging
cash from the inside cannot invest in new technology, hire top talent, or survive
economic downturns. For small business owners, the ultimate realization must be
that blind trust is a liability. True trust is built not through a lack of
oversight, but through the implementation of transparent, unbreakable internal
controls.
No comments:
Post a Comment